This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New computer - slow Firefox browser [Solved]

51 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm the one who shall say THANK YOU! What would I do without you heroes at WhattheTech? :wub:

I thought I got rid of all the Babylon stuff by myself, but I saw a line somewhere in one of the log files. I hate when "they" add stuff, I don't want! I ALWAYS choose advanced installs, to be able to avoid Babylon, Ask, Chrome etc, but sometimes it slips in without me being able to say no.

Anyway - I did run a new OTL, but only got one txt file, as below.

OTL logfile created on: 2012-10-18 11:38:40 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Annelie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7,95 Gb Total Physical Memory | 5,43 Gb Available Physical Memory | 68,28% Memory free
15,90 Gb Paging File | 12,69 Gb Available in Paging File | 79,86% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,46 Gb Total Space | 752,59 Gb Free Space | 83,03% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 718,94 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
Drive E: | 24,76 Gb Total Space | 2,54 Gb Free Space | 10,25% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,47 Gb Free Space | 90,64% Space Free | Partition Type: FAT32

Computer Name: TERRA | User Name: Annelie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Users\Annelie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\WavefaceStation\StationSystemTray.exe (Waveface)
PRC - C:\Program Files (x86)\WavefaceStation\Station.Service.exe (Waveface)
PRC - C:\Program Files (x86)\ExpressFiles\EFUpdater.exe (http://www.express-files.com/)
PRC - C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe ()
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Personal\bin\Personal.exe (Technology Nexus AB)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe (Hewlett Packard)
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
PRC - C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WavefaceStation\fastJSON.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_sv_b77a5c561934e089\System.resources.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\CustomControls.dll ()
MOD - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNOPlugIns.DLL ()
MOD - C:\Program Files (x86)\anysee\anysee-TCSeries\RemoteAPI.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_sv_b77a5c561934e089\mscorlib.resources.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WavefaceStation) – C:\Program Files (x86)\WavefaceStation\Station.Service.exe (Waveface)
SRV - (MongoDbForWaveface) – C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe ()
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (#UpdateService) – C:\Program\Box Sync\UpdateService.exe (Box, Inc.)
SRV - (TeamViewer7) – C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (avast! Antivirus) – C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ADExchange) – C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
SRV - (HPPRXSVC) – C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (ISCTAgent) – C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
SRV - (AMPPALR3) – C:\Program\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV - (btwdins) – C:\Program\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (STacSV) – C:\Program\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (EvtEng) – C:\Program\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (MyWiFiDHCPDNS) – C:\Program\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) – C:\Program\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (BTHSSecurityMgr) – C:\Program\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (CLKMSVC10_38F51D56) – C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (CronService) – C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (wlcrasvc) – C:\Program\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AutoStore) – C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe (Storegate AB)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Program\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (teamviewervpn) – C:\Windows\SysNative\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ISCT) – C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV:64bit: - (bcbtums) – C:\Windows\SysNative\drivers\bcbtums.sys (Broadcom Corporation.)
DRV:64bit: - (BTWDPAN) – C:\Windows\SysNative\drivers\btwdpan.sys (Broadcom Corporation.)
DRV:64bit: - (btwampfl) – C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (iwdbus) – C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (intaud_WaveExtensible) – C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (AMTBDA_P861F) – C:\Windows\SysNative\drivers\anyseeTU.SYS (Windows ® Win 7 DDK provider)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://isearch.babylon.com/?q={searchTerms…0001a34516924f9
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l;=dis&o;=HPNTDF
IE - HKCU\..\SearchScopes\{56E6E967-99CE-49AA-BEFA-D546A9FC620C}: "URL" = http://www.google.com/search?hl=sv&q;={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?source=gama&hl;=sv"
FF - prefs.js..extensions.enabledAddons: [removed]:1.4
FF - prefs.js..extensions.enabledAddons: [removed]:1.6.2
FF - prefs.js..extensions.enabledAddons: [removed]:1.0.1004
FF - prefs.js..extensions.enabledAddons: [removed]:1.2
FF - prefs.js..extensions.enabledAddons: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.2.2
FF - prefs.js..extensions.enabledAddons: {37fa1426-b82d-11db-8314-0800200c9a66}:2.9.13
FF - prefs.js..extensions.enabledAddons: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:1.8.1
FF - prefs.js..extensions.enabledAddons: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledAddons: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.3
FF - prefs.js..extensions.enabledAddons: {ad48108d-92a6-4eb9-87e4-978aca1dbae4}:1.2.1
FF - prefs.js..extensions.enabledAddons: {d37dc5d0-431d-44e5-8c91-49419370caa1}:3.1.26
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-09-07 18:41:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2012-09-08 20:45:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2012-09-08 20:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2012-09-09 11:57:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-10-03 23:45:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012-09-22 13:40:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files (x86)\DAP\DAPFireFox [2012-09-09 21:01:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012-10-11 04:41:59 | 000,000,000 | —D | M]

[2012-09-07 17:20:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Extensions
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Flagfox) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2012-10-07 23:48:16 | 000,000,000 | —D | M] (Integrated Gmail) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2012-10-10 00:28:38 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2012-10-03 22:58:31 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (Capriza Highlighter) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-13 15:55:22 | 000,000,000 | —D | M] (Movable Firefox Button) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Stream Photo Collector) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 20:54:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions
[2012-10-03 20:54:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions\[removed]
[2012-10-13 15:55:22 | 000,003,323 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 22:52:57 | 000,330,316 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,031,657 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 23:04:16 | 000,107,457 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-07 23:48:15 | 000,318,404 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi
[2012-10-09 23:48:17 | 000,196,700 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
[2012-10-03 23:00:02 | 000,049,607 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
[2012-10-03 22:56:01 | 000,058,343 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}.xpi
[2012-10-03 23:00:51 | 000,269,659 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2012-10-03 21:19:09 | 000,292,116 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{ad48108d-92a6-4eb9-87e4-978aca1dbae4}.xpi
[2012-10-03 23:45:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\mozilla firefox\extensions
[2012-09-09 16:41:47 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-07-14 02:15:45 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012-03-07 13:28:56 | 000,244,544 | —- | M] (SecMaker AB) – C:\Program Files (x86)\mozilla firefox\plugins\npiidplg.dll
[2012-07-14 03:16:10 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2012-09-23 18:51:09 | 000,002,362 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012-07-14 03:16:10 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012-07-14 03:16:10 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2012-07-14 03:16:10 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2012-10-17 18:12:25 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~2\ArcSoft\VIDEOD~1\ARCURL~1.DLL (ArcSoft, Inc.)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BoxSyncHelper] C:\Program Files\Box Sync\BoxSyncHelper.exe (Box, Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Net iD] C:\Program Files\Net iD\iid.exe (SecMaker AB)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SetDefault] C:\Program\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [anysee CNO] C:\Program Files (x86)\anysee\Driver\CNO.EXE ()
O4 - HKLM..\Run: [anysee_TR] C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Net iD] C:\Program Files (x86)\Net iD\iid.exe (SecMaker AB)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}] C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WavefaceStation] C:\Program Files (x86)\WavefaceStation\StationSystemTray.exe (Waveface)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8:64bit: - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8:64bit: - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8:64bit: - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9:64bit: - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{50F2544E-8FAF-43BE-A514-305A16E9A702}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll) - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20 - AppInit_DLLs: (c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll) - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-06-25 12:42:32 | 000,000,090 | —- | M] () - H:\AUTORUN.INF – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012-10-18 11:28:39 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{B56FB05D-341B-49C2-9793-A23C91D5472F}
[2012-10-17 22:58:25 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C70A3BA8-9718-4B05-BB34-92656444EF41}
[2012-10-17 18:12:32 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012-10-17 17:12:43 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-enheter
[2012-10-17 15:43:58 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Waveface
[2012-10-17 15:41:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Waveface
[2012-10-17 15:40:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waveface Stream
[2012-10-17 15:40:43 | 000,000,000 | —D | C] – C:\ProgramData\{2839f3a1-39f2-4651-b4b7-da815f8e4968}
[2012-10-17 15:40:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\WavefaceStation
[2012-10-17 12:06:41 | 000,000,000 | —D | C] – C:\Windows\temp
[2012-10-17 11:54:54 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-10-17 11:54:54 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-10-17 11:54:54 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-10-17 11:54:42 | 000,000,000 | —D | C] – C:\Qoobox
[2012-10-17 11:54:19 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012-10-17 10:58:01 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{60A0D38B-99F7-4403-BB99-49DF8F8CE473}
[2012-10-17 00:07:08 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012-10-16 22:57:37 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{2B35FE23-52DE-429F-A037-1F0632188C18}
[2012-10-16 13:53:52 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Rudbeck
[2012-10-16 13:51:15 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\WtT
[2012-10-16 11:55:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 10:57:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{5D265361-FF3C-4189-A00D-271475F09B21}
[2012-10-15 20:30:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Apple Computer
[2012-10-15 15:48:02 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FCCBC759-B42A-4616-BD4D-3659ABC701EB}
[2012-10-14 16:28:12 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E20545B1-713E-42F9-A4C3-A1F0D699629E}
[2012-10-14 00:27:32 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ArcSoft
[2012-10-13 23:59:55 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Broadcom
[2012-10-13 23:59:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ATI
[2012-10-13 23:58:10 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Adobe
[2012-10-13 23:55:27 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Box Sync
[2012-10-13 17:21:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C0C090EB-A23A-4BF9-A1D8-F8A5386A8A8A}
[2012-10-13 05:20:52 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{72885B53-526B-4BFB-AC4F-E25F507D3700}
[2012-10-12 17:20:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FAE6970D-A62C-47C4-8264-5E5D3B6C943D}
[2012-10-11 17:01:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{73CAAC98-3D7C-46E6-B408-D15C7ABE0459}
[2012-10-11 05:00:42 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{88075DDB-E0D2-43C5-B7A1-6C2B58B8F53F}
[2012-10-10 08:10:37 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{83A549E5-8671-492E-BAB7-9D1938414656}
[2012-10-10 08:08:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012-10-10 08:08:39 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012-10-10 08:08:39 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012-10-10 08:08:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012-10-10 08:08:32 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012-10-10 08:08:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012-10-10 08:08:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012-10-10 08:08:31 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012-10-10 08:08:31 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012-10-10 08:08:31 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012-10-10 08:08:31 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012-10-10 08:08:31 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012-10-10 08:08:31 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012-10-10 08:08:31 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012-10-10 08:08:31 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012-10-10 08:08:31 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:30 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:29 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:27 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:27 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012-10-10 08:08:18 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012-10-10 08:07:46 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012-10-10 08:07:45 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012-10-09 13:29:21 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E858F3C5-DFEE-4555-BF8D-DB8F97ABF686}
[2012-10-09 01:28:58 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{04E091C2-3C96-4F67-8705-2502CEC7F7A5}
[2012-10-08 13:15:57 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{1DB5DB8D-DD8D-438A-827A-1CB5BE941881}
[2012-10-07 17:29:25 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6FF32FBD-70E4-460A-BF95-365B9BB04BB7}
[2012-10-07 00:27:56 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EA4A31EE-D720-472E-86FD-48DD64D8B1BF}
[2012-10-06 21:32:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Microsoft Games
[2012-10-06 19:49:56 | 000,000,000 | —D | C] – C:\ProgramData\CNO
[2012-10-06 19:46:38 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2012-10-06 19:46:38 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2012-10-06 19:46:32 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,091,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2012-10-06 19:46:32 | 000,068,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2012-10-06 19:46:32 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2012-10-06 19:46:32 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2012-10-06 19:46:31 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2012-10-06 19:46:31 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2012-10-06 19:46:29 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2012-10-06 19:46:29 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2012-10-06 19:46:28 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2012-10-06 19:46:28 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2012-10-06 19:46:27 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2012-10-06 19:46:27 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2012-10-06 19:46:25 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2012-10-06 19:46:25 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2012-10-06 19:46:22 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2012-10-06 19:46:22 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2012-10-06 19:46:17 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2012-10-06 19:46:17 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2012-10-06 19:46:16 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2012-10-06 19:46:16 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2012-10-06 19:46:15 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2012-10-06 19:46:15 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2012-10-06 19:46:15 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2012-10-06 19:46:15 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2012-10-06 19:46:13 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2012-10-06 19:46:13 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2012-10-06 19:46:13 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2012-10-06 19:46:13 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2012-10-06 19:46:12 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2012-10-06 19:46:12 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2012-10-06 19:46:12 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2012-10-06 19:46:12 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2012-10-06 19:45:18 | 000,000,000 | —D | C] – C:\Program Files\anysee
[2012-10-06 19:45:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anysee
[2012-10-06 19:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\anysee
[2012-10-06 18:05:19 | 000,000,000 | —D | C] – C:\Program Files\PlayReady
[2012-10-06 15:58:47 | 006,949,596 | —- | C] (Transcend Information Inc.) – C:\Windows\TranscendElite.exe
[2012-10-06 12:26:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE4EF6C4-BBC0-431D-83C5-C951A22E7064}
[2012-10-05 20:03:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{0616A02C-F253-4398-BC7D-74158EEACCDB}
[2012-10-05 18:42:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\vlc
[2012-10-05 18:41:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012-10-05 18:41:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2012-10-05 08:03:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{22F04A30-B228-42E1-9EDD-16EF8340B850}
[2012-10-04 15:38:53 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{BF4DB9ED-FCE8-4179-A695-6C949032B11D}
[2012-10-03 15:20:32 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Skrivare
[2012-10-03 15:13:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Windowstema
[2012-10-03 15:03:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series användarregistrering
[2012-10-03 15:01:55 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2012-10-03 14:59:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CD-LabelPrint
[2012-10-03 14:57:22 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-10-03 14:56:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series Manual
[2012-10-03 14:56:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series
[2012-10-03 14:56:14 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2012-10-03 14:55:27 | 000,336,896 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6PPM.DLL
[2012-10-03 14:55:27 | 000,144,384 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6UI.DLL
[2012-10-03 14:55:27 | 000,000,000 | —D | C] – C:\Windows\SysNative\STRING
[2012-10-03 14:55:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\CHM
[2012-10-03 12:33:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{4E194997-6236-473A-B619-25402D855A22}
[2012-10-02 13:03:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CA10A3F4-6E0C-4D5B-91AE-5CCAAEB8773E}
[2012-09-30 20:26:50 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012-09-30 19:55:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012-09-30 19:46:04 | 000,916,456 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:46:03 | 001,034,216 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:46:03 | 000,289,768 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:52 | 000,189,416 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:52 | 000,188,904 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-30 19:45:52 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:42 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012-09-30 16:37:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C8BF6A71-0870-47F4-9284-46C843ACA4E0}
[2012-09-30 01:40:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\CoSoSys
[2012-09-29 19:59:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6D457595-7AC5-4833-8E71-2E100597B4EC}
[2012-09-29 07:37:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{F2A0CF81-187B-46A0-A0D2-DD474F6079AD}
[2012-09-28 16:34:27 | 000,000,000 | —D | C] – C:\Windows\pss
[2012-09-28 14:36:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{90AFE95C-87F7-4163-8AFB-0C0AD93B5514}
[2012-09-27 13:03:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EB89FCB8-ACC7-41A5-B4F6-AB0FDD5BEF72}
[2012-09-26 23:04:38 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9A56696E-98C4-4132-B334-0096DE526580}
[2012-09-26 11:04:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D29C45A3-349E-4383-8CA5-83D76031C5C7}
[2012-09-26 10:25:26 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2012-09-25 23:03:51 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{149ABCCC-072B-48EC-967F-5E8AD0B61E14}
[2012-09-25 11:36:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012-09-25 11:03:40 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{2EF7B70F-7186-4A20-A98C-4A17B06D6CD5}
[2012-09-24 23:03:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{79F8482C-8295-4215-80CB-4BF8263BEEC0}
[2012-09-24 11:03:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9B8FAAC8-B88E-4EC8-A899-A2F6CEFAA5FA}
[2012-09-23 21:54:41 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6F949E0A-A0C7-4F2F-9A11-3E1B15275648}
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jAlbum
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\jAlbum
[2012-09-23 18:51:18 | 000,000,000 | —D | C] – C:\Users\Annelie\Start Menu
[2012-09-23 18:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012-09-23 09:54:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{B58A0859-5EFE-492F-845C-90007BCCDA76}
[2012-09-22 19:45:28 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prey
[2012-09-22 19:45:25 | 000,000,000 | —D | C] – C:\Prey
[2012-09-22 19:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012-09-22 16:56:11 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012-09-22 16:56:09 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012-09-22 16:56:08 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012-09-22 16:56:08 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012-09-22 16:56:08 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012-09-22 16:56:08 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012-09-22 16:56:08 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012-09-22 16:56:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012-09-22 16:56:05 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012-09-22 16:56:05 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012-09-22 16:56:05 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012-09-22 16:56:05 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012-09-22 16:56:03 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012-09-22 16:56:03 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012-09-22 16:56:03 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012-09-22 16:41:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\ExpressFiles
[2012-09-22 15:46:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\mediAvatar
[2012-09-22 15:46:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint to Video Converter Personal
[2012-09-22 15:44:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerPoint to Video Converter Personal
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\ProgramData\mediAvatar
[2012-09-22 15:35:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\ExpressFiles
[2012-09-22 15:19:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sync Blocker
[2012-09-22 15:19:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sync Blocker 10.6 Release 1
[2012-09-22 14:18:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\U3
[2012-09-22 13:40:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net iD
[2012-09-22 13:40:13 | 000,000,000 | —D | C] – C:\Program Files\Net iD
[2012-09-22 13:40:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Net iD
[2012-09-22 13:40:01 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\iid
[2012-09-22 12:32:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE3FC8FC-7AAC-47FA-9379-4930B3CDD718}
[2012-09-22 12:22:22 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\JuiceboxBuilder-Lite
[2012-09-22 12:22:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\JuiceboxBuilder-Lite
[2012-09-21 19:32:59 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{50C56335-D16F-4BC7-AB80-4054189A1C8D}
[2012-09-21 12:18:06 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\Facebook
[2012-09-21 11:57:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Hjälpredor
[2012-09-21 07:32:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3CEB44EE-BF26-42A3-9D83-BF9DC84E5475}
[2012-09-20 19:38:26 | 000,000,000 | —D | C] – C:\Users\Annelie\.rainlendar2
[2012-09-20 19:38:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2
[2012-09-20 19:38:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rainlendar2
[2012-09-20 18:42:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2012-09-20 18:40:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-09-20 18:40:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012-09-20 11:04:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE7A18BB-8103-4E54-AB62-30FB89E8B683}
[2012-09-19 23:04:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3375645B-1B73-4B95-814B-36CB8A9CB377}
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BulletProof FTP Client 2009
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\BulletProof FTP Client 2009
[2012-09-19 11:04:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D6FF1E5D-CB1B-4F4F-94E2-C1A316A86B39}
[2012-09-18 23:22:26 | 000,000,000 | —D | C] – C:\Users\Annelie\Datamapp
[2012-09-18 23:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\IncrediMail
[2012-09-18 18:37:43 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\IM
[2012-09-18 18:06:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jasc Software Inc
[2012-09-18 18:03:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jasc Software
[2012-09-18 18:03:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Paint Shop Pro
[2012-09-18 13:38:32 | 000,000,000 | —D | C] – C:\ProgramData\Photo Notifier and Animation Creator
[2012-09-18 13:38:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photo Notifier and Animation Creator
[2012-09-18 13:38:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail
[2012-09-18 13:38:01 | 000,000,000 | —D | C] – C:\ProgramData\IncrediMail
[2012-09-18 13:38:01 | 000,000,000 | —D | C] – C:\ProgramData\IM
[2012-09-18 13:32:23 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{7BAED964-D3F6-47D4-AA1F-779CC2AAC060}
[2012-09-18 12:52:36 | 000,000,000 | —D | C] – C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}

========== Files - Modified Within 30 Days ==========

[2012-10-18 11:44:27 | 000,000,029 | —- | M] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-10-18 11:34:00 | 000,000,342 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012-10-18 11:11:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-18 10:50:00 | 000,000,996 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-18 08:58:42 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-18 08:58:42 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-18 08:49:48 | 000,000,992 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-18 08:48:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-10-18 08:48:17 | 2106,478,591 | -HS- | M] () – C:\hiberfil.sys
[2012-10-17 23:09:07 | 000,034,309 | —- | M] () – C:\Users\Annelie\Desktop\bbk_resultat.jpg
[2012-10-17 18:12:25 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012-10-17 16:37:02 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012-10-17 15:40:42 | 001,599,908 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012-10-17 15:40:42 | 000,662,964 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2012-10-17 15:40:42 | 000,653,368 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012-10-17 15:40:42 | 000,142,686 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2012-10-17 15:40:42 | 000,122,252 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012-10-16 11:55:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 07:39:27 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAnnelie.job
[2012-10-13 15:59:17 | 001,573,176 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012-10-09 17:11:18 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012-10-09 17:11:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012-10-06 19:59:49 | 000,471,768 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012-10-05 18:41:34 | 000,000,027 | —- | M] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | M] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:11 | 001,613,970 | —- | M] () – C:\Users\Annelie\Documents\Firefox.png
[2012-10-03 07:12:23 | 000,000,181 | —- | M] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-30 19:45:46 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:44 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:45:44 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:45:44 | 000,289,768 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:44 | 000,189,416 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:44 | 000,188,904 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-29 19:58:22 | 000,000,141 | —- | M] () – C:\Users\Annelie\Desktop\Paypal.URL
[2012-09-27 23:32:19 | 000,001,264 | —- | M] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-27 23:03:38 | 000,000,286 | —- | M] () – C:\Windows\reimage.ini
[2012-09-23 18:51:13 | 000,000,622 | —- | M] () – C:\user.js
[2012-09-19 20:17:49 | 000,000,524 | —- | M] () – C:\Users\Annelie\Desktop\Dold.lnk

========== Files Created - No Company Name ==========

[2012-10-17 23:09:07 | 000,034,309 | —- | C] () – C:\Users\Annelie\Desktop\bbk_resultat.jpg
[2012-10-17 11:54:54 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-10-17 11:54:54 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-10-17 11:54:54 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-10-17 11:54:54 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-10-17 11:54:54 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-10-05 18:41:34 | 000,000,027 | —- | C] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | C] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:10 | 001,613,970 | —- | C] () – C:\Users\Annelie\Documents\Firefox.png
[2012-09-29 12:28:49 | 000,000,181 | —- | C] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-27 23:32:19 | 000,001,264 | —- | C] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-22 19:52:21 | 000,000,029 | —- | C] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-09-22 19:34:42 | 000,000,996 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-09-22 19:34:41 | 000,000,992 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-09-22 15:35:25 | 000,000,622 | —- | C] () – C:\user.js
[2012-09-22 12:22:21 | 000,001,014 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JuiceboxBuilder-Lite.lnk
[2012-09-19 20:17:49 | 000,000,524 | —- | C] () – C:\Users\Annelie\Desktop\Dold.lnk
[2012-09-18 18:37:14 | 000,002,036 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail.lnk
[2012-09-09 20:42:30 | 000,109,216 | —- | C] () – C:\Windows\SysWow64\EasyHook64.dll
[2012-09-09 20:42:30 | 000,084,480 | —- | C] () – C:\Windows\SysWow64\EasyHook32.dll
[2012-09-09 20:25:16 | 000,000,286 | —- | C] () – C:\Windows\reimage.ini
[2012-09-08 12:08:16 | 000,000,722 | —- | C] () – C:\Windows\ODBC.INI
[2012-09-08 02:09:38 | 000,007,609 | —- | C] () – C:\Users\Annelie\AppData\Local\Resmon.ResmonCfg
[2012-04-07 04:38:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012-04-07 04:28:35 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2012-04-07 04:26:31 | 001,599,908 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011-10-02 07:16:48 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011-09-21 09:07:02 | 004,409,072 | —- | C] () – C:\Windows\SysWow64\vspdfx.dll
[2011-08-09 18:30:04 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011-08-09 18:30:02 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011-08-09 18:30:02 | 000,216,000 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011-08-09 18:23:26 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2011-08-09 17:58:38 | 013,903,872 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011-03-17 23:51:46 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012-06-09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012-06-09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009-07-14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010-11-21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009-07-14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012-09-08 20:30:09 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Acoustica
[2012-09-09 13:50:34 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Age of Japan II
[2012-09-08 22:36:57 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Ashampoo
[2012-09-08 22:01:48 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Ashampoo Slideshow Studio HD 2
[2012-09-08 23:03:23 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Axialis
[2012-09-15 22:05:08 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Box Desktop
[2012-10-18 11:01:27 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Box Sync
[2012-09-25 11:36:33 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012-09-30 01:40:05 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\CoSoSys
[2012-10-18 08:56:14 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Dropbox
[2012-09-10 22:07:01 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Easy Watermark Studio
[2012-09-22 15:35:15 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\ExpressFiles
[2012-07-15 08:16:22 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\IDT
[2012-09-22 13:40:10 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\iid
[2012-09-08 23:30:09 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\jAlbum
[2012-09-17 14:25:45 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Jasc
[2012-09-12 16:09:05 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\libimobiledevice
[2012-09-12 16:08:54 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\log
[2012-09-22 15:46:29 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mediAvatar
[2012-09-09 14:45:43 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Obsidium
[2012-09-08 14:37:03 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\PearlMountain
[2012-09-09 14:56:19 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Personal
[2012-09-09 14:25:22 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Pocket Watch, LLC
[2012-09-09 14:45:07 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Proxima Software
[2012-09-09 17:38:44 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\RoboForm
[2012-09-09 01:41:48 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Skerryvore Software
[2012-09-09 22:28:02 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Solveig Multimedia
[2012-09-09 19:19:11 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Spotify
[2012-07-15 05:41:26 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Synaptics
[2012-09-09 01:34:18 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Visan
[2012-10-18 02:13:10 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Waveface
[2012-07-15 05:42:47 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\WebApp
[2012-09-10 14:20:30 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011-10-25 02:10:43 | 000,003,783 | —- | M] () MD5=492CBE676A49756494ABAD49712DD36C – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_64117362cc347f06\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009-06-10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.BMP >
[2012-09-09 21:01:41 | 000,005,264 | —- | M] () MD5=0EF744B1DC357FDE44C78536A8108659 – C:\Program Files (x86)\DAP\Skins\dap\Explorer.bmp

< MD5 for: EXPLORER.EXE >
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011-10-25 02:19:36 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010-11-21 05:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011-10-25 02:19:36 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010-11-21 05:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2011-10-25 02:10:23 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\SysWOW64\sv-SE\explorer.exe.mui
[2011-10-25 02:10:23 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_5158254009e19998\explorer.exe.mui
[2011-10-25 02:10:31 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\sv-SE\explorer.exe.mui
[2011-10-25 02:10:31 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_47037aedd580d79d\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012-06-29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\erdnt\cache86\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012-08-24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012-08-24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012-08-24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012-06-29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012-08-24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010-11-21 05:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011-10-25 02:49:46 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012-06-29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2010-11-21 05:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012-06-29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011-10-25 02:49:46 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Program Files\Internet Explorer\fi-FI\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_a5e791a3ad57af35\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Program Files (x86)\Internet Explorer\da-DK\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_6b396f2ffbc32d02\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Program Files (x86)\Internet Explorer\fi-FI\iexplore.exe.mui
[2011-10-25 02:50:44 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_b03c3bf5e1b87130\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011-10-25 02:49:46 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Program Files (x86)\Internet Explorer\nb-NO\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_cc22808574537f93\iexplore.exe.mui
[2011-10-25 02:10:44 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=818C0D82C249F80EDB0C6FA5F06859F4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_f05f40a0bb42917b\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Program Files (x86)\Internet Explorer\sv-SE\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_f671dc8e34a59363\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Program Files\Internet Explorer\da-DK\iexplore.exe.mui
[2011-10-25 02:50:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_60e4c4ddc7626b07\iexplore.exe.mui
[2009-07-14 04:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Program Files\Internet Explorer\nb-NO\iexplore.exe.mui
[2011-10-25 02:51:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_c1cdd6333ff2bd98\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Program Files\Internet Explorer\sv-SE\iexplore.exe.mui
[2011-10-25 02:51:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_ec1d323c0044d168\iexplore.exe.mui
[2009-07-14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
[2011-10-25 02:10:44 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FCF681AEB95697B5E01832E11732A6CD – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_fab3eaf2efa35376\iexplore.exe.mui

< MD5 for: SERVICES >
[2012-09-11 21:37:51 | 000,271,966 | —- | M] () MD5=8BF884798E42CC785003876297E9D33F – C:\Kanaler\services
[2012-07-27 21:01:14 | 000,271,966 | —- | M] () MD5=8BF884798E42CC785003876297E9D33F – C:\Users\Annelie\Dropbox\TV\Kanaler\services
[2009-06-10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012-07-27 22:52:04 | 000,002,637 | —- | M] () MD5=016DFC4F3F133AE19338EECD1924886A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2012-07-27 22:52:04 | 000,002,970 | —- | M] () MD5=05A68D76420994EF8DF33184BFA98E04 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2012-07-27 22:51:54 | 000,002,555 | —- | M] () MD5=272301585AC133486E70228DA27659AC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2012-07-27 22:51:50 | 000,002,562 | —- | M] () MD5=27CE9BD3209B549BB776B8C877455A91 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2012-07-27 22:51:52 | 000,002,632 | —- | M] () MD5=2998A4AE8D0EF5122CCB985CF7E9D9D3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2012-07-27 22:51:52 | 000,002,545 | —- | M] () MD5=2EEC9DDBD0B4EE5F65532322C383938A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,629 | —- | M] () MD5=3A0082D76426A87FB4937D426C491C10 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2012-07-27 22:51:58 | 000,002,590 | —- | M] () MD5=448953BD0CF26CE03D9E7CC1A7B278BC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2012-07-27 22:51:42 | 000,002,605 | —- | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,679 | —- | M] () MD5=5DD2704563A6A79C466E44CD966B2655 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2012-07-27 22:51:40 | 000,002,711 | —- | M] () MD5=6B0E7B068BD530B8FCEBC04CC8844AA9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012-07-27 22:52:02 | 000,002,582 | —- | M] () MD5=797FC263D59784AD1498560C34FA7DA1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2012-07-27 22:51:38 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2012-07-27 22:51:50 | 000,002,634 | —- | M] () MD5=912DD5C0C7C8D7572AD598414D56E24A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx
[2012-07-27 22:51:40 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2012-07-27 22:52:06 | 000,002,638 | —- | M] () MD5=C2C37202B0E55877A64ADDBDE738284E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2012-07-27 22:51:56 | 000,002,589 | —- | M] () MD5=C313AD3602D4965A1918E86B9F3E84CF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2012-07-27 22:52:06 | 000,002,609 | —- | M] () MD5=C7FA88C21103C70826F274A0E865AEDF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2012-07-27 22:52:08 | 000,002,576 | —- | M] () MD5=D27D52045EB6A2EE031F7D2EA0349BC3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2012-07-27 22:51:46 | 000,002,560 | —- | M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2012-07-27 22:52:00 | 000,002,588 | —- | M] () MD5=DB216743CDE75637621E2FD39431BBD4 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2012-07-27 22:51:44 | 000,002,620 | —- | M] () MD5=DCF7A8843832327386B81ABD189AC236 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2012-07-27 22:52:00 | 000,002,997 | —- | M] () MD5=DD3F4DAF426555D8D85FF4D7C5A04F37 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2010-11-16 06:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2012-07-27 22:51:48 | 000,002,599 | —- | M] () MD5=F09D769A94767C3C7E7015A5C6C99A39 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2012-07-27 22:51:46 | 000,002,628 | —- | M] () MD5=F844D742DB53C7D671BF7ED6517414D1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2012-07-27 22:51:44 | 000,002,582 | —- | M] () MD5=FED4BDA3B6A9EB9DB59C254D8C987495 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx

< MD5 for: SERVICES.ASFX1 >
[2010-11-16 06:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1

< MD5 for: SERVICES.ASFX10 >
[2010-11-16 06:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10

< MD5 for: SERVICES.ASFX11 >
[2010-11-16 06:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11

< MD5 for: SERVICES.ASFX12 >
[2010-11-16 06:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12

< MD5 for: SERVICES.ASFX13 >
[2010-11-16 06:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13

< MD5 for: SERVICES.ASFX14 >
[2010-11-16 06:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14

< MD5 for: SERVICES.ASFX15 >
[2010-11-16 06:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15

< MD5 for: SERVICES.ASFX16 >
[2010-11-16 06:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16

< MD5 for: SERVICES.ASFX17 >
[2010-11-16 06:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17

< MD5 for: SERVICES.ASFX18 >
[2010-11-16 06:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18

< MD5 for: SERVICES.ASFX19 >
[2010-11-16 06:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19

< MD5 for: SERVICES.ASFX2 >
[2010-11-16 06:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2

< MD5 for: SERVICES.ASFX20 >
[2010-11-16 06:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20

< MD5 for: SERVICES.ASFX21 >
[2010-11-16 06:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21

< MD5 for: SERVICES.ASFX22 >
[2010-11-16 06:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22

< MD5 for: SERVICES.ASFX23 >
[2010-11-16 06:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23

< MD5 for: SERVICES.ASFX24 >
[2010-11-16 06:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24

< MD5 for: SERVICES.ASFX25 >
[2010-11-16 06:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25

< MD5 for: SERVICES.ASFX3 >
[2010-11-16 06:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3

< MD5 for: SERVICES.ASFX4 >
[2010-11-16 06:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4

< MD5 for: SERVICES.ASFX5 >
[2010-11-16 06:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5

< MD5 for: SERVICES.ASFX6 >
[2010-11-16 06:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6

< MD5 for: SERVICES.ASFX7 >
[2010-11-16 06:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7

< MD5 for: SERVICES.ASFX8 >
[2010-11-16 06:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8

< MD5 for: SERVICES.ASFX9 >
[2010-11-16 06:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9

< MD5 for: SERVICES.CFG >
[2012-07-27 22:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010-11-16 06:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.CNF >
[1999-11-21 20:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\250 alpen\_vti_pvt\services.cnf
[1999-11-21 20:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Bravenet Frontpage familjen\_vti_pvt\services.cnf
[2003-06-24 12:32:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Dandy\_vti_pvt\services.cnf
[2004-02-25 18:39:44 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Telia\Telia movies\_vti_pvt\services.cnf
[1999-11-21 21:17:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Users\Annelie\Documents\Mina webbplatser\Telia\Telia\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2011-10-25 02:10:27 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysNative\sv-SE\services.exe.mui
[2011-10-25 02:10:27 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_ab0e3ae787d43a6a\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009-07-14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.LOCKED >
[2012-09-11 21:37:51 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Kanaler\services.locked
[2012-07-27 21:01:14 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked

< MD5 for: SERVICES.LOCKED_BAK >
[2012-05-20 00:58:01 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked_bak

< MD5 for: SERVICES.LOCKED_ORG >
[2012-05-20 00:52:41 | 000,000,024 | —- | M] () MD5=10C2D48E10B28B6F7D568C9AE8284256 – C:\Users\Annelie\Dropbox\TV\Kanaler\services.locked_org

< MD5 for: SERVICES.MOF >
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2011-10-25 02:10:25 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysNative\sv-SE\services.msc
[2011-10-25 02:10:28 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysWOW64\sv-SE\services.msc
[2011-10-25 02:10:25 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_e5500ad35e3dd45d\services.msc
[2011-10-25 02:10:28 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_89316f4fa5e06327\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2011-10-25 02:10:43 | 000,008,194 | —- | M] () MD5=50E49C8E1C9BAD7D7C84DF88A7AC4A41 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_d61505583ec10672\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009-06-10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010-11-21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010-11-21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010-11-21 05:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011-10-25 02:10:25 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\SysNative\sv-SE\winlogon.exe.mui
[2011-10-25 02:10:25 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_sv-se_0e3a992362e4027d\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2011-10-25 02:10:27 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\SysNative\wbem\sv-SE\winlogon.mfl
[2011-10-25 02:10:27 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_69cbd726812dd878\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012-09-09 23:56:00 | 000,001,024 | —- | M] () – C:\.rnd
[2010-11-21 05:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012-10-17 18:17:29 | 000,042,039 | —- | M] () – C:\ComboFix.txt
[2012-09-14 08:48:50 | 000,000,045 | —- | M] () – C:\error.log
[2012-10-18 08:48:17 | 2106,478,591 | -HS- | M] () – C:\hiberfil.sys
[2012-09-08 20:15:07 | 000,013,042 | —- | M] () – C:\hwupgradewizard.log
[2012-10-18 08:48:23 | 4240,293,887 | -HS- | M] () – C:\pagefile.sys
[2012-09-23 18:51:13 | 000,000,622 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009-07-14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 22:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012-08-21 11:12:33 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010-11-10 11:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009-07-14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-07-15 08:15:47 | 000,000,221 | -HS- | M] () – C:\Users\Annelie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009-08-31 18:29:18 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Annelie\Desktop\ATF-Cleaner.exe
[2012-10-16 11:55:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:8FB6501C
@Alternate Data Stream - 201 bytes -> C:\ProgramData\Temp:BEF4B0E7
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:73F5BDC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:553CA6CA

< End of report >
Hi there,

Looks like we have a little bit more in there…

Run OTL.exe
  • Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL


    :Services

    :OTL
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://isearch.babylon.com/?q={searchTerms…0001a34516924f9
    IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
    [2012-09-23 18:51:09 | 000,002,362 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Please post the new OTL log and let me know how your system is running. :)
Hi Jeff,

The new OTL below - I also posted the log from the Run fix. I didn't know if you wanted that one too - better safe than sound - lol.


OTL logfile created on: 2012-10-18 16:35:02 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Annelie\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7,95 Gb Total Physical Memory | 5,26 Gb Available Physical Memory | 66,20% Memory free
15,90 Gb Paging File | 12,84 Gb Available in Paging File | 80,79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,46 Gb Total Space | 753,88 Gb Free Space | 83,17% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 718,94 Gb Free Space | 77,18% Space Free | Partition Type: NTFS
Drive E: | 24,76 Gb Total Space | 2,54 Gb Free Space | 10,25% Space Free | Partition Type: NTFS
Drive H: | 3,83 Gb Total Space | 3,47 Gb Free Space | 90,64% Space Free | Partition Type: FAT32

Computer Name: TERRA | User Name: Annelie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Users\Annelie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\WavefaceStation\StationSystemTray.exe (Waveface)
PRC - C:\Program Files (x86)\WavefaceStation\Station.Service.exe (Waveface)
PRC - C:\Program Files (x86)\ExpressFiles\EFUpdater.exe (http://www.express-files.com/)
PRC - C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe ()
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Personal\bin\Personal.exe (Technology Nexus AB)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe (Hewlett Packard)
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
PRC - C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WavefaceStation\fastJSON.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\CustomControls.dll ()
MOD - C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNO.exe ()
MOD - C:\Program Files (x86)\anysee\Driver\CNOPlugIns.DLL ()
MOD - C:\Program Files (x86)\anysee\anysee-TCSeries\RemoteAPI.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_sv_b77a5c561934e089\mscorlib.resources.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WavefaceStation) – C:\Program Files (x86)\WavefaceStation\Station.Service.exe (Waveface)
SRV - (MongoDbForWaveface) – C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe ()
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (#UpdateService) – C:\Program\Box Sync\UpdateService.exe (Box, Inc.)
SRV - (TeamViewer7) – C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (avast! Antivirus) – C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ADExchange) – C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft, Inc.)
SRV - (HPPRXSVC) – C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (ISCTAgent) – C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe ()
SRV - (AMPPALR3) – C:\Program\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV - (btwdins) – C:\Program\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (STacSV) – C:\Program\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (EvtEng) – C:\Program\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (MyWiFiDHCPDNS) – C:\Program\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV - (RegSrvc) – C:\Program\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (BTHSSecurityMgr) – C:\Program\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (CLKMSVC10_38F51D56) – C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe (CyberLink)
SRV - (CronService) – C:\Prey\platform\windows\cronsvc.exe (Fork Ltd.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (wlcrasvc) – C:\Program\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AutoStore) – C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe (Storegate AB)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) – C:\Program\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (teamviewervpn) – C:\Windows\SysNative\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ISCT) – C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV:64bit: - (bcbtums) – C:\Windows\SysNative\drivers\bcbtums.sys (Broadcom Corporation.)
DRV:64bit: - (BTWDPAN) – C:\Windows\SysNative\drivers\btwdpan.sys (Broadcom Corporation.)
DRV:64bit: - (btwampfl) – C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (iwdbus) – C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (intaud_WaveExtensible) – C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (AMTBDA_P861F) – C:\Windows\SysNative\drivers\anyseeTU.SYS (Windows ® Win 7 DDK provider)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCON/11
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCON/11
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{56E6E967-99CE-49AA-BEFA-D546A9FC620C}: "URL" = http://www.google.com/search?hl=sv&q;={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://se.search.yahoo.com/search?p={searc…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://sv.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?source=gama&hl;=sv"
FF - prefs.js..extensions.enabledAddons: [removed]:1.4
FF - prefs.js..extensions.enabledAddons: [removed]:1.6.2
FF - prefs.js..extensions.enabledAddons: [removed]:1.0.1004
FF - prefs.js..extensions.enabledAddons: [removed]:1.2
FF - prefs.js..extensions.enabledAddons: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.2.2
FF - prefs.js..extensions.enabledAddons: {37fa1426-b82d-11db-8314-0800200c9a66}:2.9.13
FF - prefs.js..extensions.enabledAddons: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:1.8.1
FF - prefs.js..extensions.enabledAddons: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledAddons: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.3
FF - prefs.js..extensions.enabledAddons: {ad48108d-92a6-4eb9-87e4-978aca1dbae4}:1.2.1
FF - prefs.js..extensions.enabledAddons: {d37dc5d0-431d-44e5-8c91-49419370caa1}:3.1.26
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-09-07 18:41:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2012-09-08 20:45:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2012-09-08 20:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2012-09-09 11:57:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-10-03 23:45:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012-09-22 13:40:10 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files (x86)\DAP\DAPFireFox [2012-09-09 21:01:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012-10-11 04:41:59 | 000,000,000 | —D | M]

[2012-09-07 17:20:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Extensions
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Flagfox) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2012-10-07 23:48:16 | 000,000,000 | —D | M] (Integrated Gmail) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2012-10-10 00:28:38 | 000,000,000 | —D | M] (WebMail Notifier) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2012-10-03 22:58:31 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2012-10-16 10:58:35 | 000,000,000 | —D | M] (Capriza Highlighter) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-13 15:55:22 | 000,000,000 | —D | M] (Movable Firefox Button) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,000,000 | —D | M] (Stream Photo Collector) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 20:54:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions
[2012-10-03 20:54:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\dkzhdk9v.default\extensions\[removed]
[2012-10-13 15:55:22 | 000,003,323 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 22:52:57 | 000,330,316 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-10 00:28:37 | 000,031,657 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-03 23:04:16 | 000,107,457 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]
[2012-10-07 23:48:15 | 000,318,404 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}.xpi
[2012-10-09 23:48:17 | 000,196,700 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
[2012-10-03 23:00:02 | 000,049,607 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
[2012-10-03 22:56:01 | 000,058,343 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}.xpi
[2012-10-03 23:00:51 | 000,269,659 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2012-10-03 21:19:09 | 000,292,116 | —- | M] () (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\{ad48108d-92a6-4eb9-87e4-978aca1dbae4}.xpi
[2012-10-03 23:45:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\mozilla firefox\extensions
[2012-09-09 16:41:47 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-07-14 02:15:45 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012-03-07 13:28:56 | 000,244,544 | —- | M] (SecMaker AB) – C:\Program Files (x86)\mozilla firefox\plugins\npiidplg.dll
[2012-07-14 03:16:10 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2012-07-14 03:16:10 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012-07-14 03:16:10 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2012-07-14 03:16:10 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2012-07-14 03:16:10 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2012-10-18 16:25:30 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~2\ArcSoft\VIDEOD~1\ARCURL~1.DLL (ArcSoft, Inc.)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm; Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\PROGRA~2\ArcSoft\RAWTHU~1\EXIFToolBar.dll (ArcSoft Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm; Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BoxSyncHelper] C:\Program Files\Box Sync\BoxSyncHelper.exe (Box, Inc.)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Net iD] C:\Program Files\Net iD\iid.exe (SecMaker AB)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SetDefault] C:\Program\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [anysee CNO] C:\Program Files (x86)\anysee\Driver\CNO.EXE ()
O4 - HKLM..\Run: [anysee_TR] C:\Program Files (x86)\anysee\anysee-TCSeries\anysee_TR.exe (Anysee)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Net iD] C:\Program Files (x86)\Net iD\iid.exe (SecMaker AB)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [{6CE6B062-EF6C-465c-AF36-96C67DAD3B65}] C:\Program Files (x86)\Pocket Watch, LLC\ActivePrint System\ActivePrintSystem.exe (Pocket Watch, LLC.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Annelie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WavefaceStation] C:\Program Files (x86)\WavefaceStation\StationSystemTray.exe (Waveface)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8:64bit: - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8:64bit: - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8:64bit: - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8:64bit: - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Skicka bild till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Skicka sida till &Bluetooth-enhet;… - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9:64bit: - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{50F2544E-8FAF-43BE-A514-305A16E9A702}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll) - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20 - AppInit_DLLs: (c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll) - c:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-06-25 12:42:32 | 000,000,090 | —- | M] () - H:\AUTORUN.INF – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012-10-18 16:24:48 | 000,000,000 | —D | C] – C:\_OTL
[2012-10-18 11:28:39 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{B56FB05D-341B-49C2-9793-A23C91D5472F}
[2012-10-17 22:58:25 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C70A3BA8-9718-4B05-BB34-92656444EF41}
[2012-10-17 18:12:32 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012-10-17 17:12:43 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-enheter
[2012-10-17 15:43:58 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Waveface
[2012-10-17 15:41:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Waveface
[2012-10-17 15:40:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waveface Stream
[2012-10-17 15:40:43 | 000,000,000 | —D | C] – C:\ProgramData\{2839f3a1-39f2-4651-b4b7-da815f8e4968}
[2012-10-17 15:40:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\WavefaceStation
[2012-10-17 12:06:41 | 000,000,000 | —D | C] – C:\Windows\temp
[2012-10-17 11:54:54 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-10-17 11:54:54 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-10-17 11:54:54 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-10-17 11:54:42 | 000,000,000 | —D | C] – C:\Qoobox
[2012-10-17 11:54:19 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012-10-17 10:58:01 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{60A0D38B-99F7-4403-BB99-49DF8F8CE473}
[2012-10-17 00:07:08 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012-10-16 22:57:37 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{2B35FE23-52DE-429F-A037-1F0632188C18}
[2012-10-16 13:53:52 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Rudbeck
[2012-10-16 13:51:15 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\WtT
[2012-10-16 11:55:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 10:57:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{5D265361-FF3C-4189-A00D-271475F09B21}
[2012-10-15 20:30:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Apple Computer
[2012-10-15 15:48:02 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FCCBC759-B42A-4616-BD4D-3659ABC701EB}
[2012-10-14 16:28:12 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E20545B1-713E-42F9-A4C3-A1F0D699629E}
[2012-10-14 00:27:32 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ArcSoft
[2012-10-13 23:59:55 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Broadcom
[2012-10-13 23:59:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ATI
[2012-10-13 23:58:10 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Adobe
[2012-10-13 23:55:27 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Box Sync
[2012-10-13 17:21:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C0C090EB-A23A-4BF9-A1D8-F8A5386A8A8A}
[2012-10-13 05:20:52 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{72885B53-526B-4BFB-AC4F-E25F507D3700}
[2012-10-12 17:20:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{FAE6970D-A62C-47C4-8264-5E5D3B6C943D}
[2012-10-11 17:01:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{73CAAC98-3D7C-46E6-B408-D15C7ABE0459}
[2012-10-11 05:00:42 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{88075DDB-E0D2-43C5-B7A1-6C2B58B8F53F}
[2012-10-10 08:10:37 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{83A549E5-8671-492E-BAB7-9D1938414656}
[2012-10-10 08:08:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012-10-10 08:08:39 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012-10-10 08:08:39 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012-10-10 08:08:33 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012-10-10 08:08:32 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012-10-10 08:08:32 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012-10-10 08:08:32 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012-10-10 08:08:31 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012-10-10 08:08:31 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012-10-10 08:08:31 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012-10-10 08:08:31 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012-10-10 08:08:31 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012-10-10 08:08:31 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012-10-10 08:08:31 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012-10-10 08:08:31 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012-10-10 08:08:31 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:30 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 08:08:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:29 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 08:08:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 08:08:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:27 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 08:08:27 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 08:08:27 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 08:08:26 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 08:08:26 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 08:08:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012-10-10 08:08:18 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012-10-10 08:07:46 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012-10-10 08:07:45 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012-10-09 13:29:21 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{E858F3C5-DFEE-4555-BF8D-DB8F97ABF686}
[2012-10-09 01:28:58 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{04E091C2-3C96-4F67-8705-2502CEC7F7A5}
[2012-10-08 13:15:57 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{1DB5DB8D-DD8D-438A-827A-1CB5BE941881}
[2012-10-07 17:29:25 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6FF32FBD-70E4-460A-BF95-365B9BB04BB7}
[2012-10-07 00:27:56 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EA4A31EE-D720-472E-86FD-48DD64D8B1BF}
[2012-10-06 21:32:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Microsoft Games
[2012-10-06 19:49:56 | 000,000,000 | —D | C] – C:\ProgramData\CNO
[2012-10-06 19:46:38 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2012-10-06 19:46:38 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2012-10-06 19:46:32 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2012-10-06 19:46:32 | 000,091,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2012-10-06 19:46:32 | 000,068,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2012-10-06 19:46:32 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2012-10-06 19:46:32 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2012-10-06 19:46:31 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2012-10-06 19:46:31 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2012-10-06 19:46:29 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2012-10-06 19:46:29 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2012-10-06 19:46:28 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2012-10-06 19:46:28 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2012-10-06 19:46:27 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2012-10-06 19:46:27 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2012-10-06 19:46:25 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2012-10-06 19:46:25 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2012-10-06 19:46:22 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2012-10-06 19:46:22 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2012-10-06 19:46:17 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2012-10-06 19:46:17 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2012-10-06 19:46:16 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2012-10-06 19:46:16 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2012-10-06 19:46:16 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2012-10-06 19:46:15 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2012-10-06 19:46:15 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2012-10-06 19:46:15 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2012-10-06 19:46:15 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2012-10-06 19:46:13 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2012-10-06 19:46:13 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2012-10-06 19:46:13 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2012-10-06 19:46:13 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2012-10-06 19:46:12 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2012-10-06 19:46:12 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2012-10-06 19:46:12 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2012-10-06 19:46:12 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2012-10-06 19:45:18 | 000,000,000 | —D | C] – C:\Program Files\anysee
[2012-10-06 19:45:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anysee
[2012-10-06 19:45:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\anysee
[2012-10-06 18:05:19 | 000,000,000 | —D | C] – C:\Program Files\PlayReady
[2012-10-06 15:58:47 | 006,949,596 | —- | C] (Transcend Information Inc.) – C:\Windows\TranscendElite.exe
[2012-10-06 12:26:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE4EF6C4-BBC0-431D-83C5-C951A22E7064}
[2012-10-05 20:03:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{0616A02C-F253-4398-BC7D-74158EEACCDB}
[2012-10-05 18:42:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\vlc
[2012-10-05 18:41:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012-10-05 18:41:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2012-10-05 08:03:03 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{22F04A30-B228-42E1-9EDD-16EF8340B850}
[2012-10-04 15:38:53 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{BF4DB9ED-FCE8-4179-A695-6C949032B11D}
[2012-10-03 15:20:32 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Skrivare
[2012-10-03 15:13:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Windowstema
[2012-10-03 15:03:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series användarregistrering
[2012-10-03 15:01:55 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2012-10-03 14:59:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CD-LabelPrint
[2012-10-03 14:57:22 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-10-03 14:56:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series Manual
[2012-10-03 14:56:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP640 series
[2012-10-03 14:56:14 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2012-10-03 14:55:27 | 000,336,896 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6PPM.DLL
[2012-10-03 14:55:27 | 000,144,384 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6UI.DLL
[2012-10-03 14:55:27 | 000,000,000 | —D | C] – C:\Windows\SysNative\STRING
[2012-10-03 14:55:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\CHM
[2012-10-03 12:33:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{4E194997-6236-473A-B619-25402D855A22}
[2012-10-02 13:03:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CA10A3F4-6E0C-4D5B-91AE-5CCAAEB8773E}
[2012-09-30 20:26:50 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012-09-30 19:55:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012-09-30 19:55:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012-09-30 19:46:04 | 000,916,456 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:46:03 | 001,034,216 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:46:03 | 000,289,768 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:52 | 000,189,416 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:52 | 000,188,904 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-30 19:45:52 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:42 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012-09-30 16:37:20 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{C8BF6A71-0870-47F4-9284-46C843ACA4E0}
[2012-09-30 01:40:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\CoSoSys
[2012-09-29 19:59:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6D457595-7AC5-4833-8E71-2E100597B4EC}
[2012-09-29 07:37:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{F2A0CF81-187B-46A0-A0D2-DD474F6079AD}
[2012-09-28 16:34:27 | 000,000,000 | —D | C] – C:\Windows\pss
[2012-09-28 14:36:04 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{90AFE95C-87F7-4163-8AFB-0C0AD93B5514}
[2012-09-27 13:03:36 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{EB89FCB8-ACC7-41A5-B4F6-AB0FDD5BEF72}
[2012-09-26 23:04:38 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9A56696E-98C4-4132-B334-0096DE526580}
[2012-09-26 11:04:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D29C45A3-349E-4383-8CA5-83D76031C5C7}
[2012-09-26 10:25:26 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OxpsConverter.exe
[2012-09-25 23:03:51 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{149ABCCC-072B-48EC-967F-5E8AD0B61E14}
[2012-09-25 11:36:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012-09-25 11:03:40 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{2EF7B70F-7186-4A20-A98C-4A17B06D6CD5}
[2012-09-24 23:03:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{79F8482C-8295-4215-80CB-4BF8263BEEC0}
[2012-09-24 11:03:05 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{9B8FAAC8-B88E-4EC8-A899-A2F6CEFAA5FA}
[2012-09-23 21:54:41 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{6F949E0A-A0C7-4F2F-9A11-3E1B15275648}
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jAlbum
[2012-09-23 20:45:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\jAlbum
[2012-09-23 18:51:18 | 000,000,000 | —D | C] – C:\Users\Annelie\Start Menu
[2012-09-23 18:51:13 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012-09-23 09:54:17 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{B58A0859-5EFE-492F-845C-90007BCCDA76}
[2012-09-22 19:45:28 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prey
[2012-09-22 19:45:25 | 000,000,000 | —D | C] – C:\Prey
[2012-09-22 19:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012-09-22 16:56:11 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012-09-22 16:56:09 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012-09-22 16:56:08 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012-09-22 16:56:08 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012-09-22 16:56:08 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012-09-22 16:56:08 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012-09-22 16:56:08 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012-09-22 16:56:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012-09-22 16:56:05 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012-09-22 16:56:05 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012-09-22 16:56:05 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012-09-22 16:56:05 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012-09-22 16:56:03 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012-09-22 16:56:03 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012-09-22 16:56:03 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012-09-22 16:41:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\ExpressFiles
[2012-09-22 15:46:29 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\mediAvatar
[2012-09-22 15:46:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint to Video Converter Personal
[2012-09-22 15:44:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerPoint to Video Converter Personal
[2012-09-22 15:43:51 | 000,000,000 | —D | C] – C:\ProgramData\mediAvatar
[2012-09-22 15:35:13 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\ExpressFiles
[2012-09-22 15:19:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sync Blocker
[2012-09-22 15:19:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sync Blocker 10.6 Release 1
[2012-09-22 14:18:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\U3
[2012-09-22 13:40:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net iD
[2012-09-22 13:40:13 | 000,000,000 | —D | C] – C:\Program Files\Net iD
[2012-09-22 13:40:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Net iD
[2012-09-22 13:40:01 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Roaming\iid
[2012-09-22 12:32:14 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE3FC8FC-7AAC-47FA-9379-4930B3CDD718}
[2012-09-22 12:22:22 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\JuiceboxBuilder-Lite
[2012-09-22 12:22:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\JuiceboxBuilder-Lite
[2012-09-21 19:32:59 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{50C56335-D16F-4BC7-AB80-4054189A1C8D}
[2012-09-21 12:18:06 | 000,000,000 | —D | C] – C:\Users\Annelie\Documents\Facebook
[2012-09-21 11:57:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Hjälpredor
[2012-09-21 07:32:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3CEB44EE-BF26-42A3-9D83-BF9DC84E5475}
[2012-09-20 19:38:26 | 000,000,000 | —D | C] – C:\Users\Annelie\.rainlendar2
[2012-09-20 19:38:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rainlendar2
[2012-09-20 19:38:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rainlendar2
[2012-09-20 18:42:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2012-09-20 18:40:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-09-20 18:40:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012-09-20 11:04:54 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{CE7A18BB-8103-4E54-AB62-30FB89E8B683}
[2012-09-19 23:04:44 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{3375645B-1B73-4B95-814B-36CB8A9CB377}
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BulletProof FTP Client 2009
[2012-09-19 19:13:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\BulletProof FTP Client 2009
[2012-09-19 11:04:33 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\{D6FF1E5D-CB1B-4F4F-94E2-C1A316A86B39}
[2012-09-18 23:22:26 | 000,000,000 | —D | C] – C:\Users\Annelie\Datamapp
[2012-09-18 23:20:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\IncrediMail
[2012-09-18 18:37:43 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\IM
[2012-09-18 18:06:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jasc Software Inc
[2012-09-18 18:03:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jasc Software
[2012-09-18 18:03:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Paint Shop Pro

========== Files - Modified Within 30 Days ==========

[2012-10-18 16:35:43 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-18 16:35:43 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-18 16:34:00 | 000,000,342 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012-10-18 16:28:00 | 000,000,992 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-18 16:27:35 | 000,000,029 | —- | M] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-10-18 16:26:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-10-18 16:26:26 | 2106,478,591 | -HS- | M] () – C:\hiberfil.sys
[2012-10-18 16:25:30 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012-10-18 16:11:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-18 15:50:00 | 000,000,996 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-17 23:09:07 | 000,034,309 | —- | M] () – C:\Users\Annelie\Desktop\bbk_resultat.jpg
[2012-10-17 16:37:02 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012-10-17 15:40:42 | 001,599,908 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012-10-17 15:40:42 | 000,662,964 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2012-10-17 15:40:42 | 000,653,368 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012-10-17 15:40:42 | 000,142,686 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2012-10-17 15:40:42 | 000,122,252 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012-10-16 11:55:14 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2012-10-16 07:39:27 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAnnelie.job
[2012-10-13 15:59:17 | 001,573,176 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012-10-09 17:11:18 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012-10-09 17:11:18 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012-10-06 19:59:49 | 000,471,768 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012-10-05 18:41:34 | 000,000,027 | —- | M] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | M] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:11 | 001,613,970 | —- | M] () – C:\Users\Annelie\Documents\Firefox.png
[2012-10-03 07:12:23 | 000,000,181 | —- | M] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-30 19:45:46 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012-09-30 19:45:44 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2012-09-30 19:45:44 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2012-09-30 19:45:44 | 000,289,768 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2012-09-30 19:45:44 | 000,189,416 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2012-09-30 19:45:44 | 000,188,904 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2012-09-29 19:58:22 | 000,000,141 | —- | M] () – C:\Users\Annelie\Desktop\Paypal.URL
[2012-09-27 23:32:19 | 000,001,264 | —- | M] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-27 23:03:38 | 000,000,286 | —- | M] () – C:\Windows\reimage.ini
[2012-09-23 18:51:13 | 000,000,622 | —- | M] () – C:\user.js
[2012-09-19 20:17:49 | 000,000,524 | —- | M] () – C:\Users\Annelie\Desktop\Dold.lnk

========== Files Created - No Company Name ==========

[2012-10-17 23:09:07 | 000,034,309 | —- | C] () – C:\Users\Annelie\Desktop\bbk_resultat.jpg
[2012-10-17 11:54:54 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-10-17 11:54:54 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-10-17 11:54:54 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-10-17 11:54:54 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-10-17 11:54:54 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-10-05 18:41:34 | 000,000,027 | —- | C] () – C:\Program Files\plugins.dat
[2012-10-04 00:20:36 | 000,000,833 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-03 20:53:14 | 001,163,509 | —- | C] () – C:\Users\Annelie\Documents\bookmarks-2012-10-03.json
[2012-10-03 20:47:10 | 001,613,970 | —- | C] () – C:\Users\Annelie\Documents\Firefox.png
[2012-09-29 12:28:49 | 000,000,181 | —- | C] () – C:\Users\Annelie\Desktop\Hitta iPhone.url
[2012-09-27 23:32:19 | 000,001,264 | —- | C] () – C:\Users\Annelie\Desktop\AVS Registry Cleaner.lnk
[2012-09-22 19:52:21 | 000,000,029 | —- | C] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2012-09-22 19:34:42 | 000,000,996 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-09-22 19:34:41 | 000,000,992 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-09-22 15:35:25 | 000,000,622 | —- | C] () – C:\user.js
[2012-09-22 12:22:21 | 000,001,014 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JuiceboxBuilder-Lite.lnk
[2012-09-19 20:17:49 | 000,000,524 | —- | C] () – C:\Users\Annelie\Desktop\Dold.lnk
[2012-09-18 18:37:14 | 000,002,036 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail.lnk
[2012-09-09 20:42:30 | 000,109,216 | —- | C] () – C:\Windows\SysWow64\EasyHook64.dll
[2012-09-09 20:42:30 | 000,084,480 | —- | C] () – C:\Windows\SysWow64\EasyHook32.dll
[2012-09-09 20:25:16 | 000,000,286 | —- | C] () – C:\Windows\reimage.ini
[2012-09-08 12:08:16 | 000,000,722 | —- | C] () – C:\Windows\ODBC.INI
[2012-09-08 02:09:38 | 000,007,609 | —- | C] () – C:\Users\Annelie\AppData\Local\Resmon.ResmonCfg
[2012-04-07 04:38:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012-04-07 04:28:35 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2012-04-07 04:26:31 | 001,599,908 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011-10-02 07:16:48 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011-09-21 09:07:02 | 004,409,072 | —- | C] () – C:\Windows\SysWow64\vspdfx.dll
[2011-08-09 18:30:04 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011-08-09 18:30:02 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011-08-09 18:30:02 | 000,216,000 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011-08-09 18:23:26 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2011-08-09 17:58:38 | 013,903,872 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011-03-17 23:51:46 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012-06-09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012-06-09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009-07-14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010-11-21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009-07-14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:8FB6501C
@Alternate Data Stream - 201 bytes -> C:\ProgramData\Temp:BEF4B0E7
@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:73F5BDC3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:553CA6CA

< End of report >


******************

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
IP-konfiguration f”r Windows
DNS-matcharens cacheminne har rensats.
C:\Users\Annelie\Desktop\cmd.bat deleted successfully.
C:\Users\Annelie\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Annelie
->Temp folder emptied: 88795 bytes
->Temporary Internet Files folder emptied: 1796152 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 122769975 bytes
->Flash cache emptied: 2083 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56478 bytes

User: Default User

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 119066386 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50550 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 233,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 10182012_162448

Files\Folders moved on Reboot…
C:\Users\Annelie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Annelie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T6IYBXPQ\sms_update[1].htm moved successfully.
C:\Users\Annelie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T6IYBXPQ\statCounter[1].htm moved successfully.
C:\Users\Annelie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6I9ZXJK8\windows_gadget[1].htm moved successfully.
C:\Users\Annelie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0N9LNJDY\stat_isp2[2].htm moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hi,

Well, it's hard to say how it runs. I've got to test some more things.

Internet via Firefox and IE is still bad, but I'll talk to my ADSL provider tomorrow, as a test gave a much too low speed, than I'm paying for. It's hard to get through to those guys at Telia, so if you don't hear anything from me, you know why.

Problems I found so far is what sometimes (not always) happens when I'm answering an email in Windows Live Mail. The translation of the message in the first picture says: The function you're trying to use, is on a CD-ROM or some other moveable disc, which is unavailable.

Then I'm supposed to use my Frontpage CD. I haven't done that yet. Wont do anything before we are ready.


***********************

Second picture showing shortcuts, which weren't there before. Can I just delete them?


***********************

Third picture - shall I remove the directories with the 'Moved files'? I saw that darned babylon there and felt like Delete at once.

Goodnight - it's tomorrow here now and it's time to hit the sack! :adios:
Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
OOOPS! Look what happened, when I tried to run AdwCleaner. I didn't dare to go on. I didn't close firewall or Avast. Should I have done that? If I had, could something bad happened? I restarted my router and got a better speed, but there is still something nasty going on. It's hard to say exactly what, but comparing to what is was earlier, there is a rather big difference. For the time being I'm working with photos - sorting and cleaning up. When I'm deleting a picture, it's still visible in the directory, but acually not there. I have to refresh to make the"text" disappear from the screen. A similar thing - I make a new directory, which is invisible till I refresh. Left side in the explorer moves up and down "by itself"!!! When I click on a directory, to be able to se the files to the right, left side suddenly slide. Most irritating - almost like someone else had access to my computer. I have blocked that, but who knows …….? Best regards Annelie

Attachments:

Hi, Very strange! Go ahead and run AdwCleaner. That is a false positive being picked up by Avast. Please post that log and we can continue from there. By the way….dont you have TeamViewer on your system?

Hi,

Very strange! Go ahead and run AdwCleaner. That is a false positive being picked up by Avast. Please post that log and we can continue from there.

By the way….dont you have TeamViewer on your system?


Yes I have it installed on this laptop. Used it last summer, when we were out sailing and I needed to get things from my home computer. Don't use that one any longer. Grandkids have taken it over.


More peculiar things happen.

1. When I start the laptop and even now and then during a session, first picture below is showing. It says something like the red text in it. (sometimes I simply translate word for word and guess that you, by experience understand).

2. Suddenly it's hardly possible to go on , wether it is opening a software or continue in it. Then - all of a sudden - everything works just fine.

3. I had some trouble starting AdwCleaner. I started it a couple of times and got different messages every time. Second to fourth pics show what I mean. Pic nr. 2 is the same as I posted earlier. I had to start it from within the Avast sandbox.

4. Some of the gadgets - 2 out of 4 - don't "disppear", when I'm opening a new window and I can't get them below either - last pic. Usually it's easy to get them "under".

Annelie

*************************


# AdwCleaner v2.005 - Logfile created 10/21/2012 at 12:24:47
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Annelie - TERRA
# Boot Mode : Normal
# Running from : C:\Users\Annelie\Desktop\AdwCleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\user.js
Folder Found : C:\ProgramData\Browser Manager

***** [Registry] *****

Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll
Key Found : HKCU\Software\BrowserMngr
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Found : HKLM\Software\Babylon
Key Found : HKLM\Software\BabylonToolbar
Key Found : HKLM\Software\BrowserMngr
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\Software\ImInstaller
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.babylon.com/?affID=116431&tt=120912_ccp_3812_4&babsrc=NT_ss&mntrId=f28598e40000000000001a34516924f9

-\\ Mozilla Firefox v14.0.1 (sv-SE)

Profile name : default-1349290452184 [Profil par défaut]
File : C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1904 octets] - [21/10/2012 12:24:47]

########## EOF - C:\AdwCleaner[R1].txt - [1964 octets] ##########
Hi, I am sorry to hear about the problems you are still having. Avast is just showing that it is a program that it does not recognize and that it wants you to run it from the Sandbox. You can do that or you can add it to your list of exceptions in Avast and that will allow adwcleaner to run uninterrupted. Either way, run AdwCleaner again and this time go ahead and when you run it select Delete instead of Search. Post the new log I am going to check on the other issues that you are having.
Of course the graphic thing didn't appear, after the restart and neither did the gadgets stay on top :yeah: I read trough the txt file and saw that babylon and chrome keys were removed. I simply hate that babylon - it must sneak in by itself - LOL. # AdwCleaner v2.005 - Logfile created 10/21/2012 at 16:33:01 # Updated 14/10/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Annelie - TERRA # Boot Mode : Normal # Running from : C:\Users\Annelie\Desktop\WhattheTech\AdwCleaner\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\ProgramData\Browser Manager File Deleted : C:\user.js ***** [Registry] ***** Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll Key Deleted : HKCU\Software\BrowserMngr Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\BabylonToolbar Key Deleted : HKLM\Software\BrowserMngr Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\ImInstaller Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.babylon.com/?affID=116431&tt=120912_ccp_3812_4&babsrc=NT_ss&mntrId=f28598e40000000000001a34516924f9 –> hxxp://www.google.com -\\ Mozilla Firefox v14.0.1 (sv-SE) Profile name : default-1349290452184 [Profil par défaut] File : C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [2033 octets] - [21/10/2012 12:24:47] AdwCleaner[R2].txt - [2116 octets] - [21/10/2012 16:31:31] AdwCleaner[S1].txt - [2119 octets] - [21/10/2012 16:33:01] ########## EOF - C:\AdwCleaner[S1].txt - [2179 octets] ##########
Nice…give it a good run around today and let me know what malware related problems you have left. If your system is running well we can remove our tools and you should be good to go. :)
The easiest way to reset services is to use this tool.

Download Windows Repair (all in one) from this site

Install and then run the program.

On the Start Repairs tab, select Advanced Mode and click Start
[external image: Posted Image]


Select the items Checked in the screen shot below (remove the checks from the rest ) and check Restart System When Finished.

[external image: Posted Image]
———-

Let me know if that fixed the problem with renaming your file.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI