This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32.downloader.gen [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 2013-06-24 12:13:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

5,96 Gb Total Physical Memory | 4,11 Gb Available Physical Memory | 68,98% Memory free
11,92 Gb Paging File | 9,65 Gb Available in Paging File | 80,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59,53 Gb Total Space | 0,61 Gb Free Space | 1,02% Space Free | Partition Type: NTFS
Drive D: | 7,35 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 931,50 Gb Total Space | 65,15 Gb Free Space | 6,99% Space Free | Partition Type: NTFS
Drive F: | 200,00 Gb Total Space | 121,08 Gb Free Space | 60,54% Space Free | Partition Type: NTFS
Drive G: | 729,50 Gb Total Space | 416,27 Gb Free Space | 57,06% Space Free | Partition Type: NTFS

Computer Name: KEVIN-DATOR | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kevin\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Kevin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
MOD - C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\libglesv2.dll ()
MOD - C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\libegl.dll ()
MOD - C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\019ed4a55ecc7d1f5b933c27970dce9b\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\2609614ca03927f7a99418c74844059b\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8732d692f02402dbd81280b0d3c4f6a9\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a9594959e951127f16eb49644ba92f79\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\7cfbbd029ef945fbcdaedd24b2b67a24\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\153143f74d840484b510d8cf5187796b\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\af18b8a8f56494da44cc448f3b9704a5\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\233661f3a2b632e9553915c8639637d0\System.Configuration.ni.dll ()
MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ac9e3eca6c148504588e7c6d09fe83e3\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\a1b65a602c75409c0c1ce7fa1f2a0983\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\e290208a6d4ea4451ac118f1e0c3b488\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\dfeff31ab1e7cd3480c8942290c92f5d\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (NisSrv) – C:\Program\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (rzudd) – C:\Windows\SysNative\drivers\rzudd.sys (Razer Inc)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Tdsshbecr) – C:\Windows\SysNative\drivers\shbecr.sys (Todos Data System AB)
DRV:64bit: - (Lycosa) – C:\Windows\SysNative\drivers\Lycosa.sys (Razer USA Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv-SE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 89 FB 6A 0C 91 05 CE 01 [binary data]
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{F5BBAAEC-843D-4935-952F-2936997D61CF}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Kevin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Kevin\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Kevin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Kevin\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Kevin\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)


[2012-08-17 14:49:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Kevin\AppData\Roaming\mozilla\Firefox\extensions
[2012-08-17 14:49:08 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\Kevin\AppData\Roaming\mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kevin\AppData\Local\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Nexus Personal (Enabled) = C:\Program Files (x86)\Personal\bin\np_prsnl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Kevin\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - Extension: Google Dokument = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4.1_0\
CHR - Extension: S\u00F6k p\u00E5 Google = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: uTorrentControl_v2 = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.16.2.509_0\
CHR - Extension: AdBlock = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.65_0\
CHR - Extension: Skype Click to Call = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\
CHR - Extension: Gmail = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013-01-19 04:28:09 | 000,445,399 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15295 more lines…
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Spotify] C:\Users\Kevin\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Kevin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4316B63E-ED38-43C1-ADCE-27F98B6E6715}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D78A1F61-4379-4A7C-9E08-A2010C53D59E}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.MP42 - C:\Windows\SysWow64\MPG4C32.dll (Microsoft Corporation)
Drivers32: vidc.MP43 - C:\Windows\SysWow64\MPG4C32.dll (Microsoft Corporation)
Drivers32: vidc.MPG4 - C:\Windows\SysWow64\MPG4C32.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013-06-24 11:47:59 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Malwarebytes
[2013-06-24 11:47:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013-06-24 11:47:37 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013-06-24 11:47:36 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013-06-24 11:47:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013-06-24 11:47:07 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\Programs
[2013-06-23 10:25:15 | 000,000,000 | —D | C] – C:\Users\Kevin\Desktop\Ny mapp
[2013-06-22 15:57:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit

========== Files - Modified Within 30 Days ==========

[2013-06-24 12:13:13 | 000,015,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-06-24 12:13:13 | 000,015,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-06-24 12:07:00 | 000,001,004 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1085837106-2852207436-3906323347-1001UA.job
[2013-06-24 11:47:42 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-06-24 11:38:00 | 000,000,868 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-06-24 10:36:40 | 001,574,032 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013-06-24 10:36:40 | 000,661,706 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2013-06-24 10:36:40 | 000,652,150 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013-06-24 10:36:40 | 000,141,508 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2013-06-24 10:36:40 | 000,121,082 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013-06-24 10:31:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013-06-21 20:07:00 | 000,000,952 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1085837106-2852207436-3906323347-1001Core.job
[2013-06-05 12:48:50 | 000,101,973 | —- | M] () – C:\Users\Kevin\Desktop\aabra.png
[2013-05-26 09:41:28 | 015,302,656 | —- | M] () – C:\Users\Kevin\Desktop\DSC01962.ARW
[2013-05-26 09:41:12 | 015,302,656 | —- | M] () – C:\Users\Kevin\Desktop\DSC01961.ARW
[2013-05-26 09:40:50 | 015,302,656 | —- | M] () – C:\Users\Kevin\Desktop\DSC01960.ARW

========== Files Created - No Company Name ==========

[2013-06-24 11:47:42 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-06-05 12:48:50 | 000,101,973 | —- | C] () – C:\Users\Kevin\Desktop\aabra.png
[2013-05-26 22:38:38 | 015,302,656 | —- | C] () – C:\Users\Kevin\Desktop\DSC01961.ARW
[2013-05-26 22:38:37 | 015,302,656 | —- | C] () – C:\Users\Kevin\Desktop\DSC01962.ARW
[2013-05-26 22:38:36 | 015,302,656 | —- | C] () – C:\Users\Kevin\Desktop\DSC01960.ARW
[2013-05-17 01:06:53 | 000,007,597 | —- | C] () – C:\Users\Kevin\AppData\Local\Resmon.ResmonCfg
[2013-04-06 15:58:17 | 001,551,882 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012-10-23 21:11:58 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012-08-17 16:28:31 | 000,000,027 | —- | C] () – C:\Program Files\plugins.dat
[2012-08-08 01:08:13 | 002,609,266 | —- | C] () – C:\Users\Kevin\fraps_3.4.7_registered%5BA4%5D.zip
[2011-12-15 06:23:04 | 010,920,472 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011-12-15 06:23:04 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011-12-15 06:23:04 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013-02-27 07:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013-02-27 06:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009-07-14 03:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010-11-20 14:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009-07-14 03:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009-07-14 09:42:52 | 000,003,783 | —- | M] () MD5=492CBE676A49756494ABAD49712DD36C – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_64117362cc347f06\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009-06-10 22:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011-02-26 08:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011-02-26 07:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009-07-14 03:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011-02-26 07:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009-10-31 07:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011-02-26 07:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011-02-25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011-02-25 08:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011-02-26 08:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010-11-20 14:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009-08-03 08:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011-02-25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011-02-25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009-10-31 08:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009-08-03 07:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010-11-20 15:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009-10-31 08:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009-08-03 07:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009-07-14 03:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009-10-31 08:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011-02-26 08:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009-08-03 08:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009-07-14 09:42:08 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\SysWOW64\sv-SE\explorer.exe.mui
[2009-07-14 09:42:08 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=B75E618BE78589FCF4992DBEF8E2EB75 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_5158254009e19998\explorer.exe.mui
[2009-07-14 09:42:23 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\sv-SE\explorer.exe.mui
[2009-07-14 09:42:23 | 000,023,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_47037aedd580d79d\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012-06-02 13:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013-01-09 03:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012-07-09 18:04:34 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2013-05-17 04:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013-05-17 04:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012-11-14 04:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012-06-29 07:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012-08-24 09:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012-04-20 07:08:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=27019747D97AB5CEFB97677DBB5CF577 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_1a11a2ba7297e4ee\iexplore.exe
[2012-10-08 10:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013-04-06 03:00:57 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013-02-25 02:58:09 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2009-07-14 03:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012-08-24 13:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013-04-05 07:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2012-06-02 11:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013-05-17 03:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2012-04-20 06:53:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=4866404D6657D6E50619CCAF56B17D27 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_1a3bf0cd8bfcb2df\iexplore.exe
[2012-10-08 14:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012-07-09 18:04:34 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012-08-24 12:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012-06-29 04:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012-06-02 14:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012-08-24 09:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013-02-21 14:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013-04-06 03:00:56 | 000,775,184 | —- | M] (Microsoft Corporation) MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013-01-09 00:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013-02-02 10:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010-11-20 15:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013-05-17 05:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2012-06-29 03:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013-02-25 01:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013-02-02 06:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013-02-02 09:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013-04-05 08:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012-11-16 05:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013-04-04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012-06-02 10:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010-11-20 14:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013-04-05 09:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012-10-08 10:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012-04-20 08:26:39 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=D889681C78E7BFE45587398AC42FC2D4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_0fbcf8683e3722f3\iexplore.exe
[2013-02-02 06:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013-04-05 09:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013-02-21 13:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2012-06-29 01:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013-05-17 05:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Program Files\Internet Explorer\iexplore.exe
[2013-05-17 05:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013-01-09 02:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013-01-08 23:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012-04-20 08:13:05 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=F293ACB373FD8F090E08F183C06E07ED – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_0fe7467b579bf0e4\iexplore.exe
[2009-07-14 03:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012-10-08 13:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012-11-14 04:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012-11-14 09:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012-07-09 18:04:34 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012-07-09 18:04:34 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013-04-06 03:02:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6374594310EBAC7C83B9819D1AFCD77D – C:\Program Files (x86)\Internet Explorer\sv-SE\iexplore.exe.mui
[2013-04-06 03:02:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6374594310EBAC7C83B9819D1AFCD77D – C:\Program Files\Internet Explorer\sv-SE\iexplore.exe.mui
[2013-04-06 03:02:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6374594310EBAC7C83B9819D1AFCD77D – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_sv-se_f5588d8e9e14ac80\iexplore.exe.mui
[2013-04-06 03:02:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6374594310EBAC7C83B9819D1AFCD77D – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_sv-se_ffad37e0d2756e7b\iexplore.exe.mui
[2009-07-14 09:42:52 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=818C0D82C249F80EDB0C6FA5F06859F4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_sv-se_ee2e2cd8be540de1\iexplore.exe.mui
[2009-07-14 09:42:52 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=818C0D82C249F80EDB0C6FA5F06859F4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_f05f40a0bb42917b\iexplore.exe.mui
[2012-07-09 18:05:02 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_f671dc8e34a59363\iexplore.exe.mui
[2013-04-06 03:00:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013-04-06 03:00:56 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013-04-06 03:00:56 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013-04-06 03:00:57 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2012-07-09 18:05:02 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_ec1d323c0044d168\iexplore.exe.mui
[2009-07-14 09:42:52 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FCF681AEB95697B5E01832E11732A6CD – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_sv-se_f882d72af2b4cfdc\iexplore.exe.mui
[2009-07-14 09:42:52 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FCF681AEB95697B5E01832E11732A6CD – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_sv-se_fab3eaf2efa35376\iexplore.exe.mui

< MD5 for: SERVICES >
[2009-06-10 23:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012-09-23 21:43:48 | 000,002,556 | —- | M] () MD5=3BE849A0D8DEEF6E14BEC19D565A965D – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Locale\sv_SE\Services\Services.asfx

< MD5 for: SERVICES.CFG >
[2012-09-23 21:43:36 | 000,603,848 | —- | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009-07-14 03:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009-07-14 09:42:16 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysNative\sv-SE\services.exe.mui
[2009-07-14 09:42:16 | 000,017,408 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_ab0e3ae787d43a6a\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009-07-14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009-07-14 06:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009-06-10 22:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009-07-14 09:42:12 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysNative\sv-SE\services.msc
[2009-07-14 09:42:17 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\SysWOW64\sv-SE\services.msc
[2009-07-14 09:42:12 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_e5500ad35e3dd45d\services.msc
[2009-07-14 09:42:17 | 000,092,744 | —- | M] () MD5=6DCF2D33F252AA7C694AFE0848D9F066 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_89316f4fa5e06327\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009-06-10 22:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009-06-10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009-07-13 22:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011-03-01 09:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2009-07-14 09:42:51 | 000,008,194 | —- | M] () MD5=50E49C8E1C9BAD7D7C84DF88A7AC4A41 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_d61505583ec10672\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009-06-10 23:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010-11-20 15:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010-11-20 15:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009-07-14 03:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009-10-28 09:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013-04-04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009-10-28 08:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2009-07-14 09:42:12 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=75FBA7C3BF9347F046870F4294079762 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_0c09855b65f57ee3\winlogon.exe.mui
[2010-11-20 15:36:15 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\SysNative\sv-SE\winlogon.exe.mui
[2010-11-20 15:36:15 | 000,023,552 | —- | M] (Microsoft Corporation) MD5=DA6129CA3B94E2B2A63F8C3B0FBA113B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_sv-se_0e3a992362e4027d\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009-07-14 09:42:16 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\SysNative\wbem\sv-SE\winlogon.mfl
[2009-07-14 09:42:16 | 000,001,080 | —- | M] () MD5=73BBDA93166AB1E88878F6EB1F0F8511 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_sv-se_69cbd726812dd878\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009-07-13 22:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >

< %systemroot%\Fonts\*.com >
[2009-07-14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009-07-14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volymen i enhet C har ingen etikett.
Volymens serienummer „r E014-9A95
Inneh†ll i katalogen C:\
2009-07-14 07:08 Documents and Settings [C:\Users]
2012-07-09 17:20 Program [C:\Program Files]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Program Files
2012-07-09 17:20 Delade filer [C:\Program Files\Common Files]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Program Files\Windows NT
2012-07-09 17:20 Tillbeh”r [C:\Program Files\Windows NT\Accessories]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\ProgramData
2009-07-14 07:08 Application Data [C:\ProgramData]
2009-07-14 07:08 Desktop [C:\Users\Public\Desktop]
2009-07-14 07:08 Documents [C:\Users\Public\Documents]
2012-07-09 17:20 Dokument [C:\Users\Public\Documents]
2012-07-09 17:20 Favoriter [C:\Users\Public\Favorites]
2009-07-14 07:08 Favorites [C:\Users\Public\Favorites]
2012-07-09 17:20 Mallar [C:\ProgramData\Microsoft\Windows\Templates]
2012-07-09 17:20 Programdata [C:\ProgramData]
2012-07-09 17:20 Skrivbord [C:\Users\Public\Desktop]
2009-07-14 07:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
2012-07-09 17:20 Start-meny [C:\ProgramData\Microsoft\Windows\Start Menu]
2009-07-14 07:08 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\ProgramData\Microsoft\Windows\Start Menu
2012-07-09 17:20 Program [C:\ProgramData\Microsoft\Windows\Start Menu\Programs]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users
2009-07-14 07:08 All Users [C:\ProgramData]
2009-07-14 07:08 Default User [C:\Users\Default]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\All Users
2009-07-14 07:08 Application Data [C:\ProgramData]
2009-07-14 07:08 Desktop [C:\Users\Public\Desktop]
2009-07-14 07:08 Documents [C:\Users\Public\Documents]
2012-07-09 17:20 Dokument [C:\Users\Public\Documents]
2012-07-09 17:20 Favoriter [C:\Users\Public\Favorites]
2009-07-14 07:08 Favorites [C:\Users\Public\Favorites]
2012-07-09 17:20 Mallar [C:\ProgramData\Microsoft\Windows\Templates]
2012-07-09 17:20 Programdata [C:\ProgramData]
2012-07-09 17:20 Skrivbord [C:\Users\Public\Desktop]
2009-07-14 07:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
2012-07-09 17:20 Start-meny [C:\ProgramData\Microsoft\Windows\Start Menu]
2009-07-14 07:08 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\All Users\Microsoft\Windows\Start Menu
2012-07-09 17:20 Program [C:\ProgramData\Microsoft\Windows\Start Menu\Programs]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Default
2009-07-14 07:08 Application Data [C:\Users\Default\AppData\Roaming]
2009-07-14 07:08 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
2009-07-14 07:08 Local Settings [C:\Users\Default\AppData\Local]
2012-07-09 17:20 Lokala inst„llningar [C:\Users\Default\AppData\Local]
2012-07-09 17:20 Mallar [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
2012-07-09 17:20 Mina dokument [C:\Users\Default\Documents]
2009-07-14 07:08 My Documents [C:\Users\Default\Documents]
2009-07-14 07:08 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
2012-07-09 17:20 N„tverket [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
2009-07-14 07:08 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
2012-07-09 17:20 Programdata [C:\Users\Default\AppData\Roaming]
2009-07-14 07:08 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
2009-07-14 07:08 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
2012-07-09 17:20 Skrivare [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
2009-07-14 07:08 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
2012-07-09 17:20 Start-meny [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
2009-07-14 07:08 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Default\AppData\Local
2009-07-14 07:08 Application Data [C:\Users\Default\AppData\Local]
2009-07-14 07:08 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
2012-07-09 17:20 Programdata [C:\Users\Default\AppData\Local]
2009-07-14 07:08 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
2012-07-09 17:20 Tidigare [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu
2012-07-09 17:20 Program [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Default\Documents
2012-07-09 17:20 Min musik [C:\Users\Default\Music]
2012-07-09 17:20 Mina bilder [C:\Users\Default\Pictures]
2012-07-09 17:20 Mina videoklipp [C:\Users\Default\Videos]
2009-07-14 07:08 My Music [C:\Users\Default\Music]
2009-07-14 07:08 My Pictures [C:\Users\Default\Pictures]
2009-07-14 07:08 My Videos [C:\Users\Default\Videos]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Kevin
2012-07-09 17:21 Cookies [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Cookies]
2012-07-09 17:21 Lokala inst„llningar [C:\Users\Kevin\AppData\Local]
2012-07-09 17:21 Mallar [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Templates]
2012-07-09 17:21 Mina dokument [C:\Users\Kevin\Documents]
2012-07-09 17:21 N„tverket [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
2012-07-09 17:21 Programdata [C:\Users\Kevin\AppData\Roaming]
2012-07-09 17:21 Recent [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Recent]
2012-07-09 17:21 SendTo [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\SendTo]
2012-07-09 17:21 Skrivare [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
2012-07-09 17:21 Start-meny [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Kevin\AppData\Local
2012-07-09 17:21 Programdata [C:\Users\Kevin\AppData\Local]
2012-07-09 17:21 Temporary Internet Files [C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
2012-07-09 17:21 Tidigare [C:\Users\Kevin\AppData\Local\Microsoft\Windows\History]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu
2012-07-09 17:21 Program [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Kevin\Documents
2012-07-09 17:21 Min musik [C:\Users\Kevin\Music]
2012-07-09 17:21 Mina bilder [C:\Users\Kevin\Pictures]
2012-07-09 17:21 Mina videoklipp [C:\Users\Kevin\Videos]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\Public\Documents
2012-07-09 17:20 Min musik [C:\Users\Public\Music]
2012-07-09 17:20 Mina bilder [C:\Users\Public\Pictures]
2012-07-09 17:20 Mina videoklipp [C:\Users\Public\Videos]
2009-07-14 07:08 My Music [C:\Users\Public\Music]
2009-07-14 07:08 My Pictures [C:\Users\Public\Pictures]
2009-07-14 07:08 My Videos [C:\Users\Public\Videos]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\UpdatusUser
2012-07-09 17:37 Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies]
2012-07-09 17:37 Lokala inst„llningar [C:\Users\UpdatusUser\AppData\Local]
2012-07-09 17:37 Mallar [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates]
2012-07-09 17:37 Mina dokument [C:\Users\UpdatusUser\Documents]
2012-07-09 17:37 N„tverket [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
2012-07-09 17:37 Programdata [C:\Users\UpdatusUser\AppData\Roaming]
2012-07-09 17:37 Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent]
2012-07-09 17:37 SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo]
2012-07-09 17:37 Skrivare [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
2012-07-09 17:37 Start-meny [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\UpdatusUser\AppData\Local
2012-07-09 17:37 Programdata [C:\Users\UpdatusUser\AppData\Local]
2012-07-09 17:37 Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
2012-07-09 17:37 Tidigare [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu
2012-07-09 17:37 Program [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs]
0 fil(er) 0 byte
Inneh†ll i katalogen C:\Users\UpdatusUser\Documents
2012-07-09 17:37 Min musik [C:\Users\UpdatusUser\Music]
2012-07-09 17:37 Mina bilder [C:\Users\UpdatusUser\Pictures]
2012-07-09 17:37 Mina videoklipp [C:\Users\UpdatusUser\Videos]
0 fil(er) 0 byte
Totalt antal filer:
0 fil(er) 0 byte
101 katalog(er) 316ÿ891ÿ136 byte ledigt

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-07-09 18:33:58 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013-01-11 02:43:29 | 000,272,896 | —- | M] () – C:\Users\Kevin\Desktop\SongParser.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


OTL Extras logfile created on: 2013-06-24 12:13:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

5,96 Gb Total Physical Memory | 4,11 Gb Available Physical Memory | 68,98% Memory free
11,92 Gb Paging File | 9,65 Gb Available in Paging File | 80,99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59,53 Gb Total Space | 0,61 Gb Free Space | 1,02% Space Free | Partition Type: NTFS
Drive D: | 7,35 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 931,50 Gb Total Space | 65,15 Gb Free Space | 6,99% Space Free | Partition Type: NTFS
Drive F: | 200,00 Gb Total Space | 121,08 Gb Free Space | 60,54% Space Free | Partition Type: NTFS
Drive G: | 729,50 Gb Total Space | 416,27 Gb Free Space | 57,06% Space Free | Partition Type: NTFS

Computer Name: KEVIN-DATOR | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02A5C873-ACA6-49EC-ABDB-63463B755224}" = lport=139 | protocol=6 | dir=in | app=system |
"{096FB44C-7B94-4328-AEE1-2E527F70D124}" = lport=138 | protocol=17 | dir=in | app=system |
"{1A1BBC4C-4154-4466-AEE3-414610820D3B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{254E8615-1CCD-44AA-A2A0-6127A5D01EC0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{37014DB3-33CC-4429-8188-662A41635E04}" = lport=137 | protocol=17 | dir=in | app=system |
"{45072B19-B006-4F56-A2A2-EB8407B40457}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5913156C-4E91-4B09-BEAA-26BBD7C28A74}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6329AD6F-ADD4-4ABD-8ABB-F0389F38796D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{65538650-924C-4574-A06E-A31C98A71BE7}" = rport=10243 | protocol=6 | dir=out | app=system |
"{7583AA97-BCB3-4EB8-915D-E84D6F422DFF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8DA4D792-943A-4116-A7AE-4359ECF4A009}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8EAFFE4D-4E88-432C-A396-9D351BAF6DC5}" = lport=445 | protocol=6 | dir=in | app=system |
"{979EA36D-3A35-4133-AD86-1E064E33214D}" = rport=138 | protocol=17 | dir=out | app=system |
"{9CA3092D-D3F9-4EB3-9C42-4A5584A9590E}" = rport=139 | protocol=6 | dir=out | app=system |
"{A6EE00FD-DF67-489D-90A2-423875DA15BB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A97A0CA7-B7D8-4C39-900E-7832326B3079}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ABBCD22C-4C13-4607-8961-1D3126C8B02F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B53EB493-B0C1-4E12-AE19-51374B907E3C}" = rport=445 | protocol=6 | dir=out | app=system |
"{CEECA395-209F-4C4F-85F4-AC35F53ECB47}" = rport=137 | protocol=17 | dir=out | app=system |
"{DB96B209-CF58-4011-A491-6D589E474B5E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EEE248A6-520F-44A4-869E-6B46ED256FC8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0377E397-26E3-4E3C-8EE6-4ACC7F2049FC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{094FEF90-F903-425F-B16D-9C756B0FC73B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{0B5624E4-74D2-4900-A143-B05A230BA4A2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{22BB14CF-2A34-4061-A3EA-7A4DB4C7003C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{28F815F0-3482-4164-A624-2E7243992831}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{2910642B-66E4-4F4A-9614-7BD1C3E9CD62}" = protocol=6 | dir=in | app=g:\steam\steam.exe |
"{29BA30FE-0934-4CCB-A499-4383701C088E}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{2BFF4E43-8434-41FF-8D7F-D49367EA69EC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{34C73C70-0262-48AF-96F5-6E2D1BE2D780}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |
"{3A2570E6-7C66-49CD-9DE5-0089A1C85B52}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3B980323-A9A4-4EBA-8371-BCD650F542FA}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3FE4568A-A41A-4944-8615-63344808841F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{40779607-0661-46D3-922F-60C0D101BF57}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{41C273BE-0645-4521-809B-8F71434AA7E4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{46E45693-BA9B-4B97-8096-52D9C79433EB}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{50C44C94-B77E-4A69-85D8-AC8F9981248D}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{53A6F1B1-C7E2-4777-B193-4ED8BAF2EA72}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{53DE3A77-6FE6-44AA-9895-68F9B82FE978}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{5466D963-F118-4BB8-9D70-4046D21C0851}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{5CCC4B63-9DF8-430E-94E4-214043A6312B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5F485894-2C74-40F1-8C1A-763189608AE8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5F8D926A-CDB9-466A-A8AF-368F1E3188DA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{60F0E2EC-C026-42EE-B813-15D8EF775356}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{61F8C574-17EB-479D-A57E-9EE38375453D}" = protocol=6 | dir=in | app=g:\maxpayne\playmaxpayne3.exe |
"{624CA3C9-562B-48E6-B793-8F285ABFBB35}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{642FBE76-5481-41B4-B88C-D3F9B35256C7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{66F7AEA4-38B3-4293-A21C-42925077CC79}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |
"{67269136-C66B-44A5-87F7-956EB9EC25C8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{6933B3B3-192A-4BED-9B00-A216138C5089}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{744DF2E1-C9DD-4BEA-A7DA-4B496EAB71E8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{74E950A5-B109-4B17-9CE7-E96FEC317871}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{7CF0ED16-1907-4A4D-A78B-531047A97A20}" = protocol=6 | dir=in | app=g:\steam\steamapps\bajen_92\counter-strike\hl.exe |
"{7D0F1D33-273D-4FFF-A8A8-C7C7B9356E16}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{83B29E99-02CC-4A5C-A928-29D20B88ADB4}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{89179CA2-38A1-4677-BCC2-98C52724A1C7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8BC34A19-1D92-401E-9A24-5473DF23F96E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8C36524B-8FDB-4665-9559-A20621AB6A0E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{9E2A44E3-4DEC-4E22-BC17-06CE89F6CE59}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9F6DED34-C925-4CFF-A8CB-C9D7D5949CB4}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{A185C900-573D-4092-BE55-C0E2DEE7132F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A3CAB948-8FD5-44BD-857C-D51DD67A82D2}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{A59C020B-B728-47D6-9867-6066E788F271}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{AE66E31A-0EF3-473B-AE12-0031D2D23FC0}" = protocol=17 | dir=in | app=g:\maxpayne\playmaxpayne3.exe |
"{B0BA6CD4-272D-4037-ABC8-7D31B693B301}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BD3A05B6-D495-48D8-B314-F39C7F9E2DD7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BD6DB5C5-8FF8-4143-823B-F29A9F0D48AE}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C05414C1-5B77-45AF-BDC7-49F4EA1D1D68}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{C1325040-731D-43BC-A70B-9ECA33EBC5EA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C30B5C7A-0955-4782-A70C-113CB457173E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C39221BA-5F66-402E-BB1E-C0647E42B2EC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D063A9EE-F4B5-4DC7-BD1F-4570F7357F6F}" = protocol=17 | dir=in | app=g:\steam\steamapps\bajen_92\counter-strike\hl.exe |
"{D34B1E1F-38D7-4834-9381-B2524DB6A527}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D59E00E7-E6E0-467C-9047-1EAF2BDC39F5}" = protocol=6 | dir=out | app=system |
"{D6DF0684-0AB6-47A6-82B2-7551CF9034D6}" = protocol=6 | dir=in | app=g:\steam\steamapps\common\half-life\hl.exe |
"{DBC09B29-E710-498C-A7CE-AEC1BEA6A3ED}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E92CA739-E752-4AA9-BF46-54BC0B805AE0}" = protocol=17 | dir=in | app=g:\steam\steamapps\common\half-life\hl.exe |
"{EBCBEE14-0D39-465D-AC83-6AB29374C1D9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EC14312C-E242-4687-9128-BF1FD7869F51}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EC4D146A-B48A-457E-A2C1-2646A45A0025}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{ED017D31-26F1-43D1-A2A7-1C9754521607}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{F311EA4A-6481-44C8-8671-029C2DA4BDBE}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{F34F5FBA-9B94-4379-8439-C93747C24E1B}" = protocol=17 | dir=in | app=g:\steam\steam.exe |
"{F454C274-DA76-4D8D-8822-88CE680116FE}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FDAF1B7D-B479-464A-BD78-F73C4218EECF}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{FEA96EDE-8739-42EF-9D86-5EE2DEB8FD89}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"TCP Query User{16C13B9B-F6E8-416D-B36A-AEF6AD314EB4}C:\users\kevin\downloads\neverwinter_nw.1.20130416a.6 (1).exe" = protocol=6 | dir=in | app=c:\users\kevin\downloads\neverwinter_nw.1.20130416a.6 (1).exe |
"TCP Query User{18B95D29-6605-4ECB-AA32-6B890F74E417}G:\maxpayne\maxpayne3.exe" = protocol=6 | dir=in | app=g:\maxpayne\maxpayne3.exe |
"TCP Query User{2F2D8A06-42FB-42B6-A83E-C46EBC34E717}C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"TCP Query User{405527AE-BBF5-45A9-9D90-5E29F48E1E87}C:\programdata\battle.net\agent\agent.524\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"TCP Query User{6D4C001E-6A99-422E-9E56-DA3C1F62E65D}G:\newerwinter\cryptic studios\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=g:\newerwinter\cryptic studios\neverwinter\live\gameclient.exe |
"TCP Query User{82564BEF-CC3C-4ACB-97E9-ABA9A1A6E275}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"TCP Query User{8AF0E4C5-818F-4D5B-8C61-83F90C3E11DB}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"TCP Query User{9516B2E1-FAE1-444D-9D7F-BE9C593CABAE}C:\users\kevin\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\kevin\appdata\roaming\spotify\spotify.exe |
"TCP Query User{A795AB0B-D633-46CA-9852-8D788EFD2E01}C:\users\kevin\desktop\quake iii arena\quake3\quake3.exe" = protocol=6 | dir=in | app=c:\users\kevin\desktop\quake iii arena\quake3\quake3.exe |
"TCP Query User{E9C544F4-2536-4F3E-A700-D7E606EE819F}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"TCP Query User{EB7DC8BC-5402-4F2B-B711-82192BB3C76E}C:\users\kevin\downloads\neverwinter_nw.1.20130416a.6.exe" = protocol=6 | dir=in | app=c:\users\kevin\downloads\neverwinter_nw.1.20130416a.6.exe |
"UDP Query User{1A067057-2DF8-4E37-A8A2-38C5E6353494}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe |
"UDP Query User{34B8A72A-9479-4F7F-8FB1-DF1A4AF96617}C:\users\kevin\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\kevin\appdata\roaming\spotify\spotify.exe |
"UDP Query User{4832BFBE-5B76-4B4C-B204-40B6F81CE921}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
"UDP Query User{93BE08E1-6F0A-4E61-8C7C-360CC1CB5779}C:\programdata\battle.net\agent\agent.524\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"UDP Query User{94F0A589-B4D0-4F00-A0EF-756762AF04A4}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |
"UDP Query User{A6241776-1546-4B39-A2DC-75B226E36FF2}G:\newerwinter\cryptic studios\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=g:\newerwinter\cryptic studios\neverwinter\live\gameclient.exe |
"UDP Query User{B09F80B0-D8EF-4EB4-9090-2E703E258B73}C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"UDP Query User{B5A63DA6-FCA4-4A32-A807-9697D624F4C5}G:\maxpayne\maxpayne3.exe" = protocol=17 | dir=in | app=g:\maxpayne\maxpayne3.exe |
"UDP Query User{B72A08F1-82EC-4492-A7E5-5EB330CE2246}C:\users\kevin\desktop\quake iii arena\quake3\quake3.exe" = protocol=17 | dir=in | app=c:\users\kevin\desktop\quake iii arena\quake3\quake3.exe |
"UDP Query User{D5960E4C-4ACA-47CB-85E2-3F9C134EFF80}C:\users\kevin\downloads\neverwinter_nw.1.20130416a.6.exe" = protocol=17 | dir=in | app=c:\users\kevin\downloads\neverwinter_nw.1.20130416a.6.exe |
"UDP Query User{E5CEA893-A698-4AC3-9811-7E9C5CE97C3D}C:\users\kevin\downloads\neverwinter_nw.1.20130416a.6 (1).exe" = protocol=17 | dir=in | app=c:\users\kevin\downloads\neverwinter_nw.1.20130416a.6 (1).exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6D8CEB72-EF89-3670-8133-966AF0CCDA86}" = Microsoft .NET Framework 4 Extended SVE Language Pack
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{96CC6DCC-8EBA-3F85-899B-933F599C4142}" = Microsoft .NET Framework 4 Client Profile SVE Language Pack
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision drivrutin 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIAs kontrollpanel 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafikdrivrutin 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision drivrutin för styrenhet 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX systemprogramvara 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA-uppdatering 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD audiodrivrutin 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile SVE Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - SVE
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended SVE Language Pack" = Microsoft .NET Framework 4 Extended Language Pack - SVE
"Microsoft Security Client" = Microsoft Security Essentials
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR 4.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{166FCF01-AC98-4288-A01C-90BEB808C059}" = Sony RAW Driver
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1AA94747-3BF6-4237-9E1A-7B3067738FE1}" = Max Payne 3
"{1C9F128C-F465-488E-AC97-B42DCF90C9C1}" = Mumble 1.2.3
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{27979F37-AF9C-33DE-8437-76F7AEFAABAD}" = Google Talk Plugin
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple-programstöd
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{8BD89760-6B5D-4A3C-8B0D-CDB93BEFC0F6}" = XSplit
"{929E7499-4B50-4C7A-8F15-D21E4061E046}" = BankID säkerhetsprogram
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{AC76BA86-7AD7-1053-7B44-AB0000000001}" = Adobe Reader XI - Svenska
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Fraps" = Fraps (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Neverwinter" = Neverwinter
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Rockstar Games Social Club" = Rockstar Games Social Club
"Steam App 10" = Counter-Strike
"uTorrent" = µTorrent
"uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar
"VLC media player" = VLC media player 2.0.3
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"optimizer_chrome" = Widevine Media Optimizer Chrome 6.0.0
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2013-06-21 15:56:30 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2012

Error - 2013-06-21 15:56:31 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2013-06-21 15:56:31 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3011

Error - 2013-06-21 15:56:31 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3011

Error - 2013-06-21 15:56:32 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2013-06-21 15:56:32 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4009

Error - 2013-06-21 15:56:32 | Computer Name = Kevin-Dator | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4009

Error - 2013-06-23 15:28:23 | Computer Name = Kevin-Dator | Source = Windows Backup | ID = 4104
Description =

Error - 2013-06-23 15:28:52 | Computer Name = Kevin-Dator | Source = Microsoft-Windows-Backup | ID = 517
Description = Säkerhetskopieringen som startades 2013-06-23T19:26:54.121540500Z
har misslyckats med felkoden 2155348000 (%%2155348000). En lösning finns i informationen
om händelsen. Kör säkerhetskopieringsåtgärden igen när problemet är löst.

Error - 2013-06-23 15:28:54 | Computer Name = Kevin-Dator | Source = Windows Backup | ID = 4104
Description =

[ System Events ]
Error - 2012-12-31 07:29:11 | Computer Name = Kevin-Dator | Source = bowser | ID = 8003
Description =

Error - 2012-12-31 14:34:19 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7038
Description = Tjänsten nvUpdatusService kunde inte logga in som .\UpdatusUser med
det för närvarande konfigurerade lösenordet på grund av följande fel: %%1330 Kontrollera
att tjänsten är korrekt konfigurerad med hjälp av snapin-modulen Tjänster i MMC
(Microsoft Management Console).

Error - 2012-12-31 14:34:19 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7000
Description = Tjänsten NVIDIA Update Service Daemon kunde inte startas på grund
av följande fel: %%1069

Error - 2012-12-31 15:31:40 | Computer Name = Kevin-Dator | Source = Microsoft-Windows-HAL | ID = 12
Description = Plattformens inbyggda programvara har skadat minne över det tidigare
systemenergilägesbytet. Sök efter uppdaterad programvara för datorn.

Error - 2012-12-31 19:13:02 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7009
Description = En timeout (30000 ms) inträffade vid väntan på att tjänsten Steam
Client Service skulle ansluta.

Error - 2012-12-31 19:13:02 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7000
Description = Tjänsten Steam Client Service kunde inte startas på grund av följande
fel: %%1053

Error - 2013-01-01 10:01:50 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7038
Description = Tjänsten nvUpdatusService kunde inte logga in som .\UpdatusUser med
det för närvarande konfigurerade lösenordet på grund av följande fel: %%1330 Kontrollera
att tjänsten är korrekt konfigurerad med hjälp av snapin-modulen Tjänster i MMC
(Microsoft Management Console).

Error - 2013-01-01 10:01:50 | Computer Name = Kevin-Dator | Source = Service Control Manager | ID = 7000
Description = Tjänsten NVIDIA Update Service Daemon kunde inte startas på grund
av följande fel: %%1069

Error - 2013-01-01 11:39:11 | Computer Name = Kevin-Dator | Source = Microsoft-Windows-HAL | ID = 12
Description = Plattformens inbyggda programvara har skadat minne över det tidigare
systemenergilägesbytet. Sök efter uppdaterad programvara för datorn.

Error - 2013-01-01 17:45:51 | Computer Name = Kevin-Dator | Source = bowser | ID = 8003
Description =


< End of report >
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
When I did the scan with GMER it gave me no results. It said " GMER hasn't found any system modification. Here is the file you wanted me to upload!
Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

F:\Users\Kevin\AppData\Local\Temp\AskSLib.dll a variant of Win32/Bundled.Toolbar.Ask application
F:\Users\Kevin\AppData\Local\Temp\ICReinstall\cnet_DTLite4402-0131_exe.exe a variant of Win32/InstallCore.D application
F:\Users\Kevin\AppData\Local\Temp\is1598539481\520496_Setup.DAT Win32/OpenCandy application
F:\Users\Kevin\AppData\Local\Temp\is1598539481\MyBabylonTB.exe a variant of Win32/Toolbar.Babylon.C application
F:\Users\Kevin\AppData\Local\Temp\YontooLayers\background.html JS/Adware.Yontoo.A application


This isn´t malware, but a security risk. I would delete these files immediately. Your choice.


Then we can do the cleanup - if you are facing any issues, report that immediately.

Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
I´m currently on my way back from a military training and will reply as soon as I´m at home. Please be patient with me. Thank you!
Then your system is clean! :)


Java update update


Your Java runtime environment is outdated. We will fix this.
  • Get the actual JRE from here
  • Save jxpiinstall.exe to your desktop
  • Close all running programs, especially your browser(s)
  • Run jxpiinstall.exe. This will download the newest JRE installer ( Java 7 Update 4 ) and install the software
  • when finished, go to
    Start–>control panel–>add/remove programs and remove all older Java versions. (if existing)
  • When finished, reboot your computer.
After the reboot
  • Open control panel again and click the java symbol.
  • Click Settings under Temporary Internet Files.
    The Temporary Files Settings dialog box appears.
  • Click Delete Files.
    The Delete Temporary Files dialog box appears
  • Click OK on Delete Temporary Files window.
  • Click OK again.




Uninstall our tools.
Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.




Reading Material
How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI