This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer [Solved]

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My computer is both slow and fast. Suddenly, when it's working OK it seems to freeze and then it seems as someone is taking over, jumping to and fro. :wacko: Thanks in advance AnnelieP —————————————————————– DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2 Run by [removed] at 23:11:22 on 2013-04-17 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.5208 [GMT 2:00] . AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D} FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\system32\WLANExt.exe C:\Program Files\AVAST Software\Avast\afwServ.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe C:\Prey\platform\windows\cronsvc.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\ProgramData\DatacardService\HWDeviceService64.exe C:\ProgramData\DatacardService\DCSHelper.exe C:\Program Files\IB Updater\ExtensionUpdaterService.exe C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\igfxpers.exe C:\ProgramData\Mobile Broadband\OnlineUpdate\ouc.exe C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe C:\Program Files\Net iD\iid.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe C:\Program Files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Cyberlink\Shared files\brs.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\SysWOW64\RunDll32.exe C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE C:\Windows\System32\WUDFHost.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Program Files (x86)\ExpressFiles\EFUpdater.exe C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Windows\System32\WUDFHost.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\Explorer.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.se/ uSearch Bar = hxxp://www.bing.com BHO: IEPlugin Class: {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: ToolbarBHO Class: {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Advanced SystemCare Browser Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll BHO: SpeedBit Link Verification Helper: {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} - C:\Program Files (x86)\DAP\LinkVerifier.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll BHO: Download Accelerator Plus Integration: {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files (x86)\DAP\dapieloader.dll TB: &RoboForm; Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll TB: RAW Thumbnail Viewer: {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll TB: &RoboForm; Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" uRun: [AshSnap] C:\Program Files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe uRun: [Yontoo Desktop] "C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe mRun: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\Users\Annelie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPWIRE~1.LNK - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 uPolicies-Explorer: NoDriveAutoRun = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveAutoRun = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: &Clean; Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm IE: &Download; with &DAP; - C:\Program Files (x86)\DAP\dapextie.htm IE: &Verify; with DAP - C:\Program Files (x86)\DAP\dapverify.htm IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr/200 IE: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download &all; with DAP - C:\Program Files (x86)\DAP\dapextie2.htm IE: E&xportera; till Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm IE: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Skicka bild till &Bluetooth-enhet;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Skicka sida till &Bluetooth-enhet;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 80.251.201.177 80.251.201.178 TCP: Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2}\4556C69616741647567716970303D22363D24343D24364D24344D27303 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1} : NameServer = 195.67.199.18 195.67.199.19 TCP: Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337} : DHCPNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Users\Annelie\AppData\Local\Microsoft\Windows Sidebar\Gadgets\SkypeGadget1.4.gadget\wrapper\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll SSODL: WebCheck - LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-BHO: IB Updater: {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension64.dll x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-TB: &RoboForm; Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [Net iD] "C:\Program Files\Net iD\iid.exe" x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll x64-Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll x64-Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\ FF - prefs.js: browser.search.defaulturl - hxxp://go.speedbit.com/search.aspx?s=D3IaWIT8&q;= FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/ FF - prefs.js: keyword.URL - hxxp://se.search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=937811&p;= FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll FF - ExtSQL: 2013-02-28 11:38; {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}; C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi FF - ExtSQL: 2013-03-18 08:52; [removed]; C:\Program Files (x86)\DAP\daplinkchecker FF - ExtSQL: 2013-04-17 16:33; [removed]; C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed] . —- FIREFOX POLICIES —- FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: browser.turbo.enabled - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.chrome.favicons - false FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: content.notify.ontimer - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.switch.threshold - 750000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . . . . . FF - user.js: extentions.y2layers.installId - 95042356-c63e-423e-932e-8e59996e2905 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . ============= SERVICES / DRIVERS =============== . R0 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2013-2-21 22600] R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\System32\drivers\aswNdis.sys [2013-2-21 12368] R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\System32\drivers\aswNdis2.sys [2013-2-21 263096] R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-6 65336] R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-6 178624] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-25 55856] R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\drivers\SmartDefragDriver.sys [2013-2-16 17720] R1 aswFW;avast! TDI Firewall driver;C:\Windows\System32\drivers\aswFW.sys [2013-2-21 127136] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-9-7 1025808] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-9-7 377920] R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408] R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2012-12-7 465216] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-9-29 204288] R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-9-1 1166848] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-9-7 33400] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-9-7 80816] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-3-13 45248] R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-3-13 136912] R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928] R2 CronService;Cron Service for Prey;C:\Prey\platform\windows\cronsvc.exe [2011-2-15 19968] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-21 103992] R2 HPPRXSVC;HPPRXSVC;C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-5 37432] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-9-24 31040] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-7-11 26680] R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-4-7 13592] R2 IB Updater;IB Updater;C:\Program Files\IB Updater\ExtensionUpdaterService.exe [2013-1-8 188760] R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-4-7 2375168] R2 IMFservice;IMF Service;C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2013-4-7 821592] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160] R2 ISCTAgent;ISCT Always Updated Agent;C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-9-6 93696] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2013-4-7 167736] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-9-26 375728] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-9-9 72216] R2 MongoDbForWaveface;MongoDB for Waveface;C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe [2012-9-18 3939840] R2 SBUpd;SpeedBit Update;C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe [2013-2-27 1097848] R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-4 3560288] R2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-4-17 23552] R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-6-7 231440] R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2013-3-30 163368] R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2012-4-7 620072] R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2013-3-30 89640] R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2012-4-7 39976] R3 hpCMSrv;HP Connection Manager 4 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-9-13 1098296] R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2013-2-11 86016] R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);C:\Windows\System32\drivers\ICCWDT.sys [2010-8-18 26136] R3 IntcDAud;Intel® bildskärmsljud;C:\Windows\System32\drivers\IntcDAud.sys [2012-6-19 342528] R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-8-9 12289472] R3 ISCT;Intel® Smart Connect Technology Device Driver;C:\Windows\System32\drivers\ISCTD64.sys [2013-4-7 46568] R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-8-5 25496] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936] R3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2012-3-26 22528] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2012-5-10 97792] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2012-5-10 217600] R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-4-7 338536] R3 SBUpdd;SpeedBit UpdateD;C:\Program Files\Common Files\SpeedBit\SBUpdate\sbw.sys [2013-2-27 40856] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784] R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-8-5 42392] S1 AMTBDA_P861F;anysee Capture Service;C:\Windows\System32\drivers\anyseeTU.SYS [2011-4-21 853632] S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/12/30 01:13:23;C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2012-9-3 245264] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 Mobile Broadband. RunOuc;Mobile Broadband. OUC;C:\Program Files (x86)\Mobile Broadband\UpdateDog\ouc.exe [2013-2-11 246112] S2 WavefaceStation;Waveface Station;C:\Program Files (x86)\WavefaceStation\Station.Service.exe [2012-10-4 342368] S3 ADExchange;ArcSoft Exchange Service;C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-8-14 43624] S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\System32\drivers\ssadadb.sys [2011-5-13 36328] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2013-2-11 117248] S3 ewusbmbb;HUAWEI USB-WWAN miniport;C:\Windows\System32\drivers\ewusbwwan.sys [2013-2-11 421376] S3 FileMonitor;FileMonitor;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2013-4-7 21384] S3 hwdatacard;Huawei DataCard USB Modem and USB Serial;C:\Windows\System32\drivers\ewusbmdm.sys [2013-2-11 221312] S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-8-5 34200] S3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-7-28 340240] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-5 19456] S3 RegFilter;RegFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys [2013-4-7 33224] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-13 157672] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-13 16872] S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-13 177640] S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);C:\Windows\System32\drivers\ssadserd.sys [2011-5-13 146920] S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2012-9-9 35112] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-5 57856] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-12-5 30208] S3 UrlFilter;UrlFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys [2013-4-7 21904] S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-7 1255736] S3 wifimansvc;Wifi Man Service;C:\Program Files (x86)\Mobile Broadband\eap\wifimansvc.exe [2013-2-11 598528] S4 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-4-7 89600] S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-2 3064000] S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184] . =============== Created Last 30 ================ . 2013-04-17 20:08:31 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-17 17:20:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{F59D4887-FFCA-46DC-8012-E9BF48328FED} 2013-04-17 14:34:12 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C655596-E6FB-4AEB-B0C4-B30C4C7B2B14}\offreg.dll 2013-04-17 14:33:40 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Yontoo 2013-04-17 14:33:40 ——– d—–w- C:\Program Files (x86)\Yontoo 2013-04-17 05:21:28 9311288 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C655596-E6FB-4AEB-B0C4-B30C4C7B2B14}\mpengine.dll 2013-04-17 05:20:18 ——– d—–w- C:\Users\Annelie\AppData\Local\{19CAF461-D7D0-4AF7-A8C6-62878A880866} 2013-04-16 10:30:38 ——– d—–w- C:\Users\Annelie\AppData\Local\{BB4051EB-F67A-4758-A092-9917D270D138} 2013-04-15 22:30:12 ——– d—–w- C:\Users\Annelie\AppData\Local\{851CAB01-93DA-4D9D-AAFE-523D8B047480} 2013-04-15 11:59:38 ——– d—–w- C:\Users\Annelie\AppData\Local\Socusoft 2013-04-15 11:56:48 ——– d—–w- C:\Program Files\Wireless Transfer App for Windows 2013-04-15 10:29:59 ——– d—–w- C:\Users\Annelie\AppData\Local\{CC5A0E84-4F62-4425-BA11-7FCDC8B9BBF4} 2013-04-15 06:27:20 ——– d—–w- C:\Users\Annelie\AppData\Local\Adobe 2013-04-14 22:29:34 ——– d—–w- C:\Users\Annelie\AppData\Local\{012D66D1-7289-4E53-8152-F34380E3D869} 2013-04-14 13:44:28 ——– d—–w- C:\Users\Annelie\AppData\Local\CrashDumps 2013-04-14 12:16:50 ——– d—–w- C:\Users\Annelie\AppData\Local\Apple Computer 2013-04-14 12:07:11 ——– d—–w- C:\Users\Annelie\AppData\Local\Axialis 2013-04-14 10:29:09 ——– d—–w- C:\Users\Annelie\AppData\Local\{BB9C8926-6BA0-4DE2-AA4D-FDBF5050F28B} 2013-04-14 05:53:18 ——– d—–w- C:\Users\Annelie\AppData\Local\Broadcom 2013-04-14 05:42:54 ——– d—–w- C:\Users\Annelie\AppData\Local\ATI 2013-04-13 22:28:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{47A4EDEA-BEF3-4D8C-846F-FE9E831F029E} 2013-04-13 11:33:24 ——– d—–w- C:\ProgramData\YTD Video Downloader 2013-04-13 11:33:20 ——– d—–w- C:\Program Files (x86)\GreenTree Applications 2013-04-13 10:28:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{0355B154-D4BB-489A-BF2D-7AC2CF49992D} 2013-04-12 16:54:45 ——– d—–w- C:\Users\Annelie\AppData\Local\{C6948BDE-BB5F-493B-98F4-E3FA915E36D9} 2013-04-12 05:37:39 248112 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll 2013-04-12 05:37:38 ——– d—–w- C:\Program Files (x86)\Net iD 2013-04-12 04:54:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{F40B6487-9F7F-4D0B-9DF2-D25A0A80AE81} 2013-04-11 09:13:47 ——– d—–w- C:\Users\Annelie\AppData\Local\{23584057-75FE-4F88-B44C-2C2D28737B28} 2013-04-10 17:44:43 ——– d—–w- C:\Users\Annelie\AppData\Local\{6EC8C167-8F39-49BF-946F-3C50556F248A} 2013-04-10 05:44:30 ——– d—–w- C:\Users\Annelie\AppData\Local\{8ABE0295-F06A-4E14-8BC7-AFCFEF196E9E} 2013-04-09 21:32:00 1655656 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2013-04-09 21:31:32 3153408 —-a-w- C:\Windows\System32\win32k.sys 2013-04-09 21:31:07 6656 —-a-w- C:\Windows\SysWow64\apisetschema.dll 2013-04-09 21:31:07 5550424 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-04-09 21:31:07 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2013-04-09 21:31:07 3968856 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-04-09 21:31:07 3913560 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-04-09 21:31:07 112640 —-a-w- C:\Windows\System32\smss.exe 2013-04-09 21:30:38 223752 —-a-w- C:\Windows\System32\drivers\fvevol.sys 2013-04-09 10:08:35 ——– d—–w- C:\Users\Annelie\AppData\Local\{ED45BEC9-1E04-4FA5-B542-7263E1E6726B} 2013-04-09 08:52:55 ——– d—–w- C:\Program Files (x86)\Common Files\Telespree 2013-04-09 05:16:52 ——– d—–w- C:\Users\Annelie\AppData\Local\Hewlett-Packard_Developme 2013-04-09 04:36:31 ——– d—–w- C:\Users\Annelie\AppData\Local\Telespree 2013-04-08 18:36:27 ——– d—–w- C:\Users\Annelie\AppData\Local\{6828577F-BE2E-4711-8374-795AD2E22327} 2013-04-08 06:36:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{F88AFE6B-87D0-47D5-A883-9492B1739113} 2013-04-07 13:58:44 ——– d—–w- C:\Driver_W64 2013-04-07 13:51:12 46568 —-a-w- C:\Windows\System32\drivers\ISCTD64.sys 2013-04-07 13:46:57 64624 —-a-w- C:\Windows\System32\drivers\HECIx64.sys 2013-04-07 12:45:52 ——– d—–w- C:\Users\Annelie\AppData\Local\Incomedia 2013-04-07 12:45:33 ——– d—–w- C:\Program Files (x86)\WebSite X5 v10 - Free 2013-04-07 12:23:38 62464 —-a-w- C:\Windows\SysWow64\sevLock.dll 2013-04-07 12:20:15 290816 —-a-w- C:\Windows\SysWow64\cyviewer.ocx 2013-04-07 11:44:36 ——– d—–w- C:\Users\Annelie\AppData\Local\{FD206D64-BBE2-4622-90D7-8E18546219E2} 2013-04-06 18:47:22 ——– d—–w- C:\Users\Annelie\AppData\Roaming\TeraCopy 2013-04-06 18:47:12 ——– d—–w- C:\Program Files\TeraCopy 2013-04-06 18:45:38 ——– d—–w- C:\Users\Annelie\AppData\Local\{D1189CA0-86AF-45D4-A0A2-A154BF584182} 2013-04-06 18:31:11 ——– d—–w- C:\Program Files (x86)\GPLGS 2013-04-06 18:30:23 87152 —-a-w- C:\Windows\System32\cpwmon64.dll 2013-04-06 18:30:22 ——– d—–w- C:\Program Files (x86)\Acro Software 2013-04-06 17:22:08 ——– d—–w- C:\Program Files (x86)\CodeStuff 2013-04-06 16:14:54 ——– d—–w- C:\ProgramData\Innovative Solutions 2013-04-06 16:14:46 42496 —-a-w- C:\Windows\SysWow64\AdvUninstCPL.cpl 2013-04-06 16:14:42 ——– d—–w- C:\Program Files (x86)\Innovative Solutions 2013-04-06 15:41:14 ——– d—–w- C:\Program Files (x86)\Revo Uninstaller 2013-04-06 06:45:13 ——– d—–w- C:\Users\Annelie\AppData\Local\{BCB4065C-B68D-45DA-8470-7051C8A48300} 2013-04-05 18:44:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{9B5AE57A-1767-4B27-9940-BDB62E0CEA25} 2013-04-05 06:44:35 ——– d—–w- C:\Users\Annelie\AppData\Local\{AF5F1FB3-13B5-4797-9D00-AF41AFDF1FD7} 2013-04-04 09:17:34 ——– d—–w- C:\Users\Annelie\AppData\Local\{51B23B88-6F06-4786-BB74-E8F350BFCB29} 2013-04-03 21:14:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{BE9AD40C-B401-4220-AB90-9EFDB66921C6} 2013-04-03 11:17:02 ——– d–h–w- C:\$WINDOWS.~BT 2013-04-03 09:13:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{D8E0889C-294F-45F0-8948-3117517ADA94} 2013-04-02 21:13:23 ——– d—–w- C:\Users\Annelie\AppData\Local\{311CF1FD-A1B3-4986-88F3-1E94DEAF6784} 2013-04-02 09:13:11 ——– d—–w- C:\Users\Annelie\AppData\Local\{A08F9EB1-241B-407A-9BA1-69A3FA80C096} 2013-04-01 21:12:45 ——– d—–w- C:\Users\Annelie\AppData\Local\{01FC165F-E39C-4E19-A2C9-FB01C90FE090} 2013-04-01 19:52:24 ——– d–h–w- C:\SkyDriveTemp 2013-04-01 09:12:20 ——– d—–w- C:\Users\Annelie\AppData\Local\{D00B07CB-4968-4E23-8181-B373F54882C1} 2013-03-31 21:11:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{F0060E73-1F4B-4B67-AC80-E04749C30CD1} 2013-03-31 08:34:22 ——– d—–w- C:\Users\Annelie\AppData\Local\{528507FC-0ED3-46F3-A753-DE1DFC0FF740} 2013-03-30 13:37:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{A39DEE3F-A4D9-44DF-9DDF-A06FDC128A28} 2013-03-30 08:42:24 9856 —-a-w- C:\Windows\System32\drivers\wstbtndb.sys 2013-03-30 08:42:24 1459712 —-a-w- C:\Windows\System32\wstbtnrb.dll 2013-03-30 08:23:30 89640 —-a-w- C:\Windows\System32\drivers\btwdpan.sys 2013-03-30 08:23:06 144896 —-a-w- C:\Windows\System32\IntelOpenCL64.dll 2013-03-30 08:22:56 104448 —-a-w- C:\Windows\SysWow64\IntelOpenCL32.dll 2013-03-30 08:17:15 163368 —-a-w- C:\Windows\System32\drivers\bcbtums.sys 2013-03-30 08:16:14 ——– d—–w- C:\temp 2013-03-30 07:08:26 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Systweak 2013-03-30 07:08:22 ——– d—–w- C:\Program Files (x86)\Advanced Driver Updater 2013-03-29 21:26:09 ——– d—–w- C:\Users\Annelie\AppData\Local\{45067BC0-95FA-4F7D-82A0-7765C2B774F9} 2013-03-29 09:25:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{00455E4A-52E0-4CE9-91B0-C7773B922FC4} 2013-03-28 19:39:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{7E1AE44F-20EA-46CE-9024-3D20AFA70094} 2013-03-28 07:39:20 ——– d—–w- C:\Users\Annelie\AppData\Local\{FCD7397C-8553-4388-912D-0F48B23DE6F8} 2013-03-28 06:59:57 ——– d—–w- C:\Users\Annelie\LiveM 2013-03-28 06:48:54 ——– d—–w- C:\Program Files (x86)\jAlbum 2013-03-27 19:38:55 ——– d—–w- C:\Users\Annelie\AppData\Local\{6A9A61E4-BC1D-4147-93FE-B3A1612D1FD9} 2013-03-27 07:38:43 ——– d—–w- C:\Users\Annelie\AppData\Local\{916EA87E-8C2F-46B3-B549-2E721889F6C4} 2013-03-26 11:02:50 ——– d—–w- C:\Users\Annelie\AppData\Local\{7DC4D1C2-BDA5-4EFA-A57D-2755560B4C79} 2013-03-25 23:02:26 ——– d—–w- C:\Users\Annelie\AppData\Local\{45A4E852-05B8-4C29-9B27-9DC79090E8FC} 2013-03-25 11:02:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{FA0C27FA-977E-44B2-9DF9-C2E2BE4418AC} 2013-03-24 15:29:54 ——– d—–w- C:\Program Files (x86)\IZArc 2013-03-24 12:11:27 ——– d—–w- C:\Users\Annelie\AppData\Local\{A9BE8FA9-F45C-437C-82F3-19E6C47EE08F} 2013-03-24 06:01:48 ——– d—–w- C:\Program Files (x86)\Common Files\Spigot 2013-03-23 21:27:33 ——– d—–w- C:\Users\Annelie\AppData\Local\{96F87812-FA75-4674-AA8F-338E1CFFE9AC} 2013-03-23 08:15:08 ——– d—–w- C:\Users\Annelie\AppData\Local\{9F82DBAF-73B1-4126-B11D-7BC2FE5D8EFA} 2013-03-23 06:42:03 20520 —-a-w- C:\Windows\SysWow64\mcmpgvout.dll 2013-03-23 06:42:02 531496 —-a-w- C:\Windows\SysWow64\mcmpeg2mux.ax 2013-03-23 06:42:02 375848 —-a-w- C:\Windows\SysWow64\mcm2ve.ax 2013-03-23 06:42:02 257064 —-a-w- C:\Windows\SysWow64\mcl2ae.ax 2013-03-23 06:42:02 244776 —-a-w- C:\Windows\SysWow64\mcmpgaout.dll 2013-03-23 06:42:02 2140712 —-a-w- C:\Windows\SysWow64\mcmpgvout.004 2013-03-22 20:14:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{5BD097B5-3571-4F56-8BB0-729B2EB869C6} 2013-03-22 07:45:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{A21774E3-8BEC-4811-966F-F69D7577FA13} 2013-03-21 19:44:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{2C288774-F91F-41F1-B412-483EF1195ACA} 2013-03-21 07:44:42 ——– d—–w- C:\Users\Annelie\AppData\Local\{15CC27D3-62BE-4659-B8D2-AA1EDFB00C5B} 2013-03-20 19:44:18 ——– d—–w- C:\Users\Annelie\AppData\Local\{CE16B5DB-D6E7-41A6-9B61-9AC39C314926} 2013-03-20 07:44:06 ——– d—–w- C:\Users\Annelie\AppData\Local\{308E0939-3544-4826-BFB2-F99EC3182044} 2013-03-19 19:43:41 ——– d—–w- C:\Users\Annelie\AppData\Local\{C141CC6E-6BF4-4ECA-8E7F-262F37D2BBC4} 2013-03-19 07:43:16 ——– d—–w- C:\Users\Annelie\AppData\Local\{5F70A8FB-14EF-4938-A6BE-8A828FE9ED0A} . ==================== Find3M ==================== . 2013-04-17 21:01:37 29 —-a-w- C:\Windows\SysWow64\TempWmicBatchFile.bat 2013-04-12 05:28:54 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-12 05:28:54 691592 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-04-09 21:29:50 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2013-04-09 21:29:50 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe 2013-04-09 21:29:50 67072 —-a-w- C:\Windows\System32\iesetup.dll 2013-04-09 21:29:50 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-04-09 21:29:50 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-04-09 21:29:50 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-04-09 21:29:50 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-04-09 21:29:50 2706432 —-a-w- C:\Windows\System32\mshtml.tlb 2013-04-09 21:29:50 2240512 —-a-w- C:\Windows\System32\wininet.dll 2013-04-09 21:29:50 1766912 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-04-09 21:29:50 136704 —-a-w- C:\Windows\System32\iesysprep.dll 2013-04-09 21:29:50 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-03-12 23:36:19 474112 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-03-12 23:36:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-03-12 23:36:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-03-12 23:36:19 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll 2013-03-12 23:36:19 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-03-12 23:36:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-03-12 23:35:37 19968 —-a-w- C:\Windows\System32\drivers\usb8023.sys 2013-03-12 23:11:22 16486616 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2013-03-11 23:10:56 282744 ——w- C:\Windows\System32\MpSigStub.exe 2013-03-06 23:33:21 70992 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2013-03-06 23:33:21 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys 2013-03-06 23:33:21 178624 —-a-w- C:\Windows\System32\drivers\aswVmm.sys 2013-03-06 23:33:21 1025808 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2013-03-06 23:33:20 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2013-03-06 23:33:20 263096 —-a-w- C:\Windows\System32\drivers\aswNdis2.sys 2013-03-06 23:33:20 22600 —-a-w- C:\Windows\System32\drivers\aswKbd.sys 2013-03-06 23:33:20 127136 —-a-w- C:\Windows\System32\drivers\aswFW.sys 2013-03-06 23:32:51 41664 —-a-w- C:\Windows\avastSS.scr 2013-03-06 10:42:59 861088 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2013-03-06 10:42:59 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-02-27 13:37:12 53248 —-a-w- C:\Windows\SysWow64\CSVer.dll 2013-02-27 05:08:22 11525872 —-a-w- C:\Windows\System32\drivers\Netwsw00.sys 2013-02-15 14:17:04 16344 —-a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll . ============= FINISH: 23:12:02,60 ===============
Hello AnnelieP. Posted Image

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your DDS log now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
  • Please be patient. Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed all clear.
  • Please reply within 3 days to avoid closing this topic.
Hello AnnelieP.

Thank you for including your DDS log. DDS should have produced a second log named attach.txt and saved it to you desktop. If it is there, please submit this log to me. If you are unable to locate this report, please rerun DDS and submit both reports.

Please run the following scans

1. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]

2. Rogue Killer

Please download Rogue Killer from HERE.
  • Quit all running programs before continuing.
  • Double-click roguekiller.exe to run it.
  • Wait for the Prescan to finish.
  • Click Scan and wait for the scan to complete.
  • A report will be created and saved on your desktop.
  • Exit the program.
Copy and paste the RKreport.txt report into your next reply.

3. Security Check

Please download Security Check by screen317 from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt. This may take a few minutes.
Please copy and paste the contents of that document into your next reply.
Hello fbfbfb,

Sorry I didn't understand that both files should be inserted. As I'm not sure if I installed or updated anything since the last scan, so here's the result of a new one.

Am I supposed to turn off my automatic scans and updates from Avast and Windows update? Any other may be updating in the background. What to do with them?

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2
Run by [removed] at 11:22:44 on 2013-04-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.4893 [GMT 2:00]
.
AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
C:\Program Files (x86)\ExpressFiles\EFUpdater.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Prey\platform\windows\cronsvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\ProgramData\DatacardService\HWDeviceService64.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\IB Updater\ExtensionUpdaterService.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe
C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Net iD\iid.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
C:\Program Files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe
C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe
C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\WavefaceStation\Station.Service.exe
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Storegate\Autostore\AutoStoreSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\ProgramData\HP Photo Creations\Communicator.exe
C:\Program Files (x86)\Paint Shop Pro\psp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.se/
uSearch Bar = hxxp://www.bing.com
BHO: IEPlugin Class: {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Video Downloader\ArcURLRecord.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: ToolbarBHO Class: {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Advanced SystemCare Browser Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll
BHO: SpeedBit Link Verification Helper: {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} - C:\Program Files (x86)\DAP\LinkVerifier.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
BHO: Download Accelerator Plus Integration: {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files (x86)\DAP\dapieloader.dll
TB: &RoboForm Toolbar: {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: RAW Thumbnail Viewer: {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll
TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
uRun: [AshSnap] C:\Program Files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe
uRun: [Yontoo Desktop] "C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe"
uRun: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
StartupFolder: C:\Users\Annelie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPWIRE~1.LNK - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: &Clean Traces - C:\Program Files (x86)\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - C:\Program Files (x86)\DAP\dapextie.htm
IE: &Verify with DAP - C:\Program Files (x86)\DAP\dapverify.htm
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: Anpassa meny - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - C:\Program Files (x86)\DAP\dapextie2.htm
IE: E&xportera till Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000
IE: Fyll i formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Läs EXIF - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: RF verktygsfält - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Skicka bild till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Skicka sida till &Bluetooth-enhet… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Spara formulär - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{AB29AE7B-DE35-4B8B-8DA1-CCDEB39FA7A2}\4556C69616741647567716970303D22363D24343D24364D24344D27303 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1} : NameServer = 195.67.199.18 195.67.199.19
TCP: Interfaces\{CBA99CC7-3ED0-4448-A03D-5DB929F71337} : DHCPNameServer = [removed] [removed]
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Users\Annelie\AppData\Local\Microsoft\Windows Sidebar\Gadgets\SkypeGadget1.4.gadget\wrapper\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie.dll
SSODL: WebCheck -
LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: IB Updater: {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension64.dll
x64-BHO: RoboForm Toolbar Helper: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: &RoboForm Toolbar: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [Net iD] "C:\Program Files\Net iD\iid.exe"
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {724d43aa-0d85-11d4-9908-00400523e39a} - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll
x64-Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\Program Files (x86)\DAP\dapie64.dll
x64-Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\
FF - prefs.js: browser.search.defaulturl - hxxp://go.speedbit.com/search.aspx?s=D3IaWIT8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/
FF - prefs.js: keyword.URL - hxxp://se.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - ExtSQL: 2013-02-28 11:38; {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}; C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
FF - ExtSQL: 2013-03-18 08:52; [removed]; C:\Program Files (x86)\DAP\daplinkchecker
FF - ExtSQL: 2013-04-17 16:33; [removed]; C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
FF - ExtSQL: 2013-04-18 12:02; [removed]; C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
.
—- FIREFOX POLICIES —-
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
.
.
.
FF - user.js: extentions.y2layers.installId - 95042356-c63e-423e-932e-8e59996e2905
FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers
.
============= SERVICES / DRIVERS ===============
.
R0 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2013-2-21 22600]
R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\System32\drivers\aswNdis.sys [2013-2-21 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\System32\drivers\aswNdis2.sys [2013-2-21 263096]
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-6 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-6 178624]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-10-25 55856]
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\drivers\SmartDefragDriver.sys [2013-2-16 17720]
R1 aswFW;avast! TDI Firewall driver;C:\Windows\System32\drivers\aswFW.sys [2013-2-21 127136]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-9-7 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-9-7 377920]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2012-12-7 465216]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-9-29 204288]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-9-1 1166848]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-9-7 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-9-7 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-3-13 45248]
R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-3-13 136912]
R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928]
R2 CronService;Cron Service for Prey;C:\Prey\platform\windows\cronsvc.exe [2011-2-15 19968]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-5-21 103992]
R2 HPPRXSVC;HPPRXSVC;C:\Program Files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-5 37432]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-9-24 31040]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-7-11 26680]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-4-7 13592]
R2 IB Updater;IB Updater;C:\Program Files\IB Updater\ExtensionUpdaterService.exe [2013-1-8 188760]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-4-7 2375168]
R2 IMFservice;IMF Service;C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2013-4-7 821592]
R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 ISCTAgent;ISCT Always Updated Agent;C:\Program Files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-9-6 93696]
R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2013-4-7 167736]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-9-26 375728]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-9-9 72216]
R2 MongoDbForWaveface;MongoDB for Waveface;C:\Program Files (x86)\WavefaceStation\MongoDB\mongod.exe [2012-9-18 3939840]
R2 SBUpd;SpeedBit Update;C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe [2013-2-27 1097848]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-4 3560288]
R2 WavefaceStation;Waveface Station;C:\Program Files (x86)\WavefaceStation\Station.Service.exe [2012-10-4 342368]
R2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-4-17 23552]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-6-7 231440]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2013-3-30 163368]
R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2012-4-7 620072]
R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2013-3-30 89640]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2012-4-7 39976]
R3 FileMonitor;FileMonitor;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2013-4-7 21384]
R3 hpCMSrv;HP Connection Manager 4 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-9-13 1098296]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2013-2-11 86016]
R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);C:\Windows\System32\drivers\ICCWDT.sys [2010-8-18 26136]
R3 IntcDAud;Intel® bildskärmsljud;C:\Windows\System32\drivers\IntcDAud.sys [2012-6-19 342528]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-8-9 12289472]
R3 ISCT;Intel® Smart Connect Technology Device Driver;C:\Windows\System32\drivers\ISCTD64.sys [2013-4-7 46568]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-8-5 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-23 77936]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2012-5-10 97792]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2012-5-10 217600]
R3 RegFilter;RegFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys [2013-4-7 33224]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-4-7 338536]
R3 SBUpdd;SpeedBit UpdateD;C:\Program Files\Common Files\SpeedBit\SBUpdate\sbw.sys [2013-2-27 40856]
R3 UrlFilter;UrlFilter;C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys [2013-4-7 21904]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-8-5 42392]
S1 AMTBDA_P861F;anysee Capture Service;C:\Windows\System32\drivers\anyseeTU.SYS [2011-4-21 853632]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/12/30 01:13:23;C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2012-9-3 245264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Mobile Broadband. RunOuc;Mobile Broadband. OUC;C:\Program Files (x86)\Mobile Broadband\UpdateDog\ouc.exe [2013-2-11 246112]
S3 ADExchange;ArcSoft Exchange Service;C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-8-14 43624]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\System32\drivers\ssadadb.sys [2011-5-13 36328]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2013-2-11 117248]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;C:\Windows\System32\drivers\ewusbwwan.sys [2013-2-11 421376]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial;C:\Windows\System32\drivers\ewusbmdm.sys [2013-2-11 221312]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-8-5 34200]
S3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-7-28 340240]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2012-3-26 22528]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-5 19456]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\System32\drivers\ssadbus.sys [2011-5-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\System32\drivers\ssadmdfl.sys [2011-5-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\System32\drivers\ssadmdm.sys [2011-5-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);C:\Windows\System32\drivers\ssadserd.sys [2011-5-13 146920]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2012-9-9 35112]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-5 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-12-5 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-7 1255736]
S3 wifimansvc;Wifi Man Service;C:\Program Files (x86)\Mobile Broadband\eap\wifimansvc.exe [2013-2-11 598528]
S4 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-4-7 89600]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-2 3064000]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2013-04-21 05:57:57 ——– d—–w- C:\Users\Annelie\AppData\Local\{9DB4ECFF-AA44-4159-9CF3-69F41F6698E5}
2013-04-20 17:57:32 ——– d—–w- C:\Users\Annelie\AppData\Local\{B6F51446-E2DF-4EF2-9030-712F6EF7E2DC}
2013-04-20 06:02:19 ——– d—–w- C:\Users\Annelie\AppData\Local\Apple Computer
2013-04-20 05:58:39 9317456 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{81CC40FA-DDAD-411F-8E5C-9DBFD5285E0C}\mpengine.dll
2013-04-20 05:57:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{CBFEDB40-9B56-466B-A34C-E32FB397E20F}
2013-04-19 17:22:17 ——– d—–w- C:\Users\Annelie\AppData\Local\{5EB981F1-791F-4ABB-B9E6-16476CD04AE6}
2013-04-19 05:22:05 ——– d—–w- C:\Users\Annelie\AppData\Local\{2ACC8B99-09E0-46D4-80FA-9761E63FE25B}
2013-04-19 04:43:14 ——– d—–w- C:\Users\Annelie\AppData\Local\Adobe
2013-04-18 17:21:40 ——– d—–w- C:\Users\Annelie\AppData\Local\{72DB9EEB-BFAF-4008-83AD-C89ED2841453}
2013-04-18 11:51:29 ——– d—–w- C:\Users\Annelie\AppData\Local\Axialis
2013-04-18 10:39:47 ——– d—–w- C:\Users\Annelie\AppData\Local\ATI
2013-04-18 10:38:35 ——– d—–w- C:\Users\Annelie\AppData\Local\Broadcom
2013-04-18 10:02:05 ——– d—–w- C:\Users\Annelie\capriza
2013-04-18 05:21:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{E0D264C1-50E9-45EE-80DF-0296024FA87C}
2013-04-17 20:08:31 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-17 17:20:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{F59D4887-FFCA-46DC-8012-E9BF48328FED}
2013-04-17 14:33:40 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Yontoo
2013-04-17 14:33:40 ——– d—–w- C:\Program Files (x86)\Yontoo
2013-04-17 05:20:18 ——– d—–w- C:\Users\Annelie\AppData\Local\{19CAF461-D7D0-4AF7-A8C6-62878A880866}
2013-04-16 10:30:38 ——– d—–w- C:\Users\Annelie\AppData\Local\{BB4051EB-F67A-4758-A092-9917D270D138}
2013-04-15 22:30:12 ——– d—–w- C:\Users\Annelie\AppData\Local\{851CAB01-93DA-4D9D-AAFE-523D8B047480}
2013-04-15 11:59:38 ——– d—–w- C:\Users\Annelie\AppData\Local\Socusoft
2013-04-15 11:56:48 ——– d—–w- C:\Program Files\Wireless Transfer App for Windows
2013-04-15 10:29:59 ——– d—–w- C:\Users\Annelie\AppData\Local\{CC5A0E84-4F62-4425-BA11-7FCDC8B9BBF4}
2013-04-14 22:29:34 ——– d—–w- C:\Users\Annelie\AppData\Local\{012D66D1-7289-4E53-8152-F34380E3D869}
2013-04-14 10:29:09 ——– d—–w- C:\Users\Annelie\AppData\Local\{BB9C8926-6BA0-4DE2-AA4D-FDBF5050F28B}
2013-04-13 22:28:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{47A4EDEA-BEF3-4D8C-846F-FE9E831F029E}
2013-04-13 11:33:24 ——– d—–w- C:\ProgramData\YTD Video Downloader
2013-04-13 11:33:20 ——– d—–w- C:\Program Files (x86)\GreenTree Applications
2013-04-13 10:28:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{0355B154-D4BB-489A-BF2D-7AC2CF49992D}
2013-04-12 16:54:45 ——– d—–w- C:\Users\Annelie\AppData\Local\{C6948BDE-BB5F-493B-98F4-E3FA915E36D9}
2013-04-12 05:37:39 248112 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
2013-04-12 05:37:38 ——– d—–w- C:\Program Files (x86)\Net iD
2013-04-12 04:54:19 ——– d—–w- C:\Users\Annelie\AppData\Local\{F40B6487-9F7F-4D0B-9DF2-D25A0A80AE81}
2013-04-11 09:13:47 ——– d—–w- C:\Users\Annelie\AppData\Local\{23584057-75FE-4F88-B44C-2C2D28737B28}
2013-04-10 17:44:43 ——– d—–w- C:\Users\Annelie\AppData\Local\{6EC8C167-8F39-49BF-946F-3C50556F248A}
2013-04-10 05:44:30 ——– d—–w- C:\Users\Annelie\AppData\Local\{8ABE0295-F06A-4E14-8BC7-AFCFEF196E9E}
2013-04-09 21:32:00 1655656 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-09 21:31:32 3153408 —-a-w- C:\Windows\System32\win32k.sys
2013-04-09 21:31:07 6656 —-a-w- C:\Windows\SysWow64\apisetschema.dll
2013-04-09 21:31:07 5550424 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-04-09 21:31:07 43520 —-a-w- C:\Windows\System32\csrsrv.dll
2013-04-09 21:31:07 3968856 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-04-09 21:31:07 3913560 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-04-09 21:31:07 112640 —-a-w- C:\Windows\System32\smss.exe
2013-04-09 21:30:38 223752 —-a-w- C:\Windows\System32\drivers\fvevol.sys
2013-04-09 10:08:35 ——– d—–w- C:\Users\Annelie\AppData\Local\{ED45BEC9-1E04-4FA5-B542-7263E1E6726B}
2013-04-09 08:52:55 ——– d—–w- C:\Program Files (x86)\Common Files\Telespree
2013-04-09 05:16:52 ——– d—–w- C:\Users\Annelie\AppData\Local\Hewlett-Packard_Developme
2013-04-09 04:36:31 ——– d—–w- C:\Users\Annelie\AppData\Local\Telespree
2013-04-08 18:36:27 ——– d—–w- C:\Users\Annelie\AppData\Local\{6828577F-BE2E-4711-8374-795AD2E22327}
2013-04-08 06:36:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{F88AFE6B-87D0-47D5-A883-9492B1739113}
2013-04-07 13:58:44 ——– d—–w- C:\Driver_W64
2013-04-07 13:51:12 46568 —-a-w- C:\Windows\System32\drivers\ISCTD64.sys
2013-04-07 13:46:57 64624 —-a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-04-07 12:45:52 ——– d—–w- C:\Users\Annelie\AppData\Local\Incomedia
2013-04-07 12:45:33 ——– d—–w- C:\Program Files (x86)\WebSite X5 v10 - Free
2013-04-07 12:23:38 62464 —-a-w- C:\Windows\SysWow64\sevLock.dll
2013-04-07 12:20:15 290816 —-a-w- C:\Windows\SysWow64\cyviewer.ocx
2013-04-07 11:44:36 ——– d—–w- C:\Users\Annelie\AppData\Local\{FD206D64-BBE2-4622-90D7-8E18546219E2}
2013-04-06 18:47:22 ——– d—–w- C:\Users\Annelie\AppData\Roaming\TeraCopy
2013-04-06 18:47:12 ——– d—–w- C:\Program Files\TeraCopy
2013-04-06 18:45:38 ——– d—–w- C:\Users\Annelie\AppData\Local\{D1189CA0-86AF-45D4-A0A2-A154BF584182}
2013-04-06 18:31:11 ——– d—–w- C:\Program Files (x86)\GPLGS
2013-04-06 18:30:23 87152 —-a-w- C:\Windows\System32\cpwmon64.dll
2013-04-06 18:30:22 ——– d—–w- C:\Program Files (x86)\Acro Software
2013-04-06 17:22:08 ——– d—–w- C:\Program Files (x86)\CodeStuff
2013-04-06 16:14:54 ——– d—–w- C:\ProgramData\Innovative Solutions
2013-04-06 16:14:46 42496 —-a-w- C:\Windows\SysWow64\AdvUninstCPL.cpl
2013-04-06 16:14:42 ——– d—–w- C:\Program Files (x86)\Innovative Solutions
2013-04-06 15:41:14 ——– d—–w- C:\Program Files (x86)\Revo Uninstaller
2013-04-06 06:45:13 ——– d—–w- C:\Users\Annelie\AppData\Local\{BCB4065C-B68D-45DA-8470-7051C8A48300}
2013-04-05 18:44:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{9B5AE57A-1767-4B27-9940-BDB62E0CEA25}
2013-04-05 06:44:35 ——– d—–w- C:\Users\Annelie\AppData\Local\{AF5F1FB3-13B5-4797-9D00-AF41AFDF1FD7}
2013-04-04 09:17:34 ——– d—–w- C:\Users\Annelie\AppData\Local\{51B23B88-6F06-4786-BB74-E8F350BFCB29}
2013-04-03 21:14:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{BE9AD40C-B401-4220-AB90-9EFDB66921C6}
2013-04-03 11:17:02 ——– d–h–w- C:\$WINDOWS.~BT
2013-04-03 09:13:48 ——– d—–w- C:\Users\Annelie\AppData\Local\{D8E0889C-294F-45F0-8948-3117517ADA94}
2013-04-02 21:13:23 ——– d—–w- C:\Users\Annelie\AppData\Local\{311CF1FD-A1B3-4986-88F3-1E94DEAF6784}
2013-04-02 09:13:11 ——– d—–w- C:\Users\Annelie\AppData\Local\{A08F9EB1-241B-407A-9BA1-69A3FA80C096}
2013-04-01 21:12:45 ——– d—–w- C:\Users\Annelie\AppData\Local\{01FC165F-E39C-4E19-A2C9-FB01C90FE090}
2013-04-01 19:52:24 ——– d–h–w- C:\SkyDriveTemp
2013-04-01 09:12:20 ——– d—–w- C:\Users\Annelie\AppData\Local\{D00B07CB-4968-4E23-8181-B373F54882C1}
2013-03-31 21:11:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{F0060E73-1F4B-4B67-AC80-E04749C30CD1}
2013-03-31 08:34:22 ——– d—–w- C:\Users\Annelie\AppData\Local\{528507FC-0ED3-46F3-A753-DE1DFC0FF740}
2013-03-30 13:37:54 ——– d—–w- C:\Users\Annelie\AppData\Local\{A39DEE3F-A4D9-44DF-9DDF-A06FDC128A28}
2013-03-30 08:42:24 9856 —-a-w- C:\Windows\System32\drivers\wstbtndb.sys
2013-03-30 08:42:24 1459712 —-a-w- C:\Windows\System32\wstbtnrb.dll
2013-03-30 08:23:30 89640 —-a-w- C:\Windows\System32\drivers\btwdpan.sys
2013-03-30 08:23:06 144896 —-a-w- C:\Windows\System32\IntelOpenCL64.dll
2013-03-30 08:22:56 104448 —-a-w- C:\Windows\SysWow64\IntelOpenCL32.dll
2013-03-30 08:17:15 163368 —-a-w- C:\Windows\System32\drivers\bcbtums.sys
2013-03-30 08:16:14 ——– d—–w- C:\temp
2013-03-30 07:08:26 ——– d—–w- C:\Users\Annelie\AppData\Roaming\Systweak
2013-03-30 07:08:22 ——– d—–w- C:\Program Files (x86)\Advanced Driver Updater
2013-03-29 21:26:09 ——– d—–w- C:\Users\Annelie\AppData\Local\{45067BC0-95FA-4F7D-82A0-7765C2B774F9}
2013-03-29 09:25:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{00455E4A-52E0-4CE9-91B0-C7773B922FC4}
2013-03-28 19:39:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{7E1AE44F-20EA-46CE-9024-3D20AFA70094}
2013-03-28 07:39:20 ——– d—–w- C:\Users\Annelie\AppData\Local\{FCD7397C-8553-4388-912D-0F48B23DE6F8}
2013-03-28 06:59:57 ——– d—–w- C:\Users\Annelie\LiveM
2013-03-28 06:48:54 ——– d—–w- C:\Program Files (x86)\jAlbum
2013-03-27 19:38:55 ——– d—–w- C:\Users\Annelie\AppData\Local\{6A9A61E4-BC1D-4147-93FE-B3A1612D1FD9}
2013-03-27 07:38:43 ——– d—–w- C:\Users\Annelie\AppData\Local\{916EA87E-8C2F-46B3-B549-2E721889F6C4}
2013-03-26 11:02:50 ——– d—–w- C:\Users\Annelie\AppData\Local\{7DC4D1C2-BDA5-4EFA-A57D-2755560B4C79}
2013-03-25 23:02:26 ——– d—–w- C:\Users\Annelie\AppData\Local\{45A4E852-05B8-4C29-9B27-9DC79090E8FC}
2013-03-25 11:02:14 ——– d—–w- C:\Users\Annelie\AppData\Local\{FA0C27FA-977E-44B2-9DF9-C2E2BE4418AC}
2013-03-24 15:29:54 ——– d—–w- C:\Program Files (x86)\IZArc
2013-03-24 12:11:27 ——– d—–w- C:\Users\Annelie\AppData\Local\{A9BE8FA9-F45C-437C-82F3-19E6C47EE08F}
2013-03-24 06:01:48 ——– d—–w- C:\Program Files (x86)\Common Files\Spigot
2013-03-23 21:27:33 ——– d—–w- C:\Users\Annelie\AppData\Local\{96F87812-FA75-4674-AA8F-338E1CFFE9AC}
2013-03-23 08:15:08 ——– d—–w- C:\Users\Annelie\AppData\Local\{9F82DBAF-73B1-4126-B11D-7BC2FE5D8EFA}
2013-03-23 06:42:03 20520 —-a-w- C:\Windows\SysWow64\mcmpgvout.dll
2013-03-23 06:42:02 531496 —-a-w- C:\Windows\SysWow64\mcmpeg2mux.ax
2013-03-23 06:42:02 375848 —-a-w- C:\Windows\SysWow64\mcm2ve.ax
2013-03-23 06:42:02 257064 —-a-w- C:\Windows\SysWow64\mcl2ae.ax
2013-03-23 06:42:02 244776 —-a-w- C:\Windows\SysWow64\mcmpgaout.dll
2013-03-23 06:42:02 2140712 —-a-w- C:\Windows\SysWow64\mcmpgvout.004
2013-03-22 20:14:44 ——– d—–w- C:\Users\Annelie\AppData\Local\{5BD097B5-3571-4F56-8BB0-729B2EB869C6}
.
==================== Find3M ====================
.
2013-04-21 09:05:53 29 —-a-w- C:\Windows\SysWow64\TempWmicBatchFile.bat
2013-04-12 05:28:54 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-12 05:28:54 691592 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-09 21:29:50 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-04-09 21:29:50 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-04-09 21:29:50 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-04-09 21:29:50 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-04-09 21:29:50 3958784 —-a-w- C:\Windows\System32\jscript9.dll
2013-04-09 21:29:50 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-09 21:29:50 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-04-09 21:29:50 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-04-09 21:29:50 2240512 —-a-w- C:\Windows\System32\wininet.dll
2013-04-09 21:29:50 1766912 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-04-09 21:29:50 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-04-09 21:29:50 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-03-12 23:36:19 474112 —-a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-03-12 23:36:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-03-12 23:36:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-03-12 23:36:19 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll
2013-03-12 23:36:19 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-03-12 23:36:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-03-12 23:35:37 19968 —-a-w- C:\Windows\System32\drivers\usb8023.sys
2013-03-12 23:11:22 16486616 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2013-03-11 23:10:56 282744 ——w- C:\Windows\System32\MpSigStub.exe
2013-03-06 23:33:21 70992 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-03-06 23:33:21 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-03-06 23:33:21 178624 —-a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-03-06 23:33:21 1025808 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-03-06 23:33:20 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-03-06 23:33:20 263096 —-a-w- C:\Windows\System32\drivers\aswNdis2.sys
2013-03-06 23:33:20 22600 —-a-w- C:\Windows\System32\drivers\aswKbd.sys
2013-03-06 23:33:20 127136 —-a-w- C:\Windows\System32\drivers\aswFW.sys
2013-03-06 23:32:51 41664 —-a-w- C:\Windows\avastSS.scr
2013-03-06 10:42:59 861088 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-03-06 10:42:59 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-02-27 13:37:12 53248 —-a-w- C:\Windows\SysWow64\CSVer.dll
2013-02-27 05:08:22 11525872 —-a-w- C:\Windows\System32\drivers\Netwsw00.sys
2013-02-15 14:17:04 16344 —-a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
.
============= FINISH: 11:23:12,89 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2012-07-15 05:40:45
System Uptime: 2013-04-21 06:54:10 (5 hours ago)
.
Motherboard: Hewlett-Packard | | 168A
Processor: Intel® Core™ i7-2670QM CPU @ 2.20GHz | CPU1 | 2201/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 906 GiB total, 688,242 GiB free.
D: is FIXED (NTFS) - 932 GiB total, 470,777 GiB free.
E: is FIXED (NTFS) - 25 GiB total, 2,538 GiB free.
F: is CDROM ()
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP237: 2013-04-09 23:28:03 - Installationsprogram för Windows-moduler
RP238: 2013-04-09 23:40:16 - Windows Update
RP239: 2013-04-12 07:12:52 - Installed BankID Security Application
RP240: 2013-04-12 07:25:49 - Installed BankID Security Application
RP241: 2013-04-12 07:26:39 - Installed BankID Security Application
RP242: 2013-04-14 07:47:33 - Backup_2013_04_14
RP243: 2013-04-17 07:19:24 - Windows Update
RP244: 2013-04-17 22:07:03 - Installed Java 7 Update 21
RP245: 2013-04-20 07:56:54 - Windows Update
.
==== Installed Programs ======================
.
3DPageFlip PDF to PowerPoint (freeware)
7-Zip 9.20 (x64 edition)
Acoustica CD/DVD Label Maker
Acoustica Photos Forever
ActivePrint System
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
Adobe AIR
Adobe Community Help
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop Elements 9
Adobe Premiere Elements 9
Adobe Reader XI (11.0.02) - Svenska
Adobe Shockwave Player 12.0
Advanced Driver Updater
Advanced SystemCare 6
Advanced Uninstaller PRO - Version 9
Age Of Japan
Age Of Japan II
AMD APP SDK Runtime
AMD Catalyst Install Manager
anysee-TCSeries
anysee Driver(2011.04.21,AD01061734) CNO 1.3.0 Uninstallation
anysee_FilterSDK
Apple-programstöd
Apple Mobile Device Support
Apple Software Update
ArcSoft Link+ 3
ArcSoft MediaImpression 2
ArcSoft Panorama Maker 4
ArcSoft Photo Book Screen Saver
ArcSoft PhotoStudio Darkroom 2
ArcSoft Portrait+
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Brochures & Flyers
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Funhouse II
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Photo Prints
ArcSoft Print Creations - Poster Creator
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
ArcSoft RAW Thumbnail Viewer
ArcSoft Scan-n-Stitch Deluxe
ArcSoft Video Downloader
Ashampoo Burning Studio 2013 v.11.0.5
Ashampoo Gadge It v.1.0.1
Ashampoo Home Designer Pro v.1.0.1
Ashampoo MyAutoplay Menu 1.0.5
Ashampoo Photo Commander 8 v.8.5.0
Ashampoo Photo Mailer v.1.0.4
Ashampoo Photo Optimizer 4 v.4.0.3
Ashampoo Slideshow Studio HD 2 2.0.5
Ashampoo Snap 5 v.5.1.5
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
avast! Internet Security
AVS Audio Converter 7
AVS Audio Editor 7.1
AVS Audio Recorder version 4.0
AVS Cover Editor [removed]
AVS Disc Creator 5
AVS Document Converter 2.2.3
AVS DVD Copy 4.1.2.283
AVS Image Converter [removed]
AVS Media Player [removed]
AVS Photo Editor
AVS Registry Cleaner version 2.2
AVS Ringtone Maker version 1.6
AVS Screen Capture version 2.0.1
AVS Update Manager 1.0
AVS Video Converter 8
AVS Video Editor 6
AVS Video Recorder 2.5
AVS Video ReMaker [removed]
AVS4YOU Software Navigator 1.4
Axialis IconWorkshop 6.0
Belltech Greeting Card Designer - Extra Templates
Belltech Greeting Card Designer 5.4.0
Bonjour
Bonjour-utskriftstjänster
Bookworm Deluxe 1.13
Broadcom Bluetooth Software
Broadcom InConcert Maestro
BulletProof FTP Client 2009 (remove only)
Canon Easy-WebPrint EX
Canon MP Navigator EX 3.0
Canon MP640 series användarregistrering
Canon MP640 series MP Drivers
Canon RAW Codec
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Canon Utilities Solution Menu
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
CD-LabelPrint
CodeStuff Starter
Compatibility Pack för Office 2007-systemet
CutePDF Writer 3.0
CyberLink PowerDVD
CyberLink YouCam
D3DX10
DAP Plug-in for 64 Bit IE
Defraggler
DirectX for Managed Code Update (Summer 2004)
Download Accelerator Plus (DAP)
DreamBoxEdit – The one and only settings editor for your Dreambox
Dropbox
Easy Watermark Studio version 3.4
Elements 9 Organizer
Elements STI Installer
ESET Online Scanner v3
ESU for Microsoft Windows 7 SP1
Evernote v. 4.5.8
ExpressFiles
FontExpert 2010
Google Earth
Google Update Helper
HP 3D DriveGuard
HP Connection Manager
HP CoolSense
HP Customer Experience Enhancements
HP Documentation
HP Launch Box
HP On Screen Display
HP Photo Creations
HP Power Manager
HP Proximity Sensor Utility
HP Quick Launch
HP Setup
HP Software Framework
HP Support Assistant
HP Wireless Audio Manager 1.0.8
IB Updater 2.0.0.550
iCloud
IDT Audio
Incomedia WebSite X5 v10 - Free
IncrediMail
IncrediMail 2.0
Intel Digital Logo
Intel PROSet Wireless
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® PROSet/Wireless WiFi Software
Intel® Rapid Storage Technology
Intel® SDK for OpenCL - CPU Only Runtime Package
Intel® Smart Connect Technology 1.0
Intel® WiDi
Intel® Wireless Display
Intel® Trusted Connect Service Client
IObit Malware Fighter
iTunes
IZArc 4.1.7
jAlbum
Java 7 Update 21
Java Auto Updater
JuiceboxBuilder-Lite
Junk Mail filter update
LogMeIn
Malwarebytes Anti-Malware version 1.65.1.1000
mediAvatar PowerPoint to Video Converter Personal
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Camera Codec Pack
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Standard
Microsoft Publisher 2002
Microsoft Research AutoCollage 2008 version 1.1
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework 2.1 Core Components (x64) ENU
Microsoft Sync Framework 2.1 Provider Services (x64) ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_CRT_x86
Mobile Broadband
Mozilla Firefox 20.0.1 (x86 sv-SE)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Net iD 5.7
Net iD 5.7 (32-bit Edition)
Paint Shop Pro 7 ESD
Photo Notifier and Animation Creator
Picasa 3
Picasa Web Albums Live Publisher
Picture Collage Maker Pro 3.3.0
PlayReady PC Runtime amd64
Porta
Power2Go
PX Profile Update
QuickTime
Rainlendar2 (remove only)
Realtek PCIE Card Reader
RealWorld Icon Editor
Recovery Manager
Recuva
Renesas Electronics USB 3.0 Host Controller Driver
Revo Uninstaller 1.93
Reynardware Incredimail Converter 0.53
RoboForm 7-8-8-5 (All Users)
RonyaSoft Poster Designer (Poster Forge) 2.01
RonyaSoft Poster Printer (ProPoster) 3.01
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Shape Collage
Simply Calenders v5.3
Skype Click to Call
Skype™ 5.10
Smart Defrag 2
SmartSound Quicktracks for Premiere Elements 9.0
Speccy
Spotify
Spotmau BootSuite 2012 (Build 7.0.1)
Storegate Online Backup
Storegate Sync
swMSM
Synaptics ClickPad Driver
Sync Blocker 10.6 Release 1
TeamViewer 8
Telia AutoStore
TeraCopy 2.27
TriDef 3D (HP) 1.0.6
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Waveface Stream
WavefaceStation
ViewRanger Map Chooser
Windows Installer Clean Up
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalleri
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
Windows Live Mesh ActiveX-objekt til fjernforbindelser
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Meshin etäyhteyksien ActiveX-komponentti
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Liven asennustyökalu
Windows Liven sähköposti
Windows Liven valokuvavalikoima
Wireless Transfer App for Windows 1.3
VLC media player 2.0.5
Wondershare DVD Slideshow Builder Deluxe(Build [removed])
Yontoo 2.051
YTD Video Downloader 4.0
.
==== End Of File ===========================


Best regards
Annelie
Hello again, next scans below! Best regards Annelie

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-04-21 11:34:36
—————————–
11:34:36.976 OS Version: Windows x64 6.1.7601 Service Pack 1
11:34:36.976 Number of processors: 8 586 0x2A07
11:34:36.976 ComputerName: TERRA UserName:
11:34:40.636 Initialize success
11:34:40.816 AVAST engine defs: 13042100
11:34:45.317 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
11:34:45.317 Disk 0 Vendor: TOSHIBA_MK1059GSMP GU001C Size: 953869MB BusType: 11
11:34:45.317 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T0L0-0
11:34:45.327 Disk 1 Vendor: TOSHIBA_MK1059GSMP GU001C Size: 953869MB BusType: 11
11:34:45.517 Disk 1 MBR read successfully
11:34:45.517 Disk 1 MBR scan
11:34:45.527 Disk 1 Windows 7 default MBR code
11:34:45.537 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
11:34:45.547 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 928213 MB offset 409600
11:34:45.577 Disk 1 Partition 3 00 07 HPFS/NTFS NTFS 25353 MB offset 1901389824
11:34:45.597 Disk 1 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
11:34:45.717 Disk 1 scanning C:\Windows\system32\drivers
11:34:54.058 Service scanning
11:35:36.822 Modules scanning
11:35:36.822 Disk 1 trace - called modules:
11:35:36.902 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
11:35:36.902 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa800852d060]
11:35:36.912 3 CLASSPNP.SYS[fffff88001d4143f] -> nt!IofCallDriver -> [0xfffffa8008356b10]
11:35:36.912 5 hpdskflt.sys[fffff88001ce8379] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80081fe680]
11:35:39.923 AVAST engine scan C:\Windows
11:35:44.153 AVAST engine scan C:\Windows\system32
11:37:47.950 AVAST engine scan C:\Windows\system32\drivers
11:38:00.993 AVAST engine scan C:\Users\Annelie
11:38:27.838 Disk 1 MBR has been saved successfully to "C:\Users\Annelie\Desktop\HJÄLP\aswMBR\MBR.dat"
11:38:27.838 The log file has been saved successfully to "C:\Users\Annelie\Desktop\HJÄLP\aswMBR\aswMBR.txt"


—————————

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Annelie [Admin rights]
Mode : Scan – Date : 04/21/2013 11:43:44
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] YontooDesktop.exe – C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe [7] -> KILLED [TermProc]
[SUSP PATH] aswMBR.exe – C:\Users\Annelie\Desktop\HJÄLP\aswMBR\aswMBR.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : Yontoo Desktop ("C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe") [7] -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1586794244-3537599945-2917857382-1000[…]\Run : Yontoo Desktop ("C:\Users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe") [7] -> FOUND
[DNS] HKLM\[…]\ControlSet001\Services\Tcpip\Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1} : NameServer (195.67.199.18 195.67.199.19) -> FOUND
[DNS] HKLM\[…]\ControlSet002\Services\Tcpip\Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1} : NameServer (195.67.199.18 195.67.199.19) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[SCREENSV][SUSP PATH] HKCU\[…]\Desktop (C:\Windows\WLXPGSS.SCR) [7] -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK1059GSMP ATA Device +++++
— User —
[MBR] bddddad88da3494c9b47feb9ded7bf93
[BSP] 031f37e6cfaa722bafedf658f4e5d7ae : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 953867 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: TOSHIBA MK1059GSMP ATA Device +++++
— User —
[MBR] 8d6de4544085758454eb77d29f5b1c66
[BSP] 6bdaf62830df61419d4af75f6a16fd84 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 928213 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1901389824 | Size: 25353 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1953312768 | Size: 102 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive2: SD Card +++++
— User —
[MBR] 5cee0f8f26171abfb24e71bbd7e9dfdc
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 8192 | Size: 3922 Mo
User = LL1 … OK!
Error reading LL2 MBR!

+++++ PhysicalDrive3: Verbatim STORE N GO USB Device +++++
— User —
[MBR] 538af679e620d753c7e114235971fba9
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 2048 | Size: 7650 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1]_S_04212013_02d1143.txt >>
RKreport[1]_S_04212013_02d1143.txt



———————————

Results of screen317's Security Check version 0.99.62
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
avast! Internet Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.1.1000
AVS Registry Cleaner version 2.2
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 11.7.700.169
Adobe Reader XI
Mozilla Firefox (20.0.1)
````````Process Check: objlist.exe by Laurent````````
IObit IObit Malware Fighter IMFsrv.exe
IObit IObit Malware Fighter IMF.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast afwServ.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1
````````````````````End of Log``````````````````````
Hello, AnnelieP.

Thank you for your logs. In answer to your question, when running scans, all script blocking programs (anti-virus, anti-spyware, and other security applications) should be turned off. Because many security programs detect these specialized tools as malicious threats, they can interfere or block them, resulting in unreliable results. Therefore, we ask that you disable these programs. You can re-enable these programs after you have completed your scans.

Before beginning your scans, you should also exit any applications that you may be running (internet, email, media players, etc).

Please scan with ComboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.
Here we go B) : ComboFix 13-04-23.02 - Annelie 2013-04-23 11:50:41.3.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.5726 [GMT 2:00] Körs från: c:\users\Annelie\Desktop\ComboFix.exe AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Skapade en ny återställningspunkt . . (((((((((((((((((((((((( Filer skapade från 2013-03-23 till 2013-04-23 )))))))))))))))))))))))))))))) . . 2013-04-23 10:11 . 2013-04-23 10:11 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-04-20 06:02 . 2013-04-21 08:59 ——– d—–w- c:\users\Annelie\AppData\Local\Apple Computer 2013-04-20 05:58 . 2013-04-10 03:46 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{81CC40FA-DDAD-411F-8E5C-9DBFD5285E0C}\mpengine.dll 2013-04-19 04:43 . 2013-04-19 08:28 ——– d—–w- c:\users\Annelie\AppData\Local\Adobe 2013-04-18 11:51 . 2013-04-18 11:52 ——– d—–w- c:\users\Annelie\AppData\Local\Axialis 2013-04-18 10:39 . 2013-04-18 10:39 ——– d—–w- c:\users\Annelie\AppData\Local\ATI 2013-04-18 10:38 . 2013-04-18 10:38 ——– d—–w- c:\users\Annelie\AppData\Local\Broadcom 2013-04-18 10:02 . 2013-04-18 12:50 ——– d—–w- c:\users\Annelie\capriza 2013-04-17 20:09 . 2013-04-17 20:09 ——– d—–w- c:\program files (x86)\Common Files\Java 2013-04-17 20:08 . 2013-04-04 03:35 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-17 14:33 . 2013-04-23 10:18 ——– d—–w- c:\users\Annelie\AppData\Roaming\Yontoo 2013-04-17 14:33 . 2013-04-17 14:33 ——– d—–w- c:\program files (x86)\Yontoo 2013-04-15 11:59 . 2013-04-15 11:59 ——– d—–w- c:\users\Annelie\AppData\Local\Socusoft 2013-04-15 11:56 . 2013-04-15 11:56 ——– d—–w- c:\program files\Wireless Transfer App for Windows 2013-04-13 11:33 . 2013-04-13 11:33 ——– d—–w- c:\programdata\YTD Video Downloader 2013-04-13 11:33 . 2013-04-13 11:33 ——– d—–w- c:\program files (x86)\GreenTree Applications 2013-04-12 05:37 . 2013-04-12 05:37 ——– d—–w- c:\program files (x86)\Net iD 2013-04-09 21:32 . 2013-04-09 21:32 1655656 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-09 21:31 . 2013-04-09 21:31 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-04-09 21:31 . 2013-04-09 21:31 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll 2013-04-09 21:31 . 2013-04-09 21:31 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-04-09 21:31 . 2013-04-09 21:31 43520 —-a-w- c:\windows\system32\csrsrv.dll 2013-04-09 21:31 . 2013-04-09 21:31 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-04-09 21:31 . 2013-04-09 21:31 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-04-09 21:31 . 2013-04-09 21:31 112640 —-a-w- c:\windows\system32\smss.exe 2013-04-09 21:30 . 2013-04-09 21:30 223752 —-a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-09 08:52 . 2013-04-09 08:52 ——– d—–w- c:\program files (x86)\Common Files\Telespree 2013-04-09 05:16 . 2013-04-09 05:16 ——– d—–w- c:\users\Annelie\AppData\Local\Hewlett-Packard_Developme 2013-04-09 04:36 . 2013-04-09 04:36 ——– d—–w- c:\users\Annelie\AppData\Local\Telespree 2013-04-07 13:58 . 2013-04-07 13:58 ——– d—–w- C:\Driver_W64 2013-04-07 13:51 . 2013-02-13 08:28 46568 —-a-w- c:\windows\system32\drivers\ISCTD64.sys 2013-04-07 13:46 . 2013-02-15 14:17 64624 —-a-w- c:\windows\system32\drivers\HECIx64.sys 2013-04-07 12:45 . 2013-04-07 12:45 ——– d—–w- c:\users\Annelie\AppData\Local\Incomedia 2013-04-07 12:45 . 2013-04-07 12:59 ——– d—–w- c:\program files (x86)\WebSite X5 v10 - Free 2013-04-07 12:23 . 2006-09-26 03:44 62464 —-a-w- c:\windows\SysWow64\sevLock.dll 2013-04-07 12:20 . 2008-05-07 13:03 290816 —-a-w- c:\windows\SysWow64\cyviewer.ocx 2013-04-06 18:47 . 2013-04-07 09:38 ——– d—–w- c:\users\Annelie\AppData\Roaming\TeraCopy 2013-04-06 18:47 . 2013-04-06 18:47 ——– d—–w- c:\program files\TeraCopy 2013-04-06 18:31 . 2013-04-06 18:31 ——– d—–w- c:\program files (x86)\GPLGS 2013-04-06 18:30 . 2012-09-12 13:33 87152 —-a-w- c:\windows\system32\cpwmon64.dll 2013-04-06 18:30 . 2013-04-06 18:30 ——– d—–w- c:\program files (x86)\Acro Software 2013-04-06 17:22 . 2013-04-06 17:22 ——– d—–w- c:\program files (x86)\CodeStuff 2013-04-06 16:14 . 2013-04-06 16:14 ——– d—–w- c:\programdata\Innovative Solutions 2013-04-06 16:14 . 2006-11-22 09:35 42496 —-a-w- c:\windows\SysWow64\AdvUninstCPL.cpl 2013-04-06 16:14 . 2013-04-06 16:14 ——– d—–w- c:\program files (x86)\Innovative Solutions 2013-04-06 15:41 . 2013-04-06 15:41 ——– d—–w- c:\program files (x86)\Revo Uninstaller 2013-04-03 11:17 . 2013-04-03 11:17 ——– d—–w- C:\$WINDOWS.~BT 2013-04-01 19:52 . 2013-04-01 19:52 ——– d—–w- C:\SkyDriveTemp 2013-03-30 08:42 . 2007-09-14 22:12 9856 —-a-w- c:\windows\system32\drivers\wstbtndb.sys 2013-03-30 08:42 . 2007-09-14 22:12 1459712 —-a-w- c:\windows\system32\wstbtnrb.dll 2013-03-30 08:23 . 2011-09-17 08:38 89640 —-a-w- c:\windows\system32\drivers\btwdpan.sys 2013-03-30 08:23 . 2012-05-15 06:13 144896 —-a-w- c:\windows\system32\IntelOpenCL64.dll 2013-03-30 08:22 . 2012-05-15 05:20 104448 —-a-w- c:\windows\SysWow64\IntelOpenCL32.dll 2013-03-30 08:17 . 2012-04-01 10:52 163368 —-a-w- c:\windows\system32\drivers\bcbtums.sys 2013-03-30 08:16 . 2013-03-30 08:16 ——– d—–w- c:\programdata\Dell 2013-03-30 08:16 . 2013-04-07 14:00 ——– d—–w- C:\temp 2013-03-30 07:08 . 2013-03-30 07:08 ——– d—–w- c:\users\Annelie\AppData\Roaming\Systweak 2013-03-30 07:08 . 2013-03-30 07:08 ——– d—–w- c:\program files (x86)\Advanced Driver Updater 2013-03-28 06:59 . 2013-03-28 07:00 ——– d—–w- c:\users\Annelie\LiveM 2013-03-28 06:48 . 2013-03-28 06:49 ——– d—–w- c:\program files (x86)\jAlbum 2013-03-24 15:29 . 2013-03-24 15:31 ——– d—–w- c:\program files (x86)\IZArc . . . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-23 10:15 . 2013-01-20 16:45 29 —-a-w- c:\windows\SysWow64\TempWmicBatchFile.bat 2013-04-12 05:28 . 2012-09-07 20:21 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-12 05:28 . 2011-10-25 00:53 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-09 21:40 . 2012-09-12 18:20 72702784 —-a-w- c:\windows\system32\MRT.exe 2013-03-12 23:36 . 2013-03-12 23:36 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-03-12 23:36 . 2013-03-12 23:36 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-03-12 23:36 . 2013-03-12 23:36 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-03-12 23:36 . 2013-03-12 23:36 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-03-12 23:36 . 2013-03-12 23:36 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-03-12 23:36 . 2013-03-12 23:36 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-03-12 23:35 . 2013-03-12 23:35 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-12 23:11 . 2013-03-12 22:11 16486616 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-03-11 23:10 . 2010-11-21 03:27 282744 ——w- c:\windows\system32\MpSigStub.exe 2013-03-06 23:33 . 2013-03-05 22:21 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-03-06 23:33 . 2013-03-05 22:21 178624 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-03-06 23:33 . 2012-09-07 15:38 377920 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-03-06 23:33 . 2012-09-07 15:38 70992 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-03-06 23:33 . 2012-09-07 15:38 68920 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-03-06 23:33 . 2012-09-07 15:38 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-03-06 23:33 . 2013-02-21 14:24 127136 —-a-w- c:\windows\system32\drivers\aswFW.sys 2013-03-06 23:33 . 2013-02-21 14:24 263096 —-a-w- c:\windows\system32\drivers\aswNdis2.sys 2013-03-06 23:33 . 2013-02-21 14:24 22600 —-a-w- c:\windows\system32\drivers\aswKbd.sys 2013-03-06 23:33 . 2012-09-07 15:38 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-03-06 23:33 . 2012-09-07 15:38 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-03-06 23:32 . 2012-09-07 15:37 41664 —-a-w- c:\windows\avastSS.scr 2013-03-06 23:32 . 2012-07-15 06:04 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-03-06 10:42 . 2012-09-09 09:55 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-03-06 10:42 . 2012-09-08 23:45 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_MAIN_A20C9DEED7314263B3D96BD96607BD6D.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_DESKTOP_5D3B25B981684A1180C818B2D3DDC933.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_AUTOSTART_EB2D11F715DE4ECA929487A2BC9D1827.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\ARPPRODUCTICON.exe 2013-02-27 13:37 . 2012-04-07 02:27 53248 —-a-w- c:\windows\SysWow64\CSVer.dll 2013-02-27 05:08 . 2013-02-27 05:08 11525872 —-a-w- c:\windows\system32\drivers\Netwsw00.sys 2013-02-15 14:17 . 2012-04-07 02:30 16344 —-a-w- c:\windows\system32\drivers\IntelMEFWVer.dll 2013-02-12 17:39 . 2013-02-12 17:39 3584 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2013-02-11 16:14 . 2013-02-11 16:15 40464 —-a-w- c:\windows\system32\drivers\npf.sys 2013-02-11 16:14 . 2013-02-11 16:14 98816 —-a-w- c:\windows\system32\drivers\ew_jucdcacm.sys 2013-02-11 16:14 . 2013-02-11 16:14 86016 —-a-w- c:\windows\system32\drivers\ew_jubusenum.sys 2013-02-11 16:14 . 2013-02-11 16:14 69632 —-a-w- c:\windows\system32\drivers\ew_jucdcecm.sys 2013-02-11 16:14 . 2013-02-11 16:14 421376 —-a-w- c:\windows\system32\drivers\ewusbwwan.sys 2013-02-11 16:14 . 2013-02-11 16:14 28672 —-a-w- c:\windows\system32\drivers\ew_juextctrl.sys 2013-02-11 16:14 . 2013-02-11 16:14 22016 —-a-w- c:\windows\system32\drivers\ew_hwupgrade.sys 2013-02-11 16:14 . 2013-02-11 16:14 212992 —-a-w- c:\windows\system32\drivers\ew_juwwanecm.sys 2013-02-11 16:14 . 2013-02-11 16:14 13952 —-a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys 2013-02-11 16:14 . 2013-02-11 16:14 117248 —-a-w- c:\windows\system32\drivers\ew_hwusbdev.sys 2013-02-11 16:14 . 2013-02-11 16:14 1001472 —-a-w- c:\windows\system32\drivers\mod7700.sys 2013-02-11 16:14 . 2013-02-11 16:14 32768 —-a-w- c:\windows\system32\drivers\ewdcsc.sys 2013-02-11 16:14 . 2013-02-11 16:14 221312 —-a-w- c:\windows\system32\drivers\ewusbmdm.sys 2013-02-11 16:14 . 2013-02-11 16:14 1490656 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll 2013-02-11 16:14 . 2013-02-11 16:14 1490656 —-a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll 2013-01-25 09:04 . 2013-01-25 09:04 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll . . (((((((((((((((((((((((((((((((((( Startpunkter i registret ))))))))))))))))))))))))))))))))))))))))))))))) . . *Not* tomma poster & legitima standardposter visas inte. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E}] 2013-03-18 07:45 432232 —-a-w- c:\program files (x86)\DAP\LinkVerifier.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2013-03-23 01:59 197920 —-a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "Rainlendar2"="c:\program files (x86)\Rainlendar2\Rainlendar2.exe" [2013-03-10 4373600] "AshSnap"="c:\program files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe" [2012-08-03 3400600] "Yontoo Desktop"="c:\users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe" [2013-03-23 42784] "RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-04-19 109784] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-29 343168] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-07-11 574008] "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-07-13 93296] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2012-09-03 78352] "HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-09-13 103992] "Net iD"="c:\program files (x86)\Net iD\iid.exe" [2013-03-21 104704] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2012-12-25 4474832] . c:\users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-8-25 1337632] HP Wireless Audio Manager.lnk - c:\program files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe [2011-9-22 742712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice] @="Service" . R1 AMTBDA_P861F;anysee Capture Service;c:\windows\system32\DRIVERS\anyseeTU.SYS [2011-04-21 853632] R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/12/30 01:13;c:\program files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2012-09-03 245264] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528] R2 Mobile Broadband. RunOuc;Mobile Broadband. OUC;c:\program files (x86)\Mobile Broadband\UpdateDog\ouc.exe [2013-02-11 246112] R2 MongoDbForWaveface;MongoDB for Waveface;c:\program files (x86)\WavefaceStation\MongoDB\mongod.exe –logpath c:\program files (x86)\WavefaceStation\\log\MongoDB.log [x] R3 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-08-14 43624] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328] R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x] R3 cpuz134;cpuz134; [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2013-02-11 117248] R3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\DRIVERS\ewusbwwan.sys [2013-02-11 421376] R3 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2012-01-05 21384] R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-09-13 1098296] R3 hwdatacard;Huawei DataCard USB Modem and USB Serial;c:\windows\system32\DRIVERS\ewusbmdm.sys [2013-02-11 221312] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-08-05 34200] R3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2012-07-05 33224] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920] R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2012-08-07 35112] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2012-07-05 21904] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784] R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-07 1255736] R3 wifimansvc;Wifi Man Service;c:\program files (x86)\Mobile Broadband\eap\wifimansvc.exe [2013-02-11 598528] R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 aswKbd;aswKbd; [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2013-01-15 465216] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-29 204288] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-01 1166848] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-03-06 80816] S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-03-06 136912] S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928] S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-05-21 103992] S2 HPPRXSVC;HPPRXSVC;c:\program files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-05 37432] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2012-09-24 31040] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-07-11 26680] S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [2011-03-14 346976] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-08-24 13592] S2 IB Updater;IB Updater;c:\program files\IB Updater\ExtensionUpdaterService.exe [2012-11-20 188760] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-08 2375168] S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2012-01-09 821592] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-09-06 93696] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2013-02-22 167736] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-16 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-09-16 15928] S2 SBUpd;SpeedBit Update;c:\program files\Common Files\SpeedBit\SBUpdate\sbu.exe [2013-02-27 1097848] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288] S2 WavefaceStation;Waveface Station;c:\program files (x86)\WavefaceStation\Station.Service.exe [2012-10-04 342368] S2 Yontoo Desktop Updater;Yontoo Desktop Updater;c:\program files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-03-23 23552] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-06-07 231440] S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-04-01 163368] S3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2011-08-25 620072] S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys [2011-09-17 89640] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-08-25 39976] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2013-02-11 86016] S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-18 26136] S3 IntcDAud;Intel® bildskärmsljud;c:\windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-08-09 12289472] S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys [2013-02-13 46568] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-08-05 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2012-05-10 97792] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2012-05-10 217600] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-31 338536] S3 SBUpdd;SpeedBit UpdateD;c:\program files\Common Files\SpeedBit\SBUpdate\sbw.sys [2013-02-27 40856] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2011-08-05 42392] . . — Övriga tjänster/drivrutiner i minnet — . *Deregistered* - CLKMDRV10_38F51D56 . Innehåll i mappen 'Schemalagda aktiviteter': . 2013-04-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 05:28] . 2013-04-17 c:\windows\Tasks\AdvancedDriverUpdater_UPDATES.job - c:\program files (x86)\Advanced Driver Updater\adu.exe [2013-03-30 14:02] . 2013-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2013-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2013-04-23 c:\windows\Tasks\HP Photo Creations Communicator.job - c:\programdata\HP Photo Creations\Communicator.exe [2013-03-28 12:44] . 2013-04-09 c:\windows\Tasks\HPCeeScheduleForAnnelie.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}] 2012-11-20 14:09 215896 —-a-w- c:\program files\IB Updater\Extension64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 0StoregateSyncAddedOverlay] @="{EDCDC9C6-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C6-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 1StoregateSyncNormalOverlay] @="{EDCDC9C5-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C5-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 2StoregateSyncIgnoredOverlay] @="{EDCDC9C7-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C7-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-03-06 23:32 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-08-16 1424896] "SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-12-19 44880] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-07-11 440640] "Net iD"="c:\program files\Net iD\iid.exe" [2013-03-21 111872] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ——- Extra genomsökning ——- . uStart Page = hxxp://google.se/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; IE: &Clean; Traces - c:\program files (x86)\DAP\Privacy Package\dapcleanerie.htm IE: &Download; with &DAP; - c:\program files (x86)\DAP\dapextie.htm IE: &Verify; with DAP - c:\program files (x86)\DAP\dapverify.htm IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: Anpassa meny - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download &all; with DAP - c:\program files (x86)\DAP\dapextie2.htm IE: E&xportera; till Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fyll i formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Läs EXIF - c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm IE: RF verktygsfält - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Skicka bild till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Skicka sida till &Bluetooth-enhet;… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: Spara formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1}: NameServer = 195.67.199.18 195.67.199.19 Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\ FF - prefs.js: browser.search.defaulturl - hxxp://go.speedbit.com/search.aspx?s=D3IaWIT8&q;= FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/ FF - prefs.js: keyword.URL - hxxp://se.search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=937811&p;= FF - ExtSQL: 2013-02-28 11:38; {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi FF - ExtSQL: 2013-03-18 08:52; [removed]; c:\program files (x86)\DAP\daplinkchecker FF - ExtSQL: 2013-04-17 16:33; [removed]; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed] FF - ExtSQL: 2013-04-18 12:02; [removed]; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed] FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: browser.turbo.enabled - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.chrome.favicons - false FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: content.notify.ontimer - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.switch.threshold - 750000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 FF - user.js: extentions.y2layers.installId - 95042356-c63e-423e-932e-8e59996e2905 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . - - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . ——————— LÅSTA REGISTERNYCKLAR ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Andra processer som körs ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe c:\program files (x86)\ExpressFiles\EFUpdater.exe c:\program files (x86)\IObit\Advanced SystemCare 6\Monitor.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe c:\programdata\Mobile Broadband\OnlineUpdate\ouc.exe c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe c:\program files (x86)\TeamViewer\Version8\tv_w32.exe c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe c:\windows\SysWOW64\RunDll32.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe c:\windows\WLXPGSS.SCR . ************************************************************************** . Sluttid: 2013-04-23 12:50:14 - datorn startades om. ComboFix-quarantined-files.txt 2013-04-23 10:50 . Före genomsökningen: 739 213 074 432 byte ledigt Efter genomsökningen: 738 853 498 880 byte ledigt . - - End Of File - - 87398492DB29948D005FF94DE3B6AA86
Hello, AnnelieP.

Thank you for the CF log. Let's run CF again from a different perspective. Please do the following:

Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
  • Start > Run.
  • Type notepad in the Open field
  • Click OK.
  • Copy and paste the text inside the code box below:
KillAll::

ClearJavaCache::

File::
c:\program files (x86)\Yontoo\YontooIEClient.dll
c:\program files\IB Updater\Extension64.dll
c:\users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe	
c:\program files\IB Updater\ExtensionUpdaterService.exe
c:\program files (x86)\Yontoo\Y2Desktop.Updater.exe

Folder::
c:\users\Annelie\AppData\Roaming\Yontoo
c:\program files (x86)\Yontoo

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yontoo Desktop"=-

Firefox::
FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\
FF - ExtSQL: 2013-04-17 16:33; [removed]; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed]
FF - user.js: extentions.y2layers.installId - 95042356-c63e-423e-932e-8e59996e2905
FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers
  • Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
  • Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

[external image: Posted Image]

  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
WARNING
  • Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
  • Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.
Hi, I'm not at home until Friday and where I am, they have a very, very slow connection, so I wont do it now. Just for your information, so you don't close down this topic. Best regards Annelie
Sorry for being late, but here we go: ComboFix 13-04-23.02 - Annelie 2013-04-26 23:21:07.4.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.46.1053.18.8140.5601 [GMT 2:00] Körs från: c:\users\Annelie\Desktop\ComboFix.exe Kommandoväxlar som använts :: c:\users\Annelie\Desktop\CFScript.txt AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files (x86)\Yontoo\Y2Desktop.Updater.exe" "c:\program files (x86)\Yontoo\YontooIEClient.dll" "c:\program files\IB Updater\Extension64.dll" "c:\program files\IB Updater\ExtensionUpdaterService.exe" "c:\users\Annelie\AppData\Roaming\Yontoo\YontooDesktop.exe" . . ((((((((((((((((((((((((((((((((((((((( Andra raderingar )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\IB Updater\Extension64.dll c:\program files\IB Updater\ExtensionUpdaterService.exe . . ((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_IB Updater . . (((((((((((((((((((((((( Filer skapade från 2013-03-26 till 2013-04-26 )))))))))))))))))))))))))))))) . . 2013-04-26 22:10 . 2013-04-26 22:10 ——– d—–w- c:\users\Public\AppData\Local\temp 2013-04-26 22:10 . 2013-04-26 22:10 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-04-24 14:59 . 2013-04-12 14:45 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-23 20:53 . 2013-04-26 08:16 ——– d—–w- c:\users\Annelie\AppData\Local\CrashDumps 2013-04-20 06:02 . 2013-04-21 08:59 ——– d—–w- c:\users\Annelie\AppData\Local\Apple Computer 2013-04-19 04:43 . 2013-04-19 08:28 ——– d—–w- c:\users\Annelie\AppData\Local\Adobe 2013-04-18 11:51 . 2013-04-18 11:52 ——– d—–w- c:\users\Annelie\AppData\Local\Axialis 2013-04-18 10:39 . 2013-04-18 10:39 ——– d—–w- c:\users\Annelie\AppData\Local\ATI 2013-04-18 10:38 . 2013-04-18 10:38 ——– d—–w- c:\users\Annelie\AppData\Local\Broadcom 2013-04-18 10:02 . 2013-04-18 12:50 ——– d—–w- c:\users\Annelie\capriza 2013-04-17 20:09 . 2013-04-17 20:09 ——– d—–w- c:\program files (x86)\Common Files\Java 2013-04-17 20:08 . 2013-04-04 03:35 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-15 11:59 . 2013-04-15 11:59 ——– d—–w- c:\users\Annelie\AppData\Local\Socusoft 2013-04-15 11:56 . 2013-04-15 11:56 ——– d—–w- c:\program files\Wireless Transfer App for Windows 2013-04-13 11:33 . 2013-04-13 11:33 ——– d—–w- c:\programdata\YTD Video Downloader 2013-04-13 11:33 . 2013-04-13 11:33 ——– d—–w- c:\program files (x86)\GreenTree Applications 2013-04-12 05:37 . 2013-04-12 05:37 ——– d—–w- c:\program files (x86)\Net iD 2013-04-09 21:31 . 2013-04-09 21:31 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-04-09 21:31 . 2013-04-09 21:31 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll 2013-04-09 21:31 . 2013-04-09 21:31 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-04-09 21:31 . 2013-04-09 21:31 43520 —-a-w- c:\windows\system32\csrsrv.dll 2013-04-09 21:31 . 2013-04-09 21:31 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-04-09 21:31 . 2013-04-09 21:31 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-04-09 21:31 . 2013-04-09 21:31 112640 —-a-w- c:\windows\system32\smss.exe 2013-04-09 21:30 . 2013-04-09 21:30 223752 —-a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-09 08:52 . 2013-04-09 08:52 ——– d—–w- c:\program files (x86)\Common Files\Telespree 2013-04-09 05:16 . 2013-04-09 05:16 ——– d—–w- c:\users\Annelie\AppData\Local\Hewlett-Packard_Developme 2013-04-09 04:36 . 2013-04-09 04:36 ——– d—–w- c:\users\Annelie\AppData\Local\Telespree 2013-04-07 13:58 . 2013-04-07 13:58 ——– d—–w- C:\Driver_W64 2013-04-07 13:51 . 2013-02-13 08:28 46568 —-a-w- c:\windows\system32\drivers\ISCTD64.sys 2013-04-07 13:46 . 2013-02-15 14:17 64624 —-a-w- c:\windows\system32\drivers\HECIx64.sys 2013-04-07 12:45 . 2013-04-07 12:45 ——– d—–w- c:\users\Annelie\AppData\Local\Incomedia 2013-04-07 12:45 . 2013-04-07 12:59 ——– d—–w- c:\program files (x86)\WebSite X5 v10 - Free 2013-04-07 12:23 . 2006-09-26 03:44 62464 —-a-w- c:\windows\SysWow64\sevLock.dll 2013-04-07 12:20 . 2008-05-07 13:03 290816 —-a-w- c:\windows\SysWow64\cyviewer.ocx 2013-04-06 18:47 . 2013-04-07 09:38 ——– d—–w- c:\users\Annelie\AppData\Roaming\TeraCopy 2013-04-06 18:47 . 2013-04-06 18:47 ——– d—–w- c:\program files\TeraCopy 2013-04-06 18:31 . 2013-04-06 18:31 ——– d—–w- c:\program files (x86)\GPLGS 2013-04-06 18:30 . 2012-09-12 13:33 87152 —-a-w- c:\windows\system32\cpwmon64.dll 2013-04-06 18:30 . 2013-04-06 18:30 ——– d—–w- c:\program files (x86)\Acro Software 2013-04-06 17:22 . 2013-04-06 17:22 ——– d—–w- c:\program files (x86)\CodeStuff 2013-04-06 16:14 . 2013-04-06 16:14 ——– d—–w- c:\programdata\Innovative Solutions 2013-04-06 16:14 . 2006-11-22 09:35 42496 —-a-w- c:\windows\SysWow64\AdvUninstCPL.cpl 2013-04-06 16:14 . 2013-04-06 16:14 ——– d—–w- c:\program files (x86)\Innovative Solutions 2013-04-06 15:41 . 2013-04-06 15:41 ——– d—–w- c:\program files (x86)\Revo Uninstaller 2013-04-03 11:17 . 2013-04-03 11:17 ——– d—–w- C:\$WINDOWS.~BT 2013-04-01 19:52 . 2013-04-01 19:52 ——– d—–w- C:\SkyDriveTemp 2013-03-30 08:42 . 2007-09-14 22:12 9856 —-a-w- c:\windows\system32\drivers\wstbtndb.sys 2013-03-30 08:42 . 2007-09-14 22:12 1459712 —-a-w- c:\windows\system32\wstbtnrb.dll 2013-03-30 08:23 . 2011-09-17 08:38 89640 —-a-w- c:\windows\system32\drivers\btwdpan.sys 2013-03-30 08:23 . 2012-05-15 06:13 144896 —-a-w- c:\windows\system32\IntelOpenCL64.dll 2013-03-30 08:22 . 2012-05-15 05:20 104448 —-a-w- c:\windows\SysWow64\IntelOpenCL32.dll 2013-03-30 08:17 . 2012-04-01 10:52 163368 —-a-w- c:\windows\system32\drivers\bcbtums.sys 2013-03-30 08:16 . 2013-03-30 08:16 ——– d—–w- c:\programdata\Dell 2013-03-30 08:16 . 2013-04-07 14:00 ——– d—–w- C:\temp 2013-03-30 07:08 . 2013-03-30 07:08 ——– d—–w- c:\users\Annelie\AppData\Roaming\Systweak 2013-03-30 07:08 . 2013-03-30 07:08 ——– d—–w- c:\program files (x86)\Advanced Driver Updater 2013-03-28 06:59 . 2013-03-28 07:00 ——– d—–w- c:\users\Annelie\LiveM 2013-03-28 06:48 . 2013-03-28 06:49 ——– d—–w- c:\program files (x86)\jAlbum . . . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-26 22:13 . 2013-01-20 16:45 29 —-a-w- c:\windows\SysWow64\TempWmicBatchFile.bat 2013-04-12 05:28 . 2012-09-07 20:21 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-12 05:28 . 2011-10-25 00:53 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-10 03:46 . 2013-04-26 08:08 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{33EDEF0E-F4B4-4E21-A218-EB8D74454ADE}\mpengine.dll 2013-04-09 21:40 . 2012-09-12 18:20 72702784 —-a-w- c:\windows\system32\MRT.exe 2013-03-12 23:36 . 2013-03-12 23:36 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-03-12 23:36 . 2013-03-12 23:36 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-03-12 23:36 . 2013-03-12 23:36 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-03-12 23:36 . 2013-03-12 23:36 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-03-12 23:36 . 2013-03-12 23:36 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-03-12 23:36 . 2013-03-12 23:36 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-03-12 23:35 . 2013-03-12 23:35 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-12 23:11 . 2013-03-12 22:11 16486616 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-03-11 23:10 . 2010-11-21 03:27 282744 ——w- c:\windows\system32\MpSigStub.exe 2013-03-06 23:33 . 2013-03-05 22:21 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-03-06 23:33 . 2013-03-05 22:21 178624 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-03-06 23:33 . 2012-09-07 15:38 377920 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-03-06 23:33 . 2012-09-07 15:38 70992 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-03-06 23:33 . 2012-09-07 15:38 68920 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-03-06 23:33 . 2012-09-07 15:38 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-03-06 23:33 . 2013-02-21 14:24 127136 —-a-w- c:\windows\system32\drivers\aswFW.sys 2013-03-06 23:33 . 2013-02-21 14:24 263096 —-a-w- c:\windows\system32\drivers\aswNdis2.sys 2013-03-06 23:33 . 2013-02-21 14:24 22600 —-a-w- c:\windows\system32\drivers\aswKbd.sys 2013-03-06 23:33 . 2012-09-07 15:38 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-03-06 23:33 . 2012-09-07 15:38 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-03-06 23:32 . 2012-09-07 15:37 41664 —-a-w- c:\windows\avastSS.scr 2013-03-06 23:32 . 2012-07-15 06:04 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-03-06 10:42 . 2012-09-09 09:55 861088 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-03-06 10:42 . 2012-09-08 23:45 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_MAIN_A20C9DEED7314263B3D96BD96607BD6D.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_DESKTOP_5D3B25B981684A1180C818B2D3DDC933.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\SHORTCUT_AUTOSTART_EB2D11F715DE4ECA929487A2BC9D1827.exe 2013-03-06 08:57 . 2013-03-06 08:57 345976 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{E98575BF-10CA-4E3A-A807-67321FBEF916}\ARPPRODUCTICON.exe 2013-02-27 13:37 . 2012-04-07 02:27 53248 —-a-w- c:\windows\SysWow64\CSVer.dll 2013-02-27 05:08 . 2013-02-27 05:08 11525872 —-a-w- c:\windows\system32\drivers\Netwsw00.sys 2013-02-15 14:17 . 2012-04-07 02:30 16344 —-a-w- c:\windows\system32\drivers\IntelMEFWVer.dll 2013-02-12 17:39 . 2013-02-12 17:39 3584 —-a-r- c:\users\Annelie\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2013-02-11 16:14 . 2013-02-11 16:15 40464 —-a-w- c:\windows\system32\drivers\npf.sys 2013-02-11 16:14 . 2013-02-11 16:14 98816 —-a-w- c:\windows\system32\drivers\ew_jucdcacm.sys 2013-02-11 16:14 . 2013-02-11 16:14 86016 —-a-w- c:\windows\system32\drivers\ew_jubusenum.sys 2013-02-11 16:14 . 2013-02-11 16:14 69632 —-a-w- c:\windows\system32\drivers\ew_jucdcecm.sys 2013-02-11 16:14 . 2013-02-11 16:14 421376 —-a-w- c:\windows\system32\drivers\ewusbwwan.sys 2013-02-11 16:14 . 2013-02-11 16:14 28672 —-a-w- c:\windows\system32\drivers\ew_juextctrl.sys 2013-02-11 16:14 . 2013-02-11 16:14 22016 —-a-w- c:\windows\system32\drivers\ew_hwupgrade.sys 2013-02-11 16:14 . 2013-02-11 16:14 212992 —-a-w- c:\windows\system32\drivers\ew_juwwanecm.sys 2013-02-11 16:14 . 2013-02-11 16:14 13952 —-a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys 2013-02-11 16:14 . 2013-02-11 16:14 117248 —-a-w- c:\windows\system32\drivers\ew_hwusbdev.sys 2013-02-11 16:14 . 2013-02-11 16:14 1001472 —-a-w- c:\windows\system32\drivers\mod7700.sys 2013-02-11 16:14 . 2013-02-11 16:14 32768 —-a-w- c:\windows\system32\drivers\ewdcsc.sys 2013-02-11 16:14 . 2013-02-11 16:14 1490656 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll 2013-02-11 16:14 . 2013-02-11 16:14 1490656 —-a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll . . (((((((((((((((((((((((((((((((((( Startpunkter i registret ))))))))))))))))))))))))))))))))))))))))))))))) . . *Not* tomma poster & legitima standardposter visas inte. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E}] 2013-03-18 07:45 432232 —-a-w- c:\program files (x86)\DAP\LinkVerifier.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-03-19 10:55 222808 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 129272 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "Rainlendar2"="c:\program files (x86)\Rainlendar2\Rainlendar2.exe" [2013-03-10 4373600] "AshSnap"="c:\program files (x86)\Ashampoo\Ashampoo Snap 5\ashsnap.exe" [2012-08-03 3400600] "RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-04-19 109784] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-29 343168] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-07-11 574008] "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-07-13 93296] "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2012-09-03 78352] "HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-09-13 103992] "Net iD"="c:\program files (x86)\Net iD\iid.exe" [2013-03-21 104704] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2012-12-25 4474832] . c:\users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Annelie\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-3-12 29106336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-8-25 1337632] HP Wireless Audio Manager.lnk - c:\program files (x86)\Hewlett-Packard\HP Wireless Audio\HPWA.exe [2011-9-22 742712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice] @="Service" . R1 AMTBDA_P861F;anysee Capture Service;c:\windows\system32\DRIVERS\anyseeTU.SYS [2011-04-21 853632] R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/12/30 01:13;c:\program files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2012-09-03 245264] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528] R2 Mobile Broadband. RunOuc;Mobile Broadband. OUC;c:\program files (x86)\Mobile Broadband\UpdateDog\ouc.exe [2013-02-11 246112] R3 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-08-14 43624] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-08-08 299008] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328] R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x] R3 cpuz134;cpuz134; [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2013-02-11 117248] R3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\DRIVERS\ewsercd.sys [2010-03-18 112896] R3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\DRIVERS\ewusbwwan.sys [2013-02-11 421376] R3 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2012-01-05 21384] R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-09-13 1098296] R3 hwdatacard;Huawei DataCard USB Modem and USB Serial;c:\windows\system32\DRIVERS\ewusbmdm.sys [2011-06-10 222976] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-08-05 34200] R3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2012-03-26 22528] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2012-07-05 33224] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920] R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2012-08-07 35112] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2012-07-05 21904] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784] R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-07 1255736] R3 wifimansvc;Wifi Man Service;c:\program files (x86)\Mobile Broadband\eap\wifimansvc.exe [2013-02-11 598528] R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 aswKbd;aswKbd; [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2013-01-15 465216] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-29 204288] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-01 1166848] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-03-06 80816] S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-03-06 136912] S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928] S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2011-02-15 19968] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-05-21 103992] S2 HPPRXSVC;HPPRXSVC;c:\program files (x86)\Hewlett-Packard\HP Proximity Sensor\HPPRXSVC.exe [2011-10-05 37432] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2012-09-24 31040] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-07-11 26680] S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [2011-03-14 346976] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-08-24 13592] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-08 2375168] S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2012-01-09 821592] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [2011-09-06 93696] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2013-02-22 167736] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-16 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-09-16 15928] S2 MongoDbForWaveface;MongoDB for Waveface;c:\program files (x86)\WavefaceStation\MongoDB\mongod.exe –logpath c:\program files (x86)\WavefaceStation\\log\MongoDB.log [x] S2 SBUpd;SpeedBit Update;c:\program files\Common Files\SpeedBit\SBUpdate\sbu.exe [2013-02-27 1097848] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288] S2 WavefaceStation;Waveface Station;c:\program files (x86)\WavefaceStation\Station.Service.exe [2012-10-04 342368] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-08-08 299008] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-06-07 231440] S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-04-01 163368] S3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2011-08-25 620072] S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys [2011-09-17 89640] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-08-25 39976] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2013-02-11 86016] S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-18 26136] S3 IntcDAud;Intel® bildskärmsljud;c:\windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-08-09 12289472] S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys [2013-02-13 46568] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-08-05 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2012-05-10 97792] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2012-05-10 217600] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-05-31 338536] S3 SBUpdd;SpeedBit UpdateD;c:\program files\Common Files\SpeedBit\SBUpdate\sbw.sys [2013-02-27 40856] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2011-08-05 42392] . . — Övriga tjänster/drivrutiner i minnet — . *Deregistered* - CLKMDRV10_38F51D56 . Innehåll i mappen 'Schemalagda aktiviteter': . 2013-04-26 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 05:28] . 2013-04-17 c:\windows\Tasks\AdvancedDriverUpdater_UPDATES.job - c:\program files (x86)\Advanced Driver Updater\adu.exe [2013-03-30 14:02] . 2013-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2013-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-22 17:34] . 2013-04-26 c:\windows\Tasks\HP Photo Creations Communicator.job - c:\programdata\HP Photo Creations\Communicator.exe [2013-03-28 12:44] . 2013-04-09 c:\windows\Tasks\HPCeeScheduleForAnnelie.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 0StoregateSyncAddedOverlay] @="{EDCDC9C6-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C6-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 1StoregateSyncNormalOverlay] @="{EDCDC9C5-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C5-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ 2StoregateSyncIgnoredOverlay] @="{EDCDC9C7-8EDB-4043-9BAF-61A440EAF0BE}" [HKEY_CLASSES_ROOT\CLSID\{EDCDC9C7-8EDB-4043-9BAF-61A440EAF0BE}] 2010-11-21 03:23 444752 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-03-19 10:55 261704 —-a-w- c:\users\Annelie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-03-06 23:32 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-11-13 23:32 162552 —-a-w- c:\users\Annelie\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-28 1935120] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-08-16 1424896] "SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-12-19 44880] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-07-11 440640] "Net iD"="c:\program files\Net iD\iid.exe" [2013-03-21 111872] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ——- Extra genomsökning ——- . uStart Page = hxxp://google.se/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; IE: &Clean Traces - c:\program files (x86)\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files (x86)\DAP\dapextie.htm IE: &Verify with DAP - c:\program files (x86)\DAP\dapverify.htm IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Anpassa meny - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download &all with DAP - c:\program files (x86)\DAP\dapextie2.htm IE: E&xportera till Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: Fyll i formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Läs EXIF - c:\program files (x86)\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm IE: RF verktygsfält - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Skicka bild till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Skicka sida till &Bluetooth-enhet… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: Spara formulär - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{7199EAAD-4BC0-43A3-9B28-C2CEDE778524}: NameServer = 195.67.199.27 195.67.199.28 TCP: Interfaces\{BF291F8C-FFEC-4B50-80C2-A29E8C2770C1}: NameServer = 195.67.199.18 195.67.199.19 Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\ FF - prefs.js: browser.search.defaulturl - hxxp://go.speedbit.com/search.aspx?s=D3IaWIT8&q= FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/ FF - prefs.js: keyword.URL - hxxp://se.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= FF - ExtSQL: 2013-02-28 11:38; {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi FF - ExtSQL: 2013-03-18 08:52; [removed]; c:\program files (x86)\DAP\daplinkchecker FF - ExtSQL: 2013-04-18 12:02; [removed]; c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\extensions\[removed] FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: browser.turbo.enabled - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.chrome.favicons - false FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: content.notify.ontimer - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.switch.threshold - 750000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . . ——————— LÅSTA REGISTERNYCKLAR ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Andra processer som körs ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe c:\program files (x86)\ExpressFiles\EFUpdater.exe c:\program files (x86)\IObit\Advanced SystemCare 6\AutoSweep.exe c:\program files (x86)\IObit\Advanced SystemCare 6\Monitor.exe c:\program files (x86)\Intel\Intel® Smart Connect Technology Agent\ISCTHidMonitor.exe c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe c:\programdata\Mobile Broadband\OnlineUpdate\ouc.exe c:\program files (x86)\WavefaceStation\MongoDB\mongod.exe c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe c:\program files (x86)\TeamViewer\Version8\tv_w32.exe c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\windows\SysWOW64\RunDll32.exe c:\program files (x86)\CyberLink\Power2Go\Power2GoExpressServer.exe . ************************************************************************** . Sluttid: 2013-04-27 00:23:00 - datorn startades om. ComboFix-quarantined-files.txt 2013-04-26 22:22 . Före genomsökningen: 735 188 054 016 byte ledigt Efter genomsökningen: 734 636 535 808 byte ledigt . - - End Of File - - 19186D05E82FA3F204F62E433FE35861
Hello, AnnelieP.

Thank you for the CF log.

Please work through the following tasks

1. Uninstall Multiple Anti-spyware Programs

I see that you are currently running multiple anti-spyware programs:

  • Avast Internet Security
  • IOBit Malware Fighter
  • Windows Defender.

All three programs have real time monitoring abilities. Running more than one set of spyware monitoring components can cause conflicts and can sometimes lead to unexpected complications and system slowdowns. It is recommended that you keep only one good anti-virus, firewall, and anti-spyware program. You can uninstall the other anti-spyware programs as follows:
  • Click Start and select Control Panel.
  • When the Control Panel window opens, click on Uninstall a program found under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
  • Look through the list of programs for the one that you would like to uninstall, and then left-click on it once to highlight it.
  • Click on the Uninstall button.
  • When asked if you are sure you want to uninstall, click Yes.
  • The program will uninstall, and when completed you will be back at the list of programs installed on your computer.
  • Repeat the above procedure to uninstall these additional programs:

  • Yontoo 2.051
  • IB Updater 2.0.0.550.

  • When finished, close the Programs and Features screen.
2. Uninstall Toolbars/Browser Add-ons from Internet Explorer

If any of these toolbars/browser add-ons(Yontoo, Incredibar, IB Updater ) still appear in your browser, continue as follows:
  • Open Internet Explorer.
  • Click Tools > Manage Add-ons.
  • In the Manage Add-ons window, under Add-on Types (found on left side) highlight Toolbars and Extensions.
  • Under the Show: drop-down menu (found on left side) make sure All add-ons is selected.
  • Highlight the toolbars you wish to remove, and select Disable.
  • The Disable add-on window may pop up to warn you that related services and add-ons will also be disabled. Click Disable.
  • Click Close to dismiss the add-ons window.
3. Reset Your Home Page and Default Search Engine

Removing the toolbars may have changed your browser settings (homepage, default search engines). If so, please follow the instructions found HERE.

Please run the following scans

1. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

2. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

3. Malwarebytes Anti-Malware

Please download Malwarebytes from Here or Here.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan
.[external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Post the report please.

4. ESET Online Scanner

Note:

  • Disable any antivirus program and antispyware programs to avoid conflicts.
  • If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted, then double click on it to install.
  • Please do not surf the internet while your security programs are disabled.
  • Let the scan run uninterrupted to avoid a stall.
  • Remember to enable your security programs when the scan has finished.
Run ESET Online Scanner from HERE.
  • Click the green ESET Online Scanner button.
  • Read the End User License Agreement and check the box YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • If prompted, allow the Add-On/Active X to install.
Under Computer scan settings:
  • Do not check Remove found threats
  • Check Scan Archives.
  • Click Advanced settings and select the following:

  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

  • Click Start. ESET will download updates, install itself, and begin scanning your computer. Please be patient as this scan could take up to a few hours to complete.
  • Wait for the scan to finish. When the scan completes, click List of found threats.
  • Click Export and save the file to your desktop using a unique name, such as ESETScan.
  • Copy and paste the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
SUMMARY: In your next reply, please post the following:
  • JRT.txt
  • adwcleaner.txt
  • MBAM log
  • ESET log
Hello, That certainly took some time! :pullhair: I thought the last scan never would end. I had some trouble with ESET. I use Firefox and it was impossible to start the scan from there. It took some time, before I realised, I had do make the scan via Explorer. Besides that, I had to find a way to unactivate Windows Defender. Well, well - it's done now. Do you know, if the Defender is activated automatically, when Windows is performing an Update? For your information, I deleted the two directories on the D disc. They and some other, which I deleted too, were from an old recovery backup from a friends computer. Here are the four logs: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.1 (04.27.2013:1) OS: Windows 7 Home Premium x64 Ran by [removed] on 2013-04-28 at 11:24:20,16 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\ib updater Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminstaller Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\iminstaller Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\search settings Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\smartbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\mybabylontb_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\mybabylontb_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\sweetim_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\sweetim_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\sweetpacksupdatemanager_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\sweetpacksupdatemanager_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajam_install_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajam_install_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip" Successfully deleted: [Registry Key] "hkey_local_machine\software\pip" ~~~ Files Successfully deleted: [File] "C:\end" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\big fish games" Successfully deleted: [Folder] "C:\ProgramData\tarma installer" Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader" Successfully deleted: [Folder] "C:\Users\Annelie\AppData\Roaming\drivercure" Successfully deleted: [Folder] "C:\Users\Annelie\AppData\Roaming\systweak" Successfully deleted: [Folder] "C:\Program Files (x86)\perion" Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\spigot" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader" Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{00455E4A-52E0-4CE9-91B0-C7773B922FC4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{012D66D1-7289-4E53-8152-F34380E3D869} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{01FC165F-E39C-4E19-A2C9-FB01C90FE090} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{024EFBF1-4539-44E6-B09E-F116302F4088} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0355B154-D4BB-489A-BF2D-7AC2CF49992D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0428E869-15D7-4C16-89F1-ADDB820A52D6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{04E091C2-3C96-4F67-8705-2502CEC7F7A5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{05F75B20-CD92-4B20-8B29-ACDF8539BB84} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0616A02C-F253-4398-BC7D-74158EEACCDB} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{06454A8A-6A4B-4CBD-8276-8D3AFE1840AF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{07DF6AE7-0D39-49A4-9C5A-661821D20B19} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{080EC4BF-7A89-46AE-940A-D690D322AD9F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{093C49B7-0746-4346-A461-E5DB8E42D752} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{09F25CDF-64DA-4644-A8B4-D6BB40A2E655} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0BCF421B-469C-44C1-B9A9-4AD2A89C8D16} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0DA96436-680B-4D28-9655-8666AE362770} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0DEF6745-811C-4C08-9F13-565DE5A382BF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0E0FFFD5-7281-4B0E-9C07-58A1308E9EB5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0E3B557A-1343-4A2D-B527-2E4BD01B61B0} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0F450348-5DA6-472B-962B-164600F85AA4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0F46E522-8D1A-45E7-9323-EF6CC0847245} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{0FAE7AC5-B6B0-42D2-B36C-8EB2BD78A150} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{101DDCD8-48CA-4486-A5C5-887254A6A6C9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{10927262-ABD6-4A9C-B750-33780F957808} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{10D18A47-1927-4A0E-A7C6-D208F8F6D0EA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1223B99C-F737-4217-9426-99D35C9A4827} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{123CCD42-D90E-4AF5-9180-A33B1EC87BCD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1246CBD8-0B77-42C2-8093-4314F4C8AD48} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1408E18C-45D8-4C58-BEC3-C0B55E28C6B8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{145C8CAB-C417-4E54-BC67-222B7BA05A83} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{149ABCCC-072B-48EC-967F-5E8AD0B61E14} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{15205A4B-6742-49F5-8F55-B616B67430B3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{157EB59C-2107-404A-ABA7-ABB518DFBB6E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{15CC27D3-62BE-4659-B8D2-AA1EDFB00C5B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1609F5A3-2477-47BD-A7EF-B8FA3919AAB6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{16FD3048-E6EF-45D2-9C2F-2C4B94977C25} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{17436617-15BC-44F0-B454-C8A72D9CCCA4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{17E7CB41-24D9-4BCC-AA33-CCD06306BE5C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{18C1F9AE-E6E0-41D9-9DC6-F1A6BF514430} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{18C287FB-52D2-4C39-8BBB-72001CF641DC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{18F0913C-1B7C-485D-BA0D-5801782EEA54} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{19CAF461-D7D0-4AF7-A8C6-62878A880866} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{19D48DCD-5225-4B5F-A2FF-ED05AE831C15} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1A655665-667C-41FA-A7DD-BDACF15E901B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1A8DD4DE-638F-492E-94C4-0DD1F058238D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1B3449E6-D547-4B00-BD07-910B9C5C81CD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1CFAFD56-75D1-45A5-81B3-1FD8040A9CFD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1D09FE80-882A-40AB-898B-D8A1B2AC2BF5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1D6BF97F-5EE8-4F31-AA67-99792EC1C213} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1D762694-6CD4-49F9-9449-D0C704F82EF3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1DB5DB8D-DD8D-438A-827A-1CB5BE941881} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{1E848DC2-B820-4D24-ACCB-B47D10BA4EC3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{21F9B9DC-72F0-4DD0-980E-E8DE61AA2722} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{22129692-D725-47F5-8735-F415596447B5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2253043C-F4B7-4C1F-8BB6-6667C870446C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{22F04A30-B228-42E1-9EDD-16EF8340B850} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{232EC810-092A-44D1-8072-10F4693B3828} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{23386973-7EC7-43BD-9651-5D76C4F1F1C0} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{23584057-75FE-4F88-B44C-2C2D28737B28} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2628C202-083F-4B3A-860D-606455E471AB} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{26321554-A668-4A9B-A17C-2507C673E576} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{269902BB-AC52-41C0-B5FD-728D4D59EA11} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{26D1401A-8E59-479C-AD01-C2552668C112} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{274735A8-DBB7-4A4D-B6F9-3CCDFC94E51B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{27B25C9E-39B8-4BEE-B518-4294BAFEA0E6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{27CAE6CB-A486-4A7B-98A4-FE90A61CC440} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{28F91FD2-F9A2-4212-8DB4-B124BEA66F50} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{29540A22-A688-4D7C-B703-B574AF75705A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2AB3482F-131D-443D-BD1F-E8A58213B18E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2ACC8B99-09E0-46D4-80FA-9761E63FE25B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2B35FE23-52DE-429F-A037-1F0632188C18} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2C288774-F91F-41F1-B412-483EF1195ACA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2E77B4F0-EF9C-49CC-9F92-B6BC077A4244} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2EF091C4-4AA8-44F7-9475-CC9BD768AADF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2EF7B70F-7186-4A20-A98C-4A17B06D6CD5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{2FCD11A1-BEB5-4EE4-88F4-692081925A37} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{308E0939-3544-4826-BFB2-F99EC3182044} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{311CF1FD-A1B3-4986-88F3-1E94DEAF6784} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3145D1DE-5177-4ABF-9E13-D9434BE175E2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3197A425-5C86-4564-8E87-7925AAA65914} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{32EE73A0-A567-4A80-8923-185D90167CA3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{33033059-65CF-4553-A484-C0F489349755} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3375645B-1B73-4B95-814B-36CB8A9CB377} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{34BE1B1C-A141-4D33-B8B3-ACFE49EF71F1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3597F7B0-8CA4-4F57-9193-1D9973564B57} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3831F6FB-296E-4A57-B840-09BC2FDE5D26} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{38C0C496-3D8A-447F-8AD1-ADBB6B78AB84} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{38C7136F-0678-4B32-A27F-B764E07E0DED} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3A1FC1CA-3346-46F4-A505-F0EBDDF08C39} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3A753021-D3A1-4D7C-96A4-5867E0BF0F40} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3B0B3011-74A6-4975-B03B-459E2D0A4A17} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3B4B16AE-D4A0-4570-B34B-8646D1B5495A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3CEB44EE-BF26-42A3-9D83-BF9DC84E5475} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{3D52592A-DF7F-43DF-981B-8388A002CA1E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{400EB045-ECA0-4850-A530-3F3A828C3DD3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{41231857-1DCF-4B6A-8308-A36E5765BA82} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{413F957C-1C53-4461-B53D-8D1B1F188E9C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4169AD5A-B573-4DC7-BE71-E09B926204C8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{41A3D11C-5FCB-4BEB-A976-049D5831771D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{431AFB63-BB3A-423C-BFCF-574D6F26153C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{44239C26-D1FB-4F29-B4E9-872EFB25E010} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{44A4014D-2360-4B8A-A3F0-F61686DB35D3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{45067BC0-95FA-4F7D-82A0-7765C2B774F9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{45A4E852-05B8-4C29-9B27-9DC79090E8FC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{463196A5-9C35-41AB-9946-E300D9E5AF75} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4631A2E0-DF13-4B8A-A6D1-80D21459A294} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{46CFAE61-3E07-4D3D-A8AE-15ABC7236C23} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{47A4EDEA-BEF3-4D8C-846F-FE9E831F029E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{48658EDE-E4BC-48CC-9C0F-30C555BD010C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4949B5CD-70AF-4E96-B13B-F109B7E91D3E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4B1FD1D0-B3CC-4A46-87D3-AE73B1DD239D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4B6A5F1D-3EE4-4193-92CA-42241B370619} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4BCAA7BA-EACB-485E-88BE-5CFD4DB98A38} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4C79A59E-3B63-4EC2-8936-571DE9C92D1C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4D9086A2-9B74-455D-891E-7ABDA3F1614C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4E194997-6236-473A-B619-25402D855A22} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4F3B7282-EB45-42F5-BA5C-38BE5C547A9E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{4FCE2971-60DB-4B0C-9410-EFF180CB15F3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{50932793-BBD8-4D9E-9C95-25C383205526} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{50C56335-D16F-4BC7-AB80-4054189A1C8D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5171D8EB-EC9B-423F-8D03-1CD8E3662BE1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{51B23B88-6F06-4786-BB74-E8F350BFCB29} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{528507FC-0ED3-46F3-A753-DE1DFC0FF740} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{52919C0B-5E7C-49DE-9E3E-4F69E5E95D05} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{540F3B3B-0E21-4723-856A-242A7FC03091} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5643DC07-07AE-47E2-BE24-ADA84F104314} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{56D7A793-505E-4F56-94BE-033BB72B5EB8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{57178373-E54E-412C-B3F8-9A3CE0EBF113} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{57E69672-AED6-4536-896C-AF1D11D8A260} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{58602D67-105D-4277-A24D-F5E786E314F3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5918F56B-D978-4ADC-BA2D-09C2D8D27050} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5A21D3FF-B7D7-4EAD-A893-361E30899D12} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5A24C706-9331-4D21-9899-AFBBE6BC5773} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5BB65590-FE40-497B-A6E5-1952BA04B708} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5BBA4D17-7685-4358-9E58-D7488663FB85} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5BCFCBCE-AE80-4196-972A-5AC91246418D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5BD097B5-3571-4F56-8BB0-729B2EB869C6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5D265361-FF3C-4189-A00D-271475F09B21} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5E5E62FF-B254-4233-A5E6-460E4F505BCE} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5EB981F1-791F-4ABB-B9E6-16476CD04AE6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5F3CDE3A-7D2C-4095-B256-40724B23569C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5F70A8FB-14EF-4938-A6BE-8A828FE9ED0A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5FA5F672-87E5-413A-BABD-923EBDE4D4B9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5FD4B9BE-FA66-4157-A922-F40EC84F259A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{5FED6DDB-6A18-4F98-8E86-AE3E14D6A375} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{60A0D38B-99F7-4403-BB99-49DF8F8CE473} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{60EE1D3A-91E1-4F9D-9F00-A8B255228F7B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{61A061B5-5979-45C9-A6F3-22CE87F2EB20} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{63BE4DB7-C43C-4921-BA8B-C2D86CD0E426} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{63F6840A-3987-40D8-A138-E08F8B325D46} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{665CF587-3AB6-4033-86D3-6F326D41A94D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{66DE04A5-9291-4F73-B1F1-660B5D4B95B2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6828577F-BE2E-4711-8374-795AD2E22327} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{684E5463-515B-4CCB-A08F-09FA16CA60E2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{68942DE7-814C-4992-BD92-D8ADB1710FB5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{68F68257-C189-4650-8A07-8394E2C7D5EA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6954624E-66D8-4481-A952-032E1B5903EB} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{69797905-4CD5-4908-918B-99FCDF715AB6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6A9A61E4-BC1D-4147-93FE-B3A1612D1FD9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6B485CE4-DBBB-40C3-9E9D-46492B7A81C4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6D457595-7AC5-4833-8E71-2E100597B4EC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6EC8C167-8F39-49BF-946F-3C50556F248A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6F4A5E63-DF7C-4AE7-896B-0819A0FF9EA2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6F949E0A-A0C7-4F2F-9A11-3E1B15275648} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{6FF32FBD-70E4-460A-BF95-365B9BB04BB7} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7233FEBD-BFFF-4E77-B372-9E17770AA338} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{72885B53-526B-4BFB-AC4F-E25F507D3700} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{72DB9EEB-BFAF-4008-83AD-C89ED2841453} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{73CAAC98-3D7C-46E6-B408-D15C7ABE0459} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{74349E0E-21DC-4EC8-872E-D46D886B2BF6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{75004CDC-5CA6-4274-92E1-AE18B0381001} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{759CCB7B-FE17-45FB-B62A-98008612AF80} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{76C4A32B-A2EB-4945-9DE4-6DBC4B5BE8F1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{76E282CC-D395-474D-8F51-CD3D676A94C6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7992E26D-97F1-48FD-BBBA-7695DD02288D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{79F8482C-8295-4215-80CB-4BF8263BEEC0} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7BAED964-D3F6-47D4-AA1F-779CC2AAC060} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7DC4D1C2-BDA5-4EFA-A57D-2755560B4C79} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7E1AE44F-20EA-46CE-9024-3D20AFA70094} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7E5A7D3F-93B0-47BA-9CFA-B46FD72321BC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7E772E58-7C22-410E-BAED-D138DC23C5F3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{7F89A363-BE83-45DF-8781-03BCFF95B889} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{82166FB2-C8FC-40A7-ADE2-63E4BF34F793} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{82C78161-D57D-462C-A22E-D7D7D91D86E2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{830B0C12-514E-451B-A23C-5DD74759FB21} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{83A549E5-8671-492E-BAB7-9D1938414656} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{83C669EB-9AD4-4116-AF0E-FB16D453E75C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{84E71FAF-1387-4ACF-BFA8-2E2F67ECE60A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{851CAB01-93DA-4D9D-AAFE-523D8B047480} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{85B7C2E1-B85C-4657-AD3C-2C1B21BF126F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{88075DDB-E0D2-43C5-B7A1-6C2B58B8F53F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{881875BA-2458-48EC-8EA2-83F3A8B9FA0A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8843C296-49C8-4DF2-9394-82E889D17F3F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8916C0E4-4D25-46B8-BE7B-476DD150251B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{89C01E02-860B-48C1-83CA-E8ABCF3D713C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8A5293A9-6799-41DF-BB04-F0E4558B075C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8ABE0295-F06A-4E14-8BC7-AFCFEF196E9E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8BB1BA4A-5DC1-4EC8-A3C1-58CFB1B582E0} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8C011A16-BA22-4F3D-A078-DDAA12762B36} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8C31B97F-3FA2-438A-8775-077215EFC4CC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8D3B8901-4485-457C-944F-A5F3E5F18A44} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8E55A94A-03C5-41D4-A572-529CA8BFE6F4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8E874D61-B0B4-4FC8-9FF5-1B2FC871694D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8E8B7B35-2118-4262-B72C-A73AFF697601} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8F0BC722-EFB5-4C79-845E-DCD914DACFCA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{8FCC2804-FDD8-469B-8063-B6150FFADF5C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{90AFE95C-87F7-4163-8AFB-0C0AD93B5514} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{916EA87E-8C2F-46B3-B549-2E721889F6C4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{91FD68FA-3DAB-4C46-B56E-F53E83F09D33} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{92AD9C57-93D9-49D3-822F-CD6B8C9C4633} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{92B1FEE5-B35F-4AE3-8509-3E28A11301C8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9321B3D1-19A1-449C-AB6C-1D6F999B22A7} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{933E9727-722E-4F17-8D2F-70F6DBE562AE} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{934828AF-FBD4-4C1F-B23C-00AE8C684D39} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{944E4849-4080-4F8B-A490-B907A645E8E9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{947B6906-08EB-4EE7-B657-73165C17E197} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{95A2B888-49CF-4E33-B409-B58C22C7A266} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{96F87812-FA75-4674-AA8F-338E1CFFE9AC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{98166092-66C5-4392-9F54-1FAE3FA93F21} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{99A38BD0-3E60-4119-955A-7FE155C596AA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{99F77D5C-012F-44A0-ABC2-CBD79AA02EE3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9A040BAE-A43D-4A2C-9160-977AE8A5CE9E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9A56696E-98C4-4132-B334-0096DE526580} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9B5AE57A-1767-4B27-9940-BDB62E0CEA25} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9B8FAAC8-B88E-4EC8-A899-A2F6CEFAA5FA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9BC61481-DD99-45DD-BBFA-D71565E92294} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9BD76FA7-ED6B-4CCB-B13E-60C20AE4B847} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9BD8E26E-F55F-4DB0-90F4-676B03317812} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9C22ECD0-91C0-4F54-AB00-820D8706A844} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9C3ECCB2-4AA3-4C58-89EE-C46D9E5DA862} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9DB4ECFF-AA44-4159-9CF3-69F41F6698E5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9F0F754B-04CB-45F1-9A8B-73BEAFAEF7AD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9F1A3102-2425-4591-B746-8778FD9D5B8A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{9F82DBAF-73B1-4126-B11D-7BC2FE5D8EFA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A08F9EB1-241B-407A-9BA1-69A3FA80C096} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A10FBFCB-EF2E-41A6-81C1-B110D52D0ADD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A1D5C3F7-AF5A-4099-B52D-24A6BFFDA881} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A21774E3-8BEC-4811-966F-F69D7577FA13} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A28568EF-6CE7-413D-B43B-75FDB5352F26} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A39DEE3F-A4D9-44DF-9DDF-A06FDC128A28} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A4BF8C14-6BD2-44C4-94C4-927D5B6D1358} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A5B80D99-5DAC-480B-89FC-3FEC838D5732} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A751DF72-DC28-4B8C-BB43-48F3A36E959A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A8353724-E9A8-4D19-B598-A6EA6F6CC29F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A939EBA9-2354-47B9-9A7F-0B22016F6735} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A9BE8FA9-F45C-437C-82F3-19E6C47EE08F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{A9EF8BC6-C0DA-47F0-98D8-3FC394983B91} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AA2E96C6-C19B-4398-BDD2-7617D5C5AC96} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{ABDADD39-0DDB-40C4-8E04-3208E5EDE0ED} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{ABF1BF73-277C-4D59-A716-3EF830D508A2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AD312E66-9DFE-4718-B02F-2B1968F9E2AD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AD9E7973-9B6C-4048-BB2A-924AB6810162} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{ADF8EB26-3E66-4717-B65E-DFD332A9ACE7} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AE60B8B1-AE34-4DC8-BABB-EE69AA95CF3F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AF5F1FB3-13B5-4797-9D00-AF41AFDF1FD7} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{AF696697-9C3F-4B91-A621-AC0D20C9927E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B024F1B9-11DF-455C-90B1-6E8FE82F6BC5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B07B19F7-2135-45BE-B083-4421C6D66870} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B213D45A-A95F-4982-BF73-84EB401BF5E9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B3EDEC23-C54E-48A7-BFBE-96A07BB1BBE2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B56FB05D-341B-49C2-9793-A23C91D5472F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B58A0859-5EFE-492F-845C-90007BCCDA76} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B5BCA48D-3A01-4A23-B20C-EF98C8871B37} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B637A70F-8E9B-468D-BC19-39C3F3607952} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B6F51446-E2DF-4EF2-9030-712F6EF7E2DC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B72947A2-BBF6-419B-AC05-FA5BF49A3993} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B9C860C2-6D79-4D8B-908A-4709E5057737} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{B9CC6AA8-5DD7-4A7D-81B7-3EA3685F1EF3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BA7984E8-589A-4399-A599-A61DA2897C2D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BAAB178F-D10E-4EDE-B8CB-5C4034D25595} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BB020475-F55F-45F4-82D7-BFA295888321} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BB4051EB-F67A-4758-A092-9917D270D138} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BB6FBA0F-FFDB-4D44-9538-68E80895D290} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BB9C8926-6BA0-4DE2-AA4D-FDBF5050F28B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BBC63720-89FD-4E75-9999-25686D831F05} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BCB4065C-B68D-45DA-8470-7051C8A48300} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BD06058B-F688-4686-8BEE-AC5192F47F08} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BE9AD40C-B401-4220-AB90-9EFDB66921C6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{BF4DB9ED-FCE8-4179-A695-6C949032B11D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C0C090EB-A23A-4BF9-A1D8-F8A5386A8A8A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C141CC6E-6BF4-4ECA-8E7F-262F37D2BBC4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C1CA5B89-5398-474C-BC70-2E073CB090E9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C449E7A7-6000-4B70-B291-325D5FAF4FC4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C4F2DE8C-C3BE-4070-8CC9-253C093105E5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C623E18B-0713-4B04-B8A8-550F599CE7FB} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C650D1A8-172E-443B-BFBA-1CF08D9D2B54} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C6948BDE-BB5F-493B-98F4-E3FA915E36D9} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C6E2D9D5-AD33-46D9-B0DE-399E9F8CC981} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C70A3BA8-9718-4B05-BB34-92656444EF41} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C7709AD8-C99B-4F2C-AEDF-FE5238B00073} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C7E88826-1B6D-411F-93CB-69D5F767C9AA} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C877A221-FED2-4A19-8C30-65EB37D8C7C5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C8BF6A71-0870-47F4-9284-46C843ACA4E0} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C937AB8D-1B42-49AD-AF5C-DCA8C4F06092} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{C94F2379-C310-4F61-A917-3AFB385EDFF3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CA10A3F4-6E0C-4D5B-91AE-5CCAAEB8773E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CB1C3681-F892-4A5E-8F00-68172847FCAF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CB3C9E06-6C9F-49A4-A215-C8EE6640D91F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CBB73731-7429-4131-88D2-924F78CD7594} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CBD5E663-17FB-4E68-952C-FFB7DB61BD3A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CBFEDB40-9B56-466B-A34C-E32FB397E20F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CC5A0E84-4F62-4425-BA11-7FCDC8B9BBF4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CCD04F24-C712-426D-B719-884DA18E3A45} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CCEC63F1-A841-4B88-8537-978692909F2E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CCFBD5EE-B20D-4A14-8800-50D30CE2B132} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CD58AF68-AB8D-47F6-9AD3-B2228EB52FF8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CE16B5DB-D6E7-41A6-9B61-9AC39C314926} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CE227A77-2D18-4246-9FAF-9444DEC46520} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CE3FC8FC-7AAC-47FA-9379-4930B3CDD718} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CE4EF6C4-BBC0-431D-83C5-C951A22E7064} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CE7A18BB-8103-4E54-AB62-30FB89E8B683} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{CF1F7701-9837-4FF6-BCAE-8EAB5C6D2555} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D00B07CB-4968-4E23-8181-B373F54882C1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D015A84C-13C7-48E0-998E-D752184C1A44} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D0B0415C-523A-414F-8570-DB71A48696B6} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D1189CA0-86AF-45D4-A0A2-A154BF584182} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D24C0B23-086D-40D5-A022-7E2997BB4BDE} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D29C45A3-349E-4383-8CA5-83D76031C5C7} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D3442EBA-8948-44D8-89F0-B68BFF9EC10E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D430E66E-6026-4CCE-9B66-350C5B829001} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D4439F1C-1175-4F11-94D2-57DBFDFDE69E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D6E48A83-B7C3-4386-95E2-9CB96E910595} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D6FF1E5D-CB1B-4F4F-94E2-C1A316A86B39} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D74964B1-4714-47A7-85A4-5DF625C8136C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D8353204-6AE9-4A1C-9121-623F3593E709} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{D8E0889C-294F-45F0-8948-3117517ADA94} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{DA406E89-246F-4E67-BE22-783736C6C692} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{DB095571-EAB1-4F45-81AD-8D8FC136010A} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{DB7D3D6B-3F6C-4349-8A7B-CDCD4E12E360} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{DE0851F3-3785-4C73-9F9F-02D2841977B5} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{DE6C9DBA-36A4-4B9C-8207-4318011E1A30} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E08873E1-98D3-41A7-85F8-409CF4353D10} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E0D264C1-50E9-45EE-80DF-0296024FA87C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E0EA0C96-D0A8-4125-A5C6-05035179407E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E20545B1-713E-42F9-A4C3-A1F0D699629E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E54D836D-4F02-4537-AFAA-35F34F5E891E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E5A29A84-0B81-4640-B72B-041F5657B047} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E60B1200-52B5-490C-A2D8-A90602665C68} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E6746A01-EE2E-43D2-9DAB-D0D8BFAB12AC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E68387F4-8570-4A52-96BA-8672C5762644} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E858F3C5-DFEE-4555-BF8D-DB8F97ABF686} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E8D6B392-D46F-4F6E-BCA0-402469ADA6AF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E8EEE258-4BC6-43B1-A5D1-D460AD11C7B4} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{E907206F-A498-4739-AEB4-1EBCD7523F71} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{EA142E3B-906B-4677-A151-0D461822DB6E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{EA4A31EE-D720-472E-86FD-48DD64D8B1BF} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{EB17E706-7A87-498B-BC76-48D640CF858C} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{EB89FCB8-ACC7-41A5-B4F6-AB0FDD5BEF72} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{ECAC97A1-8619-40E6-B43F-EF030947F4CD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{ED45BEC9-1E04-4FA5-B542-7263E1E6726B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F0060E73-1F4B-4B67-AC80-E04749C30CD1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F175A190-FE4F-4F94-AFD3-C08311D78267} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F2A0CF81-187B-46A0-A0D2-DD474F6079AD} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F40B6487-9F7F-4D0B-9DF2-D25A0A80AE81} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F4CC8F40-6E57-4532-B1C7-3E7F0CCD6ED2} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F59D4887-FFCA-46DC-8012-E9BF48328FED} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F5B31AAC-6EE9-4E69-8492-F05650D63C19} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F687035B-A8CA-4CBD-8850-821E0AC7D39E} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F6CD76A0-7DB4-4F98-AAEA-8B175398DE5D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F88AFE6B-87D0-47D5-A883-9492B1739113} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{F96EB641-3696-4335-A848-84CFCFFE3DC1} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FA0C27FA-977E-44B2-9DF9-C2E2BE4418AC} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FA18134C-7C33-427C-91FD-284BA8130274} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FAE6970D-A62C-47C4-8264-5E5D3B6C943D} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FB28FCAD-BFE5-4539-AD6F-BFD60451F19B} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FC79B829-4598-4888-A9F0-D4956721EA4F} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FCBE2518-9C71-4FD0-9C7B-DB2FB31FF7D3} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FCCBC759-B42A-4616-BD4D-3659ABC701EB} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FCD7397C-8553-4388-912D-0F48B23DE6F8} Successfully deleted: [Empty Folder] C:\Users\Annelie\appdata\local\{FD206D64-BBE2-4622-90D7-8E18546219E2} ~~~ FireFox Successfully deleted: [File] C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\user.js Successfully deleted: [File] C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\bprotector_extensions.sqlite Successfully deleted: [File] "C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\extensions\[removed]" Successfully deleted: [Folder] C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\jetpack Successfully deleted the following from C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\prefs.js user_pref("extensions.wajam.affiliate_id", "5921"); user_pref("extensions.wajam.firstrun", "false"); user_pref("extensions.wajam.log_send_info", "false"); user_pref("extensions.wajam.no_trace", "false"); user_pref("extensions.wajam.server_current_mapping_version", "0.21086"); user_pref("extensions.wajam.trace_log", ""); user_pref("extensions.wajam.unique_id", "FB770942C2CEFA2A3B9D4397BFBC35B3"); user_pref("extensions.wajam.user_current_mapping_version", "0"); user_pref("extensions.wajam.version", "1.26"); user_pref("sweetim.toolbar.RevertDialog.enable", "false"); user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true"); user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1357579677664"); user_pref("sweetim.toolbar.Visibility.enable", "true"); user_pref("sweetim.toolbar.Visibility.intervaldays", "7"); user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true"); user_pref("sweetim.toolbar.cda.HideOveride.enable", "true"); user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true"); user_pref("sweetim.toolbar.dialogs.0.enable", "true"); user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js"); user_pref("sweetim.toolbar.dialogs.0.height", "335"); user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog"); user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;"); user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?lang=$locale_id;&toolbar;_version=$ITEM_VERSION;&crg;=$cargo;"); user_pref("sweetim.toolbar.dialogs.0.width", "761"); user_pref("sweetim.toolbar.dialogs.1.enable", "true"); user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js"); user_pref("sweetim.toolbar.dialogs.1.height", "300"); user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog"); user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog"); user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"); user_pref("sweetim.toolbar.dialogs.1.width", "500"); user_pref("sweetim.toolbar.dialogs.2.enable", "true"); user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js"); user_pref("sweetim.toolbar.dialogs.2.height", "150"); user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove"); user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog"); user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp"); user_pref("sweetim.toolbar.dialogs.2.width", "530"); user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.google.com/.*|.*.google.co.in/.*|.*.google.com.br/.*|.*.google.es/.*|.*.youtube user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false"); user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); user_pref("sweetim.toolbar.mode.debug", "false"); user_pref("sweetim.toolbar.newtab.created", "false"); user_pref("sweetim.toolbar.newtab.enable", "true"); user_pref("sweetim.toolbar.previous.keyword.URL", ""); user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_VERSION;&crg;=$cargo;"); user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true"); user_pref("sweetim.toolbar.scripts.0.callback", "simVerification"); user_pref("sweetim.toolbar.scripts.0.domain-blacklist", ""); user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb"); user_pref("sweetim.toolbar.scripts.0.enable", "false"); user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb"); user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js"); user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true"); user_pref("sweetim.toolbar.scripts.1.callback", "simVerification"); user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*"); user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb"); user_pref("sweetim.toolbar.scripts.1.enable", "false"); user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS"); user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js"); user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false"); user_pref("sweetim.toolbar.scripts.2.callback", ""); user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..*|.*.yahoo..*|.*.youtube.com.*|. *ask.com.*|.*.sweetim.com.*"); user_pref("sweetim.toolbar.scripts.2.domain-whitelist", ""); user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script"); user_pref("sweetim.toolbar.scripts.2.enable", "false"); user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad"); user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid;=chff1"); user_pref("sweetim.toolbar.search.history.capacity", "10"); user_pref("sweetim.toolbar.searchguard.enable", "false"); user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true"); user_pref("sweetim.toolbar.simapp_id", "{3E9D732D-51AA-11E2-9BCD-C01885ECD5B6}"); user_pref("sweetim.toolbar.version", "1.9.0.0"); Emptied folder: C:\Users\Annelie\AppData\Roaming\mozilla\firefox\profiles\8k3w0sso.default-1349290452184\minidumps [86 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 2013-04-28 at 11:29:30,42 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # AdwCleaner v2.202 - Logfile created 04/28/2013 at 11:32:06 # Updated 23/04/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Annelie - TERRA # Boot Mode : Normal # Running from : C:\Users\Annelie\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Program Files (x86)\Common Files\Speedbit Folder Deleted : C:\ProgramData\Speedbit Folder Deleted : C:\Users\Annelie\AppData\LocalLow\Speedbit Folder Deleted : C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\SweetPacksToolbarData ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\SpeedBit Key Deleted : HKCU\Software\d4d6dcbd34b945 Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Key Deleted : HKLM\Software\SpeedBit Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\d4d6dcbd34b945 Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope] ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16537 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://go.speedbit.com/tab/?s=D3IaWIT8 –> hxxp://www.google.com -\\ Mozilla Firefox v20.0.1 (sv-SE) File : C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\8k3w0sso.default-1349290452184\prefs.js Deleted : user_pref("browser.search.defaulturl", "hxxp://go.speedbit.com/search.aspx?s=D3IaWIT8&q;="); Deleted : user_pref("browser.startup.homepage_override_url", "hxxp://go.speedbit.com/?s=D3IaWIT8"); Deleted : user_pref("extensions.enabledAddons", "movableAppButton%40Merci.chao:1.4,support.PhotoCollector%40wa[…] Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*"); File : C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\dkzhdk9v.default\prefs.js C:\Users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\dkzhdk9v.default\user.js … Deleted ! [OK] File is clean. ************************* AdwCleaner[S2].txt - [3643 octets] - [28/04/2013 11:32:06] ########## EOF - C:\AdwCleaner[S2].txt - [3703 octets] ########## Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Databasversion: v2013.04.28.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16540 Annelie :: TERRA [administratör] 2013-04-28 11:43:34 mbam-log-2013-04-28 (11-43-34).txt Skanningstyp: Snabbskanning Aktiverade skanningsalternativ: Minne | Start | Register | Filsystem | Heuristik/Extra | Heuristik/Shuriken | PUP | PUM Inaktiverade skanningsalternativ: P2P Antal skannade objekt: 222714 Förfluten tid: 4 minut(er), Upptäckta minnesprocesser: 0 (Inga skadliga poster hittades) Upptäckta minnesmoduler: 0 (Inga skadliga poster hittades) Upptäckta registernycklar: 0 (Inga skadliga poster hittades) Upptäckta registervärden: 0 (Inga skadliga poster hittades) Upptäckta registerdataposter: 0 (Inga skadliga poster hittades) Upptäckta mappar: 0 (Inga skadliga poster hittades) Upptäckta filer: 0 (Inga skadliga poster hittades) (klar) ****************************************** C:\Program Files (x86)\ExpressFiles\EFUpdater.exe a variant of Win32/YourFileDownloader.B application C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe a variant of Win32/ExpressFiles.A application C:\Program Files (x86)\ExpressFiles\uninstall.exe a variant of Win32/ExpressFiles.B application C:\Users\Annelie\Downloads\bs_Incredimail_Backup_PRO.exe Win32/OpenCandy application C:\Users\Annelie\Downloads\cutewriter.exe a variant of Win32/Bundled.Toolbar.Ask.C application C:\Users\Annelie\Downloads\ExpressFilesinstaller.exe probably a variant of Win32/ExpressFiles application C:\Users\Annelie\Downloads\IZArc_Installer.exe a variant of Win32/Somoto.A application C:\Users\Annelie\Downloads\PDFCreatorSetup.exe a variant of Win32/InstallCore.AX application C:\Users\Annelie\Downloads\youtube_downloader.exe Win32/Toggle.G application C:\Users\Annelie\Downloads\YTDSetup.exe a variant of Win32/Bundled.Toolbar.Ask.C application C:\Users\Annelie\Downloads\Bild & foto\simply_calenders.exe a variant of Win32/SWInformer.B application D:\Gun recovery\Gun2\Data Recovery 2013-01-27 at 21.21.51\Video\swf\00024126.swf SWF/Exploit.CVE-2007-0071 trojan D:\Gun recovery\Gun3\Data Recovery 2013-01-26 at 16.40.33\Raw Recovery\Video\swf\00024126.swf SWF/Exploit.CVE-2007-0071 trojan Operating memory a variant of Win32/YourFileDownloader.B application :clap:
Hello, AnnelieP.

Good job running the scans. In answer to your questions:

1. By default, Windows Defender automatically stays up-to-date through Windows Updates. For more information on Defender’s automatic settings, visit Microsoft’s website HERE.

2. To correct your browser’s color display issue, try this solution found in MozillaZine’s Knowledge Base HERE. Let me know if this has resolved the problem.

Please proceed with the following tasks

Some of the files and folders we need to delete may be hidden and need to be shown before they can be removed. Do the following:
  • Click Start, then click Control Panel.
  • Locate and double-click Folder Options.
  • Click on the View tab.
  • Under the Advanced Settings section, please do the following:

  • Under Hidden files and folders, check Show hidden files, folders, or drives.
  • Uncheck Hide file extensions for known file types.
  • Uncheck Hide protected operating system files (Recommended) . When the warning message appears, click YES.
  • Click Apply > OK.

2. Remove Files and Folders

Please do the following:

Click Start > My Computer and double click Local Disk C:.
Click the following folder: Program Files
If it exists, locate the following folder, right click on it, and click Delete.

Express Files

Go back to Local Disk C:.
Click on each of the following folders: Users > Annelie > Downloads.
Locate the following files, right click on each one, and then click Delete .

bs_Incredimail_Backup_PRO.exe
cutewriter.exe
ExpressFilesinstaller.exe
IZArc_Installer.exe
PDFCreatorSetup.exe
youtube_downloader.exe
YTDSetup.exe
Bild & foto\simply_calenders.exe

3. Hide System Files and Folders

We need to rehide the system files and folders to keep them from being accidentally changed or deleted. Do the following:
  • Click Start, then click Control Panel.
  • Locate and double-click Folder Options.
  • Click on the View tab.
  • Under the Advanced Settings section, please do the following:

  • Under Hidden files and folders, uncheck Show hidden files, folders, or drives.
  • Check Hide file extensions for known file types.
  • Check Hide protected operating system files (Recommended) . When the warning message appears, click YES.
  • Click Apply > OK.

4. Scan with DDS

Please run DDS again and send me a fresh log.

Let me know how your computer is running and if there are any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI