This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Small.CA [Solved]

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

On 2/5 Windows Action Center suddenly told me that I had this virus and since then my computer have had hiccups which I did not have before where it refuses to respond for a while (usually after trying to open a program or such but sometimes just by changing tabs on my browser or something similar) after which it works fine again. Most prominent is it when I open IE where upon my system sometimes completely stops responding. Firefox (which is my primary browser) works fine most of the time though. I have used a couple of programs to search for viruses and whilst I have found a couple of infected files I am pretty sure I have not successfully removed Win32/Small.CA yet though Windows Action Center doesn't say I need to remove it any longer.

OTL logfile created on: 2013-05-04 19:32:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Staffan\Desktop\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7.96 Gb Total Physical Memory | 6.88 Gb Available Physical Memory | 86.47% Memory free
15.91 Gb Paging File | 13.91 Gb Available in Paging File | 87.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1862.92 Gb Total Space | 467.71 Gb Free Space | 25.11% Space Free | Partition Type: NTFS

Computer Name: LOLOLOL | User Name: Staffan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Staffan\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Personal\bin\Personal.exe (Technology Nexus AB)
PRC - C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Users\Staffan\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\602a15ab5b936c31714b5c71fdfa3739\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\33ad2fd1f98d0ce8786d9350191ab232\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\9f2470616efba2f8676d5a7641f52162\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d234f412db68ceda11a6bbb961bc6a9d\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\08f7d1f2ee3db9ca9ba13bc02fddc2fe\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\7bd56806a10aa41b0aacc7b67d789965\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\3f7921e9edffaec7d25a3205a9d4a760\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\c1efb0c723b0a4e7dfce39d1cf761507\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\620a155de35a63431137ae3964f94629\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9e755d18a80e8af469b45506ab818465\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bcb84b13c749a2030fe70cd1d510f656\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\3dd5ae502f52dcec99c13d48f9366db7\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c765cc2ec81b1791569bb839b3849d65\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avast! Firewall) – C:\Program\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (HiPatchService) – C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (!SASCORE) – C:\Program\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV - (Intel® – C:\Program\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV - (wlidsvc) – C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswVmm) – C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswRvrt) – C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (ssudmdm) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iusb3xhc) – C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) – C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) – C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (ICCWDT) – C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (asusgsb) – C:\Windows\SysNative\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV:64bit: - (Tdsshbecr) – C:\Windows\SysNative\drivers\shbecr.sys (Todos Data System AB)
DRV:64bit: - (MayPro) – C:\Windows\SysNative\drivers\Maypro.sys (TigerGame.,Ltd)
DRV - (SASDIFSV) – C:\Program\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D1 32 19 CC B4 3E CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1488
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Staffan\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-03 12:27:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-04-12 01:13:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012-05-31 00:57:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Staffan\AppData\Roaming\mozilla\Extensions
[2013-02-25 16:50:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Staffan\AppData\Roaming\mozilla\Firefox\Profiles\hm4960if.default\extensions
[2013-02-25 16:50:04 | 000,182,546 | —- | M] () (No name found) – C:\Users\Staffan\AppData\Roaming\mozilla\firefox\profiles\hm4960if.default\extensions\[removed]
[2013-02-15 00:01:25 | 000,817,280 | —- | M] () (No name found) – C:\Users\Staffan\AppData\Roaming\mozilla\firefox\profiles\hm4960if.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013-04-12 01:13:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013-05-03 12:27:20 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2013-04-12 01:13:50 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012-08-30 10:31:44 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013-02-21 00:42:52 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com
CHR - Extension: Docs = C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Drive = C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: YouTube = C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: S\u00F6k p\u00E5 Google = C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\Staffan\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [googletalk] C:\Users\Staffan\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup File not found
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{089DE305-EC73-4694-8D14-4A594497B47A}: DhcpNameServer = [removed] [removed] 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.XVID - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013-05-04 16:22:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013-05-04 16:19:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013-05-04 11:34:28 | 000,000,000 | —D | C] – C:\Users\Staffan\AppData\Roaming\SUPERAntiSpyware.com
[2013-05-04 11:32:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013-05-04 11:32:49 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013-05-04 11:32:49 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013-05-03 13:15:52 | 000,000,000 | —D | C] – C:\Users\Staffan\AppData\Roaming\Malwarebytes
[2013-05-03 13:15:41 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013-05-01 01:12:48 | 000,691,592 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013-05-01 01:12:48 | 000,071,048 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013-05-01 00:40:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013-05-01 00:39:45 | 000,263,584 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013-05-01 00:39:37 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013-05-01 00:39:37 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013-05-01 00:39:37 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013-04-29 01:23:15 | 001,092,512 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013-04-29 01:23:15 | 000,971,680 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013-04-28 20:48:46 | 000,000,000 | —D | C] – C:\Users\Staffan\AppData\Roaming\Oracle
[2013-04-25 01:58:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013-04-20 19:05:50 | 000,000,000 | —D | C] – C:\Users\Staffan\AppData\Local\Warframe
[2013-04-18 14:04:24 | 026,956,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2013-04-18 14:04:24 | 020,542,752 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2013-04-18 14:04:24 | 017,990,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2013-04-18 14:04:24 | 015,508,512 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2013-04-18 14:04:24 | 013,088,000 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2013-04-18 14:04:24 | 009,414,456 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2013-04-18 14:04:24 | 007,959,000 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2013-04-18 14:04:24 | 007,573,816 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2013-04-18 14:04:24 | 006,271,872 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2013-04-18 14:04:24 | 002,913,056 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2013-04-18 14:04:24 | 002,728,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2013-04-18 14:04:24 | 002,355,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2013-04-18 14:04:24 | 001,995,552 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2013-04-18 14:04:24 | 001,807,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco6431422.dll
[2013-04-18 14:04:24 | 001,510,176 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco6431422.dll
[2013-04-18 14:04:24 | 000,968,408 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvumdshim.dll
[2013-04-18 14:04:24 | 000,250,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvinitx.dll
[2013-04-18 14:04:24 | 000,205,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvinit.dll
[2013-04-18 14:04:24 | 000,194,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2013-04-18 14:04:24 | 000,031,672 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2013-04-18 14:04:23 | 025,256,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2013-04-18 14:04:23 | 017,560,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2013-04-18 14:04:23 | 002,539,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2013-04-14 01:53:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Marvel Heroes Beta
[2013-04-12 01:13:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013-04-12 00:57:04 | 000,000,000 | —D | C] – C:\Users\Staffan\Desktop\Mutant Karaktärer
[2013-04-10 13:55:48 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013-04-10 13:55:47 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013-04-10 13:55:46 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013-04-10 13:55:43 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013-04-10 13:55:43 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013-04-10 13:55:42 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013-04-10 13:55:42 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013-04-10 13:55:41 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013-04-10 13:55:41 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013-04-10 13:55:41 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013-04-10 13:55:41 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013-04-10 13:55:40 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013-04-10 13:55:36 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013-04-10 13:55:36 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013-04-10 13:55:34 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013-04-10 11:12:42 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013-04-10 11:12:42 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013-04-10 11:12:41 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013-04-10 11:12:41 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013-04-10 11:12:41 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013-04-10 11:12:41 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013-04-10 11:12:29 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013-04-10 11:12:28 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013-04-10 11:12:28 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013-04-10 11:12:28 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013-04-10 11:12:28 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013-04-10 11:12:27 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013-04-05 21:12:26 | 000,000,000 | —D | C] – C:\Users\Staffan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joymax
[2013-04-05 21:10:34 | 000,000,000 | —D | C] – C:\Joymax
[2013-04-05 19:20:02 | 000,000,000 | —D | C] – C:\Users\Staffan\.towns
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013-05-04 19:34:00 | 000,000,996 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-05-04 19:21:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-05-04 18:56:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013-05-04 16:34:00 | 000,000,992 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-05-04 16:26:59 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-05-04 16:26:59 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-05-04 16:25:01 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013-05-04 16:22:10 | 000,002,215 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013-05-04 16:11:49 | 2112,557,055 | -HS- | M] () – C:\hiberfil.sys
[2013-05-04 11:32:51 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013-05-02 23:39:17 | 000,001,738 | —- | M] () – C:\Users\Staffan\Desktop\Unthinkable Natural Law - genväg.lnk
[2013-05-02 20:56:13 | 000,002,052 | —- | M] () – C:\Windows\epplauncher.mif
[2013-05-02 17:44:28 | 000,189,936 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013-05-02 01:34:06 | 001,025,808 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013-05-02 01:34:06 | 000,378,432 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013-05-02 01:34:06 | 000,072,016 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013-05-02 01:34:06 | 000,065,336 | —- | M] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013-05-02 01:34:06 | 000,064,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013-05-02 01:34:05 | 000,270,824 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2013-05-02 01:34:05 | 000,131,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2013-05-02 01:34:05 | 000,080,816 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013-05-02 01:34:05 | 000,033,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013-05-02 01:34:05 | 000,022,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2013-05-02 01:33:35 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013-05-02 01:33:11 | 000,287,840 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013-05-01 22:06:07 | 000,001,196 | —- | M] () – C:\Users\Staffan\Desktop\Neverwinter.lnk
[2013-05-01 16:58:06 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013-05-01 16:58:06 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013-05-01 00:39:21 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013-05-01 00:39:13 | 000,263,584 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013-05-01 00:39:13 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013-05-01 00:39:12 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013-05-01 00:39:08 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013-05-01 00:39:07 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013-04-30 21:52:39 | 001,092,512 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013-04-30 21:52:39 | 000,971,680 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013-04-27 22:51:39 | 000,001,993 | —- | M] () – C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2013-04-27 22:51:38 | 000,001,984 | —- | M] () – C:\Users\Public\Desktop\Smite.lnk
[2013-04-25 01:58:26 | 000,001,026 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013-04-25 01:58:24 | 000,000,027 | —- | M] () – C:\Program Files\plugins.dat
[2013-04-25 01:57:39 | 000,001,687 | —- | M] () – C:\Users\Public\Desktop\Planescape Torment.lnk
[2013-04-20 22:15:16 | 001,573,176 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013-04-20 22:15:16 | 000,653,330 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2013-04-20 22:15:16 | 000,651,938 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013-04-20 22:15:16 | 000,141,150 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2013-04-20 22:15:16 | 000,120,870 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013-04-14 01:53:02 | 000,001,901 | —- | M] () – C:\Users\Public\Desktop\Marvel Heroes Beta.lnk
[2013-04-10 21:35:09 | 000,295,832 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013-04-09 13:59:47 | 000,001,650 | —- | M] () – C:\Users\Staffan\Desktop\Marvel Super Heroes - genväg.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013-05-04 16:22:10 | 000,002,215 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013-05-04 16:21:26 | 000,000,996 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-05-04 16:20:21 | 000,000,992 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-05-04 11:32:51 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013-05-02 23:39:17 | 000,001,738 | —- | C] () – C:\Users\Staffan\Desktop\Unthinkable Natural Law - genväg.lnk
[2013-05-02 20:56:13 | 000,002,052 | —- | C] () – C:\Windows\epplauncher.mif
[2013-05-01 22:06:07 | 000,001,196 | —- | C] () – C:\Users\Staffan\Desktop\Neverwinter.lnk
[2013-05-01 01:12:49 | 000,000,868 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-04-27 22:51:39 | 000,001,993 | —- | C] () – C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
[2013-04-27 22:51:38 | 000,001,984 | —- | C] () – C:\Users\Public\Desktop\Smite.lnk
[2013-04-25 01:58:26 | 000,001,026 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013-04-25 01:57:39 | 000,001,687 | —- | C] () – C:\Users\Public\Desktop\Planescape Torment.lnk
[2013-03-08 00:47:20 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\XSIChooser.exe
[2013-02-05 17:52:54 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013-02-05 17:52:50 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013-02-05 17:52:50 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013-02-05 17:52:50 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013-02-05 17:52:50 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013-01-11 21:22:01 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2013-01-11 21:13:25 | 000,182,272 | —- | C] () – C:\Windows\patchw32.dll
[2012-12-22 23:08:43 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CmdLineExt03.dll
[2012-12-20 21:38:25 | 000,124,436 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2012-10-04 12:24:58 | 000,000,073 | —- | C] () – C:\Windows\cdplayer.ini
[2012-10-04 12:24:26 | 000,001,534 | —- | C] () – C:\ProgramData\ss.ini
[2012-09-06 21:06:08 | 003,915,776 | —- | C] () – C:\Windows\SysWow64\ffmpeg.dll
[2012-09-06 21:05:16 | 000,112,640 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012-09-06 21:04:38 | 000,271,360 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2012-09-06 21:04:18 | 000,157,184 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2012-09-06 21:04:18 | 000,099,840 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2012-09-06 21:04:16 | 000,147,456 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2012-09-06 21:04:14 | 001,525,760 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2012-09-06 21:04:14 | 000,211,968 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2012-09-06 21:04:14 | 000,114,688 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2012-09-06 21:04:12 | 000,330,240 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2012-08-15 13:34:03 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2012-07-03 12:34:38 | 001,542,716 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012-07-03 12:31:48 | 000,283,032 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012-07-03 12:31:29 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012-07-03 12:31:29 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012-06-04 01:31:42 | 000,000,027 | —- | C] () – C:\Program Files\plugins.dat
[2012-05-30 23:59:45 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2012-05-30 23:59:37 | 000,036,727 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2012-02-02 22:08:26 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll
[2011-09-28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012-06-09 07:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012-06-09 06:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009-07-14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010-11-21 05:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009-07-14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013-01-11 22:26:32 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\.anki
[2013-02-15 12:07:32 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\.minecraft
[2013-03-19 00:38:39 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Audacity
[2013-04-14 01:59:11 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Awesomium
[2013-04-10 02:58:23 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Azureus
[2012-07-16 17:48:31 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\BigHugeEngine
[2012-11-22 14:29:23 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\BrainCandy
[2013-03-01 01:11:31 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Carbon
[2013-03-04 13:59:37 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\com.stoicstudio.TheBannerSagaFactions
[2012-07-15 16:05:22 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\DAEMON Tools Lite
[2012-05-31 00:31:35 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\DAEMON Tools Pro
[2012-10-04 12:40:14 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Digiarty
[2013-01-24 12:36:24 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Doublefine
[2012-07-31 23:37:20 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Electronic Arts
[2012-11-22 14:25:54 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\FairyBloomReTrial
[2013-03-03 22:45:35 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Fatshark
[2013-02-19 11:17:07 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\ftblauncher
[2013-02-01 21:28:38 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\gd.sos.McPixel
[2013-02-02 01:47:45 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\GOG
[2012-08-05 16:25:47 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\HackSlashLoot
[2012-10-04 12:42:16 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\HandBrake
[2012-06-01 01:29:50 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Leadertech
[2012-11-11 23:52:55 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\LolClient
[2013-03-22 20:32:36 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Natural Selection 2
[2012-10-28 00:24:24 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\OpenOffice.org
[2013-04-28 20:48:46 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Oracle
[2013-01-10 00:58:18 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Origin
[2012-06-12 23:06:04 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Personal
[2012-09-26 02:58:13 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Quest3D
[2012-07-01 02:35:22 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\RenPy
[2012-08-11 13:29:14 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\RotMG.Production
[2012-07-08 18:33:58 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\runic games
[2013-03-31 22:19:01 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Samsung
[2013-01-25 17:37:21 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\ShanghaiAlice
[2013-01-12 12:42:10 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Wargaming.net
[2012-12-30 21:01:12 | 000,000,000 | —D | M] – C:\Users\Staffan\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%..smtmp;true;true;true FP >

< %temp%smtmp. s >

< md5start >
[2009-07-14 07:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009-07-14 07:08:49 | 000,032,514 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2013-05-01 01:12:49 | 000,000,868 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013-05-04 16:20:21 | 000,000,992 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013-05-04 16:21:26 | 000,000,996 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< iexplore. >

< explorer. >

< winlogon. >

< dll >

< zx.dll >

< hlp.dat >

< consrv.dll >

< services. >

< md5stop >

< %SYSTEMDRIVE%. >

< %systemroot%Fonts.com >

< %systemroot%Fonts.dll >

< %systemroot%Fonts.ini >

< %systemroot%Fonts.ini2 >

< %systemroot%Fonts.exe >

< %systemroot%system32spoolprtprocsw32x86. >

< %systemroot%REPAIR.bak1 >

< %systemroot%REPAIR.ini >

< %systemroot%system32.jpg >

< %systemroot%.jpg >

< %systemroot%.png >

< %systemroot%.scr >

< %systemroot%._sy >

< %APPDATA%AdobeUpdate. >

< %ALLUSERSPROFILE%Favorites. >
[2009-07-14 07:08:56 | 000,000,000 | -HSD | M] – C:\ProgramData\Favorites

< %APPDATA%Microsoft. >
[2012-12-11 14:51:23 | 000,000,000 | –SD | M] – C:\Users\Staffan\AppData\Roaming\Microsoft

< %PROGRAMFILES%. >

< %APPDATA%Update. >

< %systemroot%. mp s >

< %systemroot%System32config.sav >

< %PROGRAMFILES%bak. s >

< %systemroot%system32bak. s >

< %ALLUSERSPROFILE%Start Menu.lnk x >

< %systemroot%system32configsystemprofile.dat x >

< %systemroot%.config >

< %systemroot%system32.db >

< %PROGRAMFILES%Internet Explorer.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch.lnk x >

< %USERPROFILE%Desktop.exe >

< %PROGRAMFILES%Common Files. >
[2013-05-01 00:40:12 | 000,000,000 | —D | M] – C:\Program Files (x86)\Common Files

< %systemroot%.src >

< %systemroot%install. >

< %systemroot%system32DLL. >

< %systemroot%system32HelpFiles. >

< %systemroot%system32rundll. >

< %systemroot%winn32. >

< %systemroot%Java. >

< %systemroot%system32test. >

< %systemroot%system32Rundll32. >

< %systemroot%AppPatchCustom. >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime rs >

< End of report >



OTL Extras logfile created on: 2013-05-04 19:32:41 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Staffan\Desktop\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

7.96 Gb Total Physical Memory | 6.88 Gb Available Physical Memory | 86.47% Memory free
15.91 Gb Paging File | 13.91 Gb Available in Paging File | 87.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1862.92 Gb Total Space | 467.71 Gb Free Space | 25.11% Space Free | Partition Type: NTFS

Computer Name: LOLOLOL | User Name: Staffan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{145DE227-535A-4C07-879E-B796FE8AD737}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.x64.exe |
"{58500E8F-92F0-44C9-A466-B2AE83387DFD}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.exe |
"{708E5EA2-8507-4656-B3E3-2465B48FCA11}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{AA763D1A-38BB-4E30-8F20-71A8FA3442A4}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\steam\steamapps\common\warframe\tools\launcher.exe |
"{C78FCBF5-A3E5-40F4-AF77-0E049C502571}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00E76E5D-1A6D-4BBE-8E94-D5FB7031DF01}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
"{01C221D0-8C78-497A-BD45-B8AEBAAEBDE5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the bards tale\the bard's tale.exe |
"{01E6B7DF-72BB-4F79-A4CC-F9EA5C4467B9}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 1942\bf1942.exe |
"{02DCBBF1-ED28-4AE6-BFD4-6A7F166EE4E6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x86_steam_beta\3dmark.exe |
"{03010BFA-84EF-4274-A43F-B025E9028703}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{039ED7A2-5411-4563-8F0B-24BB74A2F007}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the spy\smp.exe |
"{051ECC1C-490E-49E5-9B93-8D8D0289C9D7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rochard\rochard.exe |
"{05F1F092-0854-44D5-993B-B6A67E8D00BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\to the moon\to the moon\to the moon.exe |
"{06031385-D4D2-44B0-86DF-0CF9DCF013AF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{06AB89E4-DBF7-4181-89D6-3FF931324764}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the spy\smp.exe |
"{07926D02-409C-4BFA-B8E6-D1DE60E87D25}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mcpixel\mclauncher.exe |
"{08DE3FFD-9E8A-4BF0-9458-10C274550389}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the scout\smp.exe |
"{08E2C37F-E72D-4255-AFC5-0298681B3CFD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{091AA6CD-F332-47B5-B2AD-A091A5B5D74D}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{09E77E6A-3701-4B36-89F2-841168F811DB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{0A0C46AA-E5CA-486B-864E-2E93F1E079C1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{0B3D3787-FC29-470D-A1B4-DCD102D8BA26}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizorb\wizorb.exe |
"{0BC4DE31-2007-46EE-AE1E-78795C234761}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0D6FD6E3-90B7-4E43-A302-606196B230B4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{0ED02131-3B4B-4EF9-918A-0C9CBB3E9DEF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{0F74F4D2-21C8-40EA-8143-8C02F2D1DDFC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |
"{13D8B7D3-4FAB-467E-8C78-4C1C6F20B4A4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\transformers fall of cybertron\binaries\tfoc.exe |
"{13FF8A8E-ED1E-4C91-A15F-4CA71398E1B5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brutallegend\brutallegend.exe |
"{144497A6-D4FA-4CFB-8173-DEA368BBB19C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{17A3A0CF-49C5-4210-A3F4-F793DE7307A2}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{18C6CD7C-3D2F-491F-B5E0-D4B8E765FF00}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tales from space mutant blobs attack\game.exe |
"{19DF21A1-4A98-4FF4-8DBC-9DF9A7EFBC90}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{1B321781-B2D2-41C1-8747-2FA3DC880BFF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{1C1F7919-530E-442A-A6C4-8B35C9895928}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{1DF036E4-1BC6-4663-8C0B-EE8BC0BF6039}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizorb\wizorb.exe |
"{1EBB300E-3CEC-4858-806C-867633C9D789}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{1EFABCD6-7521-4DCC-955C-3225F40C5CEE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{1FC904EC-0B90-4C48-B9B0-5CEEA3421970}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{21C717AC-EABF-48CF-A514-8E3B95830C48}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{21DDC2D9-5F40-47C8-98C6-5F0848EE10E1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{223A6F02-EAF7-42B4-BAC6-52DC261C8DA9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{22A9EBBE-185D-4921-AB41-2C14AB30862A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{22DA5167-3576-4459-B8EF-857792FBFCA6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{23180A23-1C5A-4627-8916-B09E8F5DD803}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenautslauncher.exe |
"{23ECF974-895F-4C59-A9C9-6818D4A3CB43}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a virus named tom\avnt.exe |
"{26470386-FE63-4106-8C81-5AD2898C2B45}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{2B9D3E2E-0CC9-4CCA-9983-DCF34381CFF9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blood bowl chaos edition\bb_chaos.exe |
"{2C60D58B-51C5-4269-8740-70569A948534}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superbrothers sword & sworcery ep\swordandsworcery_pc.exe |
"{2C66FAF2-412F-468B-8C79-88A7081EAF57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\townsdemo\towns.exe |
"{2C93D51A-DD86-4FD4-A5D1-5C081DF2990C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 - mac trailer\smp.exe |
"{2D69C771-8CBB-4159-B48F-8C0640DC78B3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{2DAAB5A8-7B1E-43B3-B7D0-D2B7200654A3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{31C7DCF8-397F-4B30-A5A7-773F9D01150F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fortune summoners\sotes.exe |
"{34E78068-350E-46E7-A2B9-A739978936DC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
"{354859A8-79E7-4B07-B062-0E4CE8F391C9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blood bowl legendary edition\bb_le.exe |
"{36337D5C-0844-4354-894F-CCD30A36AA21}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{36BBF8DE-F974-48CD-B2BF-703E418514D1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hell yeah\hellyeah.exe |
"{3763FD8B-A803-485E-B1EB-EB9B86F058F2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{377DBDBD-D0F1-4296-95B7-9066FF89D330}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x64_steam_beta\3dmark.exe |
"{3792C3B8-DFB2-459D-AFB5-C914A6773604}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brutallegend\brutallegend.exe |
"{37E2B475-92CD-4F78-9023-282B160F5535}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{3C2B47BC-AFC9-494B-A10C-4076822D26F9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\breath of death vii\bodviipc.exe |
"{3EB50636-007A-4C87-88E0-69ACA54C4E72}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
"{3F2C228E-B2AC-40DF-8862-AC0601820151}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\machinarium\machinarium.exe |
"{4090B3F1-59B1-4EAF-B28F-FE39CCF2FB6D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{4636431B-6F6E-48BD-BC9B-71E2BFE91CE6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\flyn demo\source\flyn.exe |
"{4901029A-7E0A-40D5-8387-98AD7D8A83ED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{49854464-63B7-4220-A4D0-90B7B17BE626}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |
"{4A233B90-70C7-4470-BF27-5D14A6A41E2B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{4B1EE1DC-C4F9-43E9-A619-40BE2C962469}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{4C27E406-D1D1-484B-AC69-064DACF26A00}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{4D47E000-6031-41AE-9CF2-082ED8366A62}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rochard\rochard.exe |
"{4D975306-54F3-4861-998C-E665E0EAA6C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the demoman\smp.exe |
"{4DC24929-F89D-4DA5-BF2D-7793E9D0FBBD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deponia\deponia.exe |
"{4E662ABC-A9DF-458B-B907-216767F833D7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the scout\smp.exe |
"{4FE6EDEF-1CF5-499F-9B93-6202486A1148}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\meet the engineer\smp.exe |
"{521BC8FE-F77A-4118-B50C-ECE4DAA210B8}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{52752A23-3A01-4C4E-8D40-ED5D4956CDB2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deponia\deponia.exe |
"{52EC61CD-9EDC-44E8-8FB2-D0986AE7D1D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fortune summoners\sotes.exe |
"{5459FB52-7E91-4649-B0FA-FD126D5AF1E1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{54A66079-18A5-4702-946A-7AEFFE737856}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\l.a.noire\lanlauncher.exe |
"{55A9B24B-EE9E-4396-B872-8D456C92E51C}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{55CD8448-1B34-40D6-91CC-6B644156663D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\launcher\apblauncher.exe |
"{56A81144-E679-4540-8FF1-B68C3B58944B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{581850FC-E0D6-44CC-817A-02780D9BC29C}" = protocol=58 | dir=in | app=system |
"{59692076-5347-439E-9B78-55C25D8E8784}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{5A2A0F5C-85DE-4845-9E6B-F0021490810F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the bards tale\config\the bard's setup.exe |
"{5AB8B6ED-AD80-4E28-96FC-752F800F568D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\castlecrashers\castle.exe |
"{5BD1D63A-57CD-4FF8-9B66-DB952979C173}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\game_launcher.exe |
"{5C352AE6-9031-40C7-9187-887DFDF830C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenautslauncher.exe |
"{5C5A737F-FAF3-411D-B27B-FBE96F1D58B5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |
"{5C6E03E8-E608-4DAE-882A-DC90DD1B38EB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |
"{5CF9C438-4E1E-41FA-8A73-61980A4AEAA8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cortex command\cortex command.exe |
"{5CFE8716-16D1-479A-8EBE-B46990DBD631}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the demoman\smp.exe |
"{5D6420E5-959D-4B74-B64D-AFBB9B62AE22}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{5F717DC4-15EA-4B88-849D-82DD4D842605}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{5F955D7F-2709-40D2-9522-683E504F58E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the sandvich\smp.exe |
"{5FDA0801-E5D7-4061-897F-C33BD52C2DBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mcpixel\mclauncher.exe |
"{60A01769-B83E-408E-B797-CC6EA0E127C4}" = protocol=17 | dir=out | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.x64.exe |
"{6206C35B-5C28-4199-BEE6-EA6081B97DDB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |
"{62188B03-466B-423B-800E-9B8B2593873A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{646F588E-FFA5-48A9-8FB3-EDCF3462D7FE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{652C9884-0AD6-47E7-AA60-35F75E48008B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{666214DF-32C7-442D-A249-C48DDDC5616E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{66E94E8C-D4AE-4011-8F76-8D62126A8AD6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{68A58CB9-825D-45E6-A660-5F1DEC8AEA3F}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{69722132-2FD7-4A1F-BD58-A9809BA9350D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{6A002459-DCDD-4028-BB4B-3DD79AED8E4B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenautslauncher.exe |
"{6A15816F-ABDB-46C2-B683-AC6CBDDFE17C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blood bowl chaos edition\bb_chaos.exe |
"{6A240C44-47E5-41D5-A208-460C1577C7C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the soldier\smp.exe |
"{6DA8522F-F800-4AFD-85B5-1C536D743DBC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spacechem\spacechem.exe |
"{6E397C6E-CDB4-47B8-A69A-B51B457E0BBA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders 2\darksiders2.exe |
"{6FBF8AAC-1E7B-4E7B-82A3-2AD2A01405E4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x64\3dmark.exe |
"{7007756A-525E-4750-B06B-3E594AC65561}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{7021E72D-B3E5-4645-AEAA-FC2500F6A552}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\l.a.noire\lanlauncher.exe |
"{7031AB2A-431E-4DA6-BB13-4CC7D108B5DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\awesomenauts\awesomenautslauncher.exe |
"{70A525C5-E7EE-4D1E-9A22-7F3958119D7C}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 1942\bf1942.exe |
"{70B84181-EDD0-4A05-991A-EDFC5E4E370F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe |
"{717F6DBB-9DEA-46CF-9ECB-2FE38EC862D5}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{7224926F-DE22-45A1-81BB-AB59E20E8ECF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the heavy\smp.exe |
"{726984C9-58C0-4B76-87CB-08C317C8325F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders 2\darksiders2.exe |
"{76400180-D3E5-4322-8932-D3EB49DB9B11}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{764F0F7F-E6B4-44F3-BC4E-6338DBD5F6D5}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\kingdoms of amalur reckoning demo\reckoningdemo.exe |
"{7887EDBA-2802-48FC-84A7-BB47C1E4EEAD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.x64.exe |
"{79FC05EE-11F9-4D37-B524-DF4495CFCE8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{7A446D7A-ACA0-4F2B-9CB5-C0CF35C92292}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hell yeah\hellyeah.exe |
"{7B0CFE55-3A49-4252-BD92-1CA98F0865CA}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{7EEA4AFA-C24D-4F9C-8FD8-A29379053563}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{7EF1E9CC-6583-494C-8078-3E153291C774}" = protocol=6 | dir=in | app=c:\users\staffan\appdata\local\directdownloader\directdownloader.exe |
"{7F6E586E-45FF-442E-8EF6-8B7539C07291}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathspank\deathspank.exe |
"{80B94339-499F-4D38-8536-14E24D288CD5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{81A0D612-3B38-425C-92B7-67322C41EADD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{834C9836-B6F9-419B-89DC-41363EB65CE6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warframe\tools\launcher.exe |
"{85B1170F-1E6A-4111-9E06-6C4FF557557A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{86A957EC-C925-420E-80B8-F21B8CCFADD2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{86F86C2E-1025-4960-837F-F17DF1B9CAAD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superbrothers sword & sworcery ep\swordandsworcery_pc.exe |
"{8702A836-5F50-4B8B-8239-8F4B35D4230C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{883670B9-1584-401E-970E-6739C531ACDD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deathspank\deathspank.exe |
"{883A5961-BF0D-4F02-92C8-1163F19C201B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater\run_game.exe |
"{8948F02D-3891-4845-A75E-A9F8AB582407}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\townsdemo\towns.exe |
"{8972C1C5-474B-4B88-B8EC-F71D94299876}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe |
"{8A1156E1-80D7-4BE8-AF9A-A72B17D3841C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blood bowl legendary edition\bb_le.exe |
"{8A9CDE24-2F8A-4FA6-A3AD-295C8D77065B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\machinarium\machinarium.exe |
"{8C810B7F-878A-4B8C-B12A-F8785C22017E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a virus named tom\avnt.exe |
"{8CDB201F-7467-4F46-BF60-0684F975793F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\flyn demo\source\flyn.exe |
"{8CE8376E-019F-418A-884F-659098B210A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{8FF02A6A-3799-4E46-9146-1CDA5B88DA35}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\of orcs and men\oforcsandmen_steam.exe |
"{903BD43A-920A-46DD-98D7-39391229B67C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the bards tale\config\the bard's setup.exe |
"{907FF2D2-B76B-4B8C-B01A-286EE20268C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{91C39C08-5467-4C3B-BE28-D81CEDAEE58E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
"{9372D190-68C5-4945-BE2F-FCEA76F58BDC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.exe |
"{93E96823-F6A8-4A31-A57A-9FB59E1B7E31}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 - mac trailer\smp.exe |
"{94EFE316-D339-414E-9C68-88DBD5F3BF37}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{958A853E-9713-4AFF-956F-5470B4F96BD2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{97F57599-97E3-47C8-A24A-7CCC963E6EFD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\botanicula\botanicula.exe |
"{99FC03DA-33C3-4DFA-9AAC-FBC1F28E80C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |
"{9AA4CDC0-5085-42C6-9B38-427E6D007AB5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9B4C0402-927E-4ACF-9AFC-C82C25CE82D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{9E6C5F63-8FCF-44A1-9DDF-7D27E5F1B446}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the heavy\smp.exe |
"{9E8CCAD0-7DB5-4614-8476-F725324FFAF6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x64\3dmark.exe |
"{9E9AF60F-6B7D-494B-911A-3B6A826F73CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{9F7AAE3A-F975-4320-81CB-41BD5334FF2F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |
"{9F875F6C-9230-4143-A181-D4E5ACCED5EF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{9F8E06CA-A876-40A6-9648-673E48ACF931}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{A1E73230-0D3E-4019-BAE9-17A25A28AAAB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{A2C8EF98-DD70-41EA-B9F8-A91B132BFFF2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{A34CF691-79A7-47F1-8D5A-43C160FC662D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{A5EF0481-AB48-41EB-A5CB-DE05C7BEA3A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\launcher\apblauncher.exe |
"{A6AC40F2-A9BD-4943-9ED3-AB78F6E02AB4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{A6B3BB33-395F-4095-ABBB-C43E84098045}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unmechanical\binaries\win32\udk.exe |
"{A735D33E-8B11-4390-9C98-6654BACB7F91}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{A9145904-EE90-4DF6-86E0-5112FB250E72}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the soldier\smp.exe |
"{A9CC9DAF-C887-405D-A7ED-20FB9033AB1C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\breath of death vii\bodviipc.exe |
"{AA363065-1B7C-4A8D-A253-1ABC0BF33512}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{AB4403DD-79FB-445A-8AFF-E0E2E6EEA8C1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x86\3dmark.exe |
"{ADF4BDAF-8370-4C77-814C-394AAD69C3F8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{ADF4EAF6-878B-452D-AB19-560EF7ECC74C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{AE22EF29-3D68-458C-B0D4-0C10CFA53DF1}" = protocol=17 | dir=in | app=c:\users\staffan\appdata\local\directdownloader\directdownloader.exe |
"{B00F7EAA-2F6A-4719-A6A4-2E0BF979D93F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{B0C246FE-F671-4508-BD8B-606771045DAC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cortex command\cortex command.exe |
"{B48EDE7E-AC8B-4EA4-89C0-547A0E36898D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\freedom force\fforce.exe |
"{B8EF4C4D-794F-46E6-8F70-73E46A4AAF1E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B99A752A-D402-49FB-AF70-287F6AF7B79F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{B9F8D756-6DAF-47D7-9D87-7A554D15502C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe |
"{BB9C7E99-7387-4AE2-8A96-60C47893ED98}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chantelise\chantelise.exe |
"{BD288064-EEE5-4D8F-91C5-60D05A06D7D3}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BF107A41-938D-4637-A4A8-AFE561165C41}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chantelise\custom.exe |
"{BFA2B631-23C3-474A-9134-CEE33E186640}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the sandvich\smp.exe |
"{C002CAE3-B2C6-4550-8D3C-AC0F66DF4CCB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C184F61B-E6F7-436C-B774-AFBA8C838B9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird.exe |
"{C2B38F83-C062-4227-B301-15667F017015}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe |
"{C2F6B0B0-0CC8-41D9-A061-6794CCD76D3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warframe\tools\launcher.exe |
"{C31CCE72-10CC-4EC9-8611-5462B5270446}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{C32EE7CC-F359-4875-BAF5-B76D9CC204A7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{C32FB93A-CD61-4B0B-B8B9-49DE2C1F7936}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\meet the pyro tf2\smp.exe |
"{C4A1D375-04A9-4D22-BF86-585DD4965A07}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{C5B4CC6C-1D35-4C7E-83EF-ADF9892A23A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\to the moon\to the moon\to the moon.exe |
"{C5C684EB-9B6B-431D-9238-D33949E32DC6}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{C7C92AE1-EBAF-4D1A-9165-F901D98A2E6B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{C8466F0F-5E10-4DEB-A9D4-9B50EE1E0FCE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chantelise\chantelise.exe |
"{CA7DA2D6-3447-4930-B68F-4FBE5A624783}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
"{CABC1121-B374-483F-80C4-7B3C7C63D9AE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{CBECA17B-49E5-4476-9403-BB885D492BE9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\meet the engineer\smp.exe |
"{CE8A992E-81EC-4427-8346-33713F73596B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{CF149EB8-9BB4-4DBF-9301-E806564B60D0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe |
"{CF6369A4-47A5-4C56-860D-EFDCE252B312}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{D0737DAF-9EF7-428B-8869-F3F37F9EEFDE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the sniper\smp.exe |
"{D372CEC1-0587-44BE-85AA-AF755B798B55}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{D3974F06-F945-42C3-96C6-EF46FA7AF26D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief_gold\thief.exe |
"{D3A99E33-D150-4EDB-BAC6-780D726826CE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the bards tale\the bard's tale.exe |
"{D8D733B3-4D05-4C91-9509-6570461ADA31}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{D99C7477-3821-49E2-9B29-2E97D374563A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\of orcs and men\oforcsandmen_steam.exe |
"{D9CC91B2-F0EC-4CFB-A5D0-E568CBFD9D44}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
"{DA54C30A-E88C-4C82-AA95-B707469A89A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the banner saga factions\win32\the banner saga factions.exe |
"{DC3A8C36-6B7F-464D-927A-646172A80AC9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\krater\run_game.exe |
"{DC4AE6D6-6C0F-4DC5-9F0B-383F9F57B961}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |
"{DC959EB5-9372-4C3A-95E3-427F2D63E17B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{DCF84317-DEEA-451A-8C41-669196DBEA0D}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{DD43825D-B90B-44E2-9A1C-6F7D3BA47CC3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tales from space mutant blobs attack\game.exe |
"{DE6DA019-5181-4E1B-BF04-D30B04CD3C6D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x86_steam_beta\3dmark.exe |
"{DE72CAFB-3A1A-4923-9501-22D720BCC967}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spacechem\spacechem.exe |
"{DEAF38D2-F08A-41F8-A6FA-9161E05BCB57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{DF8823F8-EB9F-464A-95D1-71129E1A3E13}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{E1394667-8174-48AE-A454-EF9DF96D0CA3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{E140C4C4-A98C-4997-9953-08DD003F6A86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x86\3dmark.exe |
"{E3D17894-F779-4258-B339-A21A322E3988}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deponia\deponia.exe |
"{E53ADFAE-F1E5-4A55-86E6-2C9EBC8018F1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\meet the pyro tf2\smp.exe |
"{E88EFB3F-BB25-4EA7-8D2E-854640F494E6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chantelise\custom.exe |
"{E972ACA5-9E9A-479C-9BF5-0956A617CD82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{EA0BB4F0-29E0-4C3B-B2C6-D444697FF863}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\3dmark\bin\x64_steam_beta\3dmark.exe |
"{EA2E5BFF-40C8-412A-8B4E-05E1FEF463A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |
"{EA4816AD-E689-4C96-9A1F-A94FBF26191A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{EBC7BFD7-F00C-4DC4-A4DD-15A105F4F710}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{F08918FF-EFF3-42B9-9C96-89D543B4DB5C}" = protocol=17 | dir=out | app=c:\program files (x86)\steam\steamapps\common\warframe\warframe.exe |
"{F0AB73FA-DC19-4083-B228-070177750812}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the sniper\smp.exe |
"{F264E7B6-3D8C-4A4C-AA89-DE85D485FE61}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{F43E1B60-A30A-4D75-AB73-41A8FB0B9645}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F43E6FE8-5261-42B6-9196-381EE56A40F8}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{F508A764-3C8A-4B55-8D72-59850E864D52}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{F5CEAF7A-0369-49E4-B979-9D5DB1BC53D5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{F6D7C05E-DF7C-4648-A3E3-2B851E591F85}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\freedom force\fforce.exe |
"{F78ACF3C-62FA-4E06-80EB-C51F2029D0E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deponia\deponia.exe |
"{FA1D793B-7FC6-4437-9F6E-951E01587325}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{FC7F837A-FAE1-46AB-BE47-B78D0D2CB7ED}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\kingdoms of amalur reckoning demo\reckoningdemo.exe |
"{FE45E74F-0F16-4303-A3BC-CA8844E51D9C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\botanicula\botanicula.exe |
"{FFBBC785-86EE-4C04-9E03-45A448E55A80}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\transformers fall of cybertron\binaries\tfoc.exe |
"TCP Query User{0BFBA1B3-FF15-4D77-9ADE-AA01B314379C}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe |
"TCP Query User{0CB47931-A4E2-4220-9107-EEFD7EDE7C9E}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{1B421C2E-C0FA-4185-B726-B20EE72E287B}C:\users\staffan\desktop\downloads\gw2.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\downloads\gw2.exe |
"TCP Query User{1F96F341-7E1B-409F-867F-1713DDA19A81}C:\program files (x86)\red 5 studios\firefall\system\bin\firefallclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\red 5 studios\firefall\system\bin\firefallclient.exe |
"TCP Query User{20B0B7E5-43DF-440D-897A-F642907F4A73}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe |
"TCP Query User{27302300-FE2A-4878-BC2E-E32452F0C3CC}C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lionhead studios ltd\black & white\runblack.exe |
"TCP Query User{41C5A174-AA15-46AC-A401-A98AA4357724}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe |
"TCP Query User{5B2CF389-B1B0-4E64-B39D-4081BAD3D311}C:\users\staffan\saved games\megaman 8-bit deathmatch\skulltag.exe" = protocol=6 | dir=in | app=c:\users\staffan\saved games\megaman 8-bit deathmatch\skulltag.exe |
"TCP Query User{5F7BB591-8747-440B-A90E-0D5A037BE14A}C:\users\staffan\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\staffan\appdata\local\akamai\netsession_win.exe |
"TCP Query User{654C866B-0D92-4DA2-8B29-199B5C13D0AD}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"TCP Query User{6768C6D9-CC75-4F84-BBC0-C10891ABFE70}C:\users\staffan\desktop\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\guild wars 2\gw2.exe |
"TCP Query User{6878CC32-BA00-4A2D-B828-9DE4DF3882FD}C:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe" = protocol=6 | dir=in | app=c:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe |
"TCP Query User{694477A6-8521-4804-8A2F-F8539168A82F}C:\windows\syswow64\rundll32.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\rundll32.exe |
"TCP Query User{6DD27E6D-DA40-4543-84BB-E69B9EE85C33}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"TCP Query User{76543F9E-15BA-42AC-9F72-22A6DEB36514}C:\users\staffan\desktop\downloads\vuze downloads\afauto\auto.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\downloads\vuze downloads\afauto\auto.exe |
"TCP Query User{778132C1-0B6C-40CC-BB5B-F5F13713A94F}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"TCP Query User{7928035F-B290-42FA-8BD9-739B285962B0}C:\users\staffan\saved games\megaman 8-bit deathmatch\zandronum.exe" = protocol=6 | dir=in | app=c:\users\staffan\saved games\megaman 8-bit deathmatch\zandronum.exe |
"TCP Query User{79F8681C-2764-44A4-89F0-144D056B57B1}C:\program files (x86)\steam\steamapps\doomside\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\doomside\team fortress 2\hl2.exe |
"TCP Query User{80C90BCA-5F65-4215-BBF8-4509D7ADCA24}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe |
"TCP Query User{8355A3ED-A04C-4BC6-B758-947E7F9EC7D7}C:\program files (x86)\electronic arts\ultima online classic\client.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\ultima online classic\client.exe |
"TCP Query User{8576AE76-0683-4B30-802A-C0DDDD09DFF2}C:\program files (x86)\steam\steamapps\zrago\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zrago\team fortress 2\hl2.exe |
"TCP Query User{882674BE-14FF-4932-9218-EE2902CDD03F}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{8CD98E0B-F4A3-427E-90B5-9EFDB750240D}C:\users\staffan\desktop\neverwinter_nw.1.20130416a.6.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\neverwinter_nw.1.20130416a.6.exe |
"TCP Query User{92001711-6961-4179-9C71-23C5EBABC935}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"TCP Query User{96B3AAC5-F284-4247-A3A7-E69DF6948755}C:\users\public\sony online entertainment\installed games\planetside 2 beta\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 beta\planetside2.exe |
"TCP Query User{AD28D9C6-1206-417B-BE50-D7869D6BA145}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe |
"TCP Query User{AD2C4F22-79D8-44E6-9467-69329179C394}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"TCP Query User{B1BD402B-BAFA-40D5-A580-F530AA67974A}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"TCP Query User{B6BB5282-1815-4426-97FA-0B5F06E59D8F}C:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe" = protocol=6 | dir=in | app=c:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe |
"TCP Query User{C61F1EAB-2CE1-456C-AF94-3CE0FEC2E06D}C:\users\staffan\desktop\downloads\vuze downloads\afhappysong\afmana.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\downloads\vuze downloads\afhappysong\afmana.exe |
"TCP Query User{DF78C682-EBAF-488D-A226-155F8782353E}C:\users\staffan\desktop\downloads\diablo-iii-8370-engb-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\staffan\desktop\downloads\diablo-iii-8370-engb-installer-downloader.exe |
"TCP Query User{E84014AF-4978-46DC-A28D-153CE2CD7259}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe |
"TCP Query User{EC394B09-E921-446F-89E5-A8D38A277D67}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"TCP Query User{F26A12E6-E550-4BCF-B32E-2B5FD64BC5E6}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"TCP Query User{FB51E511-F65F-4972-B143-7CE7EDBD2511}C:\games\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{01181E25-ACEA-40F0-AE32-D2B326287D56}C:\windows\syswow64\rundll32.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\rundll32.exe |
"UDP Query User{01A726ED-6095-4A25-96D5-9BF81B69711E}C:\users\public\sony online entertainment\installed games\planetside 2 beta\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 beta\planetside2.exe |
"UDP Query User{01F37427-0515-4C70-AC24-629966835BA7}C:\program files (x86)\red 5 studios\firefall\system\bin\firefallclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\red 5 studios\firefall\system\bin\firefallclient.exe |
"UDP Query User{054A8FFE-6821-498B-9FC6-EFA520160F18}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{07A12029-3965-413D-9489-3B8EBE776A58}C:\users\staffan\desktop\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\guild wars 2\gw2.exe |
"UDP Query User{15D82605-1F91-4147-B709-016D6A926A76}C:\users\staffan\desktop\downloads\vuze downloads\afauto\auto.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\downloads\vuze downloads\afauto\auto.exe |
"UDP Query User{1945AA24-FC19-4B4A-96EC-28B4CD2C1BFF}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe |
"UDP Query User{1FC5C61F-4B12-4E51-8733-DED6A2BBCD74}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"UDP Query User{2076795B-3AF5-40C0-85BD-1205F2C825DE}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe |
"UDP Query User{28DF3B03-57AC-4875-B32E-D79AD4403A3F}C:\users\staffan\desktop\downloads\gw2.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\downloads\gw2.exe |
"UDP Query User{30680324-11E2-4929-9A58-88282F9786B5}C:\program files (x86)\steam\steamapps\zrago\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zrago\team fortress 2\hl2.exe |
"UDP Query User{362F1EBE-03B0-4265-ACB1-56949B14AC3F}C:\users\staffan\desktop\neverwinter_nw.1.20130416a.6.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\neverwinter_nw.1.20130416a.6.exe |
"UDP Query User{3850CEDA-0C3B-4F0A-BC11-1AC18C834F3E}C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lionhead studios ltd\black & white\runblack.exe |
"UDP Query User{3B6136FE-A273-46D2-BDFF-E543C6A278B5}C:\users\staffan\saved games\megaman 8-bit deathmatch\skulltag.exe" = protocol=17 | dir=in | app=c:\users\staffan\saved games\megaman 8-bit deathmatch\skulltag.exe |
"UDP Query User{3B97F7C4-7790-4D08-B7D9-D810FCD732E8}C:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe" = protocol=17 | dir=in | app=c:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe |
"UDP Query User{3C2E03DB-C4F0-490D-8030-953C82BD68E1}C:\program files (x86)\electronic arts\ultima online classic\client.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\ultima online classic\client.exe |
"UDP Query User{446F4F4D-F4AA-4025-AB53-893906262B28}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe |
"UDP Query User{5B0650B5-FDB6-4E89-994B-ECAA0E3B7C14}C:\users\staffan\desktop\downloads\vuze downloads\afhappysong\afmana.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\downloads\vuze downloads\afhappysong\afmana.exe |
"UDP Query User{79CDAA65-97D4-41C0-8602-0EC505FDFE10}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe |
"UDP Query User{7C0506CB-4598-4AC1-A557-ACA39B92EBF2}C:\users\staffan\saved games\megaman 8-bit deathmatch\zandronum.exe" = protocol=17 | dir=in | app=c:\users\staffan\saved games\megaman 8-bit deathmatch\zandronum.exe |
"UDP Query User{7D9113EF-2E3C-4C88-809E-6B7D43CB7345}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe |
"UDP Query User{8198A272-1DF1-4A5F-8E81-7FA45C9CDB66}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe |
"UDP Query User{8672643A-47A4-4614-834F-A89B8D97D729}C:\users\public\games\cryptic studios\star trek online\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\star trek online\live\gameclient.exe |
"UDP Query User{8CD19D39-9F6C-4CAE-B9B4-3328D376F761}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{94142A48-AC79-44E5-9FD4-0519782BCA02}C:\program files (x86)\steam\steamapps\doomside\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\doomside\team fortress 2\hl2.exe |
"UDP Query User{94F9E29E-12A7-48CD-BD7D-8F6AE3714984}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{974DA936-8164-4D14-8923-EF67D092F0FD}C:\games\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\wotlauncher.exe |
"UDP Query User{9B94BCB2-68D9-4EC9-B3D8-CBC5E0CE45E6}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"UDP Query User{9F398860-24C1-40FC-B922-36E7228E960C}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe |
"UDP Query User{A90CE147-81E9-4356-8B04-BCF27CC674C4}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"UDP Query User{B8D99F91-E5E7-4B07-8A3B-659CA0267209}C:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe" = protocol=17 | dir=in | app=c:\softimage\softimage_mod_tool_7.5\application\bin\xsi.exe |
"UDP Query User{C696BFC9-41DA-48CF-8EFB-D5650272759A}C:\users\staffan\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\staffan\appdata\local\akamai\netsession_win.exe |
"UDP Query User{D256E4E8-C979-4891-ABE1-9B378C855F37}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{D43DB157-CE80-49B3-B19D-BA906FF63A88}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{FA64BE38-383C-43BF-9C35-C215F45E1C4B}C:\users\staffan\desktop\downloads\diablo-iii-8370-engb-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\staffan\desktop\downloads\diablo-iii-8370-engb-installer-downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8f376ce2-c213-4a6c-a329-0b2a7eb2bad8}.sdb" = GOG.com Planescape Torment
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96CC6DCC-8EBA-3F85-899B-933F599C4142}" = Microsoft .NET Framework 4 Client Profile SVE Language Pack
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision drivrutin 314.22
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIAs kontrollpanel 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafikdrivrutin 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision drivrutin för styrenhet 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA-uppdatering 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD audiodrivrutin [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{b6462b67-caf5-4a74-99df-cc2811bd1957}.sdb" = GOG.com Dungeon Keeper 2
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D3120436-1358-4253-9EB2-257FFE8CE1D9}" = Logitech SetPoint 5.20
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile SVE Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - SVE
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C9CB04A-5A5A-499E-95FC-F7FA9D70AA8A}" = Autodesk Softimage Mod Tool 7.5
"{1A1FA4C1-2701-401C-8CE1-FDDE45304FF5}" = ASUS nVidia Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{253CA9FD-36D9-4E02-8EC7-9F17478BF1FF}" = Black & White Creature Isle
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{287EAC0F-6C96-4712-97A6-958510872CBB}" = Utility
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars™: Knights of the Old Republic ™
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}" = Smite
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple-programstöd
"{471DCE2E-75B0-4B4F-B6B1-C4EA5A3D1E2C}" = Autodesk Softimage Mod Tool 7.5
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{51071D66-D034-4239-94E0-723FCA10B6FE}" = OpenOffice.org 3.4
"{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
"{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
"{6AE22174-4FFA-4572-B692-31F0C386ED38}" = Consolas Font Family
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1053-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Svenska
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4C30AE2-EAFE-4E28-A3BA-7CF7485E23C4}" = Handelsbanken kortläsare
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & Whiteョ 2
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E51B4CD9-A0A6-4324-B26A-31B3F2DE26CE}" = Black and White
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA7F689F-88EB-4946-B105-4C434CF5B07A}" = BankID säkerhetsprogram
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Anki" = Anki
"Audacity_is1" = Audacity 2.0.2
"AudibleManager" = AudibleManager
"avast" = avast! Internet Security
"CDisplay_is1" = CDisplay 1.8
"Cisco Connect" = Cisco Connect
"Cole2k Media - Codec Pack" = Cole2k Media - Codec Pack (Advanced) 8.0.1
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-11-11
"Constructor_is1" = Constructor
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo II" = Diablo II
"GOGDUNGEONKEEPERDOS_is1" = Dungeon Keeper
"GOGPACKBENEATH_is1" = Beneath a Steel Sky
"GOGPACKDUNGEONKEEPER2_is1" = Dungeon Keeper 2
"GOGPACKFALLOUT_is1" = Fallout
"GOGPACKPLANESCAPETORMENT_is1" = Planescape Torment
"GOGPACKSYNDICATE_is1" = Syndicate
"Google Chrome" = Google Chrome
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"LAME_is1" = LAME v3.99.3 (for Windows)
"marvelheroesbeta" = Marvel Heroes
"Mob Rule_is1" = Mob Rule
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Neverwinter" = Neverwinter
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Open Codecs" = Xiph.Org Open Codecs 0.85.17777
"Origin" = Origin
"Steam App 105600" = Terraria
"Steam App 107200" = Space Pirates and Zombies
"Steam App 107300" = Breath of Death VII
"Steam App 107800" = Rochard
"Steam App 110800" = L.A. Noire
"Steam App 17080" = Tribes: Ascend
"Steam App 17460" = Mass Effect
"Steam App 18040" = DeathSpank
"Steam App 1840" = Source Filmmaker
"Steam App 200710" = Torchlight II
"Steam App 203510" = Fortune Summoners: Secret of the Elemental Stone
"Steam App 204060" = Superbrothers: Sword & Sworcery EP
"Steam App 204300" = Awesomenauts
"Steam App 205230" = Hell Yeah!
"Steam App 206440" = To the Moon
"Steam App 206787" = Darksiders 2 - Prima Guide
"Steam App 207420" = Wizorb
"Steam App 207690" = Botanicula
"Steam App 209870" = Blacklight: Retribution
"Steam App 211180" = Unmechanical
"Steam App 211420" = Dark Souls: Prepare to Die Edition
"Steam App 211600" = Thief Gold
"Steam App 212070" = Star Conflict
"Steam App 212680" = FTL: Faster Than Light
"Steam App 213120" = Transformers: Fall of Cybertron
"Steam App 214340" = Deponia
"Steam App 214560" = Mark of the Ninja
"Steam App 216890" = Blood Bowl: Chaos Edition
"Steam App 218230" = PlanetSide 2
"Steam App 219640" = Chivalry: Medieval Warfare
"Steam App 219890" = Antichamber
"Steam App 220860" = McPixel
"Steam App 225260" = Brütal Legend
"Steam App 230410" = Warframe
"Steam App 24980" = Mass Effect 2
"Steam App 40700" = Machinarium
"Steam App 41900" = The Bard's Tale
"Steam App 42170" = Krater
"Steam App 440" = Team Fortress 2
"Steam App 50650" = Darksiders II
"Steam App 570" = Dota 2
"Steam App 58520" = Blood Bowl: Legendary Edition
"Steam App 70400" = Recettear: An Item Shop's Tale
"Steam App 70420" = Chantelise
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8880" = Freedom Force
"Steam App 8980" = Borderlands
"Swiff Player_is1" = Swiff Player 1.7.2
"The Walking Dead" = The Walking Dead
"Theme Hospital_is1" = Theme Hospital
"TigerGame PS/PS2 Game Controller Adapter series_is1" = TigerGame PS/PS2 Game Controller Adapter series to pc USB Drive
"WinLiveSuite" = Windows Live Essentials
"VLC media player" = VLC media player 2.0.6
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2013-05-04 12:14:34 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6021

Error - 2013-05-04 12:14:35 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2013-05-04 12:14:35 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7020

Error - 2013-05-04 12:14:35 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7020

Error - 2013-05-04 12:14:36 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2013-05-04 12:14:36 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 8018

Error - 2013-05-04 12:14:36 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 8018

Error - 2013-05-04 12:14:37 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2013-05-04 12:14:37 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9017

Error - 2013-05-04 12:14:37 | Computer Name = lololol | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9017

[ System Events ]
Error - 2013-05-04 10:35:54 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 10:35:54 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 10:35:54 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 11:58:13 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 11:58:13 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 11:58:13 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 11:58:13 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 13:39:59 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 13:39:59 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.

Error - 2013-05-04 13:39:59 | Computer Name = lololol | Source = atapi | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.


< End of report >
Hello Dontest,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi Dontest,

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

- - - - - Next - - - - -

Download to your desktop RogueKiller (by tigzy)
  • Quit all programs
  • Please disconnect any USB or external drives from the computer before you run this scan!
Right click and select "Run as Administrator"
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
In your next post please provide the following:
  • RogueKiller log
  • How is the computer running?
The computer is still the same like I described in the first post. A couple of programs refuses to work almost completely and will make the whole computer slow down until I force the program to shut down. I also found that longer videos also stop about 10 minutes into them and then after a little while starts working again.


RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Staffan [Admin rights]
Mode : Scan – Date : 05/05/2013 19:56:21
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 6 ¤¤¤
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST2000DL003-9VT166 ATA Device +++++
— User —
[MBR] 1a1d5ff5d5572d487996c19a5d14079f
[BSP] 49d65cb61b8f4c7daec5e1bc0b138812 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 1907627 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_05052013_02d1956.txt >>
RKreport[1]_S_05052013_02d1956.txt
Hi Dontest,

Re-run RogueKiller

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan.
  • After the scan has completed click on the Registry tab
  • Place a check mark next to each of the following entries:

    • [HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJ] HKLM\[…]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[…]\Wow6432Node\System : EnableLUA (0) -> FOUND
  • Remove the check mark from all other entries listed
  • Click the Delete button
  • Click the Report button, save the report to your desktop
- - - - - Next - - - - -

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

In your next post please provide the following:
  • RogueKiller log
  • ComboFix.txt
Seems like I can't get into my computer normally anymore, I'm in Safe mode at the moment.


RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Staffan [Admin rights]
Mode : Remove – Date : 05/06/2013 11:45:35
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 4 ¤¤¤
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[…]\System : EnableLUA (0) -> REPLACED (1)
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NOT SELECTED
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST2000DL003-9VT166 ATA Device +++++
— User —
[MBR] 1a1d5ff5d5572d487996c19a5d14079f
[BSP] 49d65cb61b8f4c7daec5e1bc0b138812 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 1907627 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[3]_D_05062013_02d1145.txt >>
RKreport[1]_S_05062013_02d1139.txt ; RKreport[2]_S_05062013_02d1141.txt ; RKreport[3]_D_05062013_02d1145.txt



ComboFix 13-05-06.01 - Staffan 2013-05-06 11:59:03.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.932.81.1053.18.8148.6505 [GMT 2:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\SysWow64\frapsvid.dll
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-04-06 to 2013-05-06 )))))))))))))))))))))))))))))))
.
.
2013-05-05 09:38 . 2013-05-05 09:38 ——– d—–w- c:\program files (x86)\Common Files\Skype
2013-05-04 14:41 . 2013-05-06 10:04 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1805B585-E38B-4FF7-AD51-C9174E0B0053}\offreg.dll
2013-05-04 14:19 . 2013-05-04 14:22 ——– d—–w- c:\program files (x86)\Google
2013-05-04 09:34 . 2013-05-04 09:34 ——– d—–w- c:\users\Staffan\AppData\Roaming\SUPERAntiSpyware.com
2013-05-04 09:32 . 2013-05-04 09:34 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-05-04 09:32 . 2013-05-04 09:32 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2013-05-03 11:15 . 2013-05-03 11:15 ——– d—–w- c:\users\Staffan\AppData\Roaming\Malwarebytes
2013-05-03 11:15 . 2013-05-03 11:15 ——– d—–w- c:\programdata\Malwarebytes
2013-05-03 09:40 . 2013-04-10 03:46 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1805B585-E38B-4FF7-AD51-C9174E0B0053}\mpengine.dll
2013-04-30 23:12 . 2013-05-01 14:58 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-30 23:12 . 2013-05-01 14:58 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-04-30 22:40 . 2013-04-30 22:40 ——– d—–w- c:\program files (x86)\Common Files\Java
2013-04-30 22:39 . 2013-04-30 22:39 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-28 23:23 . 2013-04-30 19:52 971680 —-a-w- c:\windows\system32\deployJava1.dll
2013-04-28 23:23 . 2013-04-30 19:52 1092512 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-04-28 18:48 . 2013-04-28 18:48 ——– d—–w- c:\users\Staffan\AppData\Roaming\Oracle
2013-04-24 09:30 . 2013-04-12 14:45 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-20 17:05 . 2013-04-20 19:12 ——– d—–w- c:\users\Staffan\AppData\Local\Warframe
2013-04-10 09:12 . 2013-02-15 06:06 3717632 —-a-w- c:\windows\system32\mstscax.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-02 15:44 . 2013-03-19 20:49 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys
2013-05-02 00:06 . 2010-11-21 03:27 278800 ——w- c:\windows\system32\MpSigStub.exe
2013-05-01 23:34 . 2013-03-19 20:49 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-01 23:34 . 2012-05-30 22:44 378432 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-05-01 23:34 . 2012-05-30 22:44 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-05-01 23:34 . 2012-05-30 22:44 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-01 23:34 . 2012-05-30 22:44 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-05-01 23:34 . 2012-05-30 22:48 131232 —-a-w- c:\windows\system32\drivers\aswFW.sys
2013-05-01 23:34 . 2012-05-30 22:48 270824 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2013-05-01 23:34 . 2012-05-30 22:44 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-01 23:34 . 2012-05-30 22:44 22600 —-a-w- c:\windows\system32\drivers\aswKbd.sys
2013-05-01 23:34 . 2012-05-30 22:44 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-01 23:33 . 2012-05-30 22:43 41664 —-a-w- c:\windows\avastSS.scr
2013-05-01 23:33 . 2012-05-30 22:44 287840 —-a-w- c:\windows\system32\aswBoot.exe
2013-04-30 22:39 . 2012-06-19 11:13 866720 —-a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-04-30 22:39 . 2012-06-19 11:13 788896 —-a-w- c:\windows\SysWow64\deployJava1.dll
2013-04-10 11:57 . 2012-06-01 23:38 72702784 —-a-w- c:\windows\system32\MRT.exe
2013-03-30 02:03 . 2013-03-30 02:03 97280 —-a-w- c:\windows\system32\mshtmled.dll
2013-03-30 02:03 . 2013-03-30 02:03 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-03-30 02:03 . 2013-03-30 02:03 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll
2013-03-30 02:03 . 2013-03-30 02:03 81408 —-a-w- c:\windows\system32\icardie.dll
2013-03-30 02:03 . 2013-03-30 02:03 77312 —-a-w- c:\windows\system32\tdc.ocx
2013-03-30 02:03 . 2013-03-30 02:03 762368 —-a-w- c:\windows\system32\ieapfltr.dll
2013-03-30 02:03 . 2013-03-30 02:03 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-03-30 02:03 . 2013-03-30 02:03 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-03-30 02:03 . 2013-03-30 02:03 62976 —-a-w- c:\windows\system32\pngfilt.dll
2013-03-30 02:03 . 2013-03-30 02:03 61952 —-a-w- c:\windows\SysWow64\tdc.ocx
2013-03-30 02:03 . 2013-03-30 02:03 599552 —-a-w- c:\windows\system32\vbscript.dll
2013-03-30 02:03 . 2013-03-30 02:03 523264 —-a-w- c:\windows\SysWow64\vbscript.dll
2013-03-30 02:03 . 2013-03-30 02:03 52224 —-a-w- c:\windows\system32\msfeedsbs.dll
2013-03-30 02:03 . 2013-03-30 02:03 51200 —-a-w- c:\windows\system32\imgutil.dll
2013-03-30 02:03 . 2013-03-30 02:03 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2013-03-30 02:03 . 2013-03-30 02:03 48640 —-a-w- c:\windows\system32\mshtmler.dll
2013-03-30 02:03 . 2013-03-30 02:03 452096 —-a-w- c:\windows\system32\dxtmsft.dll
2013-03-30 02:03 . 2013-03-30 02:03 441856 —-a-w- c:\windows\system32\html.iec
2013-03-30 02:03 . 2013-03-30 02:03 38400 —-a-w- c:\windows\SysWow64\imgutil.dll
2013-03-30 02:03 . 2013-03-30 02:03 361984 —-a-w- c:\windows\SysWow64\html.iec
2013-03-30 02:03 . 2013-03-30 02:03 281600 —-a-w- c:\windows\system32\dxtrans.dll
2013-03-30 02:03 . 2013-03-30 02:03 27648 —-a-w- c:\windows\system32\licmgr10.dll
2013-03-30 02:03 . 2013-03-30 02:03 270848 —-a-w- c:\windows\system32\iedkcs32.dll
2013-03-30 02:03 . 2013-03-30 02:03 247296 —-a-w- c:\windows\system32\webcheck.dll
2013-03-30 02:03 . 2013-03-30 02:03 235008 —-a-w- c:\windows\system32\url.dll
2013-03-30 02:03 . 2013-03-30 02:03 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll
2013-03-30 02:03 . 2013-03-30 02:03 226304 —-a-w- c:\windows\system32\elshyph.dll
2013-03-30 02:03 . 2013-03-30 02:03 216064 —-a-w- c:\windows\system32\msls31.dll
2013-03-30 02:03 . 2013-03-30 02:03 197120 —-a-w- c:\windows\system32\msrating.dll
2013-03-30 02:03 . 2013-03-30 02:03 185344 —-a-w- c:\windows\SysWow64\elshyph.dll
2013-03-30 02:03 . 2013-03-30 02:03 173568 —-a-w- c:\windows\system32\ieUnatt.exe
2013-03-30 02:03 . 2013-03-30 02:03 167424 —-a-w- c:\windows\system32\iexpress.exe
2013-03-30 02:03 . 2013-03-30 02:03 158720 —-a-w- c:\windows\SysWow64\msls31.dll
2013-03-30 02:03 . 2013-03-30 02:03 1509376 —-a-w- c:\windows\system32\inetcpl.cpl
2013-03-30 02:03 . 2013-03-30 02:03 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2013-03-30 02:03 . 2013-03-30 02:03 149504 —-a-w- c:\windows\system32\occache.dll
2013-03-30 02:03 . 2013-03-30 02:03 144896 —-a-w- c:\windows\system32\wextract.exe
2013-03-30 02:03 . 2013-03-30 02:03 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2013-03-30 02:03 . 2013-03-30 02:03 1400416 —-a-w- c:\windows\system32\ieapfltr.dat
2013-03-30 02:03 . 2013-03-30 02:03 138752 —-a-w- c:\windows\SysWow64\wextract.exe
2013-03-30 02:03 . 2013-03-30 02:03 13824 —-a-w- c:\windows\system32\mshta.exe
2013-03-30 02:03 . 2013-03-30 02:03 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2013-03-30 02:03 . 2013-03-30 02:03 136192 —-a-w- c:\windows\system32\iepeers.dll
2013-03-30 02:03 . 2013-03-30 02:03 135680 —-a-w- c:\windows\system32\IEAdvpack.dll
2013-03-30 02:03 . 2013-03-30 02:03 12800 —-a-w- c:\windows\SysWow64\mshta.exe
2013-03-30 02:03 . 2013-03-30 02:03 12800 —-a-w- c:\windows\system32\msfeedssync.exe
2013-03-30 02:03 . 2013-03-30 02:03 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-03-30 02:03 . 2013-03-30 02:03 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-30 02:03 . 2013-03-30 02:03 102912 —-a-w- c:\windows\system32\inseng.dll
2013-03-23 01:21 . 2012-07-03 10:45 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-03-23 01:21 . 2012-07-03 10:31 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-03-22 22:38 . 2012-07-03 10:31 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-03-15 05:53 . 2012-08-19 00:37 1118776 —-a-w- c:\windows\system32\nvumdshimx.dll
2013-03-15 05:53 . 2012-05-30 22:05 15042928 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2013-03-15 05:53 . 2012-05-30 22:05 2864144 —-a-w- c:\windows\system32\nvapi64.dll
2013-03-15 04:16 . 2011-03-23 22:52 3477280 —-a-w- c:\windows\system32\nvsvc64.dll
2013-03-15 04:16 . 2011-03-23 22:53 6398240 —-a-w- c:\windows\system32\nvcpl.dll
2013-03-15 04:16 . 2011-03-23 22:53 877856 —-a-w- c:\windows\system32\nvvsvc.exe
2013-03-15 04:16 . 2011-03-23 22:53 63776 —-a-w- c:\windows\system32\nvshext.dll
2013-03-15 04:16 . 2011-03-23 22:53 2555680 —-a-w- c:\windows\system32\nvsvcr.dll
2013-03-15 04:16 . 2011-03-23 22:53 237856 —-a-w- c:\windows\system32\nvmctray.dll
2013-03-14 20:07 . 2013-03-14 20:07 559904 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2013-03-13 16:24 . 2012-08-19 00:38 3065455 —-a-w- c:\windows\system32\nvcoproc.bin
2013-03-10 01:30 . 2012-07-03 10:31 76888 —-a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-02-26 06:55 . 2013-02-26 06:55 71680 —-a-w- c:\windows\system32\frapsv64.dll
2013-02-25 22:32 . 2012-08-19 00:37 1814304 —-a-w- c:\windows\system32\nvdispco64.dll
2013-02-25 22:32 . 2012-09-15 01:00 1510176 —-a-w- c:\windows\system32\nvdispgenco64.dll
2013-02-22 07:17 . 2013-03-31 20:21 203544 —-a-w- c:\windows\system32\drivers\ssudmdm.sys
2013-02-22 07:17 . 2013-03-31 20:21 102936 —-a-w- c:\windows\system32\drivers\ssudbus.sys
2013-02-12 05:45 . 2013-03-14 01:30 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-14 01:30 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-14 01:30 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-14 01:30 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-14 01:30 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-14 01:30 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-02-12 04:12 . 2013-03-20 20:51 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 15:53 . 2013-03-31 20:07 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll
2013-02-05 15:52 . 2013-02-05 15:52 90112 —-a-w- c:\windows\MAMCityDownload.ocx
2013-02-05 15:52 . 2013-02-05 15:52 330240 —-a-w- c:\windows\MASetupCaller.dll
2013-02-05 15:52 . 2013-02-05 15:52 30568 —-a-w- c:\windows\MusiccityDownload.exe
2013-02-05 15:52 . 2013-02-05 15:52 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll
2013-02-05 15:52 . 2013-02-05 15:52 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll
2013-02-05 15:52 . 2013-02-05 15:52 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-04-19 1631144]
"googletalk"="c:\users\Staffan\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18643560]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-03-28 1511792]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 5629312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-01 4858456]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-03-28 310640]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BankID sakerhetsprogram.lnk - [N/A]
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetPointII.exe [2009-7-21 815104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2013-04-23 9216]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-03-01 161384]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2013-02-22 102936]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-17 26136]
R3 MayPro;TigerGame SuperJoy Box Pro Filter Service;c:\windows\system32\Drivers\MayPro.sys [2007-08-12 25120]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2013-02-22 203544]
R3 Tdsshbecr;Handelsbanken card reader;c:\windows\system32\DRIVERS\shbecr.sys [2008-09-22 50176]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Aktiveringsteknologier for Windows-tjanst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-30 1255736]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 aswKbd;aswKbd; [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-03-06 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 iusb3hcs;Switchdrivrutin for Intel® USB 3.0 Vardstyrenhet;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-04 16152]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-01 80816]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-05-01 137960]
S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 628448]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264]
S3 iusb3hub;Drivrutin for Intel® USB 3.0 Nav;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-04 355096]
S3 iusb3xhc;Drivrutin for Intel® USB 3.0 Utbyggbar vardstyrenhet;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-04 786200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-04 14:22 1642448 —-a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-30 14:58]
.
2013-05-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04 14:19]
.
2013-05-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04 14:19]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-01 23:33 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-12-12 7560296]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.se/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
FF - ProfilePath - c:\users\Staffan\AppData\Roaming\Mozilla\Firefox\Profiles\hm4960if.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe
Wow6432Node-HKCU-Run-Akamai NetSession Interface - c:\users\Staffan\AppData\Local\Akamai\netsession_win.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-marvelheroesbeta - c:\programdata\bitraider\brwc.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\SecuROM\License information*]
"datasecu"=hex:bf,b6,ac,85,b6,1e,b9,9d,0e,7a,1d,bc,c0,b1,70,d2,1b,ed,60,5c,bb,
a4,0b,d0,26,e1,03,7a,c3,af,76,bb,20,e6,01,e5,74,a3,ab,77,5b,27,89,d4,0b,59,\
"rkeysecu"=hex:e6,0b,cf,9d,d3,83,e9,01,cc,63,28,ed,52,3a,aa,95
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-05-06 12:18:06
ComboFix-quarantined-files.txt 2013-05-06 10:18
.
Pre-Run: 507?069?722?624 byte ledigt
Post-Run: 510?687?375?360 byte ledigt
.
- - End Of File - - 2F89A8AF19494D1FE83AF2B7DF3187E0
Hi Dontest,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

DDS::
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com

ClearJavaCache::

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

- - - - - Next - - - - -

Reboot

- - - - - Next - - - - -

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- - - - - Next - - - - -

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
In your next post please provide the following:
  • ComboFix.txt
  • MBAM log
  • ESET's log.txt
  • How is the computer running at the moment?
As I said in my last update, can't start the computer normally anymore, have to start it in Safe Mode to get on it. Outside of that I'm not sure if anything has improved, not the easiest to tell. When I was running Combofix it said I had my Antivirus program still running even though I couldn't find it running or shut it off in Safe Mode. I let it scan away anyways. ComboFix 13-05-07.01 - Staffan 2013-05-07 12:01:17.2.4 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.932.81.1053.18.8148.7207 [GMT 2:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Staffan\Desktop\CFScript.txt AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2013-04-07 to 2013-05-07 ))))))))))))))))))))))))))))))) . . 2013-05-07 10:15 . 2013-05-07 10:15 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-05-07 10:15 . 2013-05-07 10:15 ——– d—–w- c:\users\hedev\AppData\Local\temp 2013-05-07 10:15 . 2013-05-07 10:15 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-05-05 09:38 . 2013-05-05 09:38 ——– d—–w- c:\program files (x86)\Common Files\Skype 2013-05-04 14:19 . 2013-05-04 14:22 ——– d—–w- c:\program files (x86)\Google 2013-05-04 09:34 . 2013-05-04 09:34 ——– d—–w- c:\users\Staffan\AppData\Roaming\SUPERAntiSpyware.com 2013-05-04 09:32 . 2013-05-04 09:34 ——– d—–w- c:\program files\SUPERAntiSpyware 2013-05-04 09:32 . 2013-05-04 09:32 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2013-05-03 11:15 . 2013-05-03 11:15 ——– d—–w- c:\users\Staffan\AppData\Roaming\Malwarebytes 2013-05-03 11:15 . 2013-05-03 11:15 ——– d—–w- c:\programdata\Malwarebytes 2013-05-03 09:40 . 2013-04-10 03:46 9317456 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1805B585-E38B-4FF7-AD51-C9174E0B0053}\mpengine.dll 2013-04-30 23:12 . 2013-05-01 14:58 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-30 23:12 . 2013-05-01 14:58 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-30 22:40 . 2013-04-30 22:40 ——– d—–w- c:\program files (x86)\Common Files\Java 2013-04-30 22:39 . 2013-04-30 22:39 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-28 23:23 . 2013-04-30 19:52 971680 —-a-w- c:\windows\system32\deployJava1.dll 2013-04-28 23:23 . 2013-04-30 19:52 1092512 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-04-28 18:48 . 2013-04-28 18:48 ——– d—–w- c:\users\Staffan\AppData\Roaming\Oracle 2013-04-24 09:30 . 2013-04-12 14:45 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-20 17:05 . 2013-04-20 19:12 ——– d—–w- c:\users\Staffan\AppData\Local\Warframe 2013-04-10 09:12 . 2013-02-15 06:06 3717632 —-a-w- c:\windows\system32\mstscax.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-02 15:44 . 2013-03-19 20:49 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-05-02 00:06 . 2010-11-21 03:27 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-05-01 23:34 . 2013-03-19 20:49 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-05-01 23:34 . 2012-05-30 22:44 378432 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-05-01 23:34 . 2012-05-30 22:44 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-05-01 23:34 . 2012-05-30 22:44 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-05-01 23:34 . 2012-05-30 22:44 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-05-01 23:34 . 2012-05-30 22:48 131232 —-a-w- c:\windows\system32\drivers\aswFW.sys 2013-05-01 23:34 . 2012-05-30 22:48 270824 —-a-w- c:\windows\system32\drivers\aswNdis2.sys 2013-05-01 23:34 . 2012-05-30 22:44 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-05-01 23:34 . 2012-05-30 22:44 22600 —-a-w- c:\windows\system32\drivers\aswKbd.sys 2013-05-01 23:34 . 2012-05-30 22:44 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-05-01 23:33 . 2012-05-30 22:43 41664 —-a-w- c:\windows\avastSS.scr 2013-05-01 23:33 . 2012-05-30 22:44 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-04-30 22:39 . 2012-06-19 11:13 866720 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-04-30 22:39 . 2012-06-19 11:13 788896 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-10 11:57 . 2012-06-01 23:38 72702784 —-a-w- c:\windows\system32\MRT.exe 2013-03-30 02:03 . 2013-03-30 02:03 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-03-30 02:03 . 2013-03-30 02:03 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-03-30 02:03 . 2013-03-30 02:03 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll 2013-03-30 02:03 . 2013-03-30 02:03 81408 —-a-w- c:\windows\system32\icardie.dll 2013-03-30 02:03 . 2013-03-30 02:03 77312 —-a-w- c:\windows\system32\tdc.ocx 2013-03-30 02:03 . 2013-03-30 02:03 762368 —-a-w- c:\windows\system32\ieapfltr.dll 2013-03-30 02:03 . 2013-03-30 02:03 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-03-30 02:03 . 2013-03-30 02:03 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-03-30 02:03 . 2013-03-30 02:03 62976 —-a-w- c:\windows\system32\pngfilt.dll 2013-03-30 02:03 . 2013-03-30 02:03 61952 —-a-w- c:\windows\SysWow64\tdc.ocx 2013-03-30 02:03 . 2013-03-30 02:03 599552 —-a-w- c:\windows\system32\vbscript.dll 2013-03-30 02:03 . 2013-03-30 02:03 523264 —-a-w- c:\windows\SysWow64\vbscript.dll 2013-03-30 02:03 . 2013-03-30 02:03 52224 —-a-w- c:\windows\system32\msfeedsbs.dll 2013-03-30 02:03 . 2013-03-30 02:03 51200 —-a-w- c:\windows\system32\imgutil.dll 2013-03-30 02:03 . 2013-03-30 02:03 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2013-03-30 02:03 . 2013-03-30 02:03 48640 —-a-w- c:\windows\system32\mshtmler.dll 2013-03-30 02:03 . 2013-03-30 02:03 452096 —-a-w- c:\windows\system32\dxtmsft.dll 2013-03-30 02:03 . 2013-03-30 02:03 441856 —-a-w- c:\windows\system32\html.iec 2013-03-30 02:03 . 2013-03-30 02:03 38400 —-a-w- c:\windows\SysWow64\imgutil.dll 2013-03-30 02:03 . 2013-03-30 02:03 361984 —-a-w- c:\windows\SysWow64\html.iec 2013-03-30 02:03 . 2013-03-30 02:03 281600 —-a-w- c:\windows\system32\dxtrans.dll 2013-03-30 02:03 . 2013-03-30 02:03 27648 —-a-w- c:\windows\system32\licmgr10.dll 2013-03-30 02:03 . 2013-03-30 02:03 270848 —-a-w- c:\windows\system32\iedkcs32.dll 2013-03-30 02:03 . 2013-03-30 02:03 247296 —-a-w- c:\windows\system32\webcheck.dll 2013-03-30 02:03 . 2013-03-30 02:03 235008 —-a-w- c:\windows\system32\url.dll 2013-03-30 02:03 . 2013-03-30 02:03 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll 2013-03-30 02:03 . 2013-03-30 02:03 226304 —-a-w- c:\windows\system32\elshyph.dll 2013-03-30 02:03 . 2013-03-30 02:03 216064 —-a-w- c:\windows\system32\msls31.dll 2013-03-30 02:03 . 2013-03-30 02:03 197120 —-a-w- c:\windows\system32\msrating.dll 2013-03-30 02:03 . 2013-03-30 02:03 185344 —-a-w- c:\windows\SysWow64\elshyph.dll 2013-03-30 02:03 . 2013-03-30 02:03 173568 —-a-w- c:\windows\system32\ieUnatt.exe 2013-03-30 02:03 . 2013-03-30 02:03 167424 —-a-w- c:\windows\system32\iexpress.exe 2013-03-30 02:03 . 2013-03-30 02:03 158720 —-a-w- c:\windows\SysWow64\msls31.dll 2013-03-30 02:03 . 2013-03-30 02:03 1509376 —-a-w- c:\windows\system32\inetcpl.cpl 2013-03-30 02:03 . 2013-03-30 02:03 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2013-03-30 02:03 . 2013-03-30 02:03 149504 —-a-w- c:\windows\system32\occache.dll 2013-03-30 02:03 . 2013-03-30 02:03 144896 —-a-w- c:\windows\system32\wextract.exe 2013-03-30 02:03 . 2013-03-30 02:03 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2013-03-30 02:03 . 2013-03-30 02:03 1400416 —-a-w- c:\windows\system32\ieapfltr.dat 2013-03-30 02:03 . 2013-03-30 02:03 138752 —-a-w- c:\windows\SysWow64\wextract.exe 2013-03-30 02:03 . 2013-03-30 02:03 13824 —-a-w- c:\windows\system32\mshta.exe 2013-03-30 02:03 . 2013-03-30 02:03 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2013-03-30 02:03 . 2013-03-30 02:03 136192 —-a-w- c:\windows\system32\iepeers.dll 2013-03-30 02:03 . 2013-03-30 02:03 135680 —-a-w- c:\windows\system32\IEAdvpack.dll 2013-03-30 02:03 . 2013-03-30 02:03 12800 —-a-w- c:\windows\SysWow64\mshta.exe 2013-03-30 02:03 . 2013-03-30 02:03 12800 —-a-w- c:\windows\system32\msfeedssync.exe 2013-03-30 02:03 . 2013-03-30 02:03 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-03-30 02:03 . 2013-03-30 02:03 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-03-30 02:03 . 2013-03-30 02:03 102912 —-a-w- c:\windows\system32\inseng.dll 2013-03-23 01:21 . 2012-07-03 10:45 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-03-23 01:21 . 2012-07-03 10:31 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-03-22 22:38 . 2012-07-03 10:31 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-03-15 05:53 . 2012-08-19 00:37 1118776 —-a-w- c:\windows\system32\nvumdshimx.dll 2013-03-15 05:53 . 2012-05-30 22:05 15042928 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2013-03-15 05:53 . 2012-05-30 22:05 2864144 —-a-w- c:\windows\system32\nvapi64.dll 2013-03-15 04:16 . 2011-03-23 22:52 3477280 —-a-w- c:\windows\system32\nvsvc64.dll 2013-03-15 04:16 . 2011-03-23 22:53 6398240 —-a-w- c:\windows\system32\nvcpl.dll 2013-03-15 04:16 . 2011-03-23 22:53 877856 —-a-w- c:\windows\system32\nvvsvc.exe 2013-03-15 04:16 . 2011-03-23 22:53 63776 —-a-w- c:\windows\system32\nvshext.dll 2013-03-15 04:16 . 2011-03-23 22:53 2555680 —-a-w- c:\windows\system32\nvsvcr.dll 2013-03-15 04:16 . 2011-03-23 22:53 237856 —-a-w- c:\windows\system32\nvmctray.dll 2013-03-14 20:07 . 2013-03-14 20:07 559904 —-a-w- c:\windows\SysWow64\nvStreaming.exe 2013-03-13 16:24 . 2012-08-19 00:38 3065455 —-a-w- c:\windows\system32\nvcoproc.bin 2013-03-10 01:30 . 2012-07-03 10:31 76888 —-a-w- c:\windows\SysWow64\PnkBstrA.exe 2013-02-26 06:55 . 2013-02-26 06:55 71680 —-a-w- c:\windows\system32\frapsv64.dll 2013-02-25 22:32 . 2012-08-19 00:37 1814304 —-a-w- c:\windows\system32\nvdispco64.dll 2013-02-25 22:32 . 2012-09-15 01:00 1510176 —-a-w- c:\windows\system32\nvdispgenco64.dll 2013-02-22 07:17 . 2013-03-31 20:21 203544 —-a-w- c:\windows\system32\drivers\ssudmdm.sys 2013-02-22 07:17 . 2013-03-31 20:21 102936 —-a-w- c:\windows\system32\drivers\ssudbus.sys 2013-02-12 05:45 . 2013-03-14 01:30 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 01:30 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 01:30 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 01:30 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 01:30 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 01:30 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-02-12 04:12 . 2013-03-20 20:51 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-04-19 1631144] "googletalk"="c:\users\Staffan\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18643560] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-03-28 1511792] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 5629312] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-01 4858456] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-03-28 310640] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [X] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BankID sakerhetsprogram.lnk - [N/A] SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetPointII.exe [2009-7-21 815104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R0 aswRvrt;aswRvrt; [x] R0 aswVmm;aswVmm; [x] R1 aswSnx;aswSnx; [x] R1 aswSP;aswSP; [x] R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] R2 aswFsBlk;aswFsBlk; [x] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-01 80816] R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-05-01 137960] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2013-04-23 9216] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 628448] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-03-01 161384] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264] R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2013-02-22 102936] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys [2010-08-17 26136] R3 MayPro;TigerGame SuperJoy Box Pro Filter Service;c:\windows\system32\Drivers\MayPro.sys [2007-08-12 25120] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2013-02-22 203544] R3 Tdsshbecr;Handelsbanken card reader;c:\windows\system32\DRIVERS\shbecr.sys [2008-09-22 50176] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Aktiveringsteknologier for Windows-tjanst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-30 1255736] R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 aswKbd;aswKbd; [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-03-06 12368] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S0 iusb3hcs;Switchdrivrutin for Intel® USB 3.0 Vardstyrenhet;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-04 16152] S1 aswFW;avast! TDI Firewall driver; [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S3 iusb3hub;Drivrutin for Intel® USB 3.0 Nav;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-04 355096] S3 iusb3xhc;Drivrutin for Intel® USB 3.0 Utbyggbar vardstyrenhet;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-04 786200] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-05-04 14:22 1642448 —-a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-05-06 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-30 14:58] . 2013-05-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04 14:19] . 2013-05-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04 14:19] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-01 23:33 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-12-12 7560296] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.se/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; TCP: DhcpNameServer = [removed] [removed] 192.168.1.1 FF - ProfilePath - c:\users\Staffan\AppData\Roaming\Mozilla\Firefox\Profiles\hm4960if.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia (en) . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-RunOnce- - (no file) AddRemove-marvelheroesbeta - c:\programdata\bitraider\brwc.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-742518074-3805996902-3662808339-1000\Software\SecuROM\License information*] "datasecu"=hex:bf,b6,ac,85,b6,1e,b9,9d,0e,7a,1d,bc,c0,b1,70,d2,1b,ed,60,5c,bb, a4,0b,d0,26,e1,03,7a,c3,af,76,bb,20,e6,01,e5,74,a3,ab,77,5b,27,89,d4,0b,59,\ "rkeysecu"=hex:e6,0b,cf,9d,d3,83,e9,01,cc,63,28,ed,52,3a,aa,95 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-05-07 12:19:50 ComboFix-quarantined-files.txt 2013-05-07 10:19 ComboFix2.txt 2013-05-06 10:18 . Pre-Run: 510?752?595?968 byte ledigt Post-Run: 510?674?132?992 byte ledigt . - - End Of File - - F22C227DB3ED5EFB14B11955D7E4366A Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Databasversion: v2013.05.07.04 Windows 7 Service Pack 1 x64 NTFS (Felsäkert läge med nätverk) Internet Explorer 10.0.9200.16540 Staffan :: LOLOLOL [administratör] 2013-05-07 12:28:22 mbam-log-2013-05-07 (12-28-22).txt Skanningstyp: Snabbskanning Aktiverade skanningsalternativ: Minne | Start | Register | Filsystem | Heuristik/Extra | Heuristik/Shuriken | PUP | PUM Inaktiverade skanningsalternativ: P2P Antal skannade objekt: 253051 Förfluten tid: 4 minut(er), 27 sekund(er) Upptäckta minnesprocesser: 0 (Inga skadliga poster hittades) Upptäckta minnesmoduler: 0 (Inga skadliga poster hittades) Upptäckta registernycklar: 0 (Inga skadliga poster hittades) Upptäckta registervärden: 0 (Inga skadliga poster hittades) Upptäckta registerdataposter: 0 (Inga skadliga poster hittades) Upptäckta mappar: 0 (Inga skadliga poster hittades) Upptäckta filer: 0 (Inga skadliga poster hittades) (klar) (Seems to have ended up in swedish seeing as I am a swede, don't know why it refused to install as english but oh well, it didn't find anything as far as I could tell.) No ESET log
Hi Dontest,

Here are instructions on how to disable your Avast antivirus software, should the need arise again.
  • Right- click on the avast! icon in system tray (looks like this: [external image: Posted Image] but orange in color starting with v5).
  • Select avast! shields control and there will be options to disable avast for 10 minutes, 1 hour, until the computer is restarted or permanently.
= = = = = = = = = = = = = = = = = = = =

  • Are you sure you are in Safe Mode? - Your logs indicate they have been run in Normal Mode.
  • What happens when you try and boot in Normal Mode, what error messages/ symptoms do you encounter?
1. Safe Mode with Networking is definitively what I am in. Only the last two logs come from Safe Mode though. 2. It goes to the Windows screen before you can log in and holds there for a little while before a blue screen pops up for half a second whereupon the computer restarts and repeats unless I get it into Safe Mode. Windows tries to find a solution to the problem but can't find anything. As for Avast, I know that's how you do it but in Safe Mode the icon isn't visible and I can't shut down the Avast process as far as I could see.
Hi Dontest,

Thanks for the explanation. :thumbup:

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
In your next post please provide the following:
  • FRST.txt
  • Addition.txt
Computers sure are fickle things. When I woke up today I was able to go into normal mode again. I did absolutely nothing yesterday that I can think would fix it. So I'm just going to make sure that you still want me to do what you told me to do now that I'm back in normal mode before I proceed. As for how my computer is running (now that I can tell you) it doesn't seem to be doing any better than before.
Hi Dontest,

Yes, please complete the last steps requested.

Also describe what symptoms you might be experiencing (ie freezing, won't boot, sluggish etc). :thumbup: Unfortunately, "it's not running much better than before" doesn't give me enough direction/information as to what to troubleshoot to solve the problem.
And now it won't let me boot normally again. Same way as I described it before. As for what I meant with it not running any better than before I was refering to the problems I've mentioned in the last couple of updates: Randomlly stopping videos, computer halting when I open certain programs (Skype, Internet Explorer, etc). It all happened soon after that message appeared though I suppose I can't say for certain it is because of a virus that I am having these problems. Can't really think of anything else that I did since then that would cause my computer to start acting like this though.



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-05-2013
Ran by [removed] (administrator) on 08-05-2013 21:12:05
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Swedish
Internet Explorer Version 9
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) =================

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Staffan\Desktop\FRST64.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [7560296 2011-12-12] (Realtek Semiconductor)
HKLM\…\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x]
HKCU\…\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1635752 2013-05-04] (Valve Corporation)
HKCU\…\Run: [googletalk] C:\Users\Staffan\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKCU\…\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18643560 2013-03-01] (Skype Technologies S.A.)
HKCU\…\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [1511792 2013-03-28] (Samsung)
HKCU\…\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5629312 2012-11-01] (SUPERAntiSpyware.com)
HKLM-x32\…\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291608 2012-01-04] (Intel Corporation)
HKLM-x32\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858456 2013-05-02] (AVAST Software)
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\…\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)
HKLM-x32\…\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
Startup: C:\ProgramData\Start Menu\Programs\Startup\BankID sakerhetsprogram.lnk
ShortcutTarget: BankID sakerhetsprogram.lnk -> C:\Program Files (x86)\Personal\bin\Personal.exe (Technology Nexus AB)
Startup: C:\ProgramData\Start Menu\Programs\Startup\SetPointII.lnk
ShortcutTarget: SetPointII.lnk -> C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [20992] (Microsoft Corporation)
Winsock: Catalog5-x64 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Staffan\AppData\Roaming\Mozilla\Firefox\Profiles\hm4960if.default
FF SelectedSearchEngine: Wikipedia (en)
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @se.nexus/Personal - C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF Plugin-x32: @soe.sony.com/installer,version=1.0.3 - C:\Users\Staffan\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: jid0-Iix25kwA6rvhf6Tw5M2NpHRlXvo - C:\Users\Staffan\AppData\Roaming\Mozilla\Firefox\Profiles\hm4960if.default\Extensions\[removed]
FF Extension: No Name - C:\Users\Staffan\AppData\Roaming\Mozilla\Firefox\Profiles\hm4960if.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java™ Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Nexus Personal) - C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (SOE Web Installer) - C:\Users\Staffan\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Gmail) - C:\Users\Staffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-02] (AVAST Software)
S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-05-02] (AVAST Software)
S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-03-10] ()

==================== Drivers (Whitelisted) ====================

S3 asusgsb; C:\Windows\System32\drivers\asusgsb.sys [17792 2009-02-17] (ASUSTeK Computer Inc.)
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-02] (AVAST Software)
R1 aswFW; C:\Windows\System32\Drivers\aswFW.sys [131232 2013-05-02] (AVAST Software)
R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-02] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-02] (AVAST Software)
R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2012-03-07] (ALWIL Software)
R0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [270824 2013-05-02] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-02] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-02] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1025808 2013-05-02] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378432 2013-05-02] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-02] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-05-02] ()
S3 MayPro; C:\Windows\System32\Drivers\MayPro.sys [25120 2007-08-13] (TigerGame.,Ltd)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-06-30] (Duplex Secure Ltd.)
S3 Tdsshbecr; C:\Windows\System32\DRIVERS\shbecr.sys [50176 2008-09-23] (Todos Data System AB)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S1 EIO64; system32\DRIVERS\EIO64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-05-08 21:11 - 2013-05-08 21:11 - 00000000 ____D C:\FRST
2013-05-08 21:10 - 2013-05-08 21:10 - 01874958 ____A (Farbar) C:\Users\Staffan\Desktop\FRST64.exe
2013-05-08 12:55 - 2013-05-08 12:55 - 00002745 ____A C:\Users\Staffan\Desktop\Lucky Star - genvag.lnk
2013-05-07 12:27 - 2013-05-07 12:27 - 00001069 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-05-07 12:27 - 2013-05-07 12:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-07 12:27 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-05-07 12:19 - 2013-05-07 12:19 - 00019649 ____A C:\ComboFix.txt
2013-05-06 12:22 - 2013-05-07 12:20 - 00019649 ____A C:\Users\Staffan\Desktop\Nytt textdokument.txt
2013-05-06 11:56 - 2013-05-07 12:19 - 00000000 ____D C:\Qoobox
2013-05-06 11:56 - 2013-05-06 12:17 - 00000000 ____D C:\Windows\erdnt
2013-05-06 11:56 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-05-06 11:56 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-05-06 11:56 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-05-06 11:56 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-05-06 11:56 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-05-06 11:56 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-05-06 11:56 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-05-06 11:56 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-05-06 11:47 - 2013-05-07 11:56 - 05066751 ____R (Swearware) C:\Users\Staffan\Desktop\ComboFix.exe
2013-05-06 11:37 - 2013-05-07 13:45 - 00000000 ____D C:\Users\Staffan\Desktop\Ny mapp (2)
2013-05-05 19:53 - 2013-05-06 11:45 - 00000000 ____D C:\Users\Staffan\Desktop\RK_Quarantine
2013-05-05 19:16 - 2013-05-05 19:16 - 00000188 ____A C:\Users\Staffan\defogger_reenable
2013-05-05 19:12 - 2013-05-05 19:12 - 00050477 ____A C:\Users\Staffan\Desktop\Defogger.exe
2013-05-05 19:11 - 2013-05-05 19:12 - 00791040 ____A C:\Users\Staffan\Desktop\RogueKillerX64.exe
2013-05-04 16:22 - 2013-05-04 16:22 - 00002215 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-05-04 16:21 - 2013-05-08 13:34 - 00000996 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-04 16:20 - 2013-05-08 11:28 - 00000992 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-04 16:19 - 2013-05-04 16:22 - 00000000 ____D C:\Program Files (x86)\Google
2013-05-04 11:34 - 2013-05-04 11:34 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\SUPERAntiSpyware.com
2013-05-04 11:32 - 2013-05-04 11:34 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-05-04 11:32 - 2013-05-04 11:32 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-05-04 11:32 - 2013-05-04 11:32 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-05-03 13:15 - 2013-05-03 13:15 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Malwarebytes
2013-05-03 13:15 - 2013-05-03 13:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-05-03 12:47 - 2013-05-04 17:52 - 00005044 ____A C:\Users\Staffan\Desktop\newer all sites.txt
2013-05-02 20:56 - 2013-05-02 20:56 - 00002052 ____A C:\Windows\epplauncher.mif
2013-05-01 22:06 - 2013-05-01 22:06 - 00001196 ____A C:\Users\Staffan\Desktop\Neverwinter.lnk
2013-05-01 01:12 - 2013-05-08 13:21 - 00000868 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-01 01:12 - 2013-05-01 16:58 - 00691592 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-01 01:12 - 2013-05-01 16:58 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-01 00:39 - 2013-05-01 00:39 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-04-29 01:23 - 2013-04-30 21:52 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-04-29 01:23 - 2013-04-30 21:52 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-04-28 20:53 - 2013-04-28 20:54 - 00004010 ____A C:\Windows\SysWOW64\jupdate-1.7.0_21-b11.log
2013-04-28 20:48 - 2013-04-28 20:48 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Oracle
2013-04-27 22:51 - 2013-04-27 22:51 - 00001993 ____A C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
2013-04-27 22:51 - 2013-04-27 22:51 - 00001984 ____A C:\Users\Public\Desktop\Smite.lnk
2013-04-25 01:58 - 2013-04-25 01:58 - 00001026 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-04-25 01:57 - 2013-04-25 01:57 - 00001687 ____A C:\Users\Public\Desktop\Planescape Torment.lnk
2013-04-24 11:30 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-04-20 19:05 - 2013-04-20 21:12 - 00000000 ____D C:\Users\Staffan\AppData\Local\Warframe
2013-04-18 14:04 - 2013-03-15 07:53 - 26956576 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 25256736 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 20542752 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 17990800 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 17560352 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 15508512 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 13088000 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 11048736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2013-04-18 14:04 - 2013-03-15 07:53 - 09414456 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 07959000 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 07573816 ____A (NVIDIA Corporation) C:\Windows\System32\nvopencl.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 06271872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 02913056 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 02728736 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 02539128 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 02355488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 01995552 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 01807136 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco6431422.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 01510176 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispgenco6431422.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 00968408 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 00250504 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
2013-04-18 14:04 - 2013-03-15 07:53 - 00205184 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-04-18 14:04 - 2012-12-19 07:42 - 00031672 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2013-04-18 14:04 - 2012-12-19 07:41 - 00194488 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2013-04-12 01:13 - 2013-04-12 11:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-04-12 00:57 - 2013-04-12 00:58 - 00000000 ____D C:\Users\Staffan\Desktop\Mutant Karaktarer
2013-04-10 13:55 - 2013-02-21 12:30 - 01766912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-04-10 13:55 - 2013-02-21 12:30 - 01129984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 14323200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 13761024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 02046464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-04-10 13:55 - 2013-02-21 12:29 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-04-10 13:55 - 2013-02-21 12:15 - 02240512 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-04-10 13:55 - 2013-02-21 12:15 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-04-10 13:55 - 2013-02-21 12:14 - 19230208 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 02647040 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-04-10 13:55 - 2013-02-21 12:14 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-04-10 13:55 - 2013-02-19 14:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-04-10 13:55 - 2013-02-19 13:42 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-04-10 13:55 - 2013-02-19 13:10 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-04-10 13:55 - 2013-02-19 12:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-04-10 11:12 - 2013-03-19 08:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-04-10 11:12 - 2013-03-19 07:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2013-04-10 11:12 - 2013-03-19 07:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-04-10 11:12 - 2013-03-19 07:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-04-10 11:12 - 2013-03-19 06:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-04-10 11:12 - 2013-03-19 05:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe
2013-04-10 11:12 - 2013-03-01 05:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-04-10 11:12 - 2013-02-15 08:08 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-04-10 11:12 - 2013-02-15 08:06 - 03717632 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-04-10 11:12 - 2013-02-15 08:02 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-04-10 11:12 - 2013-02-15 06:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-04-10 11:12 - 2013-02-15 06:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-04-10 11:12 - 2013-02-15 05:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-04-10 11:12 - 2013-01-24 08:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys

==================== One Month Modified Files and Folders =======

2013-05-08 21:11 - 2013-05-08 21:11 - 00000000 ____D C:\FRST
2013-05-08 21:10 - 2013-05-08 21:10 - 01874958 ____A (Farbar) C:\Users\Staffan\Desktop\FRST64.exe
2013-05-08 14:03 - 2012-05-31 04:47 - 01166073 ____A C:\Windows\WindowsUpdate.log
2013-05-08 13:34 - 2013-05-04 16:21 - 00000996 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-08 13:21 - 2013-05-01 01:12 - 00000868 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-08 12:55 - 2013-05-08 12:55 - 00002745 ____A C:\Users\Staffan\Desktop\Lucky Star - genvag.lnk
2013-05-08 12:40 - 2012-06-04 12:25 - 00000000 ____D C:\Users\Staffan\Documents\Anki
2013-05-08 12:05 - 2013-01-11 23:16 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Skype
2013-05-08 11:44 - 2009-07-14 06:45 - 00022064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-08 11:44 - 2009-07-14 06:45 - 00022064 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-08 11:36 - 2012-05-31 01:06 - 00000000 ____D C:\Program Files (x86)\Steam
2013-05-08 11:28 - 2013-05-04 16:20 - 00000992 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-08 11:28 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-08 11:27 - 2012-05-31 00:06 - 00000000 ____D C:\ProgramData\NVIDIA
2013-05-08 11:27 - 2009-07-14 06:51 - 00051095 ____A C:\Windows\setupact.log
2013-05-07 13:45 - 2013-05-06 11:37 - 00000000 ____D C:\Users\Staffan\Desktop\Ny mapp (2)
2013-05-07 12:27 - 2013-05-07 12:27 - 00001069 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-05-07 12:27 - 2013-05-07 12:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-07 12:23 - 2010-11-21 05:47 - 00061698 ____A C:\Windows\PFRO.log
2013-05-07 12:20 - 2013-05-06 12:22 - 00019649 ____A C:\Users\Staffan\Desktop\Nytt textdokument.txt
2013-05-07 12:19 - 2013-05-07 12:19 - 00019649 ____A C:\ComboFix.txt
2013-05-07 12:19 - 2013-05-06 11:56 - 00000000 ____D C:\Qoobox
2013-05-07 12:15 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-05-07 11:56 - 2013-05-06 11:47 - 05066751 ____R (Swearware) C:\Users\Staffan\Desktop\ComboFix.exe
2013-05-06 12:17 - 2013-05-06 11:56 - 00000000 ____D C:\Windows\erdnt
2013-05-06 11:45 - 2013-05-05 19:53 - 00000000 ____D C:\Users\Staffan\Desktop\RK_Quarantine
2013-05-06 00:11 - 2012-06-04 01:31 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\vlc
2013-05-05 19:16 - 2013-05-05 19:16 - 00000188 ____A C:\Users\Staffan\defogger_reenable
2013-05-05 19:16 - 2012-05-30 22:49 - 00000000 ____D C:\users\Staffan
2013-05-05 19:12 - 2013-05-05 19:12 - 00050477 ____A C:\Users\Staffan\Desktop\Defogger.exe
2013-05-05 19:12 - 2013-05-05 19:11 - 00791040 ____A C:\Users\Staffan\Desktop\RogueKillerX64.exe
2013-05-05 11:38 - 2013-01-11 23:16 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-05-05 11:38 - 2013-01-11 23:15 - 00000000 ____D C:\ProgramData\Skype
2013-05-04 17:52 - 2013-05-03 12:47 - 00005044 ____A C:\Users\Staffan\Desktop\newer all sites.txt
2013-05-04 16:25 - 2012-05-31 00:44 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2013-05-04 16:22 - 2013-05-04 16:22 - 00002215 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-05-04 16:22 - 2013-05-04 16:19 - 00000000 ____D C:\Program Files (x86)\Google
2013-05-04 16:22 - 2012-06-03 14:57 - 00000000 ____D C:\Users\Staffan\AppData\Local\Google
2013-05-04 11:34 - 2013-05-04 11:34 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\SUPERAntiSpyware.com
2013-05-04 11:34 - 2013-05-04 11:32 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-05-04 11:32 - 2013-05-04 11:32 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-05-04 11:32 - 2013-05-04 11:32 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-05-03 13:15 - 2013-05-03 13:15 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Malwarebytes
2013-05-03 13:15 - 2013-05-03 13:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-05-02 20:56 - 2013-05-02 20:56 - 00002052 ____A C:\Windows\epplauncher.mif
2013-05-02 17:44 - 2013-03-19 22:49 - 00189936 ____A C:\Windows\System32\Drivers\aswVmm.sys
2013-05-02 02:06 - 2010-11-21 05:27 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2013-05-02 01:34 - 2013-03-19 22:49 - 00065336 ____A C:\Windows\System32\Drivers\aswRvrt.sys
2013-05-02 01:34 - 2012-05-31 00:48 - 00270824 ____A (AVAST Software) C:\Windows\System32\Drivers\aswNdis2.sys
2013-05-02 01:34 - 2012-05-31 00:48 - 00131232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFW.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 01025808 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00378432 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00080816 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00072016 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00064288 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00033400 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-05-02 01:34 - 2012-05-31 00:44 - 00022600 ____A (AVAST Software) C:\Windows\System32\Drivers\aswKbd.sys
2013-05-02 01:33 - 2012-05-31 00:44 - 00287840 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-05-02 01:33 - 2012-05-31 00:43 - 00041664 ____A (AVAST Software) C:\Windows\avastSS.scr
2013-05-01 22:06 - 2013-05-01 22:06 - 00001196 ____A C:\Users\Staffan\Desktop\Neverwinter.lnk
2013-05-01 22:00 - 2012-06-01 18:47 - 01087605 ____A C:\Windows\DirectX.log
2013-05-01 16:58 - 2013-05-01 01:12 - 00691592 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-05-01 16:58 - 2013-05-01 01:12 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-05-01 00:51 - 2012-05-31 03:08 - 00000000 ____D C:\ProgramData\Adobe
2013-05-01 00:39 - 2013-05-01 00:39 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-05-01 00:39 - 2013-05-01 00:39 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-05-01 00:39 - 2012-06-19 13:13 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-05-01 00:39 - 2012-06-19 13:13 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-04-30 23:30 - 2013-03-31 22:12 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2013-04-30 23:16 - 2012-05-31 00:25 - 00000000 ____D C:\Program Files (x86)\Intel
2013-04-30 23:12 - 2012-05-31 00:27 - 00000000 ____D C:\ProgramData\Intel
2013-04-30 23:11 - 2013-03-08 00:41 - 00000000 ____D C:\Fraps
2013-04-30 21:52 - 2013-04-29 01:23 - 01092512 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-04-30 21:52 - 2013-04-29 01:23 - 00971680 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-04-30 02:26 - 2013-04-05 21:10 - 00000000 ____D C:\Joymax
2013-04-28 20:54 - 2013-04-28 20:53 - 00004010 ____A C:\Windows\SysWOW64\jupdate-1.7.0_21-b11.log
2013-04-28 20:54 - 2013-03-24 16:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-04-28 20:48 - 2013-04-28 20:48 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Oracle
2013-04-27 23:36 - 2012-06-01 18:48 - 00000000 ____D C:\Users\Staffan\Documents\My Games
2013-04-27 22:59 - 2012-08-10 23:07 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2013-04-27 22:51 - 2013-04-27 22:51 - 00001993 ____A C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
2013-04-27 22:51 - 2013-04-27 22:51 - 00001984 ____A C:\Users\Public\Desktop\Smite.lnk
2013-04-25 01:58 - 2013-04-25 01:58 - 00001026 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-04-25 01:58 - 2012-06-04 01:31 - 00000027 ____A C:\Program Files\plugins.dat
2013-04-25 01:57 - 2013-04-25 01:57 - 00001687 ____A C:\Users\Public\Desktop\Planescape Torment.lnk
2013-04-25 01:56 - 2013-02-02 01:46 - 00000000 ____D C:\GOG Games
2013-04-23 00:18 - 2013-02-15 13:16 - 00000000 ____D C:\Users\Staffan\Desktop\Feed the Beast
2013-04-22 12:33 - 2012-09-19 12:54 - 00000000 ____D C:\Users\Staffan\AppData\Local\Audible
2013-04-20 22:15 - 2011-04-12 16:28 - 00653330 ____A C:\Windows\System32\perfh01D.dat
2013-04-20 22:15 - 2011-04-12 16:28 - 00141150 ____A C:\Windows\System32\perfc01D.dat
2013-04-20 22:15 - 2009-07-14 07:13 - 01573176 ____A C:\Windows\System32\PerfStringBackup.INI
2013-04-20 21:12 - 2013-04-20 19:05 - 00000000 ____D C:\Users\Staffan\AppData\Local\Warframe
2013-04-18 14:06 - 2012-05-31 00:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-04-17 13:25 - 2013-02-07 20:49 - 00009395 ____A C:\Users\Staffan\Desktop\MAA.txt
2013-04-14 01:59 - 2012-09-29 23:32 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Awesomium
2013-04-14 01:53 - 2013-03-16 02:16 - 00001901 ____A C:\Users\Public\Desktop\Marvel Heroes Beta.lnk
2013-04-13 03:01 - 2012-05-31 00:03 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-04-12 23:48 - 2012-07-08 11:48 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\dvdcss
2013-04-12 22:24 - 2009-07-14 07:08 - 00032514 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-04-12 22:23 - 2012-05-31 00:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-04-12 16:45 - 2013-04-24 11:30 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-04-12 11:01 - 2013-04-12 01:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-04-12 00:58 - 2013-04-12 00:57 - 00000000 ____D C:\Users\Staffan\Desktop\Mutant Karaktarer
2013-04-10 21:35 - 2009-07-14 06:45 - 00295832 ____A C:\Windows\System32\FNTCACHE.DAT
2013-04-10 13:57 - 2012-06-02 01:38 - 72702784 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-04-10 02:58 - 2012-10-23 01:24 - 00000000 ____D C:\Users\Staffan\AppData\Roaming\Azureus
2013-04-09 13:59 - 2013-03-05 03:12 - 00001650 ____A C:\Users\Staffan\Desktop\Marvel Super Heroes - genvag.lnk

Other Malware:
===========
C:\ProgramData\hash.dat

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


Last Boot: 2013-05-05 16:09

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-05-2013
Ran by [removed] at 2013-05-08 21:13:09 Run:
Running from C:\Users\[removed]\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Installed Programs =======================

7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Flash Player 11 Plugin (Version: 11.7.700.169)
Adobe Reader X (10.1.6) - Svenska (Version: 10.1.6)
Anki
Antichamber
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Apple-programstod (Version: 2.3.3)
ASUS nVidia Driver (Version: 1.00.0000)
Audacity 2.0.2 (Version: 2.0.2)
AudibleManager (Version: 2005941486.48.56.39261426)
Autodesk Softimage Mod Tool 7.5 (Version: 1.00.0000)
avast! Internet Security (Version: 8.0.1488.0)
Awesomenauts
BankID sakerhetsprogram (Version: 4.19.1)
Beneath a Steel Sky (Version: 2.0.0.9)
Black & White Creature Isle
Black & Whiteョ 2 (Version: 1.00.0000)
Black and White
Blacklight: Retribution
Blood Bowl: Chaos Edition
Blood Bowl: Legendary Edition
Bonjour (Version: 3.0.0.10)
Borderlands
Botanicula
Breath of Death VII
Brutal Legend
CDisplay 1.8
Chantelise
Chivalry: Medieval Warfare
Cisco Connect (Version: 1.4.11299.0)
Cole2k Media - Codec Pack (Advanced) 8.0.1
Combined Community Codec Pack 2011-11-11 (Version: 2011.11.11.0)
Consolas Font Family (Version: 1.00.0000)
Constructor
D3DX10 (Version: 15.4.2368.0902)
DAEMON Tools Lite (Version: 4.45.4.0315)
Dark Souls: Prepare to Die Edition
Darksiders 2 - Prima Guide
Darksiders II
DeathSpank
Deponia
Diablo II
Dota 2
Dungeon Keeper (Version: 2.0.0.2)
Dungeon Keeper 2 (Version: 2.0.0.32)
erLT (Version: 1.20.0137)
Fallout (Version: 2.0.0.14)
Fortune Summoners: Secret of the Elemental Stone
Freedom Force
FTL: Faster Than Light
GOG.com Dungeon Keeper 2
GOG.com Planescape Torment
Google Chrome (Version: 26.0.1410.64)
Google Talk (remove only)
Google Update Helper (Version: 1.3.21.135)
Handelsbanken kortlasare (Version: 1.00.0000)
Hell Yeah!
Hi-Rez Studios Authenticate and Update Service (Version: 3.0.0.0)
Intel® USB 3.0 eXtensible Host Controller Driver (Version: 1.0.1.209)
IntelR Trusted Connect Service Client (Version: 1.23.605.1)
iTunes (Version: 11.0.2.26)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Junk Mail filter update (Version: 15.4.3502.0922)
Krater
L.A. Noire
LAME v3.99.3 (for Windows)
League of Legends (Version: 1.3)
Logitech SetPoint 5.20 (Version: 5.20)
Machinarium
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Mark of the Ninja
Marvel Heroes (Version: 1.8.0.514)
Mass Effect
Mass Effect 2
Mass Effect? 3 (Version: 1.05.0.0)
McPixel
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile Language Pack - SVE (Version: 4.0.30320)
Microsoft .NET Framework 4 Client Profile SVE Language Pack (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (Version: 3.5.30730.0)
Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (Version: 3.5.50.0)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (Version: 11.0.51106.1)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (Version: 11.0.51106)
Microsoft XNA Framework Redistributable 4.0 (Version: 4.0.20823.0)
Microsoft XNA Framework Redistributable 4.0 Refresh (Version: 4.0.30901.0)
Mob Rule
Mozilla Firefox 20.0.1 (x86 en-US) (Version: 20.0.1)
Mozilla Maintenance Service (Version: 20.0.1)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
Neverwinter
NVIDIA 3D Vision Controller Driver (Version: 267.67)
NVIDIA 3D Vision drivrutin 314.22 (Version: 314.22)
NVIDIA 3D Vision drivrutin for styrenhet 314.22 (Version: 314.22)
NVIDIA Grafikdrivrutin 314.22 (Version: 314.22)
NVIDIA HD audiodrivrutin [removed] (Version: 1.3.23.1)
NVIDIA Install Application (Version: 2.1002.115.743)
NVIDIA PhysX (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1422)
NVIDIA Update Components (Version: 1.12.12)
NVIDIAs kontrollpanel 314.22 (Version: 314.22)
NVIDIA-uppdatering 1.12.12 (Version: 1.12.12)
OpenOffice.org 3.4 (Version: 3.4.9590)
Origin (Version: 8.6.0.357)
PDF-Viewer (Version: 2.5.208.0)
Planescape Torment (Version: 2.0.0.8)
PlanetSide 2
Realtek Ethernet Controller Driver (Version: 7.49.927.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.6526)
Recettear: An Item Shop's Tale
Rochard
Samsung Kies (Version: 2.5.2.13021_10)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.22.0)
Skype? 6.3 (Version: 6.3.105)
Smite (Version: 0.1.1491.3)
Source Filmmaker
Space Pirates and Zombies
Star Conflict
Star Wars™: Knights of the Old Republic ™
Steam (Version: 1.0.0.0)
SUPERAntiSpyware (Version: 5.6.1014)
Superbrothers: Sword & Sworcery EP
Swiff Player 1.7.2 (Version: 1.7.2)
Syndicate (Version: 2.0.0.11)
Team Fortress 2
Terraria
The Bard's Tale
The Elder Scrolls V: Skyrim
The Walking Dead (Version: 1.0.0.15)
Theme Hospital
Thief Gold
TigerGame PS/PS2 Game Controller Adapter series to pc USB Drive
To the Moon
Torchlight II
Transformers: Fall of Cybertron
Tribes: Ascend
Unmechanical
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Utility (Version: 1.00.0002)
Warframe
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Wizorb
VLC media player 2.0.6 (Version: 2.0.6)
Vuze (Version: 4.9.0.0)
Xiph.Org Open Codecs 0.85.17777 (Version: 0.85.17777)
XviD MPEG-4 Video Codec

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============

Name: avast! Network Shield Support
Description: avast! Network Shield Support
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswTdi
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: aswVmm
Description: aswVmm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswVmm
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: aswRvrt
Description: aswRvrt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswRvrt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/08/2013 09:10:45 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext for C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 pa rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begars av programmet star i konflikt med en annan komponentversion som redan ar aktiv.
Foljande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/08/2013 09:09:00 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2013 00:13:23 PM) (Source: Application Error) (User: )
Description: Felet uppstod i programmet med namn: plugin-container.exe, version 20.0.1.4847, tidsstampel 0x51650a74
, felet uppstod i modulen med namn: NPSWF32_11_7_700_169.dll, version 11.7.700.169, tidsstampel 0x5155fd7e
Undantagskod: 0x80000003
Felforskjutning: 0x0034621d
Process-ID: 0xd5c
Programmets starttid: 0xplugin-container.exe0
Sokvag till program: plugin-container.exe1
Sokvag till modul: plugin-container.exe2
Rapport-ID: plugin-container.exe3

Error: (05/08/2013 11:29:27 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2013 00:45:41 AM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext for C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 pa rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begars av programmet star i konflikt med en annan komponentversion som redan ar aktiv.
Foljande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/07/2013 09:39:39 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/07/2013 05:14:17 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Tjansten Cryptographic Services kunde inte initiera System Writer-objektet for VSS-sakerhetskopiering.


Details:
Could not query the status of the EventSystem service.

System Error:
Systemet haller pa att avslutas.
.

Error: (05/07/2013 05:09:37 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext for C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 pa rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begars av programmet star i konflikt med en annan komponentversion som redan ar aktiv.
Foljande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/07/2013 05:09:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/07/2013 00:37:18 PM) (Source: SideBySide) (User: )
Description: Det gick inte att skapa aktiveringskontext for C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1. Det finns ett fel i manifest- eller principfilen C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 pa rad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
En komponentversion som begars av programmet star i konflikt med en annan komponentversion som redan ar aktiv.
Foljande komponenter orsakar konflikten:
Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (05/08/2013 09:10:40 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:10:40 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:10:40 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:10:40 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:09:58 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:09:58 PM) (Source: Service Control Manager) (User: )
Description: Tjansten Computer Browser ar beroende av tjansten Server. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:08:56 PM) (Source: Service Control Manager) (User: )
Description: Tjansten HomeGroup Provider ar beroende av tjansten Function Discovery Provider Host. Den sistnamnda kunde inte starta pa grund av foljande fel:
%%1068

Error: (05/08/2013 09:08:55 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (05/08/2013 09:08:55 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (05/08/2013 09:08:23 PM) (Source: atapi) (User: )
Description: Drivrutinen hittade ett styrenhetsfel pa \Device\Ide\IdePort0.


Microsoft Office Sessions:
=========================
Error: (05/08/2013 09:10:45 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Staffan\Desktop\Downloads\esetsmartinstaller_enu.exe

Error: (05/08/2013 09:09:00 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2013 00:13:23 PM) (Source: Application Error)(User: )
Description: plugin-container.exe20.0.1.484751650a74NPSWF32_11_7_700_169.dll11.7.700.1695155fd7e8000
00030034621dd5c01ce4bd48f39634aC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dlle9c5c58f-b7c7-11e2-9cb1-10bf4882be72

Error: (05/08/2013 11:29:27 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2013 00:45:41 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Staffan\Desktop\Downloads\esetsmartinstaller_enu.exe

Error: (05/07/2013 09:39:39 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/07/2013 05:14:17 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
Could not query the status of the EventSystem service.

System Error:
Systemet haller pa att avslutas.

Error: (05/07/2013 05:09:37 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Staffan\Desktop\Downloads\esetsmartinstaller_enu.exe

Error: (05/07/2013 05:09:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/07/2013 00:37:18 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Staffan\Desktop\Downloads\esetsmartinstaller_enu.exe


CodeIntegrity Errors:
===================================
Date: 2013-05-06 12:12:51.872
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-05-06 12:12:51.826
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Percentage of memory in use: 11%
Total physical RAM: 8147.59 MB
Available physical RAM: 7208.55 MB
Total Pagefile: 16293.36 MB
Available Pagefile: 15393.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:1862.92 GB) (Free:475.15 GB) NTFS (Disk=0 Partition=2)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 21C19C15)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=-198731366400) - (Type=07 NTFS)

==================== End Of Log ============================
Hi Dontest,

You can perform this step Safe Mode if necessary.

System File Checker (SFC)
  • Click on the Start button and in the Search programs and files box type the following:

    • command
  • Don't press Enter, just let the search results populate above.
  • In the search results, locate the Programs section.
  • Locate the Command Prompt shortcut and right-click on it.
  • Select Run as administrator.
  • Click Yes on the User Account Control window that appears.
  • Important: If you are see a User Account Control window but also a message that says To continue, type an administrator password, and then click Yes, then your user account must be a standard account, not an administrator account. Before you can click Yes and open an elevated command prompt, you'll need to type the password of another user on your Windows 7 computer that has administrator level privileges.
  • Note: You will not see this window at all if your User Account Control settings are turned all the way down. See How To Disable User Account Control in Windows 7 for more information.
  • An elevated Command Prompt window will appear.

    • Type: sfc /scannow (There's a space between sfc and /scannow.)
  • Type: exit to close the command prompt window
  • Include the findings in your next reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI