This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New computer - slow Firefox browser [Solved]

51 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

What a nuisance! :angry: :angry: :angry: To start Firefox takes a long time, but after that …. I can fix myself a cup of tea, by the time it takes to open another site. It's the same thing when I want to close.

Please give me a hand, before I go nuts! :pullhair:

********************************

OTL Extras logfile created on: 2012-10-16 12:13:16 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Annelie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7,95 Gb Total Physical Memory | 4,90 Gb Available Physical Memory | 61,67% Memory free
15,90 Gb Paging File | 12,51 Gb Available in Paging File | 78,71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,46 Gb Total Space | 754,62 Gb Free Space | 83,25% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 718,94 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
Drive E: | 24,76 Gb Total Space | 2,54 Gb Free Space | 10,25% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,47 Gb Free Space | 90,64% Space Free | Partition Type: FAT32

Computer Name: TERRA | User Name: Annelie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Porta.MakeAlbum] – "C:\Program Files (x86)\Porta\Porta.exe" "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Porta.MakeAlbum] – "C:\Program Files (x86)\Porta\Porta.exe" "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{009B62FC-353B-4C86-8C7A-72CEACEBBB88}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{0548BB01-C503-4973-9250-6E325C45D779}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{0625878C-8EAD-4D58-8137-9D7088F4DE19}" = rport=10243 | protocol=6 | dir=out | app=system |
"{1CDEE04E-38EB-40EF-A2AA-CD332E57BC44}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{297C7B3B-E74E-410D-9A6F-553E0758949C}" = lport=445 | protocol=6 | dir=in | app=system |
"{2B653E61-706A-48CA-ABE3-61A45CEDA448}" = lport=137 | protocol=17 | dir=in | app=system |
"{2B6E7DCF-872F-44F1-A266-FD6920FDBCE5}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5584D1EA-D123-4C65-8786-D60D10E62909}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{72FB0810-CA8B-48E8-BDB2-87EC48453286}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7B74A31E-C2CA-4B3D-B342-4D9AD95CAC4B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7CD0C65C-B120-42F9-80DF-26C26994B7E6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{88943DED-1982-4CFC-838C-8078BBE7DE51}" = lport=138 | protocol=17 | dir=in | app=system |
"{95530828-07F8-487F-BF40-5DB3A2AE3E05}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9C80421C-FF07-4F39-A46C-F9B54DE85217}" = rport=445 | protocol=6 | dir=out | app=system |
"{9FB62254-DE92-48F5-B112-622C5B875031}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AFD90E33-D5DA-487E-AD4C-82789B0D3F52}" = lport=139 | protocol=6 | dir=in | app=system |
"{B7966E91-9AF1-4A83-BA9B-7A84ECB46C3B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BE2A2A3B-923F-4429-84F8-B5AA40D0FD92}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DA49941A-4212-472D-9F3A-8979DD6EBAC9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E4726831-7EFB-4CC4-A17E-EF7C1B0B0DC7}" = rport=138 | protocol=17 | dir=out | app=system |
"{E533DAC9-845F-4455-9669-BDB8EFE87F78}" = rport=139 | protocol=6 | dir=out | app=system |
"{F2953A00-E034-42F2-8871-71302B994B5F}" = rport=137 | protocol=17 | dir=out | app=system |
"{F69FE8F6-B170-47A2-9881-FB769A04DDF8}" = lport=10243 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02C5D156-2ABD-4AEE-B4E0-A3D53CC293FD}" = dir=in | app=c:\program files (x86)\arcsoft\link+ 3\linkplus3.exe |
"{035AD0A3-4326-4867-A573-A063472B3D01}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0663E553-89CF-4489-847D-96B8D412352F}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe |
"{07B34451-DA5E-4877-B8BF-02EB0D58B90C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0B33F1B8-1BF3-486C-B57F-B4D401CCD3AC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0C646C81-CBE4-4011-B792-42B4BEAA323A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1D2AA0CC-5C3C-4C34-8CDF-1AF7A302E789}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe |
"{21CFDCCC-F4AF-4E4B-947E-169D49B62B6F}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe |
"{3303FC65-1814-4645-9305-EE2D933E6E4C}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{3E237FA7-686E-43C9-AD2A-8E7C7DF48140}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{3EF41637-FFD9-4305-8ECE-E80A204E7C3A}" = protocol=6 | dir=out | app=system |
"{41421D10-A1CD-44E9-8310-437D27C5A5A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4AA57CFC-3D10-4819-BFB5-4E3B45A83FF1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4EFF3A48-BA02-4DB6-82CD-5BA8E6DA0AB4}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{5076DECB-E990-4B58-B569-0F8DA4780CC2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{55F7385C-B8BA-4496-8D86-0A9FB18462D8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5686AF96-5789-41B0-BD74-74B57E52464E}" = dir=in | app=c:\program files (x86)\arcsoft\link+ 3\miuservice.exe |
"{5D1A987A-BC94-4589-87AF-6AC9AAD2D77A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5DEDAF19-4334-42B5-828A-E991AFBF31F7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{62FB5C63-45DD-4D26-A83C-97FA08438DD7}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe |
"{6842F20D-2303-4FC4-8B4C-2A6943EB4384}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6946848C-576B-4A9F-99CB-31756122481B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{69A21DA0-E5FC-4D2B-B337-493C3B42BF2A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E6FDF63-5AD7-455F-B40E-99C5C8CC09A7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{83C61D1C-2CD4-4A08-8C64-F915A69AF739}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{8DFE7210-0AB9-4039-BBF1-CB48755801FB}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{9201A210-CD1D-48DF-8EEF-D6A4BF391A36}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe |
"{9298EC02-6E7E-4842-99DB-87FABF649003}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97B6C337-4383-4B40-BE87-A0A35CD1074E}" = protocol=17 | dir=in | app=c:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe |
"{9DD498DC-9E85-46BC-B727-3B271F7A9160}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A3B5D57A-F3B7-42B5-88AF-3FF72D37CED8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B01BD979-B0BF-44C9-B009-A234866F321B}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B95857A3-8A56-486A-A018-BD3724750061}" = dir=in | app=c:\users\annelie\appdata\local\microsoft\skydrive\skydrive.exe |
"{BF0C3E74-02D0-452C-8476-C2966D63F72E}" = protocol=6 | dir=in | app=c:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe |
"{C1906042-EF71-45F1-8143-442D1D987B45}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C5B0472D-D1A5-401A-A787-CA7F7C37BDBA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{DDDB0DF5-3A1E-4002-B45A-AE5B272954AC}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe |
"{DDF53A28-46B5-4ADE-808C-4F5C2D4E08A7}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe |
"{E93699B6-DEF0-40F2-90D7-60942A7DDA74}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EA1A159E-6B09-4018-A5AA-A0DB98AB7CEF}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer.exe |
"{EA981EF5-16D9-46A6-8537-452073F81D15}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version7\teamviewer_service.exe |
"{EEC635C8-6569-483F-BA5B-A012C0CE9A3E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{F03FC597-F990-4251-964E-17536890BDC1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F55552BD-442A-46B6-9401-B2D34AA06B00}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{F74789C3-757E-4174-9167-D34E708CFD6F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{F9953378-A3BF-4FA0-9C01-FB02D27FF436}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{1276D662-3C26-4FA9-BE4E-024FD45D03BB}C:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{35C030CA-7E74-4209-B95B-2E55230F14A2}C:\users\annelie\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\annelie\appdata\roaming\spotify\spotify.exe |
"TCP Query User{92E0F43E-DA03-4892-9EE6-ABD3DF94EEEA}C:\program files\dreambox control center\dcc.exe" = protocol=6 | dir=in | app=c:\program files\dreambox control center\dcc.exe |
"TCP Query User{B7725079-ECCC-4F1B-9C14-0D53324633A2}C:\program files (x86)\dap\dap.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dap\dap.exe |
"UDP Query User{26E8EA14-C6F9-49C4-8FAC-A9F341E5B760}C:\users\annelie\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\annelie\appdata\roaming\spotify\spotify.exe |
"UDP Query User{A93EA4F8-8240-46DE-88B6-6AF57D672757}C:\program files\dreambox control center\dcc.exe" = protocol=17 | dir=in | app=c:\program files\dreambox control center\dcc.exe |
"UDP Query User{E46C5A6A-DC6F-46FB-A049-5C453F21568E}C:\program files (x86)\dap\dap.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dap\dap.exe |
"UDP Query User{F9F70B81-2ACC-4696-BF7B-6C52142E8680}C:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\annelie\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0DA20600-6130-443B-9D4B-F30520315FA6}" = Bonjour-utskriftstjänster
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP640_series" = Canon MP640 series MP Drivers
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1B93E2E2-EBE5-4D2A-AF2A-91C17CF31C25}" = RealWorld Icon Editor
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25FBDA9A-E868-4B3B-B9FF-D923818511A1}" = Intel® PROSet/Wireless WiFi Software
"{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit)
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel® Wireless Display
"{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4BC310C4-B898-46E2-B5FB-B85A30AA7142}" = iCloud
"{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5601F151-A69F-4E30-8C60-37928124CD07}" = HP 3D DriveGuard
"{57DD35E9-D9BB-4089-BB05-EF933C586CB3}" = Broadcom InConcert Maestro
"{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources
"{5A847522-375C-4D05-BD3D-88C450CC047F}" = HP Launch Box
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}" = Broadcom Bluetooth Software
"{72B48DB7-1C97-842F-2B25-55F40FA73E8E}" = ccc-utility64
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97E36D8D-CD1A-4DAB-BD18-0826F8A6AD78}" = Box Sync (64 bit)
"{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C2109862-4C52-C4C0-8E71-2EF3F2470CB0}" = AMD Catalyst Install Manager
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DC07D82B-CC00-4962-B541-8D5A80D0A48E}" = Microsoft Camera Codec Pack
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources
"{FB5688A1-05A2-4E9F-A5E7-872D71A6AAD6}" = DAP Plug-in for 64 Bit IE
"CCleaner" = CCleaner
"iid" = Net iD 5.6.2
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics ClickPad Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0012041D-78E1-11D2-B60F-006097C998E7}" = Microsoft FrontPage 2000
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9
"{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh
"{0125DB4D-98A0-4DBF-B68A-23BF08FFA6A3}" = Windows Live Messenger
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{075F2A5D-E1D6-50F7-47BC-255D55357F61}" = CCC Help Portuguese
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08523528-BA2F-43BB-87E3-252C081872B9}" = Catalyst Control Center - Branding
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
"{09F34EC2-935E-4214-B7E3-91EC39C8356A}" = ViewRanger Map Chooser
"{0A84393B-C09E-3184-A7D9-5A0D580B0CEB}" = Catalyst Control Center Profiles Mobile
"{0A918A9E-74F2-41CB-969F-FB0CB9A51DD8}" = Intel® Smart Connect Technology 1.0
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail
"{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh
"{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh
"{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{16B7BDA1-B967-4D2D-8B27-E12727C28350}" = HP CoolSense
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.7.2
"{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer
"{285F722C-0E45-47DE-B38E-5B3B10FA4A7C}" = HP Quick Launch
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2DB9F70A-7C32-42A7-9CB0-A56C76A75D94}" = ActivePrint System
"{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources
"{30B056AF-F414-4B68-B9B0-6EFDB9FCDF18}" = ArcSoft MediaImpression 2
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{33286280-8617-11E1-8FF6-B8AC6F97B88E}" = Google Earth Plug-in
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{363188E4-1A27-4DE6-BA48-823D2E205385}" = ArcSoft Scan-n-Stitch Deluxe
"{37530151-56A6-4CE4-9F9F-CE1F5A1356C6}" = ArcSoft Panorama Maker 4
"{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
"{39BDD209-5704-480C-9F4A-B69D0370DDBB}" = Windows Live Messenger
"{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh
"{3BFE1D0A-3F5B-CA85-CE7C-45CE319A9B67}" = CCC Help Hungarian
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40DA94AF-34B7-4BA7-A37F-26F899C031FF}" = ArcSoft PhotoStudio Darkroom 2
"{41B3BC57-AE8D-19F0-7776-04AE47AABB2F}" = PX Profile Update
"{423D8FBE-EC52-40FD-B2A0-8C9C8F973FD7}" = Microsoft Research AutoCollage 2008 version 1.1
"{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{451433B2-12F2-05A6-B5ED-B67B76493C25}" = CCC Help Chinese Traditional
"{4570FCDC-2BA6-4B29-70B0-4712211027C9}" = CCC Help Dutch
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
"{5036764A-435D-40C9-869C-31085A3D741D}" = HP Setup
"{53F45786-F5DE-9BF7-181F-410BED18299E}" = CCC Help Finnish
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5528E3E9-6C8F-0BD1-B099-0B5B48383917}" = JuiceboxBuilder-Lite
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{588E7010-AF5C-9233-514B-A3F48307F4F1}" = CCC Help Thai
"{5AA22838-7865-EBD2-FE1A-F8942E69A247}" = Catalyst Control Center
"{5B7F33B3-C72C-4408-8AF9-B855775F51DB}" = Picasa Web Albums Live Publisher
"{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{5EC71BC9-52DB-417C-807F-19E6381863E8}_is1" = Easy Watermark Studio version 3.4
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{62272BD6-5AB1-EE2A-8371-A09268FD32D3}" = CCC Help Japanese
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple-programstöd
"{64F5E5AD-66C3-437B-A620-4D07D3FCFB57}" = anysee-TCSeries
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{66AA87C9-2A10-C2E0-F59F-C613FB0C38CF}" = CCC Help Greek
"{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
"{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 3.3.0
"{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7257132D-7F65-41E6-A90F-43BF6099461A}" = Intel® WiDi
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources
"{74C0DEDD-7541-0837-7843-5F96C722152C}" = Catalyst Control Center Localization All
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78AE262D-4ED7-43C2-A0D6-C5535A421BAC}" = Intel Digital Logo
"{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
"{7B089009-DE77-0068-A3DB-B82EC2609A2F}" = CCC Help Czech
"{7D439C98-A9AC-4434-898D-21AD23636E03}" = HP Software Framework
"{7F6021AE-E688-4D03-843A-C2260482BA0D}" = Windows Live Messenger
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials
"{82FAC25D-D0E1-4D60-9268-F3DD958BF052}" = ArcSoft RAW Thumbnail Viewer
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85EB33CA-683D-2B2C-51A9-052DB5B8FF1D}" = CCC Help Swedish
"{883FC42F-0FF5-5209-F832-55E1B9064D59}" = Catalyst Control Center InstallProxy
"{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
"{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-041D-0000-0000000FF1CE}" = Compatibility Pack för Office 2007-systemet
"{90190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{90FD6C78-47B2-E9D2-C674-C8E7B8F1A3E7}" = CCC Help Polish
"{90FE9281-F7C4-D95F-5B0E-FD089C69CF24}" = CCC Help English
"{9112041D-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{97ADE6C2-363B-435E-A7AD-A79804081686}" = IncrediMail
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9EBE85AD-B155-3DC7-F5B6-E08F76245DEC}" = CCC Help Spanish
"{A0C8AF32-C6B8-08B9-0BC9-D8752EC16ACE}" = CCC Help Danish
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A40AE1FF-A9BF-0167-2C51-F1CE505B2DFC}" = CCC Help Chinese Standard
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.4) MUI
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B5948257-201E-7731-122F-FEA108166F34}" = CCC Help Norwegian
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B933B5D0-6937-4005-B354-B80B03F6974D}" = jAlbum
"{BAF0881C-77EC-1105-DAD3-8C71D260FC62}" = CCC Help Russian
"{BB4BA51A-667D-8EDD-1E04-37EB354E7039}" = CCC Help German
"{BE208C2E-A46A-426F-B2B8-CE8BEF9DB24D}" = HP Proximity Sensor Utility
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C86EDD05-3B5A-4145-96A2-E36C6C501480}" = Photo Notifier and Animation Creator
"{C8B44566-839A-459C-A73D-49764CE216CC}" = ArcSoft Video Downloader
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker
"{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common
"{CDFE9268-5C6C-41A9-A048-B0CAD9E8C039}" = anysee_FilterSDK
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEA63996-6C9E-D922-7FC8-465BBCCAAA75}" = CCC Help Turkish
"{CED24466-5389-4F15-9868-9145713851BB}" = HP Documentation
"{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
"{D3A15314-FF16-BB56-0D64-2691EE52D5AF}" = CCC Help Korean
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 ESD
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer
"{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker
"{DBCD5E64-7379-4648-9444-8A6558DCB614}" = Recovery Manager
"{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED01768-E634-11E1-AEB0-984BE15F174E}" = Evernote v. 4.5.8
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1268F35-5DBD-4630-BF33-3EB823062752}" = Simply Calenders v5.3
"{E217A3D4-2FF9-4D5F-9C20-1386E0FF9864}" = LogMeIn
"{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer
"{E2BCBC83-E08D-D581-A854-096968DE5245}" = CCC Help French
"{E2EE273D-E111-4FFD-ACD4-78E1D35E01D2}" = ArcSoft Photo Book Screen Saver
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E431A49E-6044-2581-C7BE-FF18BFCA422F}" = CCC Help Italian
"{E44578C7-4667-4124-8BC2-1161BCA54978}" = HP Power Manager
"{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer
"{E96CAA2A-0244-4A2A-8403-0C3C9534778B}" = ESU for Microsoft Windows 7 SP1
"{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{ED1BD69A-07E3-418C-91F1-D856582581BF}" = HP On Screen Display
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F03EC055-F34E-4F6B-A684-8A370E11A304}" = ArcSoft Print Creations
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Display Audio Driver
"{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
"{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help
"{F5E8F2E5-C406-4B57-A65B-AC1FDD788A19}" = Telia AutoStore
"{F694D1F7-1F12-4550-9B7A-C871273ABAD5}" = Windows Live Messenger
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3DPageFlip PDF to PowerPoint (freeware)_is1" = 3DPageFlip PDF to PowerPoint (freeware)
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Acoustica Photos Forever" = Acoustica Photos Forever
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Age Of Japan II_is1" = Age Of Japan II
"Age Of Japan_is1" = Age Of Japan
"AI RoboForm" = RoboForm 7-8-2-5 (All Users)
"anysee_Driver" = anysee Driver(2011.04.21,AD01061734) CNO 1.3.0 Uninstallation
"ArcSoft Link+" = ArcSoft Link+ 3
"Ashampoo Burning Studio 11_is1" = Ashampoo Burning Studio 11 v.11.0.4
"Ashampoo Gadge It_is1" = Ashampoo Gadge It v.1.0.1
"Ashampoo MyAutoplay Menu_is1" = Ashampoo MyAutoplay Menu 1.0.5
"Ashampoo Photo Commander 8_is1" = Ashampoo Photo Commander 8 v.8.5.0
"Ashampoo Photo Optimizer 4_is1" = Ashampoo Photo Optimizer 4 v.4.0.3
"Ashampoo Slideshow Studio HD 2_is1" = Ashampoo Slideshow Studio HD 2 2.0.5
"avast" = avast! Free Antivirus
"AVS Audio Converter_is1" = AVS Audio Converter 7
"AVS Audio Editor_is1" = AVS Audio Editor 7.1
"AVS Audio Recorder_is1" = AVS Audio Recorder version 4.0
"AVS Disc Creator_is1" = AVS Disc Creator 5
"AVS Document Converter_is1" = AVS Document Converter 2.2.3
"AVS DVD Copy_is1" = AVS DVD Copy 4.1.2.283
"AVS Image Converter_is1" = AVS Image Converter [removed]
"AVS Media Player_is1" = AVS Media Player [removed]
"AVS Photo Editor_is1" = AVS Photo Editor
"AVS Ringtone Maker 1.6_is1" = AVS Ringtone Maker version 1.6
"AVS Screen Capture_is1" = AVS Screen Capture version 2.0.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 6
"AVS Video Recorder_is1" = AVS Video Recorder 2.5
"AVS Video ReMaker_is1" = AVS Video ReMaker [removed]
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 7_is1" = AVS Video Converter 8
"AVSCoverEditor2_is1" = AVS Cover Editor [removed]
"AVSRegistryCleaner_is1" = AVS Registry Cleaner version 2.2
"Belltech Greeting Card Designer - Extra Templates_is1" = Belltech Greeting Card Designer - Extra Templates
"Belltech Greeting Card Designer 5.4.0_is1" = Belltech Greeting Card Designer 5.4.0
"Bookworm Deluxe 1.13" = Bookworm Deluxe 1.13
"BulletProof FTP Client 2009_is1" = BulletProof FTP Client 2009 (remove only)
"Canon MP640 series användarregistrering" = Canon MP640 series användarregistrering
"Canon RAW Codec" = Canon RAW Codec
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"DreamBoxEdit" = DreamBoxEdit – The one and only settings editor for your Dreambox
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"experience-hp-bundle" = TriDef 3D (HP) 1.0.6
"FontExpert 2010" = FontExpert 2010
"HP Photo Creations" = HP Photo Creations
"HP Wireless Audio Manager" = HP Wireless Audio Manager 1.0.8
"IconWorkshop" = Axialis IconWorkshop 6.0
"iid" = Net iD 5.6.2 (32-bit Edition)
"IncrediMail" = IncrediMail 2.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"JuiceboxBuilder-Lite" = JuiceboxBuilder-Lite
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"mediAvatar PowerPoint to Video Converter Personal" = mediAvatar PowerPoint to Video Converter Personal
"Mozilla Firefox 14.0.1 (x86 sv-SE)" = Mozilla Firefox 14.0.1 (x86 sv-SE)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"Personal" = BankID säkerhetsprogram 4.18.3
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"Picasa 3" = Picasa 3
"Porta" = Porta
"PremElem90" = Adobe Premiere Elements 9
"ProInst" = Intel PROSet Wireless
"Rainlendar2" = Rainlendar2 (remove only)
"Revo Uninstaller" = Revo Uninstaller 1.94
"RonyaSoft Poster Designer (Poster Forge)" = RonyaSoft Poster Designer (Poster Forge) 2.01
"RonyaSoft Poster Printer (ProPoster)" = RonyaSoft Poster Printer (ProPoster) 3.01
"ShapeCollage" = Shape Collage
"Spotify" = Spotify
"Sync Blocker 10.6 Release 1_is1" = Sync Blocker 10.6 Release 1
"TeamViewer 7" = TeamViewer 7
"WinLiveSuite" = Windows Live Essentials
"VLC media player" = VLC media player 2.0.3
"Wondershare DVD Slideshow Builder Deluxe_is1" = Wondershare DVD Slideshow Builder Deluxe(Build 6.1.8.54)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"ExpressFiles" = ExpressFiles
"SkyDriveSetup.exe" = Microsoft SkyDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2012-09-28 10:46:22 | Computer Name = Terra | Source = WinMgmt | ID = 10
Description =

Error - 2012-09-29 01:17:20 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-29 01:17:20 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-29 01:18:18 | Computer Name = Terra | Source = WinMgmt | ID = 10
Description =

Error - 2012-09-29 20:30:09 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-29 20:30:09 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-29 20:30:38 | Computer Name = Terra | Source = WinMgmt | ID = 10
Description =

Error - 2012-09-30 02:51:11 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-30 02:51:11 | Computer Name = Terra | Source = ISCT Agent | ID = 1003
Description =

Error - 2012-09-30 02:52:54 | Computer Name = Terra | Source = WinMgmt | ID = 10
Description =

[ HP Software Framework Events ]
Error - 2012-09-23 05:14:07 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-09-23 11:14:07.237|00002050|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-09-24 05:02:45 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-09-24 11:02:45.971|000021A8|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-09-24 05:02:53 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-09-24 11:02:53.648|00001448|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-09-24 05:03:01 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-09-24 11:03:01.511|00002180|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-09-24 05:03:05 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-09-24 11:03:05.442|00001504|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-10-01 05:32:16 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-10-01 11:32:16.296|000026B8|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-10-01 05:32:21 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-10-01 11:32:21.034|00002550|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-10-08 05:53:41 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-10-08 11:53:41.744|00001E50|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-10-08 05:53:45 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-10-08 11:53:45.905|00001AA8|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 2012-10-15 08:03:49 | Computer Name = Terra | Source = CaslWmi | ID = 5
Description = 2012-10-15 14:03:49.577|00000EF4|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

[ System Events ]
Error - 2012-10-13 17:59:18 | Computer Name = Terra | Source = Service Control Manager | ID = 7009
Description = En timeout (30000 ms) inträffade vid väntan på att tjänsten LogMeIn
Maintenance Service skulle ansluta.

Error - 2012-10-13 17:59:18 | Computer Name = Terra | Source = Service Control Manager | ID = 7000
Description = Tjänsten LogMeIn Maintenance Service kunde inte startas på grund av
följande fel: %%1053

Error - 2012-10-13 17:59:22 | Computer Name = Terra | Source = Service Control Manager | ID = 7011
Description = En timeout (30000 ms) inträffade vid väntan på transaktionssvar från
tjänsten HPWMISVC.

Error - 2012-10-14 10:13:43 | Computer Name = Terra | Source = Service Control Manager | ID = 7009
Description = En timeout (30000 ms) inträffade vid väntan på att tjänsten Cron Service
for Prey skulle ansluta.

Error - 2012-10-14 10:13:43 | Computer Name = Terra | Source = Service Control Manager | ID = 7000
Description = Tjänsten Cron Service for Prey kunde inte startas på grund av följande
fel: %%1053

Error - 2012-10-14 10:14:29 | Computer Name = Terra | Source = Service Control Manager | ID = 7009
Description = En timeout (30000 ms) inträffade vid väntan på att tjänsten LMIGuardianSvc
skulle ansluta.

Error - 2012-10-14 10:14:29 | Computer Name = Terra | Source = Service Control Manager | ID = 7000
Description = Tjänsten LMIGuardianSvc kunde inte startas på grund av följande fel:
%%1053

Error - 2012-10-14 10:14:53 | Computer Name = Terra | Source = Service Control Manager | ID = 7011
Description = En timeout (30000 ms) inträffade vid väntan på transaktionssvar från
tjänsten HPWMISVC.

Error - 2012-10-14 10:15:00 | Computer Name = Terra | Source = Service Control Manager | ID = 7009
Description = En timeout (30000 ms) inträffade vid väntan på att tjänsten LogMeIn
Maintenance Service skulle ansluta.

Error - 2012-10-14 10:15:00 | Computer Name = Terra | Source = Service Control Manager | ID = 7000
Description = Tjänsten LogMeIn Maintenance Service kunde inte startas på grund av
följande fel: %%1053


< End of report >

************************

OTL logfile created on: 2012-10-16 12:13:16 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Annelie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7,95 Gb Total Physical Memory | 4,90 Gb Available Physical Memory | 61,67% Memory free
15,90 Gb Paging File | 12,51 Gb Available in Paging File | 78,71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,46 Gb Total Space | 754,62 Gb Free Space | 83,25% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 718,94 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
Drive E: | 24,76 Gb Total Space | 2,54 Gb Free Space | 10,25% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,47 Gb Free Space | 90,64% Space Free | Partition Type: FAT32

Computer Name: TERRA | User Name: Annelie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Annelie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Personal\bin\Personal.exe (Technology Nexus AB)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe (Hewlett Packard)
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
PRC - C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_sv_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\CustomControls.dll ()
MOD - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNOPlugIns.DLL ()
MOD - C:\Program Files (x86)\anysee\anysee-TCSeries\RemoteAPI.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_sv_b77a5c561934e089\mscorlib.resources.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (#UpdateService) – C:\Program\Box Sync\UpdateService.exe (Box, Inc.)
SRV - (TeamViewer7) – C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (avast! Antivirus) – C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ADExchange) – C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
SRV - (HPPRXSVC) – C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (ISCTAgent) – C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
SRV - (AMPPALR3) – C:\Program\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV - (btwdins) – C:\Program\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (STacSV) – C:\Program\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (EvtEng) – C:\Program\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (MyWiFiDHCPDNS) – C:\Program\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) – C:\Program\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (BTHSSecurityMgr) – C:\Program\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (CLKMSVC10_38F51D56) – C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (CronService) – C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (wlcrasvc) – C:\Program\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AutoStore) – C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe (Storegate AB)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Program\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (teamviewervpn) – C:\Windows\SysNative\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ISCT) – C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV:64bit: - (bcbtums) – C:\Windows\SysNative\drivers\bcbtums.sys (Broadcom Corporation.)
DRV:64bit: - (BTWDPAN) – C:\Windows\SysNative\drivers\btwdpan.sys (Broadcom Corporation.)
DRV:64bit: - (btwampfl) – C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (iwdbus) – C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (intaud_WaveExtensible) – C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (AMTBDA_P861F) – C:\Windows\SysNative\drivers\anyseeTU.SYS (Windows ® Win 7 DDK provider)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/11
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/11
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://isearch.babylon.com/?q={searchTerms…0001a34516924f9
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE - HKCU\..\SearchScopes\{56E6E967-99CE-49AA-BEFA-D546A9FC620C}: "URL" = http://www.google.com/search?hl=sv&q;={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?source=gama&hl;=sv"
FF - prefs.js..extensions.enabledAddons: [removed]:1.6.2
FF - prefs.js..extensions.enabledAddons: [removed]:1.2
FF - prefs.js..extensions.enabledAddons: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:1.8.1
FF - prefs.js..extensions.enabledAddons: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledAddons: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.3
FF - prefs.js..extensions.enabledAddons: {ad48108d-92a6-4eb9-87e4-978aca1dbae4}:1.2.1
FF - prefs.js..extensions.enabledAddons: {d37dc5d0-431d-44e5-8c91-49419370caa1}:3.1.26
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:6.2.0.10687
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1466
FF - prefs.js..extensions.enabledAddons: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.2.2
FF - prefs.js..extensions.enabledAddons: {37fa1426-b82d-11db-8314-0800200c9a66}:2.9.13
FF - prefs.js..extensions.enabledAddons: [removed]:1.0.1004
FF - prefs.js..extensions.enabledAddons: {b64982b1-d112-42b5-b1e4-d3867c4533f8}:2.3.787.43
FF - prefs.js..extensions.enabledAddons: [removed]:1.4
FF - prefs.js..extensions.enabledAddons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:14.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-09-07 18:41:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2012-09-08 20:45:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2012-09-08 20:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2012-09-09 11:57:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-10-03 23:45:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012-09-22 13:40:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files (x86)\DAP\DAPFireFox [2012-09-09 21:01:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012-10-11 04:41:59 | 000,000,000 | —D | M]

[2012-09-07 17:20:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Extensions
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Flagfox) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2012-10-07 23:48:16 | 000,000,000 | —D | M] (Integrated Gmail) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2012-10-10 00:28:38 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2012-10-03 22:58:31 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (Capriza Highlighter) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-13 15:55:22 | 000,000,000 | —D | M] (Movable Firefox Button) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Stream Photo Collector) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 20:54:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions
[2012-10-03 20:54:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions\[removed]
[2012-10-13 15:55:22 | 000,003,323 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 22:52:57 | 000,330,316 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,031,657 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 23:04:16 | 000,107,457 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-07 23:48:15 | 000,318,404 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi
[2012-10-09 23:48:17 | 000,196,700 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
[2012-10-03 23:00:02 | 000,049,607 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
[2012-10-03 22:56:01 | 000,058,343 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}.xpi
[2012-10-03 23:00:51 | 000,269,659 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2012-10-03 21:19:09 | 000,292,116 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{ad48108d-92a6-4eb9-87e4-978aca1dbae4}.xpi
[2012-10-03 23:45:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\mozilla firefox\extensions
[2012-09-09 16:41:47 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-10-03 23:45:06 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012-09-07 18:41:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012-10-11 04:41:59 | 000,000,000 | —D | M] (Browser Manager) – C:\PROGRAMDATA\BROWSER MANAGER\2.3.787.43\{16CDFF19-861D-48E3-A751-D99A27784753}\FIREFOXEXTENSION
[2012-07-14 02:15:45 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012-03-07 13:28:56 | 000,244,544 | —- | M] (SecMaker AB) – C:\Program Files (x86)\mozilla firefox\plugins\npiidplg.dll
[2012-07-14 03:16:10 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2012-09-23 18:51:09 | 000,002,362 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-07-14 03:16:10 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012-07-14 03:16:10 | 000,003,368 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2012-07-14 03:16:10 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2012-07-14 03:16:10 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~2\ArcSoft\VIDEOD~1\ARCURL~1.DLL (ArcSoft, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BoxSyncHelper] C:\Program Files\Box Sync\BoxSyncHelper.exe (Box, Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Net iD] C:\Program Files\Net iD\iid.exe (SecMaker AB)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SetDefault] C:\Program\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [anysee CNO] C:\Program Files (x86)\anysee\Driver\CNO.EXE ()
O4 - HKLM..\Run: [anysee_TR] C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Net iD] C:\Program Files (x86)\Net iD\iid.exe (SecMaker AB)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}] C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8:64bit: - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8:64bit: - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8:64bit: - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8:64bit: - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9:64bit: - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-06-25 12:42:32 | 000,000,090 | —- | M] () - H:\AUTORUN.INF – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012-10-16 11:55:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 10:57:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{5D265361-FF3C-4189-A00D-271475F09B21}
[2012-10-15 20:30:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Apple Computer
[2012-10-15 15:48:02 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FCCBC759-B42A-4616-BD4D-3659ABC701EB}
[2012-10-15 13:53:40 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-enheter
[2012-10-14 16:28:12 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E20545B1-713E-42F9-A4C3-A1F0D699629E}
[2012-10-14 00:27:32 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ArcSoft
[2012-10-13 23:59:55 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Broadcom
[2012-10-13 23:59:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ATI
[2012-10-13 23:58:10 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Adobe
[2012-10-13 23:55:27 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Box Sync
[2012-10-13 17:21:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C0C090EB-A23A-4BF9-A1D8-F8A5386A8A8A}
[2012-10-13 05:20:52 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{72885B53-526B-4BFB-AC4F-E25F507D3700}
[2012-10-12 17:20:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FAE6970D-A62C-47C4-8264-5E5D3B6C943D}
[2012-10-11 17:01:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{73CAAC98-3D7C-46E6-B408-D15C7ABE0459}
[2012-10-11 05:00:42 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{88075DDB-E0D2-43C5-B7A1-6C2B58B8F53F}
[2012-10-10 08:10:37 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{83A549E5-8671-492E-BAB7-9D1938414656}
[2012-10-10 08:08:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012-10-10 08:08:39 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012-10-10 08:08:39 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012-10-10 08:08:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012-10-10 08:08:32 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012-10-10 08:08:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012-10-10 08:08:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012-10-10 08:08:31 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012-10-10 08:08:31 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012-10-10 08:08:31 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012-10-10 08:08:31 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012-10-10 08:08:31 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012-10-10 08:08:31 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012-10-10 08:08:31 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012-10-10 08:08:31 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012-10-10 08:08:31 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:30 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:29 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:27 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:27 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012-10-10 08:08:18 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012-10-10 08:07:46 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012-10-10 08:07:45 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012-10-09 13:29:21 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E858F3C5-DFEE-4555-BF8D-DB8F97ABF686}
[2012-10-09 01:28:58 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{04E091C2-3C96-4F67-8705-2502CEC7F7A5}
[2012-10-08 13:15:57 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{1DB5DB8D-DD8D-438A-827A-1CB5BE941881}
[2012-10-07 17:29:25 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6FF32FBD-70E4-460A-BF95-365B9BB04BB7}
[2012-10-07 00:27:56 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EA4A31EE-D720-472E-86FD-48DD64D8B1BF}
[2012-10-06 21:32:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Microsoft Games
[2012-10-06 19:49:56 | 000,000,000 | —D | C] – C:\ProgramData\CNO
[2012-10-06 19:46:38 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2012-10-06 19:46:38 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2012-10-06 19:46:32 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,091,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2012-10-06 19:46:32 | 000,068,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2012-10-06 19:46:32 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2012-10-06 19:46:32 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2012-10-06 19:46:31 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2012-10-06 19:46:31 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2012-10-06 19:46:29 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2012-10-06 19:46:29 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2012-10-06 19:46:28 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2012-10-06 19:46:28 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2012-10-06 19:46:27 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2012-10-06 19:46:27 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2012-10-06 19:46:25 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2012-10-06 19:46:25 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2012-10-06 19:46:22 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2012-10-06 19:46:22 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2012-10-06 19:46:17 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2012-10-06 19:46:17 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2012-10-06 19:46:16 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2012-10-06 19:46:16 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2012-10-06 19:46:15 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2012-10-06 19:46:15 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2012-10-06 19:46:15 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2012-10-06 19:46:15 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2012-10-06 19:46:13 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2012-10-06 19:46:13 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2012-10-06 19:46:13 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2012-10-06 19:46:13 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2012-10-06 19:46:12 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2012-10-06 19:46:12 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2012-10-06 19:46:12 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2012-10-06 19:46:12 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2012-10-06 19:45:18 | 000,000,000 | —D | C] – C:\Program Files\anysee
[2012-10-06 19:45:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anysee
[2012-10-06 19:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\anysee
[2012-10-06 18:05:19 | 000,000,000 | —D | C] – C:\Program Files\PlayReady
[2012-10-06 15:58:47 | 006,949,596 | —- | C] (Transcend Information Inc.) – C:\Windows\TranscendElite.exe
[2012-10-06 12:26:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE4EF6C4-BBC0-431D-83C5-C951A22E7064}
[2012-10-05 20:03:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{0616A02C-F253-4398-BC7D-74158EEACCDB}
[2012-10-05 18:42:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\vlc
[2012-10-05 18:41:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012-10-05 18:41:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2012-10-05 08:03:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{22F04A30-B228-42E1-9EDD-16EF8340B850}
[2012-10-04 15:38:53 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{BF4DB9ED-FCE8-4179-A695-6C949032B11D}
[2012-10-03 15:20:32 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Skrivare
[2012-10-03 15:13:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Windowstema
[2012-10-03 15:03:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series användarregistrering
[2012-10-03 15:01:55 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2012-10-03 14:59:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CD-LabelPrint
[2012-10-03 14:57:22 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-10-03 14:56:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series Manual
[2012-10-03 14:56:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series
[2012-10-03 14:56:14 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2012-10-03 14:55:27 | 000,336,896 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6PPM.DLL
[2012-10-03 14:55:27 | 000,144,384 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6UI.DLL
[2012-10-03 14:55:27 | 000,000,000 | —D | C] – C:\Windows\SysNative\STRING
[2012-10-03 14:55:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\CHM
[2012-10-03 12:33:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{4E194997-6236-473A-B619-25402D855A22}
[2012-10-02 13:03:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CA10A3F4-6E0C-4D5B-91AE-5CCAAEB8773E}
[2012-09-30 20:26:50 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012-09-30 19:55:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012-09-30 19:46:04 | 000,916,456 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:46:03 | 001,034,216 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:46:03 | 000,289,768 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:52 | 000,189,416 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:52 | 000,188,904 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-30 19:45:52 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:42 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012-09-30 16:37:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C8BF6A71-0870-47F4-9284-46C843ACA4E0}
[2012-09-30 01:40:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\CoSoSys
[2012-09-29 19:59:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6D457595-7AC5-4833-8E71-2E100597B4EC}
[2012-09-29 07:37:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{F2A0CF81-187B-46A0-A0D2-DD474F6079AD}
[2012-09-28 16:34:27 | 000,000,000 | —D | C] – C:\Windows\pss
[2012-09-28 14:36:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{90AFE95C-87F7-4163-8AFB-0C0AD93B5514}
[2012-09-27 13:03:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EB89FCB8-ACC7-41A5-B4F6-AB0FDD5BEF72}
[2012-09-26 23:04:38 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9A56696E-98C4-4132-B334-0096DE526580}
[2012-09-26 11:04:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D29C45A3-349E-4383-8CA5-83D76031C5C7}
[2012-09-26 10:25:26 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2012-09-25 23:03:51 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{149ABCCC-072B-48EC-967F-5E8AD0B61E14}
[2012-09-25 11:36:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012-09-25 11:03:40 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{2EF7B70F-7186-4A20-A98C-4A17B06D6CD5}
[2012-09-24 23:03:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{79F8482C-8295-4215-80CB-4BF8263BEEC0}
[2012-09-24 11:03:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9B8FAAC8-B88E-4EC8-A899-A2F6CEFAA5FA}
[2012-09-23 21:54:41 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6F949E0A-A0C7-4F2F-9A11-3E1B15275648}
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jAlbum
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\jAlbum
[2012-09-23 18:51:18 | 000,000,000 | —D | C] – C:\Users\Annelie\Start Menu
[2012-09-23 18:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012-09-23 09:54:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{B58A0859-5EFE-492F-845C-90007BCCDA76}
[2012-09-22 19:45:28 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prey
[2012-09-22 19:45:25 | 000,000,000 | —D | C] – C:\Prey
[2012-09-22 19:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012-09-22 16:56:11 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012-09-22 16:56:09 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012-09-22 16:56:08 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012-09-22 16:56:08 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012-09-22 16:56:08 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012-09-22 16:56:08 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012-09-22 16:56:08 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012-09-22 16:56:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012-09-22 16:56:05 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012-09-22 16:56:05 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012-09-22 16:56:05 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012-09-22 16:56:05 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012-09-22 16:56:03 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012-09-22 16:56:03 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012-09-22 16:56:03 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012-09-22 16:41:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\ExpressFiles
[2012-09-22 15:46:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\mediAvatar
[2012-09-22 15:46:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint to Video Converter Personal
[2012-09-22 15:44:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerPoint to Video Converter Personal
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\ProgramData\mediAvatar
[2012-09-22 15:35:15 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Babylon
[2012-09-22 15:35:15 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2012-09-22 15:35:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\ExpressFiles
[2012-09-22 15:19:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sync Blocker
[2012-09-22 15:19:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sync Blocker 10.6 Release 1
[2012-09-22 14:18:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\U3
[2012-09-22 13:40:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net iD
[2012-09-22 13:40:13 | 000,000,000 | —D | C] – C:\Program Files\Net iD
[2012-09-22 13:40:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Net iD
[2012-09-22 13:40:01 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\iid
[2012-09-22 12:32:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE3FC8FC-7AAC-47FA-9379-4930B3CDD718}
[2012-09-22 12:22:22 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\JuiceboxBuilder-Lite
[2012-09-22 12:22:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\JuiceboxBuilder-Lite
[2012-09-21 19:32:59 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{50C56335-D16F-4BC7-AB80-4054189A1C8D}
[2012-09-21 12:18:06 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\Facebook
[2012-09-21 11:57:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Hjälpredor
[2012-09-21 07:32:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3CEB44EE-BF26-42A3-9D83-BF9DC84E5475}
[2012-09-20 19:38:26 | 000,000,000 | —D | C] – C:\Users\Annelie\.rainlendar2
[2012-09-20 19:38:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2
[2012-09-20 19:38:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rainlendar2
[2012-09-20 18:42:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2012-09-20 18:40:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-09-20 18:40:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012-09-20 11:04:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE7A18BB-8103-4E54-AB62-30FB89E8B683}
[2012-09-19 23:04:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3375645B-1B73-4B95-814B-36CB8A9CB377}
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BulletProof FTP Client 2009
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\BulletProof FTP Client 2009
[2012-09-19 11:04:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D6FF1E5D-CB1B-4F4F-94E2-C1A316A86B39}
[2012-09-18 23:22:26 | 000,000,000 | —D | C] – C:\Users\Annelie\Datamapp
[2012-09-18 23:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\IncrediMail
[2012-09-18 18:37:43 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\IM
[2012-09-18 18:06:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jasc Software Inc
[2012-09-18 18:03:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jasc Software
[2012-09-18 18:03:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Paint Shop Pro
[2012-09-18 13:38:32 | 000,000,000 | —D | C] – C:\ProgramData\Photo Notifier and Animation Creator
[2012-09-18 13:38:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photo Notifier and Animation Creator
[2012-09-18 13:38:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail
[2012-09-18 13:38:01 | 000,000,000 | —D | C] – C:\ProgramData\IncrediMail
[2012-09-18 13:38:01 | 000,000,000 | —D | C] – C:\ProgramData\IM
[2012-09-18 13:32:23 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{7BAED964-D3F6-47D4-AA1F-779CC2AAC060}
[2012-09-18 12:52:36 | 000,000,000 | —D | C] – C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
[2012-09-17 21:13:31 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C623E18B-0713-4B04-B8A8-550F599CE7FB}
[2012-09-17 14:25:45 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Jasc
[2012-09-17 09:13:08 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9C22ECD0-91C0-4F54-AB00-820D8706A844}
[2012-09-17 00:23:32 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2012-09-16 21:12:45 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{F6CD76A0-7DB4-4F98-AAEA-8B175398DE5D}
[2012-09-16 15:38:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012-09-16 15:38:53 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2012-09-16 15:30:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\3DPageFlip PDF to PowerPoint
[2012-09-16 15:30:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3DPageFlip PDF to PowerPoint (freeware)
[2012-09-16 15:29:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour-utskriftstjänster
[2012-09-16 15:29:13 | 000,000,000 | —D | C] – C:\Program Files\Bonjour Print Services
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-10-16 12:11:15 | 000,000,868 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-16 12:00:33 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-16 12:00:33 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-16 11:55:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 11:52:11 | 000,000,029 | —- | M] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-10-16 11:50:10 | 000,000,996 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-16 11:34:10 | 000,000,342 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012-10-16 11:13:04 | 000,275,287 | —- | M] () – C:\Users\Annelie\Desktop\WtT01.png
[2012-10-16 07:40:40 | 000,000,992 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-16 07:39:27 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAnnelie.job
[2012-10-16 07:39:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-10-16 07:38:46 | 2106,478,591 | -HS- | M] () – C:\hiberfil.sys
[2012-10-13 15:59:17 | 001,573,176 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012-10-13 15:59:17 | 000,661,744 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2012-10-13 15:59:17 | 000,652,148 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012-10-13 15:59:17 | 000,141,514 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2012-10-13 15:59:17 | 000,121,080 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012-10-09 17:11:18 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012-10-09 17:11:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012-10-07 01:51:19 | 000,127,519 | —- | M] () – C:\Users\Annelie\Desktop\Mail 4.png
[2012-10-07 01:48:46 | 000,133,156 | —- | M] () – C:\Users\Annelie\Desktop\Mail 3.png
[2012-10-07 01:07:03 | 000,125,502 | —- | M] () – C:\Users\Annelie\Desktop\Mail 2.png
[2012-10-07 01:05:21 | 000,111,822 | —- | M] () – C:\Users\Annelie\Desktop\Mail 1.png
[2012-10-06 19:59:49 | 000,471,768 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012-10-05 18:41:34 | 000,000,027 | —- | M] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | M] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:11 | 001,613,970 | —- | M] () – C:\Users\Annelie\Documents\Firefox.png
[2012-10-03 07:12:23 | 000,000,181 | —- | M] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-30 19:45:46 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:44 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:45:44 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:45:44 | 000,289,768 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:44 | 000,189,416 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:44 | 000,188,904 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-29 19:58:22 | 000,000,141 | —- | M] () – C:\Users\Annelie\Desktop\Paypal.URL
[2012-09-27 23:32:19 | 000,001,264 | —- | M] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-27 23:03:38 | 000,000,286 | —- | M] () – C:\Windows\reimage.ini
[2012-09-23 18:51:13 | 000,000,622 | —- | M] () – C:\user.js
[2012-09-19 20:17:49 | 000,000,524 | —- | M] () – C:\Users\Annelie\Desktop\Dold.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-10-16 11:13:04 | 000,275,287 | —- | C] () – C:\Users\Annelie\Desktop\WtT01.png
[2012-10-07 01:03:35 | 000,127,519 | —- | C] () – C:\Users\Annelie\Desktop\Mail 4.png
[2012-10-07 01:01:14 | 000,133,156 | —- | C] () – C:\Users\Annelie\Desktop\Mail 3.png
[2012-10-07 00:58:19 | 000,125,502 | —- | C] () – C:\Users\Annelie\Desktop\Mail 2.png
[2012-10-07 00:54:16 | 000,111,822 | —- | C] () – C:\Users\Annelie\Desktop\Mail 1.png
[2012-10-05 18:41:34 | 000,000,027 | —- | C] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | C] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:10 | 001,613,970 | —- | C] () – C:\Users\Annelie\Documents\Firefox.png
[2012-09-29 12:28:49 | 000,000,181 | —- | C] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-27 23:32:19 | 000,001,264 | —- | C] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-22 19:52:21 | 000,000,029 | —- | C] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-09-22 19:34:42 | 000,000,996 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-09-22 19:34:41 | 000,000,992 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-09-22 15:35:25 | 000,000,622 | —- | C] () – C:\user.js
[2012-09-22 12:22:21 | 000,001,014 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JuiceboxBuilder-Lite.lnk
[2012-09-19 20:17:49 | 000,000,524 | —- | C] () – C:\Users\Annelie\Desktop\Dold.lnk
[2012-09-18 18:37:14 | 000,002,036 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail.lnk
[2012-09-09 20:42:30 | 000,109,216 | —- | C] () – C:\Windows\SysWow64\EasyHook64.dll
[2012-09-09 20:42:30 | 000,084,480 | —- | C] () – C:\Windows\SysWow64\EasyHook32.dll
[2012-09-09 20:25:16 | 000,000,286 | —- | C] () – C:\Windows\reimage.ini
[2012-09-08 12:08:16 | 000,000,722 | —- | C] () – C:\Windows\ODBC.INI
[2012-09-08 02:09:38 | 000,007,609 | —- | C] () – C:\Users\Annelie\AppData\Local\Resmon.ResmonCfg
[2012-04-07 04:38:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012-04-07 04:28:35 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2012-04-07 04:26:31 | 003,241,866 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011-10-02 07:16:48 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011-09-21 09:07:02 | 004,409,072 | —- | C] () – C:\Windows\SysWow64\vspdfx.dll
[2011-08-09 18:30:04 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011-08-09 18:30:02 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011-08-09 18:30:02 | 000,216,000 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011-08-09 18:23:26 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2011-08-09 17:58:38 | 013,903,872 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011-03-17 23:51:46 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012-06-09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012-06-09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009-07-14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010-11-21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009-07-14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012-09-08 20:30:09 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Acoustica
[2012-09-09 13:50:34 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Age of Japan II
[2012-09-08 22:36:57 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Ashampoo
[2012-09-08 22:01:48 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Ashampoo Slideshow Studio HD 2
[2012-09-08 23:03:23 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Axialis
[2012-09-22 15:35:15 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Babylon
[2012-09-15 22:05:08 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Box Desktop
[2012-10-16 11:39:44 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Box Sync
[2012-09-25 11:36:33 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012-09-30 01:40:05 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\CoSoSys
[2012-10-16 11:54:13 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Dropbox
[2012-09-10 22:07:01 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Easy Watermark Studio
[2012-09-22 15:35:15 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\ExpressFiles
[2012-07-15 08:16:22 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\IDT
[2012-09-22 13:40:10 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\iid
[2012-09-08 23:30:09 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\jAlbum
[2012-09-17 14:25:45 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Jasc
[2012-09-12 16:09:05 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\libimobiledevice
[2012-09-12 16:08:54 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\log
[2012-09-22 15:46:29 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mediAvatar
[2012-09-09 14:45:43 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Obsidium
[2012-09-08 14:37:03 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\PearlMountain
[2012-09-09 14:56:19 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Personal
[2012-09-09 14:25:22 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Pocket Watch, LLC
[2012-09-09 14:45:07 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Proxima Software
[2012-09-09 17:38:44 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\RoboForm
[2012-09-09 01:41:48 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Skerryvore Software
[2012-09-09 22:28:02 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Solveig Multimedia
[2012-09-09 19:19:11 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Spotify
[2012-07-15 05:41:26 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Synaptics
[2012-09-09 01:34:18 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Visan
[2012-07-15 05:42:47 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\WebApp
[2012-09-10 14:20:30 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011-10-25 02:10:43 | 000,003,783 | —- | M] () MD5=492CBE676A49756494ABAD49712DD36C – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_64117362cc347f06\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009-06-10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.BMP >
[2012-09-09 21:01:41 | 000,005,264 | —- | M] () MD5=0EF744B1DC357FDE44C78536A8108659 – C:\Program Files (x86)\DAP\Skins\dap\Explorer.bmp

< MD5 for: EXPLORER.EXE >
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010-11-21 05:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010-11-21 05:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2011-10-25 02:10:23 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\SysWOW64\sv-SE\explorer.exe.mui
[2011-10-25 02:10:23 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_5158254009e19998\explorer.exe.mui
[2011-10-25 02:10:31 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\sv-SE\explorer.exe.mui
[2011-10-25 02:10:31 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_47037aedd580d79d\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012-10-16 12:12:20 | 000,031,360 | —- | M] () MD5=BB647E558AFF81FC110F3222640E686B – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2012-06-29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012-08-24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012-08-24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012-08-24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012-06-29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012-08-24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010-11-21 05:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011-10-25 02:49:46 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012-06-29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2010-11-21 05:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012-06-29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011-10-25 02:49:46 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Program Files\Internet Explorer\fi-FI\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_a5e791a3ad57af35\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Program Files (x86)\Internet Explorer\da-DK\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_6b396f2ffbc32d02\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Program Files (x86)\Internet Explorer\fi-FI\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_b03c3bf5e1b87130\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Program Files (x86)\Internet Explorer\nb-NO\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_cc22808574537f93\iexplore.exe.mui
[2011-10-25 02:10:44 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=818C0D82C249F80EDB0C6FA5F06859F4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_f05f40a0bb42917b\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Program Files (x86)\Internet Explorer\sv-SE\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_f671dc8e34a59363\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Program Files\Internet Explorer\da-DK\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_60e4c4ddc7626b07\iexplore.exe.mui
[2009-07-14 04:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Program Files\Internet Explorer\nb-NO\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_c1cdd6333ff2bd98\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Program Files\Internet Explorer\sv-SE\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_ec1d323c0044d168\iexplore.exe.mui
[2009-07-14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
[2011-10-25 02:10:44 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FCF681AEB95697B5E01832E11732A6CD – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_fab3eaf2efa35376\iexplore.exe.mui

< MD5 for: SERVICES >
[2012-09-11 21:37:51 | 000,271,966 | —- | M] () MD5=8BF884798E42CC785003876297E9D33F – C:\Kanaler\services
[2012-07-27 21:01:14 | 000,271,966 | —- | M] () MD5=8BF884798E42CC785003876297E9D33F – C:\Users\Annelie\Dropbox\TV\Kanaler\services
[2009-06-10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012-07-27 22:52:04 | 000,002,637 | —- | M] () MD5=016DFC4F3F133AE19338EECD1924886A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2012-07-27 22:52:04 | 000,002,970 | —- | M] () MD5=05A68D76420994EF8DF33184BFA98E04 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2012-07-27 22:51:54 | 000,002,555 | —- | M] () MD5=272301585AC133486E70228DA27659AC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2012-07-27 22:51:50 | 000,002,562 | —- | M] () MD5=27CE9BD3209B549BB776B8C877455A91 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2012-07-27 22:51:52 | 000,002,632 | —- | M] () MD5=2998A4AE8D0EF5122CCB985CF7E9D9D3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2012-07-27 22:51:52 | 000,002,545 | —- | M] () MD5=2EEC9DDBD0B4EE5F65532322C383938A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,629 | —- | M] () MD5=3A0082D76426A87FB4937D426C491C10 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2012-07-27 22:51:58 | 000,002,590 | —- | M] () MD5=448953BD0CF26CE03D9E7CC1A7B278BC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2012-07-27 22:51:42 | 000,002,605 | —- | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,679 | —- | M] () MD5=5DD2704563A6A79C466E44CD966B2655 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2012-07-27 22:51:40 | 000,002,711 | —- | M] () MD5=6B0E7B068BD530B8FCEBC04CC8844AA9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012-07-27 22:52:02 | 000,002,582 | —- | M] () MD5=797FC263D59784AD1498560C34FA7DA1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2012-07-27 22:51:38 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2012-07-27 22:51:50 | 000,002,634 | —- | M] () MD5=912DD5C0C7C8D7572AD598414D56E24A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx
[2012-07-27 22:51:40 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2012-07-27 22:52:06 | 000,002,638 | —- | M] () MD5=C2C37202B0E55877A64ADDBDE738284E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,589 | —- | M] () MD5=C313AD3602D4965A1918E86B9F3E84CF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2012-07-27 22:52:06 | 000,002,609 | —- | M] () MD5=C7FA88C21103C70826F274A0E865AEDF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2012-07-27 22:52:08 | 000,002,576 | —- | M] () MD5=D27D52045EB6A2EE031F7D2EA0349BC3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2012-07-27 22:51:46 | 000,002,560 | —- | M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2012-07-27 22:52:00 | 000,002,588 | —- | M] () MD5=DB216743CDE75637621E2FD39431BBD4 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2012-07-27 22:51:44 | 000,002,620 | —- | M] () MD5=DCF7A8843832327386B81ABD189AC236 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2012-07-27 22:52:00 | 000,002,997 | —- | M] () MD5=DD3F4DAF426555D8D85FF4D7C5A04F37 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2010-11-16 06:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2012-07-27 22:51:48 | 000,002,599 | —- | M] () MD5=F09D769A94767C3C7E7015A5C6C99A39 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2012-07-27 22:51:46 | 000,002,628 | —- | M] () MD5=F844D742DB53C7D671BF7ED6517414D1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2012-07-27 22:51:44 | 000,002,582 | —- | M] () MD5=FED4BDA3B6A9EB9DB59C254D8C987495 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx

< MD5 for: SERVICES.ASFX1 >
[2010-11-16 06:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1

< MD5 for: SERVICES.ASFX10 >
[2010-11-16 06:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10

< MD5 for: SERVICES.ASFX11 >
[2010-11-16 06:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11

< MD5 for: SERVICES.ASFX12 >
[2010-11-16 06:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12

< MD5 for: SERVICES.ASFX13 >
[2010-11-16 06:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13

< MD5 for: SERVICES.ASFX14 >
[2010-11-16 06:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14

< MD5 for: SERVICES.ASFX15 >
[2010-11-16 06:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15

< MD5 for: SERVICES.ASFX16 >
[2010-11-16 06:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16

< MD5 for: SERVICES.ASFX17 >
[2010-11-16 06:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17

< MD5 for: SERVICES.ASFX18 >
[2010-11-16 06:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18

< MD5 for: SERVICES.ASFX19 >
[2010-11-16 06:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19

< MD5 for: SERVICES.ASFX2 >
[2010-11-16 06:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2

< MD5 for: SERVICES.ASFX20 >
[2010-11-16 06:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20

< MD5 for: SERVICES.ASFX21 >
[2010-11-16 06:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21

< MD5 for: SERVICES.ASFX22 >
[2010-11-16 06:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22

< MD5 for: SERVICES.ASFX23 >
[2010-11-16 06:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23

< MD5 for: SERVICES.ASFX24 >
[2010-11-16 06:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24

< MD5 for: SERVICES.ASFX25 >
[2010-11-16 06:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25

< MD5 for: SERVICES.ASFX3 >
[2010-11-16 06:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3

< MD5 for: SERVICES.ASFX4 >
[2010-11-16 06:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4

< MD5 for: SERVICES.ASFX5 >
[2010-11-16 06:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5

< MD5 for: SERVICES.ASFX6 >
[2010-11-16 06:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6

< MD5 for: SERVICES.ASFX7 >
[2010-11-16 06:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7

< MD5 for: SERVICES.ASFX8 >
[2010-11-16 06:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8

< MD5 for: SERVICES.ASFX9 >
[2010-11-16 06:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9

< MD5 for: SERVICES.CFG >
[2012-07-27 22:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010-11-16 06:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.CNF >
[1999-11-21 20:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\250 alpen\_vti_pvt\services.cnf
[1999-11-21 20:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Bravenet Frontpage familjen\_vti_pvt\services.cnf
[2003-06-24 12:32:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Dandy\_vti_pvt\services.cnf
[2004-02-25 18:39:44 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Telia\Telia movies\_vti_pvt\services.cnf
[1999-11-21 21:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Telia\Telia\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2011-10-25 02:10:27 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysNative\sv-SE\services.exe.mui
[2011-10-25 02:10:27 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_ab0e3ae787d43a6a\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009-07-14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.LOCKED >
[2012-09-11 21:37:51 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Kanaler\services.locked
[2012-07-27 21:01:14 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked

< MD5 for: SERVICES.LOCKED_BAK >
[2012-05-20 00:58:01 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked_bak

< MD5 for: SERVICES.LOCKED_ORG >
[2012-05-20 00:52:41 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked_org

< MD5 for: SERVICES.MOF >
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2011-10-25 02:10:25 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysNative\sv-SE\services.msc
[2011-10-25 02:10:28 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysWOW64\sv-SE\services.msc
[2011-10-25 02:10:25 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_e5500ad35e3dd45d\services.msc
[2011-10-25 02:10:28 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_89316f4fa5e06327\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2011-10-25 02:10:43 | 000,008,194 | —- | M] () MD5=50E49C8E1C9BAD7D7C84DF88A7AC4A41 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_d61505583ec10672\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009-06-10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010-11-21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010-11-21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011-10-25 02:10:25 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\SysNative\sv-SE\winlogon.exe.mui
[2011-10-25 02:10:25 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_sv-se_0e3a992362e4027d\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2011-10-25 02:10:27 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\SysNative\wbem\sv-SE\winlogon.mfl
[2011-10-25 02:10:27 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_69cbd726812dd878\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012-09-09 23:56:00 | 000,001,024 | —- | M] () – C:\.rnd
[2010-11-21 05:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012-09-14 08:48:50 | 000,000,045 | —- | M] () – C:\error.log
[2012-10-16 07:38:46 | 2106,478,591 | -HS- | M] () – C:\hiberfil.sys
[2012-09-08 20:15:07 | 000,013,042 | —- | M] () – C:\hwupgradewizard.log
[2012-10-16 07:38:54 | 4240,293,887 | -HS- | M] () – C:\pagefile.sys
[2012-09-23 18:51:13 | 000,000,622 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009-07-14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 22:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012-08-21 11:12:33 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010-11-10 11:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009-07-14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-07-15 08:15:47 | 000,000,221 | -HS- | M] () – C:\Users\Annelie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009-08-31 18:29:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Annelie\Desktop\ATF-Cleaner.exe
[2012-10-16 11:55:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:8FB6501C
@Alternate Data Stream - 201 bytes -> C:\ProgramData\Temp:BEF4B0E7
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:73F5BDC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:553CA6CA

< End of report >

Attachments:

Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Hi Jeff and thanks for helpinh me. How do I disable scripts?

If you just make sure your antivirus and firewall are disabled you will be just fine. :)
Here we go:
For the DDS I only got the text below - no Attach.txt appeared


DDS (Ver_2012-10-14.05) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 22:07:07 on 2012-10-16
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.4860 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Box Sync\UpdateService.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Prey\platform\windows\cronsvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Box Sync\BoxSyncHelper.exe
C:\Program Files\Net iD\iid.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\WUDFHost.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Personal\bin\Personal.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Box Sync\BoxSync.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Storegate\Autostore\AutoStore.exe
C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe
C:\Program Files (x86)\anysee\Driver\CNO.exe
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.se/
mWinlogon: Userinit = userinit.exe
BHO: IEPlugin Class: {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: ToolbarBHO Class: {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
TB: &RoboForm Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: RAW Thumbnail Viewer: {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
uRun: [{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}] "C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe"
uRun: [SkyDrive] "C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
uRun: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun: [anysee_TR] C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe
mRun: [anysee CNO] C:\Program Files (x86)\anysee\Driver\CNO.EXE
StartupFolder: C:\Users\Annelie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Annelie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BANKID~1.LNK - C:\Program Files (x86)\Personal\bin\Personal.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BOXSYN~1.LNK - C:\Program Files\Box Sync\BoxSync.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPWIRE~1.LNK - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\TELIAA~1.LNK - C:\Program Files (x86)\Storegate\Autostore\AutoStore.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Clean Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - C:\Program Files (x86)\DAP\dapextie.htm
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - C:\Program Files (x86)\DAP\dapextie2.htm
IE: E&xportera till Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337} : DHCPNameServer = [removed] [removed]
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Users\Annelie\AppData\Local\Microsoft\Windows Sidebar\Gadgets\SkypeGadget1.4.gadget\wrapper\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll
SSODL: WebCheck -
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [BoxSyncHelper] "C:\Program Files\Box Sync\BoxSyncHelper.exe"
x64-Run: [Net iD] "C:\Program Files\Net iD\iid.exe"
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll
x64-Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gama&hl=sv
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
FF - plugin: C:\Program Files (x86)\Personal\bin\np_prsnl.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-09-07 18:41; [removed]; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-09-08 20:45; {B728AB94-9BC7-49b7-B76A-422BB31B2FD0}; C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox
FF - ExtSQL: 2012-09-08 20:46; [removed]; C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension
FF - ExtSQL: 2012-09-09 11:57; {22119944-ED35-4ab1-910B-E619EA06A115}; C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox
FF - ExtSQL: 2012-09-09 16:41; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2012-09-09 21:01; {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}; C:\Program Files (x86)\DAP\DAPFireFox
FF - ExtSQL: 2012-09-23 18:51; {b64982b1-d112-42b5-b1e4-d3867c4533f8}; C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-25 55856]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-9-7 969200]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-9-7 359464]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 #UpdateService;Box Sync Auto-updater;C:\Program Files\Box Sync\UpdateService.exe [2012-9-4 8704]
R2 ADExchange;ArcSoft Exchange Service;C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-3-19 43072]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-4-7 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-9-29 204288]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-9-1 1166848]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-9-7 25232]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-9-7 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-9-7 44808]
R2 Browser Manager;Browser Manager;C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2012-10-11 2309656]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928]
R2 CronService;Cron Service for Prey;C:\Prey\platform\windows\cronsvc.exe [2011-2-15 19968]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-8-16 227896]
R2 HPPRXSVC;HPPRXSVC;C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-5 37432]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-7-11 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-4-7 13592]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-4-7 2375168]
R2 ISCTAgent;ISCT Always Updated Agent;C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-9-6 93696]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-9-26 375208]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-9-9 72216]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-8-13 3064000]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-9-9 2735528]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-4-7 2656280]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-9-29 9981952]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-9-29 309248]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-6-7 231440]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2012-4-7 133672]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2012-4-7 620072]
R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2012-4-7 89640]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2012-4-7 39976]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-8-9 12289472]
R3 ISCT;Intel® Smart Connect Technology Device Driver;C:\Windows\System32\drivers\ISCTD64.sys [2011-9-6 44992]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-8-5 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-10-20 56344]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2011-8-4 8604672]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-11 91648]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-11 208896]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-4-7 338536]
R3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2012-9-9 35112]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-8-5 42392]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920]
S1 AMTBDA_P861F;anysee Capture Service;C:\Windows\System32\drivers\anyseeTU.SYS [2011-4-21 853632]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/04/06 19:45:21;C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2011-2-25 241648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Tjänsten Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-9-22 136176]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-9-7 250808]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
S3 gupdatem;Tjänsten Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-9-22 136176]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-8-5 34200]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-9-10 114144]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-7-28 340240]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2012-3-26 22528]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-7 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-10-16 09:55:17 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6363B6DA-3D35-4086-AECE-2BC5B0F751DE}\offreg.dll
2012-10-16 08:57:13 ——– d—–w- C:\Users\Annelie\AppData\Local\{5D265361-FF3C-4189-A00D-271475F09B21}
2012-10-16 08:38:52 9308616 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6363B6DA-3D35-4086-AECE-2BC5B0F751DE}\mpengine.dll
2012-10-15 18:30:20 ——– d—–w- C:\Users\Annelie\AppData\Local\Apple Computer
2012-10-15 13:48:02 ——– d—–w- C:\Users\Annelie\AppData\Local\{FCCBC759-B42A-4616-BD4D-3659ABC701EB}
2012-10-14 14:28:12 ——– d—–w- C:\Users\Annelie\AppData\Local\{E20545B1-713E-42F9-A4C3-A1F0D699629E}
2012-10-13 22:27:32 ——– d—–w- C:\Users\Annelie\AppData\Local\ArcSoft
2012-10-13 21:59:55 ——– d—–w- C:\Users\Annelie\AppData\Local\Broadcom
2012-10-13 21:59:54 ——– d—–w- C:\Users\Annelie\AppData\Local\ATI
2012-10-13 21:58:10 ——– d—–w- C:\Users\Annelie\AppData\Local\Adobe
2012-10-13 21:55:27 ——– d—–w- C:\Users\Annelie\AppData\Local\Box Sync
2012-10-13 15:21:03 ——– d—–w- C:\Users\Annelie\AppData\Local\{C0C090EB-A23A-4BF9-A1D8-F8A5386A8A8A}
2012-10-13 03:20:52 ——– d—–w- C:\Users\Annelie\AppData\Local\{72885B53-526B-4BFB-AC4F-E25F507D3700}
2012-10-12 15:20:29 ——– d—–w- C:\Users\Annelie\AppData\Local\{FAE6970D-A62C-47C4-8264-5E5D3B6C943D}
2012-10-11 15:01:05 ——– d—–w- C:\Users\Annelie\AppData\Local\{73CAAC98-3D7C-46E6-B408-D15C7ABE0459}
2012-10-11 03:00:42 ——– d—–w- C:\Users\Annelie\AppData\Local\{88075DDB-E0D2-43C5-B7A1-6C2B58B8F53F}
2012-10-10 06:10:37 ——– d—–w- C:\Users\Annelie\AppData\Local\{83A549E5-8671-492E-BAB7-9D1938414656}
2012-10-10 06:07:53 715776 —-a-w- C:\Windows\System32\kerberos.dll
2012-10-10 06:07:53 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll
2012-10-10 06:07:46 1464320 —-a-w- C:\Windows\System32\crypt32.dll
2012-10-10 06:07:45 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2012-10-10 06:07:45 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-10-10 06:07:45 140288 —-a-w- C:\Windows\System32\cryptnet.dll
2012-10-10 06:07:45 1159680 —-a-w- C:\Windows\SysWow64\crypt32.dll
2012-10-10 06:07:45 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2012-10-09 11:29:21 ——– d—–w- C:\Users\Annelie\AppData\Local\{E858F3C5-DFEE-4555-BF8D-DB8F97ABF686}
2012-10-08 23:28:58 ——– d—–w- C:\Users\Annelie\AppData\Local\{04E091C2-3C96-4F67-8705-2502CEC7F7A5}
2012-10-08 11:15:57 ——– d—–w- C:\Users\Annelie\AppData\Local\{1DB5DB8D-DD8D-438A-827A-1CB5BE941881}
2012-10-07 15:29:25 ——– d—–w- C:\Users\Annelie\AppData\Local\{6FF32FBD-70E4-460A-BF95-365B9BB04BB7}
2012-10-06 22:27:56 ——– d—–w- C:\Users\Annelie\AppData\Local\{EA4A31EE-D720-472E-86FD-48DD64D8B1BF}
2012-10-06 19:32:20 ——– d—–w- C:\Users\Annelie\AppData\Local\Microsoft Games
2012-10-06 17:49:56 ——– d—–w- C:\ProgramData\CNO
2012-10-06 17:45:18 ——– d—–w- C:\Program Files\anysee
2012-10-06 17:45:14 ——– d—–w- C:\Program Files (x86)\anysee
2012-10-06 16:05:19 ——– d—–w- C:\Program Files\PlayReady
2012-10-06 13:58:47 6949596 —-a-w- C:\Windows\TranscendElite.exe
2012-10-06 10:26:22 ——– d—–w- C:\Users\Annelie\AppData\Local\{CE4EF6C4-BBC0-431D-83C5-C951A22E7064}
2012-10-05 18:03:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{0616A02C-F253-4398-BC7D-74158EEACCDB}
2012-10-05 16:41:04 ——– d—–w- C:\Program Files (x86)\VideoLAN
2012-10-05 06:03:03 ——– d—–w- C:\Users\Annelie\AppData\Local\{22F04A30-B228-42E1-9EDD-16EF8340B850}
2012-10-04 13:38:53 ——– d—–w- C:\Users\Annelie\AppData\Local\{BF4DB9ED-FCE8-4179-A695-6C949032B11D}
2012-10-03 12:57:22 ——– d—–w- C:\Program Files\Canon
2012-10-03 12:55:27 336896 —-a-w- C:\Windows\System32\CNMN6PPM.DLL
2012-10-03 12:55:27 144384 —-a-w- C:\Windows\System32\CNMN6UI.DLL
2012-10-03 12:55:27 ——– d—–w- C:\Windows\System32\STRING
2012-10-03 12:55:26 ——– d—–w- C:\Windows\System32\CHM
2012-10-03 10:33:36 ——– d—–w- C:\Users\Annelie\AppData\Local\{4E194997-6236-473A-B619-25402D855A22}
2012-10-02 11:03:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{CA10A3F4-6E0C-4D5B-91AE-5CCAAEB8773E}
2012-09-30 18:26:50 ——– d—–w- C:\Windows\SysWow64\Adobe
2012-09-30 17:46:04 916456 —-a-w- C:\Windows\System32\deployJava1.dll
2012-09-30 17:46:03 1034216 —-a-w- C:\Windows\System32\npDeployJava1.dll
2012-09-30 17:45:52 108008 —-a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-09-30 14:37:20 ——– d—–w- C:\Users\Annelie\AppData\Local\{C8BF6A71-0870-47F4-9284-46C843ACA4E0}
2012-09-29 23:40:05 ——– d—–w- C:\Users\Annelie\AppData\Roaming\CoSoSys
2012-09-29 17:59:22 ——– d—–w- C:\Users\Annelie\AppData\Local\{6D457595-7AC5-4833-8E71-2E100597B4EC}
2012-09-29 05:37:36 ——– d—–w- C:\Users\Annelie\AppData\Local\{F2A0CF81-187B-46A0-A0D2-DD474F6079AD}
2012-09-28 14:34:27 ——– d—–w- C:\Windows\pss
2012-09-28 12:36:04 ——– d—–w- C:\Users\Annelie\AppData\Local\{90AFE95C-87F7-4163-8AFB-0C0AD93B5514}
2012-09-27 11:03:36 ——– d—–w- C:\Users\Annelie\AppData\Local\{EB89FCB8-ACC7-41A5-B4F6-AB0FDD5BEF72}
2012-09-26 21:04:38 ——– d—–w- C:\Users\Annelie\AppData\Local\{9A56696E-98C4-4132-B334-0096DE526580}
2012-09-26 09:04:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{D29C45A3-349E-4383-8CA5-83D76031C5C7}
2012-09-26 08:25:26 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe
2012-09-25 21:03:51 ——– d—–w- C:\Users\Annelie\AppData\Local\{149ABCCC-072B-48EC-967F-5E8AD0B61E14}
2012-09-25 09:36:33 ——– d—–w- C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-09-25 09:03:40 ——– d—–w- C:\Users\Annelie\AppData\Local\{2EF7B70F-7186-4A20-A98C-4A17B06D6CD5}
2012-09-24 21:03:17 ——– d—–w- C:\Users\Annelie\AppData\Local\{79F8482C-8295-4215-80CB-4BF8263BEEC0}
2012-09-24 09:03:05 ——– d—–w- C:\Users\Annelie\AppData\Local\{9B8FAAC8-B88E-4EC8-A899-A2F6CEFAA5FA}
2012-09-23 19:54:41 ——– d—–w- C:\Users\Annelie\AppData\Local\{6F949E0A-A0C7-4F2F-9A11-3E1B15275648}
2012-09-23 18:45:25 ——– d—–w- C:\Program Files (x86)\jAlbum
2012-09-23 16:51:13 ——– d—–w- C:\ProgramData\Browser Manager
2012-09-23 07:54:17 ——– d—–w- C:\Users\Annelie\AppData\Local\{B58A0859-5EFE-492F-845C-90007BCCDA76}
2012-09-22 17:52:21 29 —-a-w- C:\Windows\SysWow64\TempWmicBatchFile.bat
2012-09-22 17:45:25 ——– d—–w- C:\Prey
2012-09-22 14:41:07 ——– d—–w- C:\Program Files (x86)\ExpressFiles
2012-09-22 13:46:29 ——– d—–w- C:\Users\Annelie\AppData\Roaming\mediAvatar
2012-09-22 13:44:58 ——– d—–w- C:\Program Files (x86)\MSECache
2012-09-22 13:43:51 ——– d—–w- C:\ProgramData\mediAvatar
2012-09-22 13:43:51 ——– d—–w- C:\Program Files (x86)\PowerPoint to Video Converter Personal
2012-09-22 13:35:15 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Babylon
2012-09-22 13:35:15 ——– d—–w- C:\ProgramData\Babylon
2012-09-22 13:35:13 ——– d—–w- C:\Users\Annelie\AppData\Roaming\ExpressFiles
2012-09-22 13:19:27 ——– d—–w- C:\Program Files (x86)\Sync Blocker 10.6 Release 1
2012-09-22 11:40:13 ——– d—–w- C:\Program Files\Net iD
2012-09-22 11:40:10 244544 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
2012-09-22 11:40:10 ——– d—–w- C:\Program Files (x86)\Net iD
2012-09-22 11:40:01 ——– d—–w- C:\Users\Annelie\AppData\Roaming\iid
2012-09-22 10:32:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{CE3FC8FC-7AAC-47FA-9379-4930B3CDD718}
2012-09-22 10:22:20 ——– d—–w- C:\Program Files (x86)\JuiceboxBuilder-Lite
2012-09-21 17:32:59 ——– d—–w- C:\Users\Annelie\AppData\Local\{50C56335-D16F-4BC7-AB80-4054189A1C8D}
2012-09-21 05:32:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{3CEB44EE-BF26-42A3-9D83-BF9DC84E5475}
2012-09-20 17:38:26 ——– d—–w- C:\Users\Annelie\.rainlendar2
2012-09-20 17:38:14 ——– d—–w- C:\Program Files (x86)\Rainlendar2
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-09-20 16:40:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-09-20 09:04:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{CE7A18BB-8103-4E54-AB62-30FB89E8B683}
2012-09-19 21:04:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{3375645B-1B73-4B95-814B-36CB8A9CB377}
2012-09-19 17:13:27 ——– d—–w- C:\Program Files (x86)\BulletProof FTP Client 2009
2012-09-19 09:04:33 ——– d—–w- C:\Users\Annelie\AppData\Local\{D6FF1E5D-CB1B-4F4F-94E2-C1A316A86B39}
2012-09-18 21:22:26 ——– d—–w- C:\Users\Annelie\Datamapp
2012-09-18 21:20:16 ——– d—–w- C:\Program Files (x86)\IncrediMail
2012-09-18 16:37:43 ——– d—–w- C:\Users\Annelie\AppData\Local\IM
2012-09-18 16:07:51 401462 —-a-w- C:\Windows\SysWow64\~GLH0024.TMP
2012-09-18 16:06:59 ——– d—–w- C:\Program Files (x86)\Jasc Software Inc
2012-09-18 16:03:16 ——– d—–w- C:\Program Files (x86)\Paint Shop Pro
2012-09-18 11:38:32 ——– d—–w- C:\ProgramData\Photo Notifier and Animation Creator
2012-09-18 11:38:32 ——– d—–w- C:\Program Files (x86)\Photo Notifier and Animation Creator
2012-09-18 11:38:01 ——– d—–w- C:\ProgramData\IncrediMail
2012-09-18 11:38:01 ——– d—–w- C:\ProgramData\IM
2012-09-18 11:32:23 ——– d—–w- C:\Users\Annelie\AppData\Local\{7BAED964-D3F6-47D4-AA1F-779CC2AAC060}
2012-09-18 10:52:36 ——– d—–w- C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-09-17 19:13:31 ——– d—–w- C:\Users\Annelie\AppData\Local\{C623E18B-0713-4B04-B8A8-550F599CE7FB}
2012-09-17 12:25:45 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Jasc
2012-09-17 07:13:08 ——– d—–w- C:\Users\Annelie\AppData\Local\{9C22ECD0-91C0-4F54-AB00-820D8706A844}
.
==================== Find3M ====================
.
2012-10-09 15:11:18 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-09 15:11:18 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-09-14 19:19:29 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-09-09 21:56:43 87488 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll
2012-09-09 21:56:43 80800 —-a-w- C:\Windows\System32\LMIinit.dll
2012-09-09 21:56:43 34720 —-a-w- C:\Windows\System32\LMIport.dll
2012-09-09 19:01:36 50688 —-a-w- C:\Windows\SysWow64\wbhelp2.dll
2012-09-09 19:01:36 479298 —-a-w- C:\Windows\SysWow64\wbocx.ocx
2012-09-09 18:40:22 84480 —-a-w- C:\Windows\SysWow64\EasyHook32.dll
2012-09-09 18:40:22 109216 —-a-w- C:\Windows\SysWow64\EasyHook64.dll
2012-09-09 18:40:21 172032 —-a-w- C:\Windows\SysWow64\AniGIF.ocx
2012-09-09 09:55:15 477168 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-09-09 09:55:15 473072 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 11:01:20 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-08-21 11:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll
2012-08-21 11:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-08-21 09:13:13 969200 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-08-21 09:13:12 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-08-21 09:13:12 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-08-21 09:12:33 41224 —-a-w- C:\Windows\avastSS.scr
2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-08-07 10:36:00 35112 —-a-w- C:\Windows\System32\drivers\teamviewervpn.sys
2012-08-02 17:58:52 574464 —-a-w- C:\Windows\System32\d3d10level9.dll
2012-08-02 16:57:20 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
.
============= FINISH: 22:23:27,49 ===============


The aswMBR scan started up just fine, but suddenly (after a very long time) it closed down Windows. I've attached how it looked like. Before the scan stopped I did save - twice at least - as I thought it was ready - result is below. However, after the last saving a red line appeared, saying I had some virus. Anyway - I'm posting this and tomorrow (it's after 1 am here now) I'll make another try.


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-16 22:51:29
—————————–
22:51:29.383 OS Version: Windows x64 6.1.7601 Service Pack 1
22:51:29.383 Number of processors: 8 586 0x2A07
22:51:29.383 ComputerName: TERRA UserName:
22:51:31.052 Initialize success
22:51:31.286 AVAST engine defs: 12101600
22:52:08.695 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:52:08.695 Disk 0 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
22:52:08.710 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
22:52:08.710 Disk 1 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
22:52:08.757 Disk 0 MBR read successfully
22:52:08.773 Disk 0 MBR scan
22:52:08.788 Disk 0 Windows 7 default MBR code
22:52:08.788 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
22:52:08.820 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928213 MB offset 409600
22:52:09.132 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 25353 MB offset 1901389824
22:52:09.366 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
22:52:09.459 Disk 0 scanning C:\Windows\system32\drivers
22:52:16.027 Service scanning
22:52:31.689 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
22:52:31.705 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-16 22:51:29
—————————–
22:51:29.383 OS Version: Windows x64 6.1.7601 Service Pack 1
22:51:29.383 Number of processors: 8 586 0x2A07
22:51:29.383 ComputerName: TERRA UserName:
22:51:31.052 Initialize success
22:51:31.286 AVAST engine defs: 12101600
22:52:08.695 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:52:08.695 Disk 0 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
22:52:08.710 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
22:52:08.710 Disk 1 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
22:52:08.757 Disk 0 MBR read successfully
22:52:08.773 Disk 0 MBR scan
22:52:08.788 Disk 0 Windows 7 default MBR code
22:52:08.788 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
22:52:08.820 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928213 MB offset 409600
22:52:09.132 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 25353 MB offset 1901389824
22:52:09.366 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
22:52:09.459 Disk 0 scanning C:\Windows\system32\drivers
22:52:16.027 Service scanning
22:52:31.689 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
22:52:31.705 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"
22:52:53.182 Modules scanning
22:52:53.198 Disk 0 trace - called modules:
22:52:53.229 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
22:52:53.244 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800a662790]
22:52:53.260 3 CLASSPNP.SYS[fffff8800143b43f] -> nt!IofCallDriver -> [0xfffffa800a574b10]
22:52:53.260 5 hpdskflt.sys[fffff880019f7189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800820c050]
22:52:54.820 AVAST engine scan C:\Windows
22:52:57.675 AVAST engine scan C:\Windows\system32
22:54:36.844 AVAST engine scan C:\Windows\system32\drivers
22:54:45.596 AVAST engine scan C:\Users\Annelie
22:57:06.137 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
22:57:06.152 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"


Nite, nite//Annelie

Attachments:

Hi,

Good job!!

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Hi,

Here's the new aswMBR file! Today the scan worked just fine. The combofix file is inserted too.//Annelie

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-17 12:10:10
—————————–
12:10:10.016 OS Version: Windows x64 6.1.7601 Service Pack 1
12:10:10.016 Number of processors: 8 586 0x2A07
12:10:10.016 ComputerName: TERRA UserName:
12:10:11.842 Initialize success
12:10:11.935 AVAST engine defs: 12101601
12:10:15.289 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
12:10:15.305 Disk 0 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
12:10:15.305 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
12:10:15.320 Disk 1 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
12:10:15.414 Disk 0 MBR read successfully
12:10:15.414 Disk 0 MBR scan
12:10:15.414 Disk 0 Windows 7 default MBR code
12:10:15.430 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
12:10:15.461 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928213 MB offset 409600
12:10:15.492 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 25353 MB offset 1901389824
12:10:15.523 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
12:10:15.554 Disk 0 scanning C:\Windows\system32\drivers
12:10:22.247 Service scanning
12:10:58.392 Modules scanning
12:10:58.408 Disk 0 trace - called modules:
12:10:58.486 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
12:10:58.501 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800a644790]
12:10:58.501 3 CLASSPNP.SYS[fffff88001c8c43f] -> nt!IofCallDriver -> [0xfffffa800a55ab10]
12:10:58.517 5 hpdskflt.sys[fffff880017ed189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80081c7050]
12:10:59.983 AVAST engine scan C:\Windows
12:11:03.150 AVAST engine scan C:\Windows\system32
12:12:47.952 AVAST engine scan C:\Windows\system32\drivers
12:12:56.938 AVAST engine scan C:\Users\Annelie
12:27:12.098 File: C:\Users\Annelie\Dropbox\DOTEASY\Emoticons new\SweetImSetup.exe **INFECTED** Win32:Trojan-gen
12:31:31.215 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
12:31:31.231 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-17 12:10:10
—————————–
12:10:10.016 OS Version: Windows x64 6.1.7601 Service Pack 1
12:10:10.016 Number of processors: 8 586 0x2A07
12:10:10.016 ComputerName: TERRA UserName:
12:10:11.842 Initialize success
12:10:11.935 AVAST engine defs: 12101601
12:10:15.289 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
12:10:15.305 Disk 0 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
12:10:15.305 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
12:10:15.320 Disk 1 Vendor: TOSHIBA_ GU00 Size: 953869MB BusType: 3
12:10:15.414 Disk 0 MBR read successfully
12:10:15.414 Disk 0 MBR scan
12:10:15.414 Disk 0 Windows 7 default MBR code
12:10:15.430 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
12:10:15.461 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 928213 MB offset 409600
12:10:15.492 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 25353 MB offset 1901389824
12:10:15.523 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
12:10:15.554 Disk 0 scanning C:\Windows\system32\drivers
12:10:22.247 Service scanning
12:10:58.392 Modules scanning
12:10:58.408 Disk 0 trace - called modules:
12:10:58.486 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
12:10:58.501 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800a644790]
12:10:58.501 3 CLASSPNP.SYS[fffff88001c8c43f] -> nt!IofCallDriver -> [0xfffffa800a55ab10]
12:10:58.517 5 hpdskflt.sys[fffff880017ed189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80081c7050]
12:10:59.983 AVAST engine scan C:\Windows
12:11:03.150 AVAST engine scan C:\Windows\system32
12:12:47.952 AVAST engine scan C:\Windows\system32\drivers
12:12:56.938 AVAST engine scan C:\Users\Annelie
12:27:12.098 File: C:\Users\Annelie\Dropbox\DOTEASY\Emoticons new\SweetImSetup.exe **INFECTED** Win32:Trojan-gen
12:31:31.215 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
12:31:31.231 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"
12:49:37.827 AVAST engine scan C:\ProgramData
12:59:43.936 Scan finished successfully
13:02:13.181 Disk 0 MBR has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\MBR.dat"
13:02:13.181 The log file has been saved successfully to "C:\Users\Annelie\Desktop\WtT\aswMBR\aswMBR.txt"


*****************************

ComboFix 12-10-16.02 - Annelie 2012-10-17 11:56:38.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.5602 [GMT 2:00]
Körs från: c:\users\Annelie\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\SysWow64\~GLH0023.TMP
c:\windows\SysWow64\~GLH0024.TMP
c:\windows\SysWow64\msstdfmt.dll
.
.
(((((((((((((((((((((((( Filer skapade från 2012-09-17 till 2012-10-17 ))))))))))))))))))))))))))))))
.
.
2012-10-17 10:04 . 2012-10-17 10:04 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-10-16 09:55 . 2012-10-17 10:00 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6363B6DA-3D35-4086-AECE-2BC5B0F751DE}\offreg.dll
2012-10-16 08:38 . 2012-08-30 07:27 9308616 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6363B6DA-3D35-4086-AECE-2BC5B0F751DE}\mpengine.dll
2012-10-15 18:30 . 2012-10-16 05:42 ——– d—–w- c:\users\Annelie\AppData\Local\Apple Computer
2012-10-13 22:27 . 2012-10-13 22:27 ——– d—–w- c:\users\Annelie\AppData\Local\ArcSoft
2012-10-13 21:59 . 2012-10-13 21:59 ——– d—–w- c:\users\Annelie\AppData\Local\Broadcom
2012-10-13 21:59 . 2012-10-13 21:59 ——– d—–w- c:\users\Annelie\AppData\Local\ATI
2012-10-13 21:58 . 2012-10-13 21:58 ——– d—–w- c:\users\Annelie\AppData\Local\Adobe
2012-10-13 21:55 . 2012-10-13 21:55 ——– d—–w- c:\users\Annelie\AppData\Local\Box Sync
2012-10-10 06:07 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll
2012-10-10 06:07 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll
2012-10-10 06:07 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll
2012-10-10 06:07 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 06:07 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-10 06:07 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-10 06:07 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll
2012-10-10 06:07 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-06 19:32 . 2012-10-06 21:37 ——– d—–w- c:\users\Annelie\AppData\Local\Microsoft Games
2012-10-06 17:49 . 2012-10-06 17:49 ——– d—–w- c:\programdata\CNO
2012-10-06 17:45 . 2012-10-06 17:45 ——– d—–w- c:\program files\anysee
2012-10-06 17:45 . 2012-10-06 17:48 ——– d—–w- c:\program files (x86)\anysee
2012-10-06 16:05 . 2012-10-06 16:05 ——– d—–w- c:\program files\PlayReady
2012-10-06 13:58 . 2012-03-16 14:21 6949596 —-a-w- c:\windows\TranscendElite.exe
2012-10-05 16:42 . 2012-10-16 18:13 ——– d—–w- c:\users\Annelie\AppData\Roaming\vlc
2012-10-05 16:41 . 2012-10-05 16:41 ——– d—–w- c:\program files (x86)\VideoLAN
2012-10-03 12:57 . 2012-10-03 12:57 ——– d—–w- c:\program files\Canon
2012-10-03 12:56 . 2012-10-03 12:56 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2012-10-03 12:55 . 2012-10-03 12:55 ——– d—–w- c:\windows\system32\STRING
2012-10-03 12:55 . 2009-04-03 07:51 144384 —-a-w- c:\windows\system32\CNMN6UI.DLL
2012-10-03 12:55 . 2009-04-03 07:51 336896 —-a-w- c:\windows\system32\CNMN6PPM.DLL
2012-10-03 12:55 . 2012-10-03 12:55 ——– d—–w- c:\windows\system32\CHM
2012-09-30 18:26 . 2012-09-30 18:26 ——– d—–w- c:\windows\SysWow64\Adobe
2012-09-30 17:55 . 2012-09-30 17:55 ——– d—–w- c:\program files\Microsoft Silverlight
2012-09-30 17:55 . 2012-09-30 17:55 ——– d—–w- c:\program files (x86)\Microsoft Silverlight
2012-09-30 17:46 . 2012-09-30 17:45 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-30 17:46 . 2012-09-30 17:45 289768 —-a-w- c:\windows\system32\javaws.exe
2012-09-30 17:46 . 2012-09-30 17:45 1034216 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-09-30 17:45 . 2012-09-30 17:45 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-30 17:45 . 2012-09-30 17:45 189416 —-a-w- c:\windows\system32\javaw.exe
2012-09-30 17:45 . 2012-09-30 17:45 188904 —-a-w- c:\windows\system32\java.exe
2012-09-30 17:45 . 2012-09-30 17:45 ——– d—–w- c:\program files\Java
2012-09-29 23:40 . 2012-09-29 23:40 ——– d—–w- c:\users\Annelie\AppData\Roaming\CoSoSys
2012-09-26 08:25 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-09-25 09:36 . 2012-09-25 09:36 ——– d—–w- c:\users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2012-09-23 18:45 . 2012-09-23 18:45 ——– d—–w- c:\program files (x86)\jAlbum
2012-09-23 16:51 . 2012-10-11 02:41 ——– d—–w- c:\programdata\Browser Manager
2012-09-22 17:52 . 2012-10-17 10:00 29 —-a-w- c:\windows\SysWow64\TempWmicBatchFile.bat
2012-09-22 17:45 . 2012-09-22 17:52 ——– d—–w- C:\Prey
2012-09-22 14:55 . 2012-08-24 10:39 10925568 —-a-w- c:\windows\system32\ieframe.dll
2012-09-22 14:41 . 2012-09-23 16:51 ——– d—–w- c:\program files (x86)\ExpressFiles
2012-09-22 13:46 . 2012-09-22 13:46 ——– d—–w- c:\users\Annelie\AppData\Roaming\mediAvatar
2012-09-22 13:44 . 2012-09-22 14:51 ——– d—–w- c:\program files (x86)\MSECache
2012-09-22 13:43 . 2012-09-22 13:51 ——– d—–w- c:\program files (x86)\PowerPoint to Video Converter Personal
2012-09-22 13:43 . 2012-09-22 13:43 ——– d—–w- c:\programdata\mediAvatar
2012-09-22 13:35 . 2012-09-23 16:51 622 —-a-w- C:\user.js
2012-09-22 13:35 . 2012-09-22 13:35 ——– d—–w- c:\users\Annelie\AppData\Roaming\Babylon
2012-09-22 13:35 . 2012-09-22 13:35 ——– d—–w- c:\programdata\Babylon
2012-09-22 13:35 . 2012-09-22 13:35 ——– d—–w- c:\users\Annelie\AppData\Roaming\ExpressFiles
2012-09-22 13:19 . 2012-09-22 13:19 ——– d—–w- c:\program files (x86)\Sync Blocker 10.6 Release 1
2012-09-22 12:18 . 2012-09-22 12:18 ——– d—–w- c:\users\Annelie\AppData\Roaming\U3
2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\program files\Net iD
2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\program files (x86)\Net iD
2012-09-22 11:40 . 2012-03-07 11:28 244544 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npiidplg.dll
2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\users\Annelie\AppData\Roaming\iid
2012-09-22 10:22 . 2012-09-22 10:22 ——– d—–w- c:\program files (x86)\JuiceboxBuilder-Lite
2012-09-20 17:38 . 2012-10-17 05:51 ——– d—–w- c:\users\Annelie\.rainlendar2
2012-09-20 17:38 . 2012-09-20 17:38 ——– d—–w- c:\program files (x86)\Rainlendar2
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-09-20 16:40 . 2012-09-20 16:40 ——– d—–w- c:\program files (x86)\QuickTime
2012-09-19 17:13 . 2012-09-19 17:13 ——– d—–w- c:\program files (x86)\BulletProof FTP Client 2009
2012-09-18 21:22 . 2012-09-18 21:22 ——– d—–w- c:\users\Annelie\Datamapp
2012-09-18 21:20 . 2012-09-18 21:20 ——– d—–w- c:\program files (x86)\IncrediMail
2012-09-18 16:37 . 2012-09-18 21:56 ——– d—–w- c:\users\Annelie\AppData\Local\IM
2012-09-18 16:06 . 2012-09-18 16:06 ——– d—–w- c:\program files (x86)\Jasc Software Inc
2012-09-18 16:03 . 2012-09-18 16:08 ——– d—–w- c:\program files (x86)\Paint Shop Pro
2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\Photo Notifier and Animation Creator
2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\program files (x86)\Photo Notifier and Animation Creator
2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\IM
2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\IncrediMail
2012-09-18 10:52 . 2012-09-18 10:52 ——– d—–w- c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-09-17 12:25 . 2012-09-17 12:25 ——– d—–w- c:\users\Annelie\AppData\Roaming\Jasc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 14:36 . 2012-09-12 18:20 65309168 —-a-w- c:\windows\system32\MRT.exe
2012-10-09 15:11 . 2012-09-07 20:21 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-09 15:11 . 2011-10-25 00:53 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-10 15:54 . 2012-09-10 15:54 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-09-10 15:54 . 2012-09-10 15:54 346960 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-09-09 21:56 . 2012-09-09 21:56 34720 —-a-w- c:\windows\system32\LMIport.dll
2012-09-09 21:56 . 2012-09-09 21:56 87488 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-09-09 21:56 . 2012-09-09 21:56 80800 —-a-w- c:\windows\system32\LMIinit.dll
2012-09-09 19:01 . 2012-09-09 19:01 50688 —-a-w- c:\windows\SysWow64\wbhelp2.dll
2012-09-09 19:01 . 2012-09-09 19:01 479298 —-a-w- c:\windows\SysWow64\wbocx.ocx
2012-09-09 18:40 . 2012-09-09 18:42 84480 —-a-w- c:\windows\SysWow64\EasyHook32.dll
2012-09-09 18:40 . 2012-09-09 18:42 109216 —-a-w- c:\windows\SysWow64\EasyHook64.dll
2012-09-09 18:40 . 2012-09-09 18:40 172032 —-a-w- c:\windows\SysWow64\AniGIF.ocx
2012-09-09 09:55 . 2012-09-09 09:55 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-09-09 09:55 . 2012-09-08 23:45 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-07 15:16 . 2010-06-24 18:33 19720 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-22 18:12 . 2012-09-12 10:38 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 10:38 950128 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 10:38 376688 —-a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 10:38 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 11:01 . 2012-09-13 17:47 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2012-09-09 22:14 125872 —-a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 11:01 . 2012-09-09 22:14 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll
2012-08-21 09:13 . 2012-09-07 15:38 359464 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-09-07 15:38 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-09-07 15:38 969200 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-09-07 15:38 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2012-09-07 15:38 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-09-07 15:38 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2012-09-07 15:37 41224 —-a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-09-07 15:37 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-08-21 09:12 . 2012-07-15 06:04 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-08-20 17:38 . 2012-10-10 06:08 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2012-08-07 10:36 . 2012-09-09 20:39 35112 —-a-w- c:\windows\system32\drivers\teamviewervpn.sys
2012-08-02 17:58 . 2012-09-12 10:38 574464 —-a-w- c:\windows\system32\d3d10level9.dll
2012-08-02 16:57 . 2012-09-12 10:38 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll
.
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-09-09 21:39 220608 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-09-09 21:39 220608 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-09-09 21:39 220608 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}"="c:\program files (x86)\Pocket Watch" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-09-09 109336]
"SkyDrive"="c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2012-09-09 238528]
"Rainlendar2"="c:\program files (x86)\Rainlendar2\Rainlendar2.exe" [2011-08-12 3820032]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-29 343168]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-04-15 113288]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-08-16 75048]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-07-11 574008]
"HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960]
"HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"Net iD"="c:\program files (x86)\Net iD\iid.exe" [2012-03-07 100160]
"anysee_TR"="c:\program files (x86)\anysee\anysee-TCSeries\anysee_TR.exe" [2011-04-04 1503744]
"anysee CNO"="c:\program files (x86)\anysee\Driver\CNO.EXE" [2011-04-21 1323008]
.
c:\users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-8-27 26924984]
EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-8-14 1014624]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BankID säkerhetsprogram.lnk - c:\program files (x86)\Personal\bin\Personal.exe [2012-9-9 1088920]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-8-25 1337632]
Box Sync.lnk - c:\program files\Box Sync\BoxSync.exe [2012-9-4 8710144]
HP Wireless Audio Manager.lnk - c:\program files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe [2011-9-22 742712]
Telia AutoStore.lnk - c:\program files (x86)\Storegate\Autostore\AutoStore.exe [2009-11-3 832792]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\23787~1.43\{16cdf~1\browsemngr.dll
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 AMTBDA_P861F;anysee Capture Service;c:\windows\system32\DRIVERS\anyseeTU.SYS [2011-04-21 853632]
R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/04/06 19:45;c:\program files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2011-02-25 241648]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Tjänsten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 136176]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008]
R3 cpuz134;cpuz134;c:\users\Annelie\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
R3 gupdatem;Tjänsten Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-08-05 34200]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-10 114144]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-07 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 8704pdateService;Box Sync Auto-updater;c:\program files\Box Sync\UpdateService.exe [2012-09-04 8704]
S2 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-03-19 43072]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-29 204288]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-01 1166848]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-08-21 71600]
S2 Browser Manager;Browser Manager;c:\programdata\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2012-10-10 2309656]
S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]
S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-08-16 227896]
S2 HPPRXSVC;HPPRXSVC;c:\program files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-05 37432]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-27 30520]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-07-11 26680]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-08-24 13592]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-08 2375168]
S2 ISCTAgent;ISCT Always Updated Agent;c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-09-06 93696]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-09-09 375208]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-09-16 15928]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-08-24 2735528]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-22 2656280]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-09-29 9981952]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-09-29 309248]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-06-07 231440]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2011-08-25 133672]
S3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2011-08-25 620072]
S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys [2011-08-25 89640]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-08-25 39976]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-08-09 12289472]
S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys [2011-09-06 44992]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-08-05 25496]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-06-11 91648]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-06-11 208896]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-31 338536]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2012-08-07 35112]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2011-08-05 42392]
.
.
— Övriga tjänster/drivrutiner i minnet —
.
*Deregistered* - CLKMDRV10_38F51D56
.
Innehåll i mappen 'Schemalagda aktiviteter':
.
2012-10-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 15:11]
.
2012-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34]
.
2012-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34]
.
2012-10-17 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2011-08-23 09:11]
.
2012-10-16 c:\windows\Tasks\HPCeeScheduleForAnnelie.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-09-09 21:39 244672 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-09-09 21:39 244672 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-09-09 21:39 244672 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727_1\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopFileLocked]
@="{C253B817-3A00-475f-A5A3-6F2DD704B48D}"
[HKEY_CLASSES_ROOT\CLSID\{C253B817-3A00-475f-A5A3-6F2DD704B48D}]
2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSynced]
@="{19ACC806-F7AA-46AA-A80A-726A07CA6637}"
[HKEY_CLASSES_ROOT\CLSID\{19ACC806-F7AA-46AA-A80A-726A07CA6637}]
2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSyncedCollabs]
@="{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}"
[HKEY_CLASSES_ROOT\CLSID\{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}]
2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSynced]
@="{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}"
[HKEY_CLASSES_ROOT\CLSID\{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}]
2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSyncedCollab]
@="{9E48C232-F601-4E41-BB3E-16CBAF317AA4}"
[HKEY_CLASSES_ROOT\CLSID\{9E48C232-F601-4E41-BB3E-16CBAF317AA4}]
2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:11 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-08-16 1424896]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2011-09-16 57928]
"SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-12-19 44880]
"BoxSyncHelper"="c:\program files\Box Sync\BoxSyncHelper.exe" [2012-09-04 393216]
"Net iD"="c:\program files\Net iD\iid.exe" [2012-03-07 110912]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-23 2184520]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]
.
——- Extra genomsökning ——-
.
uStart Page = hxxp://www.google.se/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files (x86)\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files (x86)\DAP\dapextie.htm
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Anpassa meny - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - c:\program files (x86)\DAP\dapextie2.htm
IE: E&xportera till Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Läs EXIF - c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: RF verktygsfält - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Spara formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
TCP: DhcpNameServer = 192.168.1.1
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll
FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gama&hl=sv
FF - ExtSQL: 2012-09-07 18:41; [removed]; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-09-08 20:45; {B728AB94-9BC7-49b7-B76A-422BB31B2FD0}; c:\program files (x86)\ArcSoft\Video Downloader\Plugin_FireFox
FF - ExtSQL: 2012-09-08 20:46; [removed]; c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension
FF - ExtSQL: 2012-09-09 11:57; {22119944-ED35-4ab1-910B-E619EA06A115}; c:\program files (x86)\Siber Systems\AI RoboForm\Firefox
FF - ExtSQL: 2012-09-09 16:41; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2012-09-09 21:01; {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}; c:\program files (x86)\DAP\DAPFireFox
FF - ExtSQL: 2012-09-23 18:51; {b64982b1-d112-42b5-b1e4-d3867c4533f8}; c:\programdata\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
——————— LÅSTA REGISTERNYCKLAR ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Sluttid: 2012-10-17 12:06:38
ComboFix-quarantined-files.txt 2012-10-17 10:06
.
Före genomsökningen: 808 284 905 472 byte ledigt
Efter genomsökningen: 809 125 609 472 byte ledigt
.
- - End Of File - - 675AD286C7501C239974B654C77169A2
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    ClearJavaCache::

    File::
    C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    Folder::
    c:\users\Annelie\AppData\Roaming\Babylon
    c:\programdata\Babylon

    Driver::
    Browser Manager

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Please post the new ComboFix log and let me know how your system is running now. :)
Hi, here it is! I had to restart the computer after Combofix's restart, as neither Firefofox or IE worked. Neither did Avast. ComboFix 12-10-16.02 - Annelie 2012-10-17 18:01:15.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.5566 [GMT 2:00] Körs från: c:\users\Annelie\Desktop\ComboFix.exe Kommandoväxlar som använts :: c:\users\Annelie\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\programdata\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe" . . ((((((((((((((((((((((((((((((((((((((( Andra raderingar )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Babylon c:\programdata\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe c:\users\Annelie\AppData\Roaming\Babylon c:\users\Annelie\AppData\Roaming\Babylon\log_file.txt . . ((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_Browser Manager . . (((((((((((((((((((((((( Filer skapade från 2012-09-17 till 2012-10-17 )))))))))))))))))))))))))))))) . . 2012-10-17 16:08 . 2012-10-17 16:08 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-17 13:43 . 2012-10-17 13:43 ——– d—–w- c:\users\Annelie\AppData\Local\Waveface 2012-10-17 13:41 . 2012-10-17 13:41 ——– d—–w- c:\users\Annelie\AppData\Roaming\Waveface 2012-10-17 13:40 . 2012-10-17 13:40 ——– d—–w- c:\programdata\{2839f3a1-39f2-4651-b4b7-da815f8e4968} 2012-10-17 13:40 . 2012-10-17 13:41 ——– d—–w- c:\program files (x86)\WavefaceStation 2012-10-16 08:38 . 2012-08-30 07:27 9308616 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6363B6DA-3D35-4086-AECE-2BC5B0F751DE}\mpengine.dll 2012-10-15 18:30 . 2012-10-16 05:42 ——– d—–w- c:\users\Annelie\AppData\Local\Apple Computer 2012-10-13 22:27 . 2012-10-13 22:27 ——– d—–w- c:\users\Annelie\AppData\Local\ArcSoft 2012-10-13 21:59 . 2012-10-13 21:59 ——– d—–w- c:\users\Annelie\AppData\Local\Broadcom 2012-10-13 21:59 . 2012-10-13 21:59 ——– d—–w- c:\users\Annelie\AppData\Local\ATI 2012-10-13 21:58 . 2012-10-13 21:58 ——– d—–w- c:\users\Annelie\AppData\Local\Adobe 2012-10-13 21:55 . 2012-10-13 21:55 ——– d—–w- c:\users\Annelie\AppData\Local\Box Sync 2012-10-10 06:07 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll 2012-10-10 06:07 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll 2012-10-10 06:07 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll 2012-10-10 06:07 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-10 06:07 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-10 06:07 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-10-10 06:07 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-10-10 06:07 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-10-06 19:32 . 2012-10-06 21:37 ——– d—–w- c:\users\Annelie\AppData\Local\Microsoft Games 2012-10-06 17:49 . 2012-10-06 17:49 ——– d—–w- c:\programdata\CNO 2012-10-06 17:45 . 2012-10-06 17:45 ——– d—–w- c:\program files\anysee 2012-10-06 17:45 . 2012-10-06 17:48 ——– d—–w- c:\program files (x86)\anysee 2012-10-06 16:05 . 2012-10-06 16:05 ——– d—–w- c:\program files\PlayReady 2012-10-06 13:58 . 2012-03-16 14:21 6949596 —-a-w- c:\windows\TranscendElite.exe 2012-10-05 16:42 . 2012-10-16 18:13 ——– d—–w- c:\users\Annelie\AppData\Roaming\vlc 2012-10-05 16:41 . 2012-10-05 16:41 ——– d—–w- c:\program files (x86)\VideoLAN 2012-10-03 12:57 . 2012-10-03 12:57 ——– d—–w- c:\program files\Canon 2012-10-03 12:56 . 2012-10-03 12:56 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information 2012-10-03 12:55 . 2012-10-03 12:55 ——– d—–w- c:\windows\system32\STRING 2012-10-03 12:55 . 2009-04-03 07:51 144384 —-a-w- c:\windows\system32\CNMN6UI.DLL 2012-10-03 12:55 . 2009-04-03 07:51 336896 —-a-w- c:\windows\system32\CNMN6PPM.DLL 2012-10-03 12:55 . 2012-10-03 12:55 ——– d—–w- c:\windows\system32\CHM 2012-09-30 18:26 . 2012-09-30 18:26 ——– d—–w- c:\windows\SysWow64\Adobe 2012-09-30 17:55 . 2012-09-30 17:55 ——– d—–w- c:\program files\Microsoft Silverlight 2012-09-30 17:55 . 2012-09-30 17:55 ——– d—–w- c:\program files (x86)\Microsoft Silverlight 2012-09-30 17:46 . 2012-09-30 17:45 916456 —-a-w- c:\windows\system32\deployJava1.dll 2012-09-30 17:46 . 2012-09-30 17:45 289768 —-a-w- c:\windows\system32\javaws.exe 2012-09-30 17:46 . 2012-09-30 17:45 1034216 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-09-30 17:45 . 2012-09-30 17:45 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2012-09-30 17:45 . 2012-09-30 17:45 189416 —-a-w- c:\windows\system32\javaw.exe 2012-09-30 17:45 . 2012-09-30 17:45 188904 —-a-w- c:\windows\system32\java.exe 2012-09-30 17:45 . 2012-09-30 17:45 ——– d—–w- c:\program files\Java 2012-09-29 23:40 . 2012-09-29 23:40 ——– d—–w- c:\users\Annelie\AppData\Roaming\CoSoSys 2012-09-26 08:25 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-25 09:36 . 2012-09-25 09:36 ——– d—–w- c:\users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2012-09-23 18:45 . 2012-09-23 18:45 ——– d—–w- c:\program files (x86)\jAlbum 2012-09-23 16:51 . 2012-10-11 02:41 ——– d—–w- c:\programdata\Browser Manager 2012-09-22 17:52 . 2012-10-17 16:11 29 —-a-w- c:\windows\SysWow64\TempWmicBatchFile.bat 2012-09-22 17:45 . 2012-09-22 17:52 ——– d—–w- C:\Prey 2012-09-22 14:55 . 2012-08-24 10:39 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-09-22 14:41 . 2012-09-23 16:51 ——– d—–w- c:\program files (x86)\ExpressFiles 2012-09-22 13:46 . 2012-09-22 13:46 ——– d—–w- c:\users\Annelie\AppData\Roaming\mediAvatar 2012-09-22 13:44 . 2012-09-22 14:51 ——– d—–w- c:\program files (x86)\MSECache 2012-09-22 13:43 . 2012-09-22 13:51 ——– d—–w- c:\program files (x86)\PowerPoint to Video Converter Personal 2012-09-22 13:43 . 2012-09-22 13:43 ——– d—–w- c:\programdata\mediAvatar 2012-09-22 13:35 . 2012-09-23 16:51 622 —-a-w- C:\user.js 2012-09-22 13:35 . 2012-09-22 13:35 ——– d—–w- c:\users\Annelie\AppData\Roaming\ExpressFiles 2012-09-22 13:19 . 2012-09-22 13:19 ——– d—–w- c:\program files (x86)\Sync Blocker 10.6 Release 1 2012-09-22 12:18 . 2012-09-22 12:18 ——– d—–w- c:\users\Annelie\AppData\Roaming\U3 2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\program files\Net iD 2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\program files (x86)\Net iD 2012-09-22 11:40 . 2012-03-07 11:28 244544 —-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npiidplg.dll 2012-09-22 11:40 . 2012-09-22 11:40 ——– d—–w- c:\users\Annelie\AppData\Roaming\iid 2012-09-22 10:22 . 2012-09-22 10:22 ——– d—–w- c:\program files (x86)\JuiceboxBuilder-Lite 2012-09-20 17:38 . 2012-10-17 15:11 ——– d—–w- c:\users\Annelie\.rainlendar2 2012-09-20 17:38 . 2012-09-20 17:38 ——– d—–w- c:\program files (x86)\Rainlendar2 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-09-20 16:40 . 2012-09-20 16:40 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-09-20 16:40 . 2012-09-20 16:40 ——– d—–w- c:\program files (x86)\QuickTime 2012-09-19 17:13 . 2012-09-19 17:13 ——– d—–w- c:\program files (x86)\BulletProof FTP Client 2009 2012-09-18 21:22 . 2012-09-18 21:22 ——– d—–w- c:\users\Annelie\Datamapp 2012-09-18 21:20 . 2012-09-18 21:20 ——– d—–w- c:\program files (x86)\IncrediMail 2012-09-18 16:37 . 2012-09-18 21:56 ——– d—–w- c:\users\Annelie\AppData\Local\IM 2012-09-18 16:06 . 2012-09-18 16:06 ——– d—–w- c:\program files (x86)\Jasc Software Inc 2012-09-18 16:03 . 2012-09-18 16:08 ——– d—–w- c:\program files (x86)\Paint Shop Pro 2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\Photo Notifier and Animation Creator 2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\program files (x86)\Photo Notifier and Animation Creator 2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\IM 2012-09-18 11:38 . 2012-09-18 11:38 ——– d—–w- c:\programdata\IncrediMail 2012-09-18 10:52 . 2012-09-18 10:52 ——– d—–w- c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} . . . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-10 14:36 . 2012-09-12 18:20 65309168 —-a-w- c:\windows\system32\MRT.exe 2012-10-09 15:11 . 2012-09-07 20:21 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-09 15:11 . 2011-10-25 00:53 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-10 15:54 . 2012-09-10 15:54 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2012-09-10 15:54 . 2012-09-10 15:54 346960 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-09-09 21:56 . 2012-09-09 21:56 34720 —-a-w- c:\windows\system32\LMIport.dll 2012-09-09 21:56 . 2012-09-09 21:56 87488 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-09-09 21:56 . 2012-09-09 21:56 80800 —-a-w- c:\windows\system32\LMIinit.dll 2012-09-09 19:01 . 2012-09-09 19:01 50688 —-a-w- c:\windows\SysWow64\wbhelp2.dll 2012-09-09 19:01 . 2012-09-09 19:01 479298 —-a-w- c:\windows\SysWow64\wbocx.ocx 2012-09-09 18:40 . 2012-09-09 18:42 84480 —-a-w- c:\windows\SysWow64\EasyHook32.dll 2012-09-09 18:40 . 2012-09-09 18:42 109216 —-a-w- c:\windows\SysWow64\EasyHook64.dll 2012-09-09 18:40 . 2012-09-09 18:40 172032 —-a-w- c:\windows\SysWow64\AniGIF.ocx 2012-09-09 09:55 . 2012-09-09 09:55 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-09-09 09:55 . 2012-09-08 23:45 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-09-07 15:16 . 2010-06-24 18:33 19720 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-08-22 18:12 . 2012-09-12 10:38 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 18:12 . 2012-09-12 10:38 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 18:12 . 2012-09-12 10:38 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 18:12 . 2012-09-12 10:38 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-21 11:01 . 2012-09-13 17:47 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-08-21 11:01 . 2012-09-09 22:14 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 11:01 . 2012-09-09 22:14 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2012-08-21 09:13 . 2012-09-07 15:38 359464 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-08-21 09:13 . 2012-09-07 15:38 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-08-21 09:13 . 2012-09-07 15:38 969200 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-08-21 09:13 . 2012-09-07 15:38 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-08-21 09:13 . 2012-09-07 15:38 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-08-21 09:13 . 2012-09-07 15:38 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-08-21 09:12 . 2012-09-07 15:37 41224 —-a-w- c:\windows\avastSS.scr 2012-08-21 09:12 . 2012-09-07 15:37 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-08-21 09:12 . 2012-07-15 06:04 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-08-20 17:38 . 2012-10-10 06:08 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-08-07 10:36 . 2012-09-09 20:39 35112 —-a-w- c:\windows\system32\drivers\teamviewervpn.sys 2012-08-02 17:58 . 2012-09-12 10:38 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-08-02 16:57 . 2012-09-12 10:38 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll . . (((((((((((((((((((((((((((((((((( Startpunkter i registret ))))))))))))))))))))))))))))))))))))))))))))))) . . *Not* tomma poster & legitima standardposter visas inte. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-10-17 15:19 220632 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-10-17 15:19 220632 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-10-17 15:19 220632 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}"="c:\program files (x86)\Pocket Watch" [X] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-09-09 109336] "SkyDrive"="c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2012-10-17 238552] "Rainlendar2"="c:\program files (x86)\Rainlendar2\Rainlendar2.exe" [2011-08-12 3820032] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280] "WavefaceStation"="c:\program files (x86)\WavefaceStation\StationSystemTray.exe" [2012-10-04 1836896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-29 343168] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-04-15 113288] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-08-16 75048] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-07-11 574008] "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728] "Net iD"="c:\program files (x86)\Net iD\iid.exe" [2012-03-07 100160] "anysee_TR"="c:\program files (x86)\anysee\anysee-TCSeries\anysee_TR.exe" [2011-04-04 1503744] "anysee CNO"="c:\program files (x86)\anysee\Driver\CNO.EXE" [2011-04-21 1323008] . c:\users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-8-27 26924984] EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-8-14 1014624] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BankID säkerhetsprogram.lnk - c:\program files (x86)\Personal\bin\Personal.exe [2012-9-9 1088920] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-8-25 1337632] Box Sync.lnk - c:\program files\Box Sync\BoxSync.exe [2012-9-4 8710144] HP Wireless Audio Manager.lnk - c:\program files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe [2011-9-22 742712] Telia AutoStore.lnk - c:\program files (x86)\Storegate\Autostore\AutoStore.exe [2009-11-3 832792] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll c:\progra~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R1 AMTBDA_P861F;anysee Capture Service;c:\windows\system32\DRIVERS\anyseeTU.SYS [2011-04-21 853632] R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/04/06 19:45;c:\program files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2011-02-25 241648] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Tjänsten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 136176] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008] R3 cpuz134;cpuz134;c:\users\Annelie\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 gupdatem;Tjänsten Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 136176] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-08-05 34200] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-10 114144] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-07 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 8704pdateService;Box Sync Auto-updater;c:\program files\Box Sync\UpdateService.exe [2012-09-04 8704] S2 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-03-19 43072] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-29 204288] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-01 1166848] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-08-21 71600] S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928] S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-08-16 227896] S2 HPPRXSVC;HPPRXSVC;c:\program files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-05 37432] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-27 30520] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-07-11 26680] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-08-24 13592] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-08 2375168] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-09-06 93696] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-09-09 375208] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-09-16 15928] S2 MongoDbForWaveface;MongoDB for Waveface;c:\program files (x86)\WavefaceStation\MongoDB\mongod.exe –logpath c:\program files (x86)\WavefaceStation\\log\MongoDB.log [x] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-08-24 2735528] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-22 2656280] S2 WavefaceStation;Waveface Station;c:\program files (x86)\WavefaceStation\Station.Service.exe [2012-10-04 342368] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-09-29 9981952] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-09-29 309248] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-06-07 231440] S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2011-08-25 133672] S3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2011-08-25 620072] S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys [2011-08-25 89640] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-08-25 39976] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-08-09 12289472] S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys [2011-09-06 44992] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-08-05 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-06-11 91648] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-06-11 208896] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-31 338536] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2012-08-07 35112] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2011-08-05 42392] . . — Övriga tjänster/drivrutiner i minnet — . *Deregistered* - CLKMDRV10_38F51D56 . Innehåll i mappen 'Schemalagda aktiviteter': . 2012-10-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 15:11] . 2012-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2012-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2012-10-17 c:\windows\Tasks\HP Photo Creations Communicator.job - c:\programdata\HP Photo Creations\Communicator.exe [2011-08-23 09:11] . 2012-10-16 c:\windows\Tasks\HPCeeScheduleForAnnelie.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-10-17 15:19 244696 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-10-17 15:19 244696 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-10-17 15:19 244696 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopFileLocked] @="{C253B817-3A00-475f-A5A3-6F2DD704B48D}" [HKEY_CLASSES_ROOT\CLSID\{C253B817-3A00-475f-A5A3-6F2DD704B48D}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSynced] @="{19ACC806-F7AA-46AA-A80A-726A07CA6637}" [HKEY_CLASSES_ROOT\CLSID\{19ACC806-F7AA-46AA-A80A-726A07CA6637}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopNotSyncedCollabs] @="{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}" [HKEY_CLASSES_ROOT\CLSID\{337D9DE0-3F8B-4430-AF0F-FFC24A95AE8F}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSynced] @="{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}" [HKEY_CLASSES_ROOT\CLSID\{B7AC9C6D-F15B-4B1A-A88D-F518D13861D9}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\000BoxDesktopSyncedCollab] @="{9E48C232-F601-4E41-BB3E-16CBAF317AA4}" [HKEY_CLASSES_ROOT\CLSID\{9E48C232-F601-4E41-BB3E-16CBAF317AA4}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-08-21 09:11 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-08-16 1424896] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2011-09-16 57928] "SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-12-19 44880] "BoxSyncHelper"="c:\program files\Box Sync\BoxSyncHelper.exe" [2012-09-04 393216] "Net iD"="c:\program files\Net iD\iid.exe" [2012-03-07 110912] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-23 2184520] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312] . ——- Extra genomsökning ——- . uStart Page = hxxp://www.google.se/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: &Clean Traces - c:\program files (x86)\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files (x86)\DAP\dapextie.htm IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Anpassa meny - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download &all with DAP - c:\program files (x86)\DAP\dapextie2.htm IE: E&xportera till Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fyll i formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Läs EXIF - c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm IE: RF verktygsfält - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Skicka bild till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Skicka sida till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: Spara formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html TCP: DhcpNameServer = 192.168.1.1 Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gama&hl=sv FF - ExtSQL: 2012-09-07 18:41; [removed]; c:\program files\AVAST Software\Avast\WebRep\FF FF - ExtSQL: 2012-09-08 20:45; {B728AB94-9BC7-49b7-B76A-422BB31B2FD0}; c:\program files (x86)\ArcSoft\Video Downloader\Plugin_FireFox FF - ExtSQL: 2012-09-08 20:46; [removed]; c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension FF - ExtSQL: 2012-09-09 11:57; {22119944-ED35-4ab1-910B-E619EA06A115}; c:\program files (x86)\Siber Systems\AI RoboForm\Firefox FF - ExtSQL: 2012-09-09 16:41; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - ExtSQL: 2012-09-09 21:01; {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}; c:\program files (x86)\DAP\DAPFireFox FF - ExtSQL: 2012-09-23 18:51; {b64982b1-d112-42b5-b1e4-d3867c4533f8}; c:\programdata\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension . . ——————— LÅSTA REGISTERNYCKLAR ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Andra processer som körs ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\ExpressFiles\EFUpdater.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe c:\program files (x86)\WavefaceStation\MongoDB\mongod.exe c:\program files (x86)\TeamViewer\Version7\TeamViewer.exe c:\program files (x86)\TeamViewer\Version7\tv_w32.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Sluttid: 2012-10-17 18:17:28 - datorn startades om. ComboFix-quarantined-files.txt 2012-10-17 16:17 ComboFix2.txt 2012-10-17 10:06 . Före genomsökningen: 810 129 547 264 byte ledigt Efter genomsökningen: 809 650 913 280 byte ledigt . - - End Of File - - D000051027FE724AD52C95A82B84FBEA
Hi,

I had to restart the computer after Combofix's restart, as neither Firefofox or IE worked. Neither did Avast.

Before you restarted your system did you get an error message or anything when trying to run these programs? What was it? How is your system running now?
Yes, the same error message for all of them. Stupid me didn't take either a prt sc or wrote down the message. My memory is too short, but it was something about register information that was said to be removed - it was very cryptic and even if it was written in Swedish, I didn't understand what it meant. Sorry! :(
Hi,

No problem…. :)

Did it look like this >>

" Illegal operation attempted on a registry key that has been marked for deletion "



How is your system running?
Yes, that's it, although it was in Swedish and probably a bad translation. Actually it's easier to understand in English, even for me. I've tested a lot of things, but it's still way too slow. Could I still have some junk, which isn't supposed to be in the computer? Or did I do something stupid, when I restarted?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI