Hej...
Det skal lige siges...at hvergang jeg logger på nettet/mail... hopper billedet.. Et hop der ligner.. den måde en skærm opfører sig på.. ved tagning af et screenshot.
Den gør det ligeledes i det jeg er ved at markere teksten i OTL.txt log.. inden jeg når at trykke Ctrl+C.
Hvergang jeg logger på mailen.. får jeg beskeden google.com svarer ikke... someetider IE svarer ikke.
Ved google søgninger... og klik på et resultat.. Får jeg at vide at IE ikke kan vise siden.
OTL logfile created on: 26-06-2013 21:36:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\starman\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
5,00 Gb Total Physical Memory | 3,86 Gb Available Physical Memory | 77,29% Memory free
10,20 Gb Paging File | 8,97 Gb Available in Paging File | 87,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 915,70 Gb Total Space | 868,84 Gb Free Space | 94,88% Space Free | Partition Type: NTFS
Drive D: | 15,81 Gb Total Space | 2,19 Gb Free Space | 13,83% Space Free | Partition Type: NTFS
Computer Name: STARMAN-PC | User Name: starman | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\starman\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
========== Modules (No Company Name) ========== ========== Services (SafeList) ========== SRV:
64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:
64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HPBtnSrv) -- C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
========== Driver Services (SafeList) ========== DRV:
64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:
64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:
64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:
64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:
64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:
64bit: - (AswRdr) -- C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:
64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:
64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:
64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (netr28x) -- C:\Windows\SysNative\DRIVERS\netr28x.sys (Ralink Technology, Corp.)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (HCW85BDA) -- C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (Cyberlink Corp.)
DRV - (PCD5SRVC{8AAF211B-043E02A9-05040000}) -- C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms (PC-Doctor, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cndtIE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {304B45FB-64E8-48EC-842C-53C35FEC5373}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE:
64bit: - HKLM\..\SearchScopes\{2FEB3821-8AA8-43D9-BE10-22F16D6B95FF}: "URL" =
http://dk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008IE:
64bit: - HKLM\..\SearchScopes\{304B45FB-64E8-48EC-842C-53C35FEC5373}: "URL" =
http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1312&query={searchTerms}&invocationType=tb50hpcndtie7-da-dkIE:
64bit: - HKLM\..\SearchScopes\{FAB135E2-41DF-4BF4-AAE8-B6F55F10168C}: "URL" =
http://dk.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913940IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cndtIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cndtIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{2FEB3821-8AA8-43D9-BE10-22F16D6B95FF}: "URL" =
http://dk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008IE - HKLM\..\SearchScopes\{304B45FB-64E8-48EC-842C-53C35FEC5373}: "URL" =
http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1312&query={searchTerms}&invocationType=tb50hpcndtie7-da-dkIE - HKLM\..\SearchScopes\{FAB135E2-41DF-4BF4-AAE8-B6F55F10168C}: "URL" =
http://dk.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913940 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.bing.comIE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\SearchScopes,DefaultScope = {304B45FB-64E8-48EC-842C-53C35FEC5373}
IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\SearchScopes\{2FEB3821-8AA8-43D9-BE10-22F16D6B95FF}: "URL" =
http://dk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\SearchScopes\{304B45FB-64E8-48EC-842C-53C35FEC5373}: "URL" =
http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1312&query={searchTerms}&invocationType=tb50hpcndtie7-da-dkIE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\SearchScopes\{FAB135E2-41DF-4BF4-AAE8-B6F55F10168C}: "URL" =
http://dk.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913940IE - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-06-22 21:55:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013-06-18 22:15:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\starman\AppData\Roaming\mozilla\Extensions
[2013-06-12 00:32:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013-06-12 00:32:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
http://www.google.dk/CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Dokumenter = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Dokumenter = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drev = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Google Drev = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: YouTube = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-s\u00F8gning = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google-s\u00F8gning = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\starman\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013-06-01 04:04:22 | 005,960,821 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost #IPv4
O1 - Hosts: ::1 localhost # IPv6
O1 - Hosts: 127.0.0.1 ---.chine-li.info
O1 - Hosts: 127.0.0.1 0-29.com
O1 - Hosts: 127.0.0.1 0-pdf.com
O1 - Hosts: 127.0.0.1 0.gvt0.com
O1 - Hosts: 127.0.0.1 00.eatgoogle.bee.pl
O1 - Hosts: 127.0.0.1 00.eatgoogle.osa.pl
O1 - Hosts: 127.0.0.1 00.googleeat.bee.pl
O1 - Hosts: 127.0.0.1 00.googleeat.osa.pl
O1 - Hosts: 127.0.0.1 00.moregoogle.bee.pl
O1 - Hosts: 127.0.0.1 00.moregoogle.osa.pl
O1 - Hosts: 127.0.0.1 000-101.org
O1 - Hosts: 127.0.0.1 0000.in
O1 - Hosts: 127.0.0.1 00002l8.previewcoxhosting.com
O1 - Hosts: 127.0.0.1 0000a-fast-proxy.de
O1 - Hosts: 127.0.0.1 00161dcc.linkbucks.com
O1 - Hosts: 127.0.0.1 00185.com
O1 - Hosts: 127.0.0.1 001galerie.com
O1 - Hosts: 127.0.0.1 001host.net
O1 - Hosts: 127.0.0.1 002b0372.linkbucks.com
O1 - Hosts: 127.0.0.1 002c63f4.linkbucks.com
O1 - Hosts: 127.0.0.1 003f3f9b.linkbucks.com
O1 - Hosts: 127.0.0.1 005.free-counter.co.uk
O1 - Hosts: 127.0.0.1 0058f8d6.linkbucks.com
O1 - Hosts: 193800 more lines...
O2:
64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE (Microsoft)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2143842749-563978281-1954728513-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.249.14.50 89.249.14.54
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E6A97BB4-9BB0-41ED-8C90-8963A9F4FB0D}: DhcpNameServer = 89.249.14.50 89.249.14.54
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2013-06-26 21:34:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\starman\Desktop\OTL.exe
[2013-06-25 22:03:54 | 004,378,864 | ---- | C] (Piriform Ltd) -- C:\Users\starman\Desktop\ccsetup402.exe
[2013-06-23 01:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013-06-23 01:02:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2013-06-23 01:01:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2013-06-23 01:01:12 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Adobe
[2013-06-22 23:42:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\hpHosts
[2013-06-22 23:40:20 | 001,220,592 | ---- | C] (I.T. Mate ) -- C:\Users\starman\Desktop\hpHosts-Setup-Win32.exe
[2013-06-22 21:56:46 | 000,378,944 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2013-06-22 21:56:46 | 000,059,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2013-06-22 21:56:46 | 000,033,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013-06-22 21:56:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013-06-22 21:56:45 | 001,030,440 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2013-06-22 21:56:45 | 000,064,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2013-06-22 21:56:44 | 000,287,840 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2013-06-22 21:56:44 | 000,080,816 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013-06-22 21:55:30 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2013-06-22 21:54:55 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013-06-22 21:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013-06-22 21:46:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013-06-18 22:15:25 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Mozilla
[2013-06-18 22:15:25 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Mozilla
[2013-06-16 21:44:36 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
[2013-06-16 21:44:35 | 000,000,000 | ---D | C] -- C:\totalcmd
[2013-06-16 21:44:35 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\GHISLER
[2013-06-16 21:03:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProcessMonitor
[2013-06-16 21:01:14 | 004,329,488 | ---- | C] (Ghisler Software GmbH) -- C:\Users\starman\Desktop\tcm801x64.exe
[2013-06-16 12:10:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2013-06-16 11:44:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro
[2013-06-16 11:44:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HD Tune Pro
[2013-06-16 11:43:26 | 002,195,900 | ---- | C] (EFD Software ) -- C:\Users\starman\Desktop\hdtunepro_550_trial.exe
[2013-06-15 18:54:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskCheckup
[2013-06-15 18:54:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DiskCheckup
[2013-06-15 18:33:30 | 001,058,176 | ---- | C] (PassMark Software ) -- C:\Users\starman\Desktop\diskcheckup.exe
[2013-06-15 15:11:14 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WindowsPowerShell
[2013-06-15 15:10:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\WindowsPowerShell
[2013-06-15 11:43:02 | 000,000,000 | ---D | C] -- C:\Users\starman\Desktop\tdsskiller
[2013-06-15 11:40:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2013-06-15 11:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2013-06-15 11:40:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinZip
[2013-06-15 11:37:17 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\CyberLink
[2013-06-14 21:55:44 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Malwarebytes
[2013-06-14 21:55:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013-06-14 21:45:06 | 000,000,000 | ---D | C] -- C:\Users\starman\Desktop\RK_Quarantine
[2013-06-14 21:41:43 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\starman\Desktop\mbam-setup-1.75.0.1300.exe
[2013-06-14 00:16:25 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\ParetoLogic
[2013-06-14 00:16:25 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\DriverCure
[2013-06-14 00:16:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ParetoLogic
[2013-06-13 23:28:15 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2013-06-13 23:28:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices
[2013-06-13 14:04:07 | 000,355,651 | ---- | C] (Farbar) -- C:\Users\starman\Desktop\FSS.exe
[2013-06-12 23:38:39 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013-06-12 22:55:47 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013-06-12 22:55:47 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\temp
[2013-06-12 22:33:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013-06-12 22:33:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013-06-12 22:33:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013-06-12 21:03:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013-06-12 21:00:45 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013-06-12 21:00:04 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Tific
[2013-06-12 20:58:56 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Symantec
[2013-06-12 20:45:29 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2013-06-12 20:37:40 | 005,078,680 | R--- | C] (Swearware) -- C:\Users\starman\Desktop\ComboFix.exe
[2013-06-12 01:05:27 | 000,000,000 | ---D | C] -- C:\Users\starman\Documents\Symantec
[2013-06-12 00:35:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2013-06-12 00:33:50 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Opera
[2013-06-12 00:33:50 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Opera
[2013-06-12 00:33:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2013-06-12 00:32:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013-06-12 00:32:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013-06-12 00:32:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013-06-12 00:30:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013-06-12 00:30:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013-06-12 00:30:13 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Google
[2013-06-12 00:29:56 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Deployment
[2013-06-12 00:29:56 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Apps
[2013-06-12 00:04:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vi-VN
[2013-06-12 00:04:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\eu-ES
[2013-06-12 00:04:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\eu-ES
[2013-06-12 00:04:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ca-ES
[2013-06-12 00:04:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ca-ES
[2013-06-12 00:04:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vi-VN
[2013-06-11 23:56:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2013-06-11 22:19:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2013-06-11 21:14:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2013-06-11 19:11:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2013-06-11 18:50:42 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2013-06-11 18:41:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013-06-11 18:41:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013-06-11 18:17:00 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\ATI
[2013-06-11 18:17:00 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\ATI
[2013-06-11 18:16:28 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Hewlett-Packard
[2013-06-11 18:03:46 | 000,000,000 | R--D | C] -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013-06-11 18:03:46 | 000,000,000 | R--D | C] -- C:\Users\starman\Searches
[2013-06-11 18:03:46 | 000,000,000 | R--D | C] -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013-06-11 18:03:39 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Identities
[2013-06-11 18:03:37 | 000,000,000 | R--D | C] -- C:\Users\starman\Contacts
[2013-06-11 18:03:36 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\VirtualStore
[2013-06-11 17:57:48 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Macromedia
[2013-06-11 17:57:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2013-06-11 17:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
[2013-06-11 17:56:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2013-06-11 17:56:41 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Adobe
[2013-06-11 17:56:14 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Hewlett-Packard
[2013-06-11 17:54:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brugervejledninger
[2013-06-11 17:54:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pr°v Microsoft Office 2007 i 60 dage
[2013-06-11 17:54:22 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Documents\Videoer
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\AppData\Local\Temporary Internet Files
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Skabeloner
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\SendTo
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Recent
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Printere
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\AppData\Local\Oversigt
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Documents\Musik
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Menuen Start
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Lokale indstillinger
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Dokumenter
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Cookies
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Documents\Billeder
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Application Data
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\AppData\Local\Application Data
[2013-06-11 17:54:00 | 000,000,000 | -HSD | C] -- C:\Users\starman\Andre computere
[2013-06-11 17:53:59 | 000,000,000 | --SD | C] -- C:\Users\starman\AppData\Roaming\Microsoft
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Videos
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Saved Games
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Pictures
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Music
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Links
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Favorites
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Downloads
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Documents
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\Desktop
[2013-06-11 17:53:59 | 000,000,000 | R--D | C] -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013-06-11 17:53:59 | 000,000,000 | -H-D | C] -- C:\Users\starman\AppData
[2013-06-11 17:53:59 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Local\Microsoft
[2013-06-11 17:53:59 | 000,000,000 | ---D | C] -- C:\Users\starman\AppData\Roaming\Media Center Programs
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Start-meny
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Skrivbord
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\Program
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mina videoklipp
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mina bilder
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Min musik
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Mallar
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriter
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokument
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\Program Files\Delade filer
[2013-06-11 17:50:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Application Data
[2013-06-11 17:50:46 | 000,000,000 | -HSD | C] -- C:\Documents and Settings
[2013-05-31 15:54:54 | 002,489,024 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\Users\starman\Desktop\Procmon.exe
[1 C:\Users\starman\AppData\Local\*.tmp files -> C:\Users\starman\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2013-06-26 21:35:00 | 000,000,934 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-06-26 21:34:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\starman\Desktop\OTL.exe
[2013-06-26 21:28:27 | 001,030,440 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2013-06-26 21:28:27 | 000,378,944 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2013-06-26 21:28:27 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013-06-26 21:28:27 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013-06-26 21:28:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-06-26 21:26:17 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013-06-26 21:26:17 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013-06-26 21:25:27 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-06-26 21:25:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-06-25 22:03:55 | 004,378,864 | ---- | M] (Piriform Ltd) -- C:\Users\starman\Desktop\ccsetup402.exe
[2013-06-23 22:21:29 | 000,007,052 | ---- | M] () -- C:\Users\starman\AppData\Local\d3d9caps.dat
[2013-06-22 23:40:20 | 001,220,592 | ---- | M] (I.T. Mate ) -- C:\Users\starman\Desktop\hpHosts-Setup-Win32.exe
[2013-06-22 21:56:46 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013-06-22 21:56:44 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013-06-19 21:38:18 | 000,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013-06-18 21:23:24 | 000,000,056 | -H-- | M] () -- C:\Windows\SysWow64\ezsidmv.dat
[2013-06-16 21:44:37 | 000,000,598 | ---- | M] () -- C:\Users\starman\Desktop\Total Commander 64 bit.lnk
[2013-06-16 21:01:14 | 004,329,488 | ---- | M] (Ghisler Software GmbH) -- C:\Users\starman\Desktop\tcm801x64.exe
[2013-06-16 21:00:01 | 001,110,478 | ---- | M] () -- C:\Users\starman\Desktop\ProcessMonitor.zip
[2013-06-16 14:32:54 | 001,264,078 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-06-16 14:32:54 | 000,595,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-06-16 14:32:54 | 000,472,154 | ---- | M] () -- C:\Windows\SysNative\perfh006.dat
[2013-06-16 14:32:54 | 000,103,872 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-06-16 14:32:54 | 000,080,180 | ---- | M] () -- C:\Windows\SysNative\perfc006.dat
[2013-06-16 11:44:57 | 000,000,872 | ---- | M] () -- C:\Users\starman\Desktop\HD Tune Pro.lnk
[2013-06-16 11:43:27 | 002,195,900 | ---- | M] (EFD Software ) -- C:\Users\starman\Desktop\hdtunepro_550_trial.exe
[2013-06-15 18:54:30 | 000,000,882 | ---- | M] () -- C:\Users\starman\Desktop\DiskCheckup.lnk
[2013-06-15 18:33:30 | 001,058,176 | ---- | M] (PassMark Software ) -- C:\Users\starman\Desktop\diskcheckup.exe
[2013-06-15 18:11:00 | 000,308,352 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-06-15 11:40:28 | 000,001,896 | ---- | M] () -- C:\Users\Public\Desktop\WinZip.lnk
[2013-06-15 11:32:20 | 002,218,636 | ---- | M] () -- C:\Users\starman\Desktop\tdsskiller.zip
[2013-06-14 21:41:45 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\starman\Desktop\mbam-setup-1.75.0.1300.exe
[2013-06-14 21:40:04 | 000,907,776 | ---- | M] () -- C:\Users\starman\Desktop\RogueKiller.exe
[2013-06-13 23:27:41 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013-06-13 14:04:07 | 000,355,651 | ---- | M] (Farbar) -- C:\Users\starman\Desktop\FSS.exe
[2013-06-12 20:37:40 | 005,078,680 | R--- | M] (Swearware) -- C:\Users\starman\Desktop\ComboFix.exe
[2013-06-12 00:38:44 | 000,000,973 | ---- | M] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013-06-12 00:38:39 | 000,002,049 | ---- | M] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013-06-12 00:33:49 | 000,001,692 | ---- | M] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2013-06-12 00:33:49 | 000,001,668 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2013-06-12 00:32:53 | 000,000,912 | ---- | M] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013-06-12 00:32:53 | 000,000,888 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-06-12 00:25:40 | 000,008,798 | ---- | M] () -- C:\Windows\SysWow64\icrav03.rat
[2013-06-12 00:25:40 | 000,008,798 | ---- | M] () -- C:\Windows\SysNative\icrav03.rat
[2013-06-12 00:25:40 | 000,001,988 | ---- | M] () -- C:\Windows\SysWow64\ticrf.rat
[2013-06-12 00:25:40 | 000,001,988 | ---- | M] () -- C:\Windows\SysNative\ticrf.rat
[2013-06-12 00:25:21 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013-06-12 00:25:13 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013-06-12 00:09:59 | 000,262,144 | ---- | M] () -- C:\Windows\SPInstall.etl
[2013-06-11 21:54:42 | 000,001,589 | ---- | M] () -- C:\Users\Public\Desktop\Valg af webbrowser.lnk
[2013-06-11 21:53:44 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2013-06-11 18:51:43 | 000,588,472 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWow64\ezsvc7x.dll
[2013-06-11 18:49:22 | 000,061,517 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013-06-11 18:03:31 | 000,000,044 | ---- | M] () -- C:\Windows\System\hpsysdrv.dat
[2013-06-11 17:54:41 | 000,001,843 | RHS- | M] () -- C:\Windows\SysWow64\drivers\103C_HP_CPC_NC229AA-UUW m9566sc-a_YC_0Pavi_QCZH903_E91PNv6PrA1_49_INARRA3_SPEGATRON CORPORATION_V3.02_B5.17_T081009_WUH1_L406_M5118_J1000_7AMD_8Phenom 8650 Triple-Core_92.3_#130611_N10DE03EF_Z_G10029598.MRK
[2013-06-11 17:54:41 | 000,001,843 | RHS- | M] () -- C:\Windows\SysNative\drivers\103C_HP_CPC_NC229AA-UUW m9566sc-a_YC_0Pavi_QCZH903_E91PNv6PrA1_49_INARRA3_SPEGATRON CORPORATION_V3.02_B5.17_T081009_WUH1_L406_M5118_J1000_7AMD_8Phenom 8650 Triple-Core_92.3_#130611_N10DE03EF_Z_G10029598.MRK
[2013-06-11 17:54:30 | 000,001,422 | ---- | M] () -- C:\Users\Public\Desktop\Snapfish online foto service.lnk
[2013-06-01 04:04:22 | 005,960,821 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\HOSTS
[2013-05-31 15:54:54 | 002,489,024 | ---- | M] (Sysinternals -
www.sysinternals.com) -- C:\Users\starman\Desktop\Procmon.exe
[1 C:\Users\starman\AppData\Local\*.tmp files -> C:\Users\starman\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ========== [2013-06-26 21:28:27 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013-06-26 21:28:27 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013-06-23 01:02:00 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-06-22 21:56:46 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013-06-22 21:56:45 | 000,189,936 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2013-06-22 21:56:45 | 000,065,336 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2013-06-22 21:56:44 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2013-06-18 21:23:24 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2013-06-17 19:54:32 | 000,007,052 | ---- | C] () -- C:\Users\starman\AppData\Local\d3d9caps.dat
[2013-06-16 21:44:37 | 000,000,598 | ---- | C] () -- C:\Users\starman\Desktop\Total Commander 64 bit.lnk
[2013-06-16 21:00:01 | 001,110,478 | ---- | C] () -- C:\Users\starman\Desktop\ProcessMonitor.zip
[2013-06-16 11:44:57 | 000,000,872 | ---- | C] () -- C:\Users\starman\Desktop\HD Tune Pro.lnk
[2013-06-15 18:54:30 | 000,000,882 | ---- | C] () -- C:\Users\starman\Desktop\DiskCheckup.lnk
[2013-06-15 15:05:03 | 000,201,184 | ---- | C] () -- C:\Windows\SysWow64\winrm.vbs
[2013-06-15 15:05:03 | 000,201,184 | ---- | C] () -- C:\Windows\SysNative\winrm.vbs
[2013-06-15 15:05:03 | 000,004,675 | ---- | C] () -- C:\Windows\SysWow64\wsmanconfig_schema.xml
[2013-06-15 15:05:03 | 000,004,675 | ---- | C] () -- C:\Windows\SysNative\wsmanconfig_schema.xml
[2013-06-15 15:05:03 | 000,002,426 | ---- | C] () -- C:\Windows\SysWow64\WsmTxt.xsl
[2013-06-15 15:05:03 | 000,002,426 | ---- | C] () -- C:\Windows\SysNative\WsmTxt.xsl
[2013-06-15 11:40:28 | 000,001,896 | ---- | C] () -- C:\Users\Public\Desktop\WinZip.lnk
[2013-06-15 11:38:12 | 014,501,192 | ---- | C] () -- C:\Users\starman\Desktop\winzip145.exe
[2013-06-15 11:32:17 | 002,218,636 | ---- | C] () -- C:\Users\starman\Desktop\tdsskiller.zip
[2013-06-14 21:40:04 | 000,907,776 | ---- | C] () -- C:\Users\starman\Desktop\RogueKiller.exe
[2013-06-13 23:27:41 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2013-06-13 00:27:46 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013-06-13 00:27:46 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013-06-12 22:33:18 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013-06-12 22:33:18 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013-06-12 22:33:18 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013-06-12 22:33:18 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013-06-12 22:33:18 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013-06-12 00:33:49 | 000,001,692 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2013-06-12 00:33:49 | 000,001,680 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2013-06-12 00:33:49 | 000,001,668 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2013-06-12 00:32:53 | 000,000,912 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013-06-12 00:32:53 | 000,000,900 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013-06-12 00:32:53 | 000,000,888 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-06-12 00:30:49 | 000,002,049 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013-06-12 00:30:49 | 000,002,025 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013-06-12 00:30:20 | 000,000,934 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-06-12 00:30:20 | 000,000,930 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-06-12 00:25:21 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013-06-12 00:25:13 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013-06-11 23:12:24 | 000,395,723 | ---- | C] () -- C:\Windows\SysNative\onex.tmf
[2013-06-11 23:12:17 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2013-06-11 23:12:05 | 000,009,212 | ---- | C] () -- C:\Windows\SysWow64\RacUR.xml
[2013-06-11 23:12:05 | 000,009,212 | ---- | C] () -- C:\Windows\SysNative\RacUR.xml
[2013-06-11 23:11:54 | 000,471,992 | ---- | C] () -- C:\Windows\SysNative\dot3.tmf
[2013-06-11 23:11:46 | 000,700,507 | ---- | C] () -- C:\Windows\SysNative\eaphost.tmf
[2013-06-11 23:11:44 | 000,121,856 | ---- | C] () -- C:\Windows\SysNative\EhStorAuthn.dll
[2013-06-11 23:11:44 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2013-06-11 23:11:03 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2013-06-11 23:11:03 | 000,107,612 | ---- | C] () -- C:\Windows\SysNative\StructuredQuerySchema.bin
[2013-06-11 23:10:57 | 000,262,552 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2013-06-11 23:10:43 | 000,207,968 | ---- | C] () -- C:\Windows\SysNative\WFP.TMF
[2013-06-11 23:10:37 | 000,092,918 | ---- | C] () -- C:\Windows\SysWow64\slmgr.vbs
[2013-06-11 23:10:37 | 000,092,918 | ---- | C] () -- C:\Windows\SysNative\slmgr.vbs
[2013-06-11 23:10:34 | 000,009,239 | ---- | C] () -- C:\Windows\SysWow64\spcinstrumentation.man
[2013-06-11 23:10:34 | 000,009,239 | ---- | C] () -- C:\Windows\SysNative\spcinstrumentation.man
[2013-06-11 22:46:58 | 000,262,144 | ---- | C] () -- C:\Windows\SPInstall.etl
[2013-06-11 21:54:42 | 000,001,589 | ---- | C] () -- C:\Users\Public\Desktop\Valg af webbrowser.lnk
[2013-06-11 20:08:25 | 000,000,456 | ---- | C] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2013-06-11 18:41:23 | 000,000,973 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013-06-11 18:09:55 | 002,608,861 | ---- | C] () -- C:\Windows\SysNative\wlan.tmf
[2013-06-11 18:09:50 | 000,000,949 | ---- | C] () -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013-06-11 18:03:47 | 000,000,979 | ---- | C] () -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013-06-11 18:03:45 | 000,000,974 | ---- | C] () -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2013-06-11 18:03:37 | 000,000,915 | ---- | C] () -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2013-06-11 18:03:31 | 000,000,044 | ---- | C] () -- C:\Windows\System\hpsysdrv.dat
[2013-06-11 17:57:15 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Fremviser 2007.lnk
[2013-06-11 17:57:04 | 000,001,060 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Opgavestarter.lnk
[2013-06-11 17:54:44 | 000,001,526 | ---- | C] () -- C:\Users\Public\Desktop\Pr°v Microsoft Office 2007 i 60 dage.lnk
[2013-06-11 17:54:35 | 000,001,843 | RHS- | C] () -- C:\Windows\SysWow64\drivers\103C_HP_CPC_NC229AA-UUW m9566sc-a_YC_0Pavi_QCZH903_E91PNv6PrA1_49_INARRA3_SPEGATRON CORPORATION_V3.02_B5.17_T081009_WUH1_L406_M5118_J1000_7AMD_8Phenom 8650 Triple-Core_92.3_#130611_N10DE03EF_Z_G10029598.MRK
[2013-06-11 17:54:35 | 000,001,843 | RHS- | C] () -- C:\Windows\SysNative\drivers\103C_HP_CPC_NC229AA-UUW m9566sc-a_YC_0Pavi_QCZH903_E91PNv6PrA1_49_INARRA3_SPEGATRON CORPORATION_V3.02_B5.17_T081009_WUH1_L406_M5118_J1000_7AMD_8Phenom 8650 Triple-Core_92.3_#130611_N10DE03EF_Z_G10029598.MRK
[2013-06-11 17:54:30 | 000,001,422 | ---- | C] () -- C:\Users\Public\Desktop\Snapfish online foto service.lnk
[2013-06-11 17:54:21 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\Til børn.lnk
[2013-06-11 17:54:21 | 000,001,872 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Til børn.lnk
[2013-06-11 17:53:59 | 000,001,358 | ---- | C] () -- C:\Users\starman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk
[2013-06-11 17:53:59 | 000,000,258 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013-06-11 17:53:59 | 000,000,240 | ---- | C] () -- C:\Users\starman\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
========== ZeroAccess Check ========== [2006-11-02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012-06-08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-04-11 00:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2009-04-10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008-01-21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll
========== LOP Check ========== [2013-06-14 00:16:25 | 000,000,000 | ---D | M] -- C:\Users\starman\AppData\Roaming\DriverCure
[2013-06-16 21:44:35 | 000,000,000 | ---D | M] -- C:\Users\starman\AppData\Roaming\GHISLER
[2013-06-12 00:33:50 | 000,000,000 | ---D | M] -- C:\Users\starman\AppData\Roaming\Opera
[2013-06-14 00:16:25 | 000,000,000 | ---D | M] -- C:\Users\starman\AppData\Roaming\ParetoLogic
[2013-06-12 21:00:04 | 000,000,000 | ---D | M] -- C:\Users\starman\AppData\Roaming\Tific
========== Purity Check ========== < End of report >
Det skal lige siges at der i standard indstillingen under filescan var afkrydset "Skip microsoft files"... Hvilket jeg lige studsede over.