<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>Säkerhet</title>
	<description>Säkerhet - Eforum</description>
	<link>http://eforum.idg.se/index.php</link>
	<pubDate>Sun, 16 Jun 2013 17:30:28 +0000</pubDate>
	<ttl>5</ttl>
	<item>
		<title>Virusvarning: Exploit:W32/CVE-2013-1331.A</title>
		<link>http://eforum.idg.se/topic/341808-virusvarning-exploitw32cve-2013-1331a/</link>
		<description><![CDATA[Sedan i fredags varnar mitt virusprogram (Telia Säker surf dvs F-secure) många gånger för Exploit:W32/CVE-2013-1331.A  (virus). Viruset finns enbart i vanliga Wordfiler på min dator. Det går inte att sätta filerna i karantän. En del filer har jag lyckats radera men inte alla.<br />
Har också scannat med Malwarebytes Anti-Malware och SuperAntiSpyware men de hittar inga virus el dyl. <br />
Vad är detta och vad ska jag göra?<br />
Väldigt tacksam för svar!]]></description>
		<pubDate>Sun, 16 Jun 2013 17:30:28 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341808-virusvarning-exploitw32cve-2013-1331a/</guid>
	</item>
	<item>
		<title>PCMService</title>
		<link>http://eforum.idg.se/topic/341803-pcmservice/</link>
		<description><![CDATA[Hej!<br />
Det har efter flera år dykt upp ett meddelande, som inte går att ta bort:<br />
<br />
PCMServie <br />
en nödvändig resurs var inte tillgänglig.<br />
<br />
Vad är detta?<br />
Funktion?<br />
Är det farligt?<br />
Har F-secure installerad.<br />
<br />
Tacksam för hjälp med att skingra dimman!]]></description>
		<pubDate>Sun, 16 Jun 2013 09:26:31 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341803-pcmservice/</guid>
	</item>
	<item>
		<title>Avast kan ej skanna......</title>
		<link>http://eforum.idg.se/topic/341801-avast-kan-ej-skanna/</link>
		<description>Mitt antivirusprogram Avast ger ett felmeddelande: Kunde inte skanna viss filer som är lösenordsskyddade.Vad göra?</description>
		<pubDate>Sun, 16 Jun 2013 08:56:47 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341801-avast-kan-ej-skanna/</guid>
	</item>
	<item>
		<title>Task.exe</title>
		<link>http://eforum.idg.se/topic/341788-taskexe/</link>
		<description>Update Task.exe begär åtkomst till Internet. Vad är Task.exe? Är det något som jag bör ha i datorn eller är det någon phishing-grej?</description>
		<pubDate>Fri, 14 Jun 2013 13:11:21 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341788-taskexe/</guid>
	</item>
	<item>
		<title>Plötsliga pop-up på webbsidorna...</title>
		<link>http://eforum.idg.se/topic/341786-plotsliga-pop-up-pa-webbsidorna/</link>
		<description><![CDATA[Hej !<br />
<br />
Det verkar som att jag har fått in något i min dator, möjligen i samband med någon uppdatering, som trögar ned webbhanteringen, samtidigt som vissa ord har blivit understrukna och visar en pop-up med reklam när man hovrar över dem. <br />
Detta gäller såväl FireFox som Internet Explorer !<br />
<br />
Hur får man bort eländet och var kommer sådant ifrån ? <br />
<br />
Jag är rädd för att jag medverkar till spridning av denna dynga, då jag ansvarar för en webbsida som webbmaster och plötsligt fann understrukna ord även på denna !<br />
Jag hittar dock ingen ändring i html-koden till 'mina' webbsidor !<br />
<br />
(När jag förhandsgranskar ovanstående, har orden "ned" och "spridning" - efter några sekunder - blivit understrukna på samma sätt !)<br />
<br />
Mvh<br />
<br />
/Kalle]]></description>
		<pubDate>Fri, 14 Jun 2013 09:51:37 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341786-plotsliga-pop-up-pa-webbsidorna/</guid>
	</item>
	<item>
		<title>Skatten.se</title>
		<link>http://eforum.idg.se/topic/341766-skattense/</link>
		<description><![CDATA[Skatten borde väl ha högsta möjliga säkerhet tycker man...<br />
<br />
2 epic fail - både ang certifikatet som inte går att kolla om det blivit återkallat och TLS som borde vara 1.1 alt 1.2 för högsta säkerhet  <img src='http://eforum.idg.se/public/style_emoticons/default/thumbsdown.gif' class='bbc_emoticon' alt=':thumbsdown:' /><div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade bilder</h4>
	<ul>
		
			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_06_2013/post-2793-0-53191400-1371035340.png" class='bbc_img linked-image' alt="Bifogad bild: monthly_06_2013/post-2793-0-53191400-1371035340.png" />
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 12 Jun 2013 11:11:43 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341766-skattense/</guid>
	</item>
	<item>
		<title>Hur återställer man en mapp?</title>
		<link>http://eforum.idg.se/topic/341756-hur-aterstaller-man-en-mapp/</link>
		<description><![CDATA[Hej. <br />
<br />
Jag vet inte riktigt hur jag har lycktas men hemma på min dator så har jag råkat radera en mapp. Jag måste ha klickat med högerknappen och plötsligt så stod det att mappen kommer att tas bort permanent från datorn. Sedan försvann den bara samt dokumenten som fanns i mappen... När jag kollar i datorns papperskorg så finns inte mappen eller dokumenten där. Finns det något sätt som man kan återställa den borttagna mappen? <br />
<br />
<br />
Mvh j]]></description>
		<pubDate>Tue, 11 Jun 2013 07:53:46 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341756-hur-aterstaller-man-en-mapp/</guid>
	</item>
	<item>
		<title>Testa ditt skydd</title>
		<link>http://eforum.idg.se/topic/341752-testa-ditt-skydd/</link>
		<description><![CDATA[Testa ditt skydd<br />
<br />
Kontrollera om funktioner är korrekt konfigurerade<br />
<br />
<a href='http://www.amtso.org/feature-settings-check.html' class='bbc_url' title='Extern länk' rel='external'>http://www.amtso.org...ings-check.html</a><br />
<br />
<a href='http://translate.google.se/translate?hl=sv&sl=en&u=http://www.amtso.org/feature-settings-check.html&prev=/search%3Fq%3Dhttp://www.amtso.org/feature-settings-check.html%26biw%3D998%26bih%3D533' class='bbc_url' title='Extern länk' rel='external'>http://translate.goo...998%26bih%3D533</a>]]></description>
		<pubDate>Mon, 10 Jun 2013 18:41:46 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341752-testa-ditt-skydd/</guid>
	</item>
	<item>
		<title>Diverse funderingar</title>
		<link>http://eforum.idg.se/topic/341741-diverse-funderingar/</link>
		<description><![CDATA[En XP-dator som  2014 antagligen bör bytas upp till windows7.<br />
<br />
men i nuläget:<br />
<br />
<strong class='bbc'>1. Malware /liknande? </strong><br />
Har 2 instanser av  <em class='bbc'>"avgcsrvx"</em>   under aktivitetshanterare och efter lite googlande finns det tyvärr två vilt skilda<br />
åsikter. Antingen är det normal,dvs att en instans är email-scanner  och den andra toolbar. Motstridiga uppgifter säger dock att vissa malware gömmer sig<br />
med det namnet och har ofta sökväg till <em class='bbc'>C:/Windows</em> <br />
<br />
<span class='bbc_underline'><strong class='bbc'>1 A  </strong>avgcsrvx</span>.exe  har ibland mycket högre PCU.   uppe i 20k  för några dagar sen.<br />
När man söker efter fil med namnet hittas 3 stycken.<br />
Den första finns under <span style='color: #0000FF'><em class='bbc'>Documents and Settings&#092;All users&#092;Application Data&#092;MFAData&#092;SelfUpd</em></span><br />
Och är blå! Vilket betyder windows anser den som inaktiv.<br />
Den andra har samma filnamn i versaler "AVGCSRVX.EXE-02B71481.pf	(under <em class='bbc'>C:&#092;WINDOWS&#092;Prefetch</em><br />
Tredje  ligger en aning mer Förväntad  under  <em class='bbc'>&#092;Program&#092;AVG&#092;AVG2013</em><br />
<br />
<a href='http://postimg.org/image/q7a5pupn5/' class='bbc_url' title='Extern länk' rel='external'>http://postimg.org/image/q7a5pupn5/</a><br />
<br />
<span class='bbc_underline'><strong class='bbc'>1  B </strong> </span>Är detta för skit?  Körde netstat ano och hittade skumt (rödmarkerat) notera jag har vitmålat Användarnamnet. <br />
<br />
<a href='http://postimg.org/image/3qz0f1m4z/' class='bbc_url' title='Extern länk' rel='external'>http://postimg.org/image/3qz0f1m4z/</a><br />
<br />
AVG kanske finns i två versioner (massa .old ?) eller anser ni att jag ska rensa och testa köra med ett annat antivirus.<br />
Typ  MSE  en stund? <br />
<br />
<strong class='bbc'>2.</strong><br />
En viss seghet och ofta problem med visuella saker har börjat störa.Är det grafikkort som är dåligt eller? <br />
Har försökt snabba upp datorn ifråga lite grand. Bla sitter ett usbminne i med växlingsfil. Som sagt det är inte min egna dator men ägaren vittnar om<br />
en del förändringar på sistone.   Bla har msconfig varit uppe + evt en systemåterställning gjorts.]]></description>
		<pubDate>Sun, 09 Jun 2013 14:59:05 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341741-diverse-funderingar/</guid>
	</item>
	<item>
		<title>Hur välja och installera nytt, gratis antivirusprogram?</title>
		<link>http://eforum.idg.se/topic/341704-hur-valja-och-installera-nytt-gratis-antivirusprogram/</link>
		<description><![CDATA[På min knappt två månader gamla bärbara dator med Windows 8 har det börjat dyka upp "prenumerationsvarningar" om att min "prenumeration" på Norton Internet Security går ut om några dagar. Nu har jag ju inte precis prenumererat - Norton dök upp mer eller mindre automatiskt när jag tog den nya datorn i bruk och det stod visst något om 60 dagar.<br />
I varningarna står inget om att det kostar att "förnya" men det rör sig förmodligen om en ca 700:- för ett år, gissar jag, så jag vill byta till ett gratis antivirusprogram.<br />
Vilket gratis rekommenderar ni?<br />
Ska jag avinstallera Norton före eller efter installationen av ett annat antivirusprogram - kan det bli farligt i övergången?]]></description>
		<pubDate>Thu, 06 Jun 2013 16:29:51 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341704-hur-valja-och-installera-nytt-gratis-antivirusprogram/</guid>
	</item>
	<item>
		<title>Bitdefender 60 Second Virus Scanner FREE</title>
		<link>http://eforum.idg.se/topic/341695-bitdefender-60-second-virus-scanner-free/</link>
		<description><![CDATA[<a href='http://www.downloadcrew.com/article/29075-bitdefender_60_second_virus_scanner' class='bbc_url' title='Extern länk' rel='external'>Bitdefender 60 Second Virus Scanner FREE</a>]]></description>
		<pubDate>Wed, 05 Jun 2013 20:10:00 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341695-bitdefender-60-second-virus-scanner-free/</guid>
	</item>
	<item>
		<title>Win32/Heur virus hittat av AVG 2013</title>
		<link>http://eforum.idg.se/topic/341677-win32heur-virus-hittat-av-avg-2013/</link>
		<description><![CDATA[Hej!<br />
<br />
Mitt antivirus program AVG 2013 har hittat Win32/Heur virus när jag försöker köra spelet Age of Empires 2: The Conquerors.<br />
<br />
Detta meddelande får jag fram av AVG:<br />
<br />
<br />
Virus found Win32&#092;Heur<br />
<br />
Object name:<br />
C:&#092;Program&#092;Microsoft Games&#092;Age of Empires II&#092;age2_x1&#092;AGE2_X1.ICD<br />
<br />
Om jag försöker ignorera meddelandet av AVG, för att gå vidare får jag felmeddelandet Access denied (Open FIle Error).<br />
<br />
Jag försöker därefter ta bort viruset genom att välja "Protect Me" som finns på mitt antivirusprogram. Det lyckas ta bort viruset och jag tror att problemet är löst. Jag försöker köra spelet igen och kommer det ett meddelande från AVG att Win32/Heur virus har hittats på min CD-skiva:<br />
<br />
J:&#092;GAME&#092;AGE2_X1&#092;AGE2_X1.ICD<br />
<br />
Om jag försöker ta bort viruset med hjälp av AVG går det inte, jag får Access denied.<br />
<br />
Hur ska jag få bort Win32/Heur viruset?<br />
]]></description>
		<pubDate>Tue, 04 Jun 2013 07:50:41 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341677-win32heur-virus-hittat-av-avg-2013/</guid>
	</item>
	<item>
		<title>Bitdefender Total Security 2014 (v17) BETA</title>
		<link>http://eforum.idg.se/topic/341673-bitdefender-total-security-2014-v17-beta/</link>
		<description><![CDATA[<a href='http://www.downloadcrew.com/article/29778-bitdefender_total_security_2014' class='bbc_url' title='Extern länk' rel='external'>Bitdefender Total Security 2014 (v17) BETA</a><br />
<br />
<a href='http://www.bitdefender.com/media/html/beta/?cid=Beta_homepage' class='bbc_url' title='Extern länk' rel='external'>Tävlingen är dock över</a><br />
<br />
<a href='https://my.bitdefender.com/en_us/my/#page=main.ts.welcome' class='bbc_url' title='Extern länk' rel='external'>https://my.bitdefender.com/en_us/my/#page=main.ts.welcome</a><div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade bilder</h4>
	<ul>
		
			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_06_2013/post-2793-0-57972300-1370300063.png" class='bbc_img linked-image' alt="Bifogad bild: monthly_06_2013/post-2793-0-57972300-1370300063.png" />
			</li>
		

			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_06_2013/post-2793-0-80461500-1370299265.png" class='bbc_img linked-image' alt="Bifogad bild: monthly_06_2013/post-2793-0-80461500-1370299265.png" />
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Mon, 03 Jun 2013 22:33:38 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341673-bitdefender-total-security-2014-v17-beta/</guid>
	</item>
	<item>
		<title>Någon har tillgång till min dator</title>
		<link>http://eforum.idg.se/topic/341670-nagon-har-tillgang-till-min-dator/</link>
		<description><![CDATA[<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Problems.....</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>I natt satt jag vid en av hemmadatorerna - Frugans dator som egentligen bara har Spotify och webläsare. För övrigt har vi en bunt datorer till på nätverket.</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Under tiden jag satt där så fick jag påhälsning av någon utifrån. Det började bläddras i mappar och annat. Efter en kort stund började han skriva till mig i sökrutan ovanför startknappen på Win7.</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Jag skrev tillbaka och fick svar = Det var en levande person. Sedan ryckte jag ur nätverkssladden. Sekunderna senare var han och hälsade på i kidsens datorer. Skrev någonting på Slovenska genom att använda Fästisar</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Då ryckte jag ur Routern.</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Kidsen är spelmissbrukare och har damp när de inte får använda nätet men jag tänker inte göra något förrän jag kommer hem. Frågan är bara i vilken ände jag skall börja?</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Jag gjorde en scan på den dator jag satt vid. Både virusscan med Microsoft Security Essentials, SpyBot Search&Destry, CCleaner för att städa registret samt en scan med HijackThis. Inga problems någonstans. Inget skumt i brandväggen heller.</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Några seriösa idéer?</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Frånsett att slänga ut kidsen och datorer alltså!</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'><br />
</span></span></span><br />
<br />
<span style='color: #282828'><span style='font-family: helvetica, arial, sans-serif'><span style='font-size: 17px;'>Har varit användare till och från på detta forum genom "alla" åren, typ 10-15 år. Nu hade jag tydligen varit inaktiv alltför länge så jag skapade en ny profil <img src='http://eforum.idg.se/public/style_emoticons/default/smile.gif' class='bbc_emoticon' alt=':)' /></span></span></span><br />
<br />
]]></description>
		<pubDate>Mon, 03 Jun 2013 10:53:42 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341670-nagon-har-tillgang-till-min-dator/</guid>
	</item>
	<item>
		<title>Upprepat SPAM från en mejl-adress</title>
		<link>http://eforum.idg.se/topic/341663-upprepat-spam-fran-en-mejl-adress/</link>
		<description><![CDATA[Jag har under en lång tid (något år) fått SPAM eller skräppost från adressen<br />
info@blixt-vinsten.se.<br />
Jag har förstås aldrig öppnat eller accepterat alla de erbjudanden m.m., som dess mejl innehållit.<br />
I förhoppning om att få hjälp med att om möjligt för alltid bli kvitt dessa SPAM, skickar jag här nedan mejlet och därefter källkoden för att någon skall kunna hjälpa mig att hitta "den befriande lösningen".<br />
<br />
<span class='bbc_underline'>Här är skräp-mejlet:</span> <br />
<br />
"Trevlig helg Carl-Gustaf!<br />
Vi har dragit lott och du har blivit utvald att få en kolgrill utan kostnad<br />
Om X@telia.com är rätt e-mail behöver du bara fylla i din adress i Lule så att vi kan skicka hem grillen till dig.<br />
Du kan även få en lyxgasolgrill från Weber om du skriver vad du tycker om grillen efter att du har använt den en månad.<br />
Klicka här och njut av sommaren med en ny grill<br />
Många hälsningar,<br />
Maria Hansson<br />
Blixt-Vinsten Sverige<br />
Du får detta mail eftersom du har deltagit i en tävling eller en undersökning på nätet och samtyckt till att få<br />
vår lilla nyhetsbrev.<br />
Avanmäl dig här.<br />
Kom ihåg att alltid läsa villkoren innan du deltar/p&gt;<br />
Vid frågor kan du skriva till info@starflymedia.dk"<br />
<br />
[b]<span class='bbc_underline'>HÄR ÄR KÄLLKODEN:[/</span>b]<br />
From - Sun Jun 02 14:52:21 2013<br />
X-Account-Key: account1<br />
X-UIDL: 62268<br />
X-Mozilla-Status: 0001<br />
X-Mozilla-Status2: 00000000<br />
X-Mozilla-Keys:                                                                                 <br />
Return-Path: &lt;bounce+3-68-883d64d1-297b-49e6-8065-3a5aa91e993c@blixt-vinsten.se&gt;<br />
Original-Recipient: rfc822;X@telia.com<br />
Received: from smtp-in21.han.skanova.net (195.67.226.205) by ms16.han.skanova.net (8.5.142)<br />
        id 51A57C5C00358846 for Xn@telia.com; Sun, 2 Jun 2013 14:40:06 +0200<br />
Received: from star-smtp16.dk (109.74.7.10) by smtp-in21.han.skanova.net (8.5.133)<br />
        id 516D0CAD02946DAD for Xn@telia.com; Sun, 2 Jun 2013 14:40:05 +0200<br />
Date: Sun, 2 Jun 2013 14:40:05 +0200<br />
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=blixt-vinsten.se;<br />
	s=sf1305; t=1370176805;<br />
	bh=GR3pxKTMa0B+u3K09mmQCY2aS9GgpNzOStGC1XX2Z1M=;<br />
	h=To:From:Reply-To:Subject:List-Unsubscribe:From;<br />
	b=UL/f/xpRqfSTr2zMXZHYrbeyueO5EreX84jqdhDm02EcOEac3WAoF7yqIC8arhOeI<br />
	 trSk5K9bv82iD2azBFvTok7umbClFUo5ICel+gZUqQRjOl2zBNJv2kLYWhlDOV9q2F<br />
	 ZZh/X43X18tREsPSS0m22vBQ+pIFx7fOUznlBric=<br />
To: Carl-Gustaf Carlsson &lt;Xn@telia.com&gt;<br />
From: Maria Hansson &lt;info@blixt-vinsten.se&gt;<br />
Reply-To: Starfly Media Aps &lt;reply+3-68-883d64d1-297b-49e6-8065-3a5aa91e993c@blixt-vinsten.se&gt;<br />
Subject: =?UTF-8?Q?X@telia.com_har_f=C3=A5tt_en_kolgrill_utan_kostnad.?=<br />
Message-ID: &lt;883d64d1-297b-49e6-8065-3a5aa91e993c@blixt-vinsten.se&gt;<br />
List-Unsubscribe: &lt;mailto:unsubscribe+3-68-883d64d1-297b-49e6-8065-3a5aa91e993c@blixt-vinsten.se&gt;, &lt;http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&email=X@telia.com&gt;<br />
Precedence: bulk<br />
MIME-Version: 1.0<br />
Content-Type: multipart/alternative;<br />
	boundary="b1_db76cd8b440497f95ccc35bc45a633f2"<br />
<br />
--b1_db76cd8b440497f95ccc35bc45a633f2<br />
Content-Type: text/plain; charset=UTF-8<br />
Content-Transfer-Encoding: 8bit<br />
<br />
Avanmäl dig här.<br />
<br />
&gt;&gt; <a href='http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&email=X@telia.com' class='bbc_url' title='Extern länk' rel='external'>http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&email=X@telia.com</a><br />
<br />
 Trevlig helg Carl-Gustaf!<br />
 Vi har dragit lott och du har blivit utvald att få en kolgrill utan kostnad<br />
 Om Xn@telia.com är rätt e-mail behöver du bara fylla i din adress i Lule så att vi kan skicka hem grillen till dig.<br />
 Du kan även få en lyxgasolgrill från Weber om du skriver vad du tycker om grillen efter att du har använt den en månad.<br />
Klicka här och njut av sommaren med en ny grill<br />
&gt;&gt; <a href='http://media.blixt-vinsten.se/tracking/v2/c/bed41a2/883d64d1-297b-49e6-8065-3a5aa91e993c' class='bbc_url' title='Extern länk' rel='external'>http://media.blixt-vinsten.se/tracking/v2/c/bed41a2/883d64d1-297b-49e6-8065-3a5aa91e993c</a><br />
 <br />
 Många hälsningar,<br />
Maria Hansson<br />
 Blixt-Vinsten Sverige<br />
<br />
 Du får detta mail eftersom du har deltagit i en tävling<br />
 eller en undersökning på nätet och samtyckt till att få<br />
 vår lilla nyhetsbrev.<br />
Avanmäl dig här.<br />
&gt;&gt; <a href='http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&email=Xn@telia.com' class='bbc_url' title='Extern länk' rel='external'>http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&email=Xn@telia.com</a><br />
<br />
Kom ihåg att alltid läsa villkoren innan du deltar/p&gt; <br />
Vid frågor kan du skriva till info@starflymedia.dk<br />
&gt;&gt; mailto:info@starflymedia.dk<br />
<br />
--b1_db76cd8b440497f95ccc35bc45a633f2<br />
Content-Type: text/html; charset=UTF-8<br />
Content-Transfer-Encoding: 8bit<br />
<br />
&lt;!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"&gt;<br />
&lt;html&gt;&lt;head&gt;&lt;title&gt;&lt;/title&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=UTF-8"&gt;&lt;/head&gt;&lt;body&gt;&lt;table style="margin-bottom: 2em; width: 100%; background-color: #CCC"&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&amp;email=X@telia.com" style="font-family: arial; font-size: 8pt; text-decoration: none; color: #555;"&gt;Avanmäl dig här.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;<br />
	 &lt;/p&gt;<br />
&lt;p&gt;	 &lt;/p&gt;<br />
&lt;p&gt;	&lt;span style="font-size:12px;"&gt;&lt;span style="font-family:arial, helvetica, sans-serif;"&gt;Trevlig helg Carl-Gustaf!&lt;br&gt;&lt;br&gt;<br />
	Vi har dragit lott och du har blivit utvald att få en kolgrill utan kostnad&lt;br&gt;<br />
	Om X@telia.com är rätt e-mail behöver du bara fylla i din adress i Lule så att vi kan skicka hem grillen till dig.&lt;br&gt;&lt;br&gt;<br />
	Du kan även få en lyxgasolgrill från Weber om du skriver vad du tycker om grillen efter att du har använt den en månad.&lt;br&gt;&lt;br&gt;&lt;a href="http://media.blixt-vinsten.se/tracking/v2/c/bed41a2/883d64d1-297b-49e6-8065-3a5aa91e993c"&gt;&lt;strong&gt;Klicka här och njut av sommaren med en ny grill&lt;/strong&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;<br />
&lt;p&gt;	 &lt;/p&gt;<br />
&lt;p&gt;	 &lt;/p&gt;<br />
&lt;p&gt;	 &lt;/p&gt;<br />
&lt;p&gt;	&lt;span style="font-size:11px;"&gt;&lt;span style="font-family:arial, helvetica, sans-serif;"&gt;Många hälsningar,&lt;br&gt;&lt;br&gt;&lt;strong&gt;Maria Hansson&lt;/strong&gt;&lt;br&gt;<br />
	Blixt-Vinsten Sverige&lt;br&gt;&lt;br&gt;<br />
	Du får detta mail eftersom du har deltagit i en tävling&lt;br&gt;<br />
	eller en undersökning på nätet och samtyckt till att få&lt;br&gt;<br />
	vår lilla nyhetsbrev.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;<br />
     &lt;p&gt;&lt;a href="http://media.blixt-vinsten.se/?id=883d64d1-297b-49e6-8065-3a5aa91e993c&amp;email=X@telia.com" style="font-family: arial; font-size: 10pt; color: #555;"&gt;Avanmäl dig här.&lt;/a&gt;&lt;/p&gt;&lt;img width="1" height="1" src="http://media.blixt-vinsten.se/tracking/v2/o/883d64d1-297b-49e6-8065-3a5aa91e993c.gif" alt=""&gt;<br />
        &lt;div&gt;<br />
&lt;p style="font-family: arial; font-size: 8pt; color: #555;"&gt;Kom ihåg att alltid läsa villkoren innan du deltar/p&gt;<br />
&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: arial; font-size: 8pt; color: #555;"&gt;Vid frågor kan du skriva till &lt;a href="mailto:info@starflymedia.dk"&gt;info@starflymedia.dk&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;<br />
&lt;/div&gt;<br />
    &lt;/body&gt;&lt;/html&gt;<br />
<br />
--b1_db76cd8b440497f95ccc35bc45a633f2--]]></description>
		<pubDate>Sun, 02 Jun 2013 13:48:27 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341663-upprepat-spam-fran-en-mejl-adress/</guid>
	</item>
	<item>
		<title><![CDATA[Hjälp med att använda FRST på &#34;polis-virus&#34;]]></title>
		<link>http://eforum.idg.se/topic/341660-hjalp-med-att-anvanda-frst-pa-polis-virus/</link>
		<description><![CDATA[Hej,<br />
Jag har fått polis-viruset på min bärbara dator och har försökt följa tråd på annat ställe för att rensa bort det med FRST.<br />
Jag har kommit så långt att jag har skapat en fix-list på USB-minnet men den hittar inte den när jag kör "REPAIR"<br />
Detta är loggen jag får av den:<br />
<br />
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-06-2013 02<br />
Ran by Expert (administrator) on 02-06-2013 12:10:31<br />
Running from F:&#092;<br />
Windows 7 Home Premium Service Pack 1 (X86) OS Language: Swedish<br />
Internet Explorer Version 8<br />
Boot Mode: Safe Mode (minimal)<br />
<br />
==================== Processes (Whitelisted) ===================<br />
<br />
(Microsoft Corporation) C:&#092;Windows&#092;system32&#092;cmd.exe<br />
<br />
==================== Registry (Whitelisted) ==================<br />
<br />
HKLM&#092;...&#092;Run: [RtHDVCpl] C:&#092;Program Files&#092;Realtek&#092;Audio&#092;HDA&#092;RtHDVCpl.exe -s [8120864 2009-12-15] (Realtek Semiconductor)<br />
HKLM&#092;...&#092;Run: [SynTPEnh] %ProgramFiles%&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe [1578280 2009-10-10] (Synaptics Incorporated)<br />
HKLM&#092;...&#092;Run: [UpdateLBPShortCut] "C:&#092;Program Files&#092;CyberLink&#092;LabelPrint&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;LabelPrint" UpdateWithCreateOnce "Software&#092;CyberLink&#092;LabelPrint&#092;2.5" [222504 2009-05-19] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [CLMLServer] "C:&#092;Program Files&#092;CyberLink&#092;Power2Go&#092;CLMLSvc.exe" [103720 2009-06-03] (CyberLink)<br />
HKLM&#092;...&#092;Run: [UpdateP2GoShortCut] "C:&#092;Program Files&#092;CyberLink&#092;Power2Go&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;Power2Go" UpdateWithCreateOnce "SOFTWARE&#092;CyberLink&#092;Power2Go&#092;6.0" [222504 2009-05-19] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [UpdatePDRShortCut] "C:&#092;Program Files&#092;CyberLink&#092;PowerDirector&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;PowerDirector" UpdateWithCreateOnce "Software&#092;CyberLink&#092;PowerDirector&#092;7.0" [222504 2008-01-04] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [RemoteControl8] "C:&#092;Program Files&#092;CyberLink&#092;PowerDVD8&#092;PDVD8Serv.exe" [91432 2009-04-15] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [PDVD8LanguageShortcut] "C:&#092;Program Files&#092;CyberLink&#092;PowerDVD8&#092;Language&#092;Language.exe" [50472 2009-04-15] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [UpdatePPShortCut] "C:&#092;Program Files&#092;CyberLink&#092;PowerProducer&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;PowerProducer" UpdateWithCreateOnce "Software&#092;CyberLink&#092;PowerProducer&#092;5.0" [218408 2008-12-03] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [UpdatePSTShortCut] "C:&#092;Program Files&#092;CyberLink&#092;DVD Suite&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;DVD Suite" UpdateWithCreateOnce "Software&#092;CyberLink&#092;PowerStarter" [210216 2009-07-21] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [APLangApp] "C:&#092;Program Files&#092;AnyPC Client&#092;APLangApp.exe" [13312 2009-11-20] (DoctorSoft)<br />
HKLM&#092;...&#092;Run: [UCam_Menu] "C:&#092;Program Files&#092;CyberLink&#092;YouCam&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;YouCam" UpdateWithCreateOnce "Software&#092;CyberLink&#092;YouCam&#092;2.0" [222504 2009-05-19] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [CNAP2 Launcher] C:&#092;windows&#092;system32&#092;spool&#092;DRIVERS&#092;W32X86&#092;3&#092;CNAP2LAK.EXE [406944 2007-09-06] (CANON INC.)<br />
HKLM&#092;...&#092;Run: [Adobe ARM] "C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)<br />
HKLM&#092;...&#092;Run: [DivXUpdate] "C:&#092;Program Files&#092;DivX&#092;DivX Update&#092;DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] ()<br />
HKLM&#092;...&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;qttask.exe" -atboottime [282624 2006-09-01] (Apple Computer, Inc.)<br />
HKLM&#092;...&#092;Run: [AveoSTI.exe] C:&#092;Program Files&#092;AVEO USB2.0 PC Camera(U2HGCV3P31048)&#092;AveoSTI.exe [32768 2010-12-02] (AVEO)<br />
HKLM&#092;...&#092;Run: [PSUAMain] "C:&#092;Program Files&#092;Panda Security&#092;Panda Cloud Antivirus&#092;PSUAMain.exe" /LaunchSysTray [32480 2013-01-27] (Panda Security, S.L.)<br />
HKLM&#092;...&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)<br />
HKCU&#092;...&#092;Run: [Google Update] "C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Update&#092;GoogleUpdate.exe" /c [135664 2010-07-06] (Google Inc.)<br />
HKCU&#092;...&#092;Run: [Sidebar] C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe /autoRun [1174016 2010-11-20] (Microsoft Corporation)<br />
HKCU&#092;...&#092;Winlogon: [Shell] explorer.exe,C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;skype.dat &lt;==== ATTENTION <br />
Startup: C:&#092;ProgramData&#092;Start Menu&#092;Programs&#092;Startup&#092;BankID säkerhetsprogram.lnk<br />
ShortcutTarget: BankID säkerhetsprogram.lnk -&gt; C:&#092;Program Files&#092;Personal&#092;bin&#092;Personal.exe (Technology Nexus AB)<br />
Startup: C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;OpenOffice.org 3.2.lnk<br />
ShortcutTarget: OpenOffice.org 3.2.lnk -&gt; C:&#092;Program Files&#092;OpenOffice.org 3&#092;program&#092;quickstart.exe ()<br />
<br />
==================== Internet (Whitelisted) ====================<br />
<br />
HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href='http://search.babylon.com/?babsrc=HP_ss&affID=101240&mntrId=56322052000000000000000000000000' class='bbc_url' title='Extern länk' rel='external'>http://search.babylon.com/?babsrc=HP_ss&affID=101240&mntrId=56322052000000000000000000000000</a><br />
HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href='http://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn' class='bbc_url' title='Extern länk' rel='external'>http://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn</a><br />
HKCU SearchScopes: DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = <a href='http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000' class='bbc_url' title='Extern länk' rel='external'>http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000</a><br />
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = <a href='http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000' class='bbc_url' title='Extern länk' rel='external'>http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000</a><br />
BHO: DivX Plus Web Player HTML5 &lt;video&gt; - {326E768D-4182-46FD-9C16-1449A49795F4} - C:&#092;Program Files&#092;DivX&#092;DivX Plus Web Player&#092;ie&#092;DivXHTML5&#092;DivXHTML5.dll (DivX, LLC)<br />
BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre7&#092;bin&#092;ssv.dll (Oracle Corporation)<br />
BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:&#092;ProgramData&#092;Partner&#092;Partner.dll (Google Inc.)<br />
BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll (Microsoft Corporation)<br />
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.7.8313.1002&#092;swg.dll (Google Inc.)<br />
BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre7&#092;bin&#092;jp2ssv.dll (Oracle Corporation)<br />
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:&#092;PROGRA~1&#092;WIC4A1~1&#092;MESSEN~1&#092;MSGRAP~1.DLL (Microsoft Corporation)<br />
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Information Retrieval&#092;msitss.dll (Microsoft Corporation)<br />
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:&#092;PROGRA~1&#092;WIC4A1~1&#092;MESSEN~1&#092;MSGRAP~1.DLL (Microsoft Corporation)<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;PROGRA~1&#092;COMMON~1&#092;Skype&#092;SKYPE4~1.DLL (Skype Technologies)<br />
Tcpip&#092;Parameters: [DhcpNameServer] 192.168.1.1<br />
<br />
FireFox:<br />
========<br />
FF ProfilePath: C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;k76wazx2.default<br />
FF Homepage: hxxp://www.superstart.se/#<br />
FF Keyword.URL: hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=56322052000000000000000000000000&tlver=1.4.35.10&affID=101240<br />
FF Plugin: @adobe.com/FlashPlayer - C:&#092;windows&#092;system32&#092;Macromed&#092;Flash&#092;NPSWF32_11_7_700_202.dll ()<br />
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:&#092;Program Files&#092;DivX&#092;DivX Plus Web Player&#092;npdivx32.dll (DivX, LLC)<br />
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:&#092;Program Files&#092;DivX&#092;DivX OVS Helper&#092;npovshelper.dll (DivX, LLC.)<br />
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:&#092;windows&#092;system32&#092;npDeployJava1.dll (Oracle Corporation)<br />
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:&#092;Program Files&#092;Java&#092;jre7&#092;bin&#092;plugin2&#092;npjp2.dll (Oracle Corporation)<br />
FF Plugin: @microsoft.com/GENUINE - disabled No File<br />
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:&#092;Program Files&#092;Microsoft Silverlight&#092;3.0.40624.0&#092;npctrl.dll ( Microsoft Corporation)<br />
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:&#092;Program Files&#092;Microsoft&#092;Office Live&#092;npOLW.dll (Microsoft Corp.)<br />
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:&#092;Program Files&#092;Windows Live&#092;Photo Gallery&#092;NPWLPG.dll (Microsoft Corporation)<br />
FF Plugin: @se.nexus/Personal - C:&#092;Program Files&#092;Personal&#092;bin&#092;np_prsnl.dll (Technology Nexus AB)<br />
FF Plugin: @tools.google.com/Google Update;version=3 - C:&#092;Program Files&#092;Google&#092;Update&#092;1.3.21.145&#092;npGoogleUpdate3.dll (Google Inc.)<br />
FF Plugin: @tools.google.com/Google Update;version=9 - C:&#092;Program Files&#092;Google&#092;Update&#092;1.3.21.145&#092;npGoogleUpdate3.dll (Google Inc.)<br />
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:&#092;Program Files&#092;VideoLAN&#092;VLC&#092;npvlc.dll (VideoLAN)<br />
FF Plugin: Adobe Reader - C:&#092;Program Files&#092;Adobe&#092;Reader 10.0&#092;Reader&#092;AIR&#092;nppdf32.dll (Adobe Systems Inc.)<br />
FF Extension: Visualisateur 3D de 20-20 - C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;k76wazx2.default&#092;Extensions&#092;2020Player_IKEA@2020Technologies.com<br />
FF Extension: British English Dictionary - C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;k76wazx2.default&#092;Extensions&#092;en-GB@dictionaries.addons.mozilla.org<br />
FF Extension: United States English Spellchecker - C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;k76wazx2.default&#092;Extensions&#092;en-US@dictionaries.addons.mozilla.org<br />
FF Extension: No Name - C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;k76wazx2.default&#092;Extensions&#092;{5F590AA2-1221-4113-A6F4-A4BB62414FAC}.xpi<br />
<br />
Chrome: <br />
=======<br />
CHR HomePage: hxxp://search.babylon.com/?babsrc=HP_ss&affID=101240&mntrId=56322052000000000000000000000000<br />
CHR RestoreOnStartup: "hxxp://search.babylon.com/?babsrc=HP_ss&affID=101240&mntrId=56322052000000000000000000000000"<br />
CHR DefaultSearchURL: (Search the web (Babylon)) - <a href='http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000' class='bbc_url' title='Extern länk' rel='external'>http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101240&mntrId=56322052000000000000000000000000</a><br />
CHR DefaultSuggestURL: (Search the web (Babylon)) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}<br />
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer<br />
CHR Plugin: (Native Client) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;Application&#092;23.0.1271.97&#092;ppGoogleNaClPluginChrome.dll No File<br />
CHR Plugin: (Chrome PDF Viewer) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;Application&#092;23.0.1271.97&#092;pdf.dll No File<br />
CHR Plugin: (Shockwave Flash) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;Application&#092;23.0.1271.97&#092;gcswf32.dll No File<br />
CHR Plugin: (Shockwave Flash) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;User Data&#092;PepperFlash&#092;11.2.31.144&#092;pepflashplayer.dll ()<br />
CHR Plugin: (Shockwave Flash) - C:&#092;windows&#092;system32&#092;Macromed&#092;Flash&#092;NPSWF32_11_2_202_235.dll No File<br />
CHR Plugin: (Skype Toolbars) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;User Data&#092;Default&#092;Extensions&#092;lifbcibllhkdhoafpjfnlhfpfgnpldfl&#092;5.2.0.7165_0&#092;npSkypeChromePlugin.dll (Skype Technologies S.A.)<br />
CHR Plugin: (Adobe Acrobat) - C:&#092;Program Files&#092;Adobe&#092;Reader 10.0&#092;Reader&#092;Browser&#092;nppdf32.dll (Adobe Systems Inc.)<br />
CHR Plugin: (Microsoft&#092;u00AE Windows Media Player Firefox Plugin) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;np-mswmp.dll (Microsoft Corporation)<br />
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npdeployJava1.dll No File<br />
CHR Plugin: (Java&#153; Platform SE 6 U31) - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;plugin2&#092;npjp2.dll No File<br />
CHR Plugin: (EModel scriptable Plugin) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npEModelPlugin.dll (Dassault Systèmes SolidWorks Corp.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin2.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin3.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin4.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin5.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin6.dll (Apple Computer, Inc.)<br />
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin7.dll (Apple Computer, Inc.)<br />
CHR Plugin: (DivX VOD Helper Plug-in) - C:&#092;Program Files&#092;DivX&#092;DivX OVS Helper&#092;npovshelper.dll (DivX, LLC.)<br />
CHR Plugin: (DivX Web Player) - C:&#092;Program Files&#092;DivX&#092;DivX Plus Web Player&#092;npdivx32.dll (DivX, LLC)<br />
CHR Plugin: (Google Update) - C:&#092;Program Files&#092;Google&#092;Update&#092;1.3.21.111&#092;npGoogleUpdate3.dll No File<br />
CHR Plugin: (Silverlight Plug-In) - C:&#092;Program Files&#092;Microsoft Silverlight&#092;3.0.40624.0&#092;npctrl.dll ( Microsoft Corporation)<br />
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:&#092;Program Files&#092;Microsoft&#092;Office Live&#092;npOLW.dll (Microsoft Corp.)<br />
CHR Plugin: (Nexus Personal) - C:&#092;Program Files&#092;Personal&#092;bin&#092;np_prsnl.dll (Technology Nexus AB)<br />
CHR Plugin: (Windows Live&#092;u00AE Photo Gallery) - C:&#092;Program Files&#092;Windows Live&#092;Photo Gallery&#092;NPWLPG.dll (Microsoft Corporation)<br />
CHR Plugin: (Unity Player) - C:&#092;Users&#092;Expert&#092;AppData&#092;LocalLow&#092;Unity&#092;WebPlayer&#092;loader&#092;npUnity3D32.dll (Unity Technologies ApS)<br />
CHR Extension: (Skype Extension) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;User Data&#092;Default&#092;Extensions&#092;lifbcibllhkdhoafpjfnlhfpfgnpldfl&#092;5.2.0.7165_0<br />
CHR Extension: (DivX Plus Web Player HTML5 &#092;u003Cvideo&#092;u003E) - C:&#092;Users&#092;Expert&#092;AppData&#092;Local&#092;Google&#092;Chrome&#092;User Data&#092;Default&#092;Extensions&#092;nneajnkjbffgblleaoojgaacokifdkhm&#092;2.1.2.126_0<br />
<br />
========================== Services (Whitelisted) =================<br />
<br />
S3 CoordinatorServiceHost; C:&#092;Program Files&#092;SolidWorks Corp&#092;SolidWorks&#092;swScheduler&#092;DTSCoordinatorService.exe [87336 2009-10-15] (Dassault Systèmes SolidWorks Corp.)<br />
S4 msvsmon80; C:&#092;Program Files&#092;Microsoft Visual Studio 8&#092;Common7&#092;IDE&#092;Remote Debugger&#092;x86&#092;msvsmon.exe [2799808 2005-09-23] (Microsoft Corporation)<br />
S2 NanoServiceMain; C:&#092;Program Files&#092;Panda Security&#092;Panda Cloud Antivirus&#092;PSANHost.exe [140512 2013-01-27] (Panda Security, S.L.)<br />
S2 OberonGameConsoleService; C:&#092;Program Files&#092;Samsung Casual Games&#092;GameConsole&#092;OberonGameConsoleService.exe [44312 2009-08-13] ()<br />
S3 Partner Service; C:&#092;ProgramData&#092;Partner&#092;Partner.exe [332272 2010-01-12] (Google Inc.)<br />
S2 PSUAService; C:&#092;Program Files&#092;Panda Security&#092;Panda Cloud Antivirus&#092;PSUAService.exe [37088 2013-01-27] (Panda Security, S.L.)<br />
S2 RichVideo; C:&#092;Program Files&#092;CyberLink&#092;Shared files&#092;RichVideo.exe [247152 2009-07-07] ()<br />
S3 SolidWorks Licensing Service; C:&#092;Program Files&#092;Common Files&#092;SolidWorks Shared&#092;Service&#092;SolidWorksLicensing.exe [79360 2011-09-29] (SolidWorks)<br />
<br />
==================== Drivers (Whitelisted) ====================<br />
<br />
S3 AVEO; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;AVEOdcnt.sys [318592 2012-02-08] (AVEO)<br />
S1 NNSALPC; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSAlpc.sys [82728 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSHTTP; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSHttp.sys [119080 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSHTTPS; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSHttps.sys [95584 2013-01-09] (Panda Security, S.L.)<br />
S1 NNSIDS; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSIds.sys [123944 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSNAHSL; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSNAHSL.sys [29224 2012-10-22] (Panda Security, S.L.)<br />
S1 NNSPICC; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPicc.sys [94632 2012-11-26] (Panda Security, S.L.)<br />
S4 NNSPIHSW; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPihsw.sys [60968 2012-11-28] (Panda Security, S.L.)<br />
S1 NNSPOP3; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPop3.sys [105640 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSPROT; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSProt.sys [286888 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSPRV; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPrv.sys [159528 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSSMTP; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSSmtp.sys [108200 2012-11-26] (Panda Security, S.L.)<br />
S1 NNSSTRM; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSStrm.sys [218024 2012-11-28] (Panda Security, S.L.)<br />
S1 NNSTLSC; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSTlsc.sys [93096 2012-11-26] (Panda Security, S.L.)<br />
S2 PSINAflt; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINAflt.sys [149544 2012-11-09] (Panda Security, S.L.)<br />
S2 PSINFile; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINFile.sys [104488 2012-11-09] (Panda Security, S.L.)<br />
S1 PSINKNC; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;psinknc.sys [174632 2012-11-09] (Panda Security, S.L.)<br />
S2 PSINProc; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINProc.sys [114216 2012-11-09] (Panda Security, S.L.)<br />
S2 PSINProt; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINProt.sys [123944 2012-11-09] (Panda Security, S.L.)<br />
S1 SABI; C:&#092;windows&#092;system32&#092;Drivers&#092;SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS)<br />
S3 hwdatacard; system32&#092;DRIVERS&#092;ewusbmdm.sys [x]<br />
S3 hwusbdev; system32&#092;DRIVERS&#092;ewusbdev.sys [x]<br />
S3 massfilter; system32&#092;DRIVERS&#092;massfilter.sys [x]<br />
S3 massfilter_hs; system32&#092;drivers&#092;massfilter_hs.sys [x]<br />
S3 ZTEusbmdm6k; system32&#092;DRIVERS&#092;ZTEusbmdm6k.sys [x]<br />
S3 ZTEusbnet; system32&#092;DRIVERS&#092;ZTEusbnet.sys [x]<br />
S3 ZTEusbnmea; system32&#092;DRIVERS&#092;ZTEusbnmea.sys [x]<br />
S3 ZTEusbser6k; system32&#092;DRIVERS&#092;ZTEusbser6k.sys [x]<br />
<br />
========================== Drivers MD5 =======================<br />
<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;1394ohci.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;ACPI.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;acpipmi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;adp94xx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;adpahci.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;adpu320.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;afd.sys 9EBBBA55060F786F0FCAA3893BFA2806<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;agp440.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;djsvs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;aliide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;amdagp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;amdide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;amdk8.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;amdppm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;amdsata.sys D320BF87125326F996D4904FE24300FC<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;amdsbs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;appid.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;arc.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;arcsas.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;asyncmac.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;atapi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;athr.sys EE32C0A39B6D3D0834C4D46D8C45E1D0<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;AVEOdcnt.sys 4CEBFB8FC39544033DC1CA644B2162FA<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;bxvbdx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;b57nd60x.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Beep.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;blbdrive.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;bowser.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;BrFiltLo.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;BrFiltUp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Brserid.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;BrSerWdm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;BrUsbMdm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;BrUsbSer.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;bthmodem.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;cdfs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;cdrom.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;circlass.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;CLFS.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;CmBatt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;cmdide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;cng.sys 247B4CE2DAB1160CD422D532D5241E1F<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;compbatt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;CompositeBus.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;crcdisk.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;dfsc.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;discache.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;disk.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;drmkaud.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;dxgkrnl.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;evbdx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;elxstor.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;errdev.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;exfat.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;fastfat.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;fdc.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;fileinfo.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;filetrace.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;flpydisk.sys ==&gt; MD5 is legitB<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;fltmgr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;FsDepends.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;fssfltr.sys B74B0578FD1D3F897E95F2A2B69EA051<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;fvevol.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;gagp30kx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;hcw85cir.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;HdAudio.sys A5EF29D5315111C80A5C1ABAD14C8972<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;HDAudBus.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;HidBatt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;hidbth.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;hidir.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;hidusb.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;HpSAMD.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;HTTP.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;hwpolicy.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;i8042prt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;iaStor.sys 0BAA4115DFFFD6A6D809A89D65E1281A<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;igdkmd32.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;iirsp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;RTKVHDA.sys 96282FBCE4534C9BF147CFFE9E1FA8DB<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;IntcHdmi.sys 264632ADE8127B7BAA2190CF6FAD435B<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;intelide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;intelppm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ipfltdrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;IPMIDrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;ipnat.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;irenum.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;isapnp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;msiscsi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;kbdclass.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;kbdhid.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;ksecdd.sys B7895B4182C0D16F6EFADEB8081E8D36<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;ksecpkg.sys D30159AC9237519FBC62C6EC247D2D46<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;lltdio.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;lsi_fc.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;lsi_sas.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;lsi_sas2.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;lsi_scsi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;luafv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;megasas.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;MegaSR.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;modem.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;monitor.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;mouclass.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;mouhid.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;mountmgr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;mpio.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;mpsdrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;mrxdav.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;mrxsmb.sys 5D16C921E3671636C0EBA3BBAAC5FD25<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;mrxsmb10.sys 6D17A4791ACA19328C685D256349FEFC<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;mrxsmb20.sys B81F204D146000BE76651A50670A5E9E<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;msahci.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;msdsm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Msfs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;mshidkmdf.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;msisadrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;MSKSSRV.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;MSPCLOCK.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;MSPQM.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;MsRPC.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;mssmbios.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;MSTEE.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;MTConfig.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;mup.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;nwifi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;ndis.sys 8C9C922D71F1CD4DEF73F186416B7896<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ndiscap.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ndistapi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ndisuio.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ndiswan.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;NDProxy.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;netbios.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;netbt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;nfrd960.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSAlpc.sys DD834264C3A3C3B12333CE27AE2F4BE5<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSHttp.sys 15D5A84DCF62E51201DE338C2E057FBE<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSHttps.sys B8EF512752407FB3A2B0E57E1DB33ED8<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSIds.sys 7725EBE34AFC990015255768BEB2FA3E<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSNAHSL.sys FEE70AB8FBA7A2A0304070850801B035<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPicc.sys 59C95C55ECD98AA167038DE29CD5D994<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPihsw.sys 8B602236D4B7A8785F6087D50B95286D<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPop3.sys 81955B1424B4355DDFE2EBAF98F188C7<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSProt.sys 7F7584B99174061B3964146EBD212CA9<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSPrv.sys 82A1E37F372085518ED4322D99A4FAEF<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSSmtp.sys A8266DEAF8643A8E060E08B73FFD6114<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSStrm.sys 82EFF92A4CCB8288D993F5B4A0C53F2E<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;NNSTlsc.sys 418402FE2C590B92942CC98ED254FF6C<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Npfs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;nsiproxy.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Ntfs.sys 0D87503986BB3DFED58E343FE39DDE13<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;Null.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;nvraid.sys B3E25EE28883877076E0E1FF877D02E0<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;nv_agp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;ohci1394.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;parport.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;parvdm.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;pci.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;pciide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;pcmcia.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;pcw.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;peauth.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;raspptp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;processr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;pacer.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINAflt.sys 50B5B13DDDC8775E03C4408817757213<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINFile.sys E339A77ADA178CB428168DF06F20CFB6<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;psinknc.sys B1447062C65829066BB1C526DAEEB2DF<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINProc.sys A44A3B9F7BCB58BC6601874F514A12B0<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;PSINProt.sys DE283A666A070ACC371BFBCEA07DA024<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;ql2300.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;ql40xx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;qwavedrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;rasacd.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;AgileVpn.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;rasl2tp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;raspppoe.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;rassstp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;rdbss.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;rdpbus.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;RDPCDD.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;rdpencdd.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;rdprefmp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;RDPWD.sys F031683E6D1FEA157ABB2FF260B51E61<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;rdyboost.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;rspndr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;Rt86win7.sys 7DFD48E24479B68B258D8770121155A0<br />
C:&#092;windows&#092;system32&#092;Drivers&#092;SABI.sys 6E5FBB7CBAEC47038B945D5E9B144A64<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;sbp2port.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;scfilter.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;secdrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;serenum.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;serial.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;sermouse.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;sffdisk.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;sffp_mmc.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;sffp_sd.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;sfloppy.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;sisagp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;SiSRaid2.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;sisraid4.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;smb.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;spldr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;srv.sys E4C2764065D66EA1D2D3EBC28FE99C46<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;stexstor.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;swenum.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;SynTP.sys 215A45246C6E2D0A9C263CE1786C8D8A<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;tcpip.sys E23A56F843E2AEBBB209D0ACCA73C640<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;tcpip.sys E23A56F843E2AEBBB209D0ACCA73C640<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;tdpipe.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;tdx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;termdd.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;tssecsrv.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;tsusbflt.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;tunnel.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;uagp35.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;udfs.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;uliagpkx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;umbus.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;umpass.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;usbccgp.sys BD9C55D7023C5DE374507ACC7A14E2AC<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;usbcir.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;usbehci.sys F92DE757E4B7CE9C07C5E65423F3AE3B<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;usbhub.sys 8DC94AEC6A7E644A06135AE7506DC2E9<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;usbohci.sys E185D44FAC515A18D9DEDDC23C2CDF44<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;usbprint.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;USBSTOR.SYS F991AB9CC6B908DB552166768176896A<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;usbuhci.sys 68DF884CF41CDADA664BEB01DAF67E3D<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;usbvideo.sys 45F4E7BF43DB40A6C6B4D92C76CBC3F2<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;vdrvroot.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;vgapnp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;vga.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;vhdmp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;viaagp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;viac7.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;viaide.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;volmgr.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;volmgrx.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;volsnap.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;vsmraid.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;vwifibus.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;vwififlt.sys 7090D3436EEB4E7DA3373090A23448F7<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;vwifimp.sys A3F04CBEA6C2A10E6CB01F8B47611882<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;wacompen.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;wanarp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;wanarp.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;DRIVERS&#092;wd.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;Wdf01000.sys A840213F1ACDCC175B4D1D5AAEAC0D7A<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;wfplwf.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;wimmount.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;wmiacpi.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;system32&#092;drivers&#092;ws2ifsl.sys ==&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;drivers&#092;WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF<br />
C:&#092;Windows&#092;System32&#092;DRIVERS&#092;yk62x86.sys B07C5B7EFDF936FF93D4F540938725BE<br />
<br />
==================== NetSvcs (Whitelisted) ===================<br />
<br />
<br />
==================== One Month Created Files and Folders ========<br />
<br />
2013-06-02 09:18 - 2013-06-02 09:18 - 00000000 ____D C:&#092;FRST<br />
2013-06-01 23:11 - 2013-06-01 23:33 - 00000004 ____A C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;skype.ini<br />
2013-05-31 11:16 - 2013-05-31 11:28 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part01(1).rar<br />
2013-05-29 14:35 - 2013-05-29 14:38 - 00000000 ____D C:&#092;Users&#092;Expert&#092;Desktop&#092;Anna<br />
2013-05-27 11:51 - 2013-05-27 11:51 - 00014060 ____A C:&#092;Users&#092;Expert&#092;Documents&#092;Untitled 1.odt<br />
2013-05-27 11:51 - 2013-05-27 11:51 - 00014060 ____A C:&#092;Users&#092;Expert&#092;Desktop&#092;Installationstips.odt<br />
2013-05-27 10:08 - 2013-05-27 10:08 - 00060386 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;[kat.ph]solidworks.2013.sp3.0.32.bit.64.bit.multi.torrent<br />
2013-05-27 09:49 - 2013-05-27 09:49 - 00222384 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;SolidWorks.2012.SP5.0.WIN64.Multilanguage.Integrated.ISOSolidSQUAD.part01.exe<br />
2013-05-09 11:44 - 2013-05-09 11:56 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part02.rar<br />
2013-05-08 21:51 - 2013-05-08 22:03 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part01.rar<br />
2013-05-08 13:22 - 2013-05-08 13:35 - 307200001 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;Felicitas.part2.rar<br />
2013-05-07 23:08 - 2013-05-07 23:23 - 307200001 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;Felicitas.part1.rar<br />
<br />
==================== One Month Modified Files and Folders ========<br />
<br />
2013-06-02 09:18 - 2013-06-02 09:18 - 00000000 ____D C:&#092;FRST<br />
2013-06-02 09:16 - 2010-01-13 03:39 - 00625756 ____A C:&#092;Windows&#092;System32&#092;perfh01D.dat<br />
2013-06-02 09:16 - 2010-01-13 03:39 - 00123910 ____A C:&#092;Windows&#092;System32&#092;perfc01D.dat<br />
2013-06-02 09:16 - 2009-07-26 22:06 - 01466674 ____A C:&#092;Windows&#092;System32&#092;PerfStringBackup.INI<br />
2013-06-01 23:34 - 2010-01-12 09:56 - 01548060 ____A C:&#092;Windows&#092;WindowsUpdate.log<br />
2013-06-01 23:33 - 2013-06-01 23:11 - 00000004 ____A C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;skype.ini<br />
2013-06-01 23:22 - 2010-07-06 00:05 - 00001008 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-655814321-1652077291-3099334160-1000UA.job<br />
2013-06-01 23:22 - 2009-07-14 06:34 - 00014736 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0<br />
2013-06-01 23:22 - 2009-07-14 06:34 - 00014736 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0<br />
2013-06-01 23:19 - 2010-07-06 00:03 - 00000978 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineCore.job<br />
2013-06-01 23:15 - 2009-07-14 06:53 - 00000006 ___AH C:&#092;Windows&#092;Tasks&#092;SA.DAT<br />
2013-06-01 23:15 - 2009-07-14 06:39 - 00171565 ____A C:&#092;Windows&#092;setupact.log<br />
2013-06-01 23:09 - 2010-07-06 00:03 - 00000982 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineUA.job<br />
2013-06-01 22:56 - 2012-05-20 09:55 - 00000868 ____A C:&#092;Windows&#092;Tasks&#092;Adobe Flash Player Updater.job<br />
2013-06-01 13:22 - 2010-07-06 00:05 - 00000956 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-655814321-1652077291-3099334160-1000Core.job<br />
2013-05-31 11:39 - 2012-08-18 09:59 - 00000000 ____D C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;vlc<br />
2013-05-31 11:28 - 2013-05-31 11:16 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part01(1).rar<br />
2013-05-29 14:38 - 2013-05-29 14:35 - 00000000 ____D C:&#092;Users&#092;Expert&#092;Desktop&#092;Anna<br />
2013-05-27 19:59 - 2011-04-26 15:32 - 00000000 ____D C:&#092;Users&#092;Expert&#092;Desktop&#092;MILab<br />
2013-05-27 19:08 - 2010-08-04 19:26 - 00000000 ____D C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;tixati<br />
2013-05-27 11:51 - 2013-05-27 11:51 - 00014060 ____A C:&#092;Users&#092;Expert&#092;Documents&#092;Untitled 1.odt<br />
2013-05-27 11:51 - 2013-05-27 11:51 - 00014060 ____A C:&#092;Users&#092;Expert&#092;Desktop&#092;Installationstips.odt<br />
2013-05-27 10:08 - 2013-05-27 10:08 - 00060386 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;[kat.ph]solidworks.2013.sp3.0.32.bit.64.bit.multi.torrent<br />
2013-05-27 09:49 - 2013-05-27 09:49 - 00222384 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;SolidWorks.2012.SP5.0.WIN64.Multilanguage.Integrated.ISOSolidSQUAD.part01.exe<br />
2013-05-24 12:23 - 2010-07-06 00:07 - 00002369 ____A C:&#092;Users&#092;Expert&#092;Desktop&#092;Google Chrome.lnk<br />
2013-05-24 07:29 - 2011-11-02 14:20 - 00000000 ____A C:&#092;END<br />
2013-05-23 06:17 - 2012-04-28 13:58 - 00000000 ____D C:&#092;Program Files&#092;Mozilla Maintenance Service<br />
2013-05-18 01:03 - 2013-02-20 00:14 - 00000000 ____D C:&#092;Program Files&#092;Mozilla Firefox<br />
2013-05-15 11:56 - 2012-05-20 09:55 - 00692104 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;System32&#092;FlashPlayerApp.exe<br />
2013-05-15 11:56 - 2011-05-22 18:31 - 00071048 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;System32&#092;FlashPlayerCPLApp.cpl<br />
2013-05-09 11:56 - 2013-05-09 11:44 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part02.rar<br />
2013-05-08 22:03 - 2013-05-08 21:51 - 307200002 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;smm.part01.rar<br />
2013-05-08 13:35 - 2013-05-08 13:22 - 307200001 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;Felicitas.part2.rar<br />
2013-05-07 23:23 - 2013-05-07 23:08 - 307200001 ____A C:&#092;Users&#092;Expert&#092;Downloads&#092;Felicitas.part1.rar<br />
<br />
Files to move or delete:<br />
====================<br />
C:&#092;ProgramData&#092;FullRemove.exe<br />
C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;skype.dat<br />
C:&#092;Users&#092;Expert&#092;AppData&#092;Roaming&#092;skype.ini<br />
<br />
==================== Bamital & volsnap Check =================<br />
<br />
C:&#092;Windows&#092;explorer.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;winlogon.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;wininit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;svchost.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;services.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;User32.dll =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;userinit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;volsnap.sys =&gt; MD5 is legit<br />
<br />
==================== BCD ================================<br />
<br />
Starthanteraren<br />
---------------<br />
identifier          	{bootmgr}<br />
device              	partition=&#092;Device&#092;HarddiskVolume2<br />
description         	Windows Boot Manager<br />
locale              	sv-SE<br />
inherit             	{globalsettings}<br />
default             	{current}<br />
resumeobject        	{b2623872-ffe1-11de-97b1-0024543ac06f}<br />
displayorder        	{current}<br />
toolsdisplayorder   	{memdiag}<br />
timeout             	30<br />
<br />
Startinl„saren<br />
--------------<br />
identifier          	{current}<br />
device              	partition=C:<br />
path                	&#092;windows&#092;system32&#092;winload.exe<br />
description         	Windows 7<br />
locale              	sv-SE<br />
inherit             	{bootloadersettings}<br />
recoverysequence    	{b2623874-ffe1-11de-97b1-0024543ac06f}<br />
recoveryenabled     	Yes<br />
osdevice            	partition=C:<br />
systemroot          	&#092;windows<br />
resumeobject        	{b2623872-ffe1-11de-97b1-0024543ac06f}<br />
nx                  	OptIn<br />
numproc             	2<br />
quietboot           	Yes<br />
usefirmwarepcisettings  No<br />
<br />
Startinl„saren<br />
--------------<br />
identifier          	{b2623874-ffe1-11de-97b1-0024543ac06f}<br />
device              	ramdisk=[C:]&#092;Recovery&#092;b2623874-ffe1-11de-97b1-0024543ac06f&#092;Winre.wim,{b2623875-ffe1-11de-97b1-0024543ac06f}<br />
path                	&#092;windows&#092;system32&#092;winload.exe<br />
description         	Windows Recovery Environment<br />
inherit             	{bootloadersettings}<br />
osdevice            	ramdisk=[C:]&#092;Recovery&#092;b2623874-ffe1-11de-97b1-0024543ac06f&#092;Winre.wim,{b2623875-ffe1-11de-97b1-0024543ac06f}<br />
systemroot          	&#092;windows<br />
nx                  	OptIn<br />
winpe               	Yes<br />
<br />
Start fr†n vilol„ge<br />
-------------------<br />
identifier          	{b2623872-ffe1-11de-97b1-0024543ac06f}<br />
device              	partition=C:<br />
path                	&#092;windows&#092;system32&#092;winresume.exe<br />
description         	Windows Resume Application<br />
locale              	sv-SE<br />
inherit             	{resumeloadersettings}<br />
filedevice          	partition=C:<br />
filepath            	&#092;hiberfil.sys<br />
pae                 	No<br />
debugoptionenabled  	No<br />
<br />
Minnestestaren<br />
--------------<br />
identifier          	{memdiag}<br />
device              	partition=&#092;Device&#092;HarddiskVolume2<br />
path                	&#092;boot&#092;memtest.exe<br />
description         	Windows Memory Diagnostic<br />
locale              	sv-SE<br />
inherit             	{globalsettings}<br />
badmemoryaccess     	Yes<br />
<br />
EMS-inst„llningar<br />
-----------------<br />
identifier          	{emssettings}<br />
bootems             	Yes<br />
<br />
Inst„llningar f”r fels”kare<br />
---------------------------<br />
identifier          	{dbgsettings}<br />
debugtype           	Serial<br />
debugport           	1<br />
baudrate            	115200<br />
<br />
RAM-fel<br />
-------<br />
identifier          	{badmemory}<br />
<br />
Globala inst„llningar<br />
---------------------<br />
identifier          	{globalsettings}<br />
inherit             	{dbgsettings}<br />
                    	{emssettings}<br />
                    	{badmemory}<br />
<br />
Inst„llningar f”r Startinl„saren<br />
------------------------------<br />
identifier          	{bootloadersettings}<br />
inherit             	{globalsettings}<br />
                    	{hypervisorsettings}<br />
<br />
Hypervisorinst„llningar<br />
-------------------<br />
identifier          	{hypervisorsettings}<br />
hypervisordebugtype 	Serial<br />
hypervisordebugport 	1<br />
hypervisorbaudrate  	115200<br />
<br />
terst„ll inst„llningar f”r inl„saren<br />
-------------------------------------<br />
identifier          	{resumeloadersettings}<br />
inherit             	{globalsettings}<br />
<br />
Enhetsalternativ<br />
----------------<br />
identifier          	{b2623875-ffe1-11de-97b1-0024543ac06f}<br />
description         	Ramdisk Options<br />
ramdisksdidevice    	partition=C:<br />
ramdisksdipath      	&#092;Recovery&#092;b2623874-ffe1-11de-97b1-0024543ac06f&#092;boot.sdi<br />
<br />
<br />
<br />
Last Boot: 2013-05-24 00:01<br />
<br />
==================== End Of Log ============================<br />
<br />
<br />
<br />
<br />
<br />
Hjälp för att lösa detta mottages TACKSAMT !!<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade filer</h4>
	<ul>
		
			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17522" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17522" title="Ladda ner bilaga">FRST.txt</a> <span class='desc'><strong>(42Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 0</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 02 Jun 2013 10:41:11 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341660-hjalp-med-att-anvanda-frst-pa-polis-virus/</guid>
	</item>
	<item>
		<title>Problem med datorn</title>
		<link>http://eforum.idg.se/topic/341657-problem-med-datorn/</link>
		<description><![CDATA[Nu krånglar datorn igen, vet ej varför. Bluestack verkar vara ett av problemen. Datorn är dessutom ruskigt seg och hårddiskminne äts upp, har under 4-6 mån försvunnit ungefär 30gb och det jag laddat ner har givetvis inte motsvarat det minne som försvunnit. Just nu har jag 500mb vilket givetvis är på tok för lite<br />
<br />
DDS-logg<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 9.0.8112.16483  BrowserJavaVersion: 10.7.2<br />
Run by Dan at 8:51:51 on 2013-06-02<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:&#092;Windows&#092;system32&#092;lsm.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k DcomLaunch<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;COMODO&#092;launcher_service.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k RPCSS<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkService<br />
C:&#092;Windows&#092;system32&#092;atiesrxx.exe<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalServiceNetworkRestricted<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalSystemNetworkRestricted<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k netsvcs<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalService<br />
C:&#092;Windows&#092;system32&#092;atieclxx.exe<br />
C:&#092;Windows&#092;system32&#092;Dwm.exe<br />
C:&#092;Windows&#092;Explorer.EXE<br />
C:&#092;Windows&#092;system32&#092;WLANExt.exe<br />
C:&#092;Windows&#092;System32&#092;spoolsv.exe<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Program Files&#092;Realtek&#092;Audio&#092;HDA&#092;RtkNGUI64.exe<br />
C:&#092;Windows&#092;system32&#092;taskhost.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;sched.exe<br />
C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;AthBtTray.exe<br />
C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cfp.exe<br />
C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;Personal.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceNoNetwork<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPMSGSVC.exe<br />
C:&#092;Program Files (x86)&#092;OpenOffice.org 3&#092;program&#092;soffice.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP On Screen Display&#092;HPOSD.exe<br />
C:&#092;Program Files (x86)&#092;Winamp&#092;winampa.exe<br />
C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;avgnt.exe<br />
C:&#092;Program Files (x86)&#092;COMODO&#092;GeekBuddy&#092;unit_manager.exe<br />
C:&#092;Program Files (x86)&#092;OpenOffice.org 3&#092;program&#092;soffice.bin<br />
C:&#092;Program Files (x86)&#092;COMODO&#092;GeekBuddy&#092;unit.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe<br />
C:&#092;Program Files (x86)&#092;DivX&#092;DivX Update&#092;DivXUpdate.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;armsvc.exe<br />
C:&#092;Program Files&#092;ATI Technologies&#092;ATI.ACE&#092;Reservation Manager&#092;AMD Reservation Manager.exe<br />
C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;avguard.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;COMODO&#092;GeekBuddyRSP.exe<br />
C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;Ath_CoexAgent.exe<br />
C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;adminservice.exe<br />
C:&#092;Windows&#092;System32&#092;lpksetup.exe<br />
C:&#092;Program Files (x86)&#092;BlueStacks&#092;HD-LogRotatorService.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceAndNoImpersonation<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;COMODO&#092;GeekBuddyRSP.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPWMISVC.exe<br />
C:&#092;Program Files (x86)&#092;PDF Complete&#092;pdfsvc.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k imgsvc<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSVC.EXE<br />
C:&#092;Program Files&#092;ATI Technologies&#092;ATI.ACE&#092;Fuel&#092;Fuel.Service.exe<br />
C:&#092;Program Files (x86)&#092;BlueStacks&#092;HD-Service.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSvcM.exe<br />
C:&#092;Program Files (x86)&#092;BlueStacks&#092;HD-Network.exe<br />
C:&#092;Program Files (x86)&#092;BlueStacks&#092;HD-BlockDevice.exe<br />
C:&#092;Program Files (x86)&#092;BlueStacks&#092;HD-SharedFolder.exe<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Program Files (x86)&#092;CyberLink&#092;YouCam&#092;YCMMirage.exe<br />
C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;avshadow.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k bthsvcs<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkServiceNetworkRestricted<br />
C:&#092;Windows&#092;system32&#092;SearchIndexer.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Shared&#092;hpqWmiEx.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;hpsa_service.exe<br />
C:&#092;Program Files&#092;Windows Media Player&#092;wmpnetwk.exe<br />
C:&#092;Windows&#092;system32&#092;SearchProtocolHost.exe<br />
C:&#092;Windows&#092;system32&#092;UI0Detect.exe<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalServicePeerNet<br />
C:&#092;Windows&#092;system32&#092;taskhost.exe<br />
C:&#092;Windows&#092;Microsoft.Net&#092;Framework64&#092;v3.0&#092;WPF&#092;PresentationFontCache.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPHelper.exe<br />
C:&#092;Program Files (x86)&#092;Opera&#092;opera.exe<br />
C:&#092;Windows&#092;system32&#092;SearchFilterHost.exe<br />
C:&#092;Windows&#092;system32&#092;wuauclt.exe<br />
C:&#092;Program Files (x86)&#092;Last.fm&#092;Last.fm Scrobbler.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Windows&#092;System32&#092;cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
BHO: DivX Plus Web Player HTML5 &lt;video&gt;: {326E768D-4182-46FD-9C16-1449A49795F4} - C:&#092;Program Files (x86)&#092;DivX&#092;DivX Plus Web Player&#092;ie&#092;DivXHTML5&#092;DivXHTML5.dll<br />
BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;ssv.dll<br />
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;IEPlugIn.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files (x86)&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Companion&#092;companioncore.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;jp2ssv.dll<br />
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - <br />
uRun: [msnmsgr] "C:&#092;Program Files (x86)&#092;Windows Live&#092;Messenger&#092;msnmsgr.exe" /background<br />
mRun: [StartCCC] "C:&#092;Program Files (x86)&#092;ATI Technologies&#092;ATI.ACE&#092;Core-Static&#092;CLIStart.exe" MSRun<br />
mRun: [HP Quick Launch] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPMSGSVC.exe<br />
mRun: [PDF Complete] C:&#092;Program Files (x86)&#092;PDF Complete&#092;pdfsty.exe<br />
mRun: [HPOSD] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP On Screen Display&#092;HPOSD.exe<br />
mRun: [WinampAgent] "C:&#092;Program Files (x86)&#092;Winamp&#092;winampa.exe"<br />
mRun: [avgnt] "C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;avgnt.exe" /min<br />
mRun: [SunJavaUpdateSched] "C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe"<br />
mRun: [DivXMediaServer] C:&#092;Program Files (x86)&#092;DivX&#092;DivX Media Server&#092;DivXMediaServer.exe<br />
mRun: [DivXUpdate] "C:&#092;Program Files (x86)&#092;DivX&#092;DivX Update&#092;DivXUpdate.exe" /CHECKNOW<br />
mRun: [Adobe ARM] "C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe"<br />
mRun: [gbrspcontrol] "C:&#092;Program Files (x86)&#092;Common Files&#092;COMODO&#092;GeekBuddyRSP.exe" -controlservice -slave<br />
uPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Companion&#092;companioncore.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Writer&#092;WriterBrowserExtension.dll<br />
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;Resources&#092;HPNetworkCheck&#092;NCLauncherFromIE.exe<br />
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;IEPlugIn.dll<br />
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:&#092;Program Files (x86)&#092;Evernote&#092;Evernote&#092;EvernoteIE.dll/204<br />
TCP: NameServer = 192.168.1.1<br />
TCP: Interfaces&#092;{0897557E-D04E-45A1-86E9-B1DFD79DC7F4} : DHCPNameServer = 192.168.1.1<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C} : NameServer = 8.26.56.26,156.154.70.22<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C} : DHCPNameServer = 192.168.1.1<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C}&#092;27563656074796F6E623 : NameServer = 8.26.56.26,156.154.70.22<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C}&#092;27563656074796F6E623 : DHCPNameServer = 192.168.1.1<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C}&#092;3547F62716E60205C616E623 : NameServer = 8.26.56.26,156.154.70.22<br />
TCP: Interfaces&#092;{16B07F8C-ECE5-4B00-8DF8-78EC59C6FD2C}&#092;3547F62716E60205C616E623 : DHCPNameServer = 10.35.4.1<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;Program Files (x86)&#092;Common Files&#092;Skype&#092;Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Photo Gallery&#092;AlbumDownloadProtocolHandler.dll<br />
AppInit_DLLs= C:&#092;Windows&#092;SysWOW64&#092;guard32.dll<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />
x64-BHO: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <br />
x64-Run: [RTHDVCPL] C:&#092;Program Files&#092;Realtek&#092;Audio&#092;HDA&#092;RtkNGUI64.exe -s<br />
x64-Run: [SynTPEnh] C:&#092;Program Files (x86)&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
x64-Run: [AtherosBtStack] "C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;BtvStack.exe"<br />
x64-Run: [AthBtTray] "C:&#092;Program Files (x86)&#092;Bluetooth Suite&#092;AthBtTray.exe"<br />
x64-Run: [HPWirelessAssistant] C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Wireless Assistant&#092;DelayedAppStarter.exe 120 C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Wireless Assistant&#092;HPWA_Main.exe /hidden<br />
x64-Run: [COMODO Internet Security] "C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cfp.exe" -h<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:&#092;Users&#092;Dan&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;xv4e85lg.default&#092;<br />
FF - prefs.js: browser.startup.homepage - hxxp://wb865394.one.se/voffsingarna/<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 11.0&#092;Reader&#092;AIR&#092;nppdf32.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;DivX&#092;DivX OVS Helper&#092;npovshelper.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;DivX&#092;DivX Plus Web Player&#092;npdivx32.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;plugin2&#092;npjp2.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Microsoft Silverlight&#092;5.1.20125.0&#092;npctrlui.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;np_prsnl.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;WildTangent Games&#092;App&#092;BrowserIntegration&#092;Registered&#092;1&#092;NP_wtapp.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Windows Live&#092;Photo Gallery&#092;NPWLPG.dll<br />
FF - plugin: C:&#092;ProgramData&#092;Zylom&#092;ZylomGamesPlayer&#092;npzylomgamesplayer.dll<br />
FF - plugin: C:&#092;Windows&#092;SysWOW64&#092;Macromed&#092;Flash&#092;NPSWF32_11_7_700_202.dll<br />
FF - plugin: C:&#092;Windows&#092;SysWOW64&#092;npDeployJava1.dll<br />
FF - plugin: C:&#092;Windows&#092;SysWOW64&#092;npmproxy.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R? AERTFilters;Andrea RT Filters Service<br />
R? CFRMD;CFRMD<br />
R? fssfltr;fssfltr<br />
R? fsssvc;Windows Live Family Safety Service<br />
R? GamesAppService;GamesAppService<br />
R? HP Wireless Assistant Service;HP Wireless Assistant Service<br />
R? IconMan_R;IconMan_R<br />
R? RTL8167;Realtek 8167 NT Driver<br />
R? SkypeUpdate;Skype Updater<br />
R? SrvHsfHDA;SrvHsfHDA<br />
R? SrvHsfV92;SrvHsfV92<br />
R? SrvHsfWinac;SrvHsfWinac<br />
R? TsUsbFlt;TsUsbFlt<br />
R? TsUsbGD;Remote Desktop Generic USB Device<br />
R? WatAdminSvc;Aktiveringsteknologier f”r Windows-tj„nst<br />
R? wlcrasvc;Windows Live Mesh remote connections service<br />
R? XobniService;XobniService<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-06-02 05:32:20	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{3CD1D431-650C-4C4B-B304-236D5176D937}<br />
2013-06-01 16:43:03	--------	d-----w-	C:&#092;Program Files (x86)&#092;BlueStacks<br />
2013-06-01 16:41:40	--------	d-----w-	C:&#092;ProgramData&#092;BlueStacksSetup<br />
2013-06-01 16:41:37	--------	d-----w-	C:&#092;ProgramData&#092;BlueStacks<br />
2013-06-01 07:02:42	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{674D5CBE-127B-4BFB-BDAA-384FC919BF2B}<br />
2013-05-31 15:17:47	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{FAA08ABC-4569-4A96-8E15-E917294AA4E1}<br />
2013-05-30 14:19:46	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{C1C551CD-0D7D-46D4-A7F1-8B0857694C2B}<br />
2013-05-29 20:05:21	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{28C4D2AE-906D-4357-86EB-016B9ED746E8}<br />
2013-05-28 20:32:30	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{76B17B6A-3EF2-43C5-837B-DAF24F0B88FE}<br />
2013-05-28 06:32:29	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{E0069704-2AB4-4CDE-87AA-B570DC8933A1}<br />
2013-05-27 09:24:59	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{A8027A8C-55EA-4340-BC67-71610D45C08C}<br />
2013-05-26 20:56:49	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{009446B3-6ACB-409E-84D3-89527AD9F554}<br />
2013-05-26 06:04:14	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{CCBE07F4-8373-416D-A632-3B4407742D87}<br />
2013-05-25 07:33:23	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{676D4DC2-7F7F-4BEE-8A58-6017A78D3AD4}<br />
2013-05-24 14:24:08	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{E7312527-58EC-447B-AD19-70B18BD62AEA}<br />
2013-05-23 16:19:05	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{A8D80755-C0F7-4E90-A454-14867CB8CF49}<br />
2013-05-22 08:00:28	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{A1814FDD-C0B5-4FDF-95C1-32D28D09BA0F}<br />
2013-05-21 19:59:52	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{8BDF8719-5873-4F1D-B24F-B07805188FDE}<br />
2013-05-21 07:46:02	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{40784459-6CA1-4600-A549-94AE687B3840}<br />
2013-05-20 19:45:06	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{8093B20B-73D5-4C62-B23D-6A8528394DBF}<br />
2013-05-19 18:01:58	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{BE6216E8-E27B-48D1-B0CD-11E15DBB6F1D}<br />
2013-05-19 05:59:27	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{BB691B3A-856F-4963-9F09-7D7F1DF52690}<br />
2013-05-18 09:00:24	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{88AE2BD2-7CD0-4DA3-97BE-045FB6994D14}<br />
2013-05-17 20:57:47	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{A66340CB-218D-40FC-A6F5-A55E3C0DECA4}<br />
2013-05-17 11:24:21	2382848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;mshtml.tlb<br />
2013-05-17 11:24:21	2382848	----a-w-	C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-05-17 11:03:36	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{F5F73ADE-68CA-43EE-9851-0DA409CF6A0E}<br />
2013-05-16 10:06:30	983400	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;dxgkrnl.sys<br />
2013-05-16 10:06:30	265064	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;dxgmms1.sys<br />
2013-05-16 10:06:30	144384	----a-w-	C:&#092;Windows&#092;System32&#092;cdd.dll<br />
2013-05-16 10:06:04	1930752	----a-w-	C:&#092;Windows&#092;System32&#092;authui.dll<br />
2013-05-16 10:06:03	1796096	----a-w-	C:&#092;Windows&#092;SysWow64&#092;authui.dll<br />
2013-05-16 10:06:03	111448	----a-w-	C:&#092;Windows&#092;System32&#092;consent.exe<br />
2013-05-16 10:06:02	70144	----a-w-	C:&#092;Windows&#092;System32&#092;appinfo.dll<br />
2013-05-16 10:05:52	3153920	----a-w-	C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-05-16 09:55:43	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{C3A5B61E-2B82-4293-B884-0678D66CDFFB}<br />
2013-05-15 14:52:44	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{03A42D5E-BDE8-47FF-BCCA-5312CB348906}<br />
2013-05-14 07:58:15	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{B9D2DEF3-BE73-4EB6-8749-CC04F60B2C9F}<br />
2013-05-13 07:52:23	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{F8E19831-0ADD-418A-9F6A-73FFE1ED9BE1}<br />
2013-05-12 03:46:12	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{CE183B44-2C18-4BDE-A3C5-E21514E9C802}<br />
2013-05-11 08:40:11	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{D8A62C1E-348E-4C82-9F6F-526073375455}<br />
2013-05-10 10:57:28	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{715FADDB-0194-453A-BF92-068FFC22C3D5}<br />
2013-05-10 08:35:04	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{3DF24530-DB76-45B2-9C23-61410A0BDDB3}<br />
2013-05-09 09:03:59	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{BF6F30D8-CB22-4ADA-9822-986EE345153B}<br />
2013-05-08 07:36:07	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{9DA0792D-97ED-4676-A5AF-1AE29F46D9A5}<br />
2013-05-07 09:58:11	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{7AC23B56-C156-4E81-BF05-1825EDD43627}<br />
2013-05-06 07:39:22	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{9F8CE99E-6CAF-42D4-A0AB-54C8EE6DBE28}<br />
2013-05-05 08:19:52	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{3404BA57-701D-4B40-B24C-C64FB9809557}<br />
2013-05-04 07:55:31	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{9102A55C-982F-4FA8-9B6D-84F202113B22}<br />
2013-05-03 08:03:10	--------	d-----w-	C:&#092;Users&#092;Dan&#092;AppData&#092;Local&#092;{B758EDA6-68E0-46F3-8761-D501E6F95217}<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-28 07:23:36	71048	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerCPLApp.cpl<br />
2013-05-28 07:23:36	692104	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerApp.exe<br />
2013-04-12 14:45:08	1656680	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;ntfs.sys<br />
2013-04-05 01:08:44	2312704	----a-w-	C:&#092;Windows&#092;System32&#092;jscript9.dll<br />
2013-04-05 01:00:30	1392128	----a-w-	C:&#092;Windows&#092;System32&#092;wininet.dll<br />
2013-04-05 00:59:24	1494528	----a-w-	C:&#092;Windows&#092;System32&#092;inetcpl.cpl<br />
2013-04-05 00:56:16	173056	----a-w-	C:&#092;Windows&#092;System32&#092;ieUnatt.exe<br />
2013-04-05 00:55:47	599040	----a-w-	C:&#092;Windows&#092;System32&#092;vbscript.dll<br />
2013-04-04 22:11:34	1800704	----a-w-	C:&#092;Windows&#092;SysWow64&#092;jscript9.dll<br />
2013-04-04 22:02:59	1427968	----a-w-	C:&#092;Windows&#092;SysWow64&#092;inetcpl.cpl<br />
2013-04-04 22:02:17	1129472	----a-w-	C:&#092;Windows&#092;SysWow64&#092;wininet.dll<br />
2013-04-04 21:58:51	142848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ieUnatt.exe<br />
2013-04-04 21:57:45	420864	----a-w-	C:&#092;Windows&#092;SysWow64&#092;vbscript.dll<br />
2013-03-19 06:04:06	5550424	----a-w-	C:&#092;Windows&#092;System32&#092;ntoskrnl.exe<br />
2013-03-19 05:46:56	43520	----a-w-	C:&#092;Windows&#092;System32&#092;csrsrv.dll<br />
2013-03-19 05:04:13	3968856	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntoskrnl.exe<br />
2013-03-19 04:47:50	6656	----a-w-	C:&#092;Windows&#092;SysWow64&#092;apisetschema.dll<br />
2013-03-19 03:06:33	112640	----a-w-	C:&#092;Windows&#092;System32&#092;smss.exe<br />
.<br />
============= FINISH:  9:00:21,69 ===============<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade filer</h4>
	<ul>
		
			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17521" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17521" title="Ladda ner bilaga">attach.txt</a> <span class='desc'><strong>(5,16Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 1</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Sun, 02 Jun 2013 08:05:30 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341657-problem-med-datorn/</guid>
	</item>
	<item>
		<title>V9 portal site</title>
		<link>http://eforum.idg.se/topic/341651-v9-portal-site/</link>
		<description><![CDATA[Hej!<br />
Jag kan inte bli av med V9 portal site, trots upprepade försök.<br />
<br />
Mvh/Kattan]]></description>
		<pubDate>Sat, 01 Jun 2013 13:22:38 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341651-v9-portal-site/</guid>
	</item>
	<item>
		<title>Polistrojan</title>
		<link>http://eforum.idg.se/topic/341650-polistrojan/</link>
		<description><![CDATA[Hej, för ett tag sen fick jag en trojan på min andra laptop, eftersom jag har två har jag inte brytt mig om problemet men tänkte nu ta tag i det.<br />
<br />
Det som gäller är ett virus som tidigare är känt här, när jag startar datorn kommer en sida med polisens logga och en möjlighet till att låsa upp datorn genom att köpa en ukash kupong på pressbyron ect.<br />
<br />
Har läst lite andra trådar med samma problem men skulle behöva hjälp.<br />
<br />
Vindows vista på datorn.<br />
<br />
Har fattat att man ska köra DDS (?) men hur gör jag det när datorn är låst?<br />
<br />
Tacksam för all hjälp!]]></description>
		<pubDate>Sat, 01 Jun 2013 10:34:39 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341650-polistrojan/</guid>
	</item>
	<item>
		<title><![CDATA[Trojan &#34;Ukash&#34;]]></title>
		<link>http://eforum.idg.se/topic/341637-trojan-ukash/</link>
		<description><![CDATA[God kväll!<br />
<br />
Min dator har drabbats av den nämnda trojanen Ukash.<br />
<br />
Eftersom trojanprogrammet även körs i felsäkert läge så följde jag Cecilias råd från en annan liknande tråd och körde programmet FRST.exe. Jag bifogar loggen nedan så att någon kan guida mig vad jag ska göra härnäst. Tack på förhand!<br />
<br />
Ps. Vad är trojanens formella namn?<br />
<br />
--------------------------------------------------------<br />
<br />
<br />
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-05-2013<br />
Ran by SYSTEM on 30-05-2013 22:57:22<br />
Running from F:&#092;<br />
Windows Vista &#153; Home Basic (X86) OS Language: English(US)<br />
Internet Explorer Version 9<br />
Boot Mode: Recovery<br />
<br />
The current controlset is ControlSet001<br />
<strong class='bbc'>ATTENTION!:=====&gt; FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.</strong><br />
<br />
==================== Registry (Whitelisted) ==================<br />
<br />
HKLM&#092;...&#092;Run: [Windows Defender] %ProgramFiles%&#092;Windows Defender&#092;MSASCui.exe -hide [1008184 2008-01-20] (Microsoft Corporation)<br />
HKLM&#092;...&#092;Run: [RemoteControl8] "C:&#092;Program Files&#092;ASUSTek&#092;ASUSDVD 8&#092;PDVD8Serv.exe" [91432 2008-10-17] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [PDVD8LanguageShortcut] "C:&#092;Program Files&#092;ASUSTek&#092;ASUSDVD 8&#092;Language&#092;Language.exe" [50472 2007-12-14] ()<br />
HKLM&#092;...&#092;Run: [CLMLServer] "C:&#092;Program Files&#092;Cyberlink&#092;Power2Go&#092;CLMLSvc.exe" [104936 2008-07-18] (CyberLink)<br />
HKLM&#092;...&#092;Run: [P2Go_Menu] "C:&#092;Program Files&#092;CyberLink&#092;Power2Go&#092;MUITransfer&#092;MUIStartMenu.exe" "C:&#092;Program Files&#092;CyberLink&#092;Power2Go" UpdateWithCreateOnce "SOFTWARE&#092;CyberLink&#092;Power2Go&#092;6.0" [210216 2008-06-13] (CyberLink Corp.)<br />
HKLM&#092;...&#092;Run: [HDAudDeck] C:&#092;Program Files&#092;VIA&#092;VIAudioi&#092;VDeck&#092;VDeck.exe -r [17149952 2009-03-22] (VIA)<br />
HKLM&#092;...&#092;Run: [HControlUser] C:&#092;Program Files&#092;ASUS&#092;ATK Hotkey&#092;HControlUser.exe [98304 2008-08-18] (ASUS)<br />
HKLM&#092;...&#092;Run: [ATKOSD2] C:&#092;Program Files&#092;ASUS&#092;ATKOSD2&#092;ATKOSD2.exe [8392704 2009-03-04] (ASUS)<br />
HKLM&#092;...&#092;Run: [ATKMEDIA] C:&#092;Program Files&#092;ASUS&#092;ATK Media&#092;DMedia.exe [159744 2008-12-29] (ASUS)<br />
HKLM&#092;...&#092;Run: [ADSMTray] C:&#092;Program Files&#092;ASUS&#092;ASUS Data Security Manager&#092;ADSMTray.exe [266240 2008-03-31] (ASUSTek Computer Inc.)<br />
HKLM&#092;...&#092;Run: [ACMON] C:&#092;Program Files&#092;ASUS&#092;Splendid&#092;ACMON.exe [851968 2008-09-30] (ATK)<br />
HKLM&#092;...&#092;Run: [Wireless Console 3] C:&#092;Program Files&#092;ASUS&#092;Wireless Console 3&#092;wcourier.exe [1593344 2009-02-06] ()<br />
HKLM&#092;...&#092;Run: [ASUS Screen Saver Protector] C:&#092;Windows&#092;AsScrPro.exe [3054136 2009-05-30] (ASUS)<br />
HKLM&#092;...&#092;Run: [ASUS Camera ScreenSaver] C:&#092;Windows&#092;AsScrProlog.exe [47672 2009-05-30] ()<br />
HKLM&#092;...&#092;Run: [ETDWare] C:&#092;Program Files&#092;Elantech&#092;ETDCtrl.exe [424352 2009-03-06] (ELAN Microelectronic Corp.)<br />
HKLM&#092;...&#092;Run: [Bar] C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;Microsoft&#092;Windows&#092;Temporary Internet Files&#092;Content.IE5&#092;DUA1Y9YG&#092;access[1].exe [x]<br />
HKLM&#092;...&#092;Run: [Net iD] "C:&#092;Program Files&#092;Net iD&#092;iid.exe" [99640 2010-02-01] (SecMaker AB)<br />
HKLM&#092;...&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe" [35760 2010-09-22] (Adobe Systems Incorporated)<br />
HKLM&#092;...&#092;Run: [Adobe ARM] "C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe" [932288 2010-09-20] (Adobe Systems Incorporated)<br />
HKLM&#092;...&#092;Run: [vProt] "C:&#092;Program Files&#092;AVG Secure Search&#092;vprot.exe" [1226928 2013-05-21] (AVG Secure Search)<br />
HKLM&#092;...&#092;Run: [EEventManager] "C:&#092;Program Files&#092;Epson Software&#092;Event Manager&#092;EEventManager.exe" [976320 2009-12-03] (SEIKO EPSON CORPORATION)<br />
HKLM&#092;...&#092;Run: [APSDaemon] "C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Apple Application Support&#092;APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)<br />
HKLM&#092;...&#092;Run: [AVG_UI] "C:&#092;Program Files&#092;AVG&#092;AVG2013&#092;avgui.exe" /TRAYONLY [3039352 2012-09-13] (AVG Technologies CZ, s.r.o.)<br />
HKLM&#092;...&#092;Run: [QuickTime Task] "C:&#092;Program Files&#092;QuickTime&#092;QTTask.exe" -atboottime [421888 2012-10-24] (Apple Inc.)<br />
HKLM&#092;...&#092;Run: [SunJavaUpdateSched] "C:&#092;Program Files&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)<br />
HKLM&#092;...&#092;Run: []  [x]<br />
HKLM&#092;...&#092;Run: [ApnUpdater] "C:&#092;Program Files&#092;Ask.com&#092;Updater&#092;Updater.exe" [1644680 2013-02-08] (Ask)<br />
HKLM&#092;...&#092;Run: [iTunesHelper] "C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)<br />
HKU&#092;Mirjana&#092;...&#092;Run: [LightScribe Control Panel] C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LightScribeControlPanel.exe -hidden [ 2008-06-09] (Hewlett-Packard Company)<br />
HKU&#092;Mirjana&#092;...&#092;Run: [Google Update] "C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;Google&#092;Update&#092;GoogleUpdate.exe" /c [ 2010-03-14] (Google Inc.)<br />
HKU&#092;Mirjana&#092;...&#092;Run: [EPSON SX218 Series] C:&#092;Windows&#092;system32&#092;spool&#092;DRIVERS&#092;W32X86&#092;3&#092;E_FATIGDE.EXE /FU "C:&#092;Windows&#092;TEMP&#092;E_SED35.tmp" /EF "HKCU" [x]<br />
HKU&#092;Mirjana&#092;...&#092;Run: [Yontoo Desktop] "C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Yontoo&#092;YontooDesktop.exe" [x]<br />
HKU&#092;Mirjana&#092;...&#092;Run: [ctfmon32.exe] C:&#092;PROGRA~2&#092;rundll32.exe C:&#092;PROGRA~2&#092;27wie.dat,XFG00 [ 2013-05-29] (Microsoft Corporation)<br />
Lsa: [Notification Packages] scecli C:&#092;Program Files&#092;ASUS&#092;ASUS Data Security Manager&#092;ASPWDFLT<br />
Startup: C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;regmonstd.lnk<br />
ShortcutTarget: regmonstd.lnk -&gt; C:&#092;PROGRA~2&#092;27wie.dat (?????????? ??????????)<br />
<br />
========================== Services (Whitelisted) =================<br />
<br />
S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:&#092;Program Files&#092;Common Files&#092;ABBYY&#092;FineReaderSprint&#092;9.00&#092;Licensing&#092;NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)<br />
S2 ADSMService; C:&#092;Program Files&#092;ASUS&#092;ASUS Data Security Manager&#092;ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.)<br />
S2 ASLDRService; C:&#092;Program Files&#092;ASUS&#092;ATK Hotkey&#092;ASLDRSrv.exe [100920 2008-08-13] ()<br />
S2 ASO3DiskOptimizer; C:&#092;Program Files&#092;Advanced System Optimizer 3&#092;ASO3DefragSrv.exe [241448 2013-02-06] (Systweak Software, (www.systweak.com))<br />
S2 ATKGFNEXSrv; C:&#092;Program Files&#092;ATKGFNEX&#092;GFNEXSrv.exe [94208 2007-08-07] ()<br />
S2 AVGIDSAgent; C:&#092;Program Files&#092;AVG&#092;AVG2013&#092;avgidsagent.exe [5751928 2012-08-19] (AVG Technologies CZ, s.r.o.)<br />
S2 avgwd; C:&#092;Program Files&#092;AVG&#092;AVG2013&#092;avgwdsvc.exe [184304 2012-08-19] (AVG Technologies CZ, s.r.o.)<br />
S2 bProtector; C:&#092;ProgramData&#092;bProtectorForWindows&#092;2.0.392.106&#092;bProtect.exe [1441784 2012-05-18] (bProtector)<br />
S2 DSUDiskOptimizer; C:&#092;Program Files&#092;Disk Speedup&#092;DSUDefragSrv.exe [669480 2013-02-06] (Systweak Inc., (www.systweak.com))<br />
S2 IBUpdaterService; C:&#092;ProgramData&#092;IBUpdaterService&#092;ibsvc.exe [396248 2012-05-18] ()<br />
S3 McComponentHostService; C:&#092;Program Files&#092;McAfee Security Scan&#092;3.0.285&#092;McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)<br />
S2 RichVideo; C:&#092;Program Files&#092;Cyberlink&#092;Shared files&#092;RichVideo.exe [272024 2007-05-13] ()<br />
S2 vToolbarUpdater15.2.0; C:&#092;Program Files&#092;Common Files&#092;AVG Secure Search&#092;vToolbarUpdater&#092;15.2.0&#092;ToolbarUpdater.exe [1015984 2013-05-21] (AVG Secure Search)<br />
S3 Winmgmt; C:&#092;PROGRA~2&#092;27wie.dat [116736 2013-05-29] (?????????? ??????????)<br />
S2 Yontoo Desktop Updater; C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Yontoo&#092;YontooDesktop.exe [47392 2013-05-21] (Yontoo LLC)<br />
S3 msiserver; %systemroot%&#092;system32&#092;msiexec /V [x]<br />
S2 Norton Internet Security; "C:&#092;Program Files&#092;Norton Internet Security&#092;Engine&#092;16.0.0.125&#092;ccSvcHst.exe" /s "Norton Internet Security" /m "C:&#092;Program Files&#092;Norton Internet Security&#092;Engine&#092;16.0.0.125&#092;diMaster.dll" /prefetch:1 [x]<br />
<br />
==================== Drivers (Whitelisted) ====================<br />
<br />
S0 AsDsm; C:&#092;Windows&#092;System32&#092;Drivers&#092;AsDsm.sys [30264 2009-05-30] (ASUSTek Computer Inc)<br />
S2 ASMMAP; C:&#092;Program Files&#092;ATKGFNEX&#092;ASMMAP.sys [13880 2007-07-24] ()<br />
S1 AVGIDSDriver; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgidsdriverx.sys [176096 2012-08-13] (AVG Technologies CZ, s.r.o. )<br />
S0 AVGIDSHX; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgidshx.sys [51936 2012-09-17] (AVG Technologies CZ, s.r.o. )<br />
S1 AVGIDSShim; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgidsshimx.sys [19808 2012-08-09] (AVG Technologies CZ, s.r.o. )<br />
S1 Avgldx86; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgldx86.sys [151648 2012-09-12] (AVG Technologies CZ, s.r.o.)<br />
S0 Avglogx; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avglogx.sys [178656 2012-08-09] (AVG Technologies CZ, s.r.o.)<br />
S1 Avgmfx86; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgmfx86.sys [89440 2012-09-13] (AVG Technologies CZ, s.r.o.)<br />
S0 Avgrkx86; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgrkx86.sys [35168 2012-08-09] (AVG Technologies CZ, s.r.o.)<br />
S1 Avgtdix; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;avgtdix.sys [164704 2012-09-12] (AVG Technologies CZ, s.r.o.)<br />
S1 avgtp; C:&#092;Windows&#092;system32&#092;drivers&#092;avgtpx86.sys [37664 2013-05-21] (AVG Technologies)<br />
S3 ETD; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ETD.sys [140800 2009-03-12] (ELAN Microelectronic Corp.)<br />
S3 kbfiltr; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;kbfiltr.sys [13880 2008-11-02] ( )<br />
S3 L1E; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;L1E60x86.sys [48640 2009-08-04] (Atheros Communications, Inc.)<br />
S0 lullaby; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;lullaby.sys [15416 2008-05-29] (Windows &reg; Codename Longhorn DDK provider)<br />
S3 MTsensor; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;ATKACPI.sys [14392 2008-12-24] (ATK0100)<br />
S3 SNP2UVC; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;snp2uvc.sys [1752704 2008-08-10] ()<br />
S3 SRS_PremiumSound_Service; C:&#092;Windows&#092;System32&#092;drivers&#092;srs_PremiumSound_i386.sys [230952 2009-01-14] ()<br />
S3 VIAHdAudAddService; C:&#092;Windows&#092;System32&#092;drivers&#092;viahduaa.sys [984064 2009-03-19] (VIA Technologies, Inc.)<br />
S3 IpInIp; system32&#092;DRIVERS&#092;ipinip.sys [x]<br />
S3 NAVENG; &#092;??&#092;C:&#092;ProgramData&#092;Norton&#092;{0C55C096-0F1D-4F28-AAA2-85EF591126E7}&#092;Norton&#092;Definitions&#092;VirusDefs&#092;20080829.024&#092;NAVENG.SYS [x]<br />
S3 NAVEX15; &#092;??&#092;C:&#092;ProgramData&#092;Norton&#092;{0C55C096-0F1D-4F28-AAA2-85EF591126E7}&#092;Norton&#092;Definitions&#092;VirusDefs&#092;20080829.024&#092;NAVEX15.SYS [x]<br />
S3 NwlnkFlt; system32&#092;DRIVERS&#092;nwlnkflt.sys [x]<br />
S3 NwlnkFwd; system32&#092;DRIVERS&#092;nwlnkfwd.sys [x]<br />
S1 SRTSP; &#092;??&#092;C:&#092;Windows&#092;system32&#092;drivers&#092;NIS&#092;1000000.07D&#092;SRTSP.SYS [x]<br />
S1 SRTSPX; &#092;??&#092;C:&#092;Windows&#092;system32&#092;drivers&#092;NIS&#092;1000000.07D&#092;SRTSPX.SYS [x]<br />
<br />
==================== NetSvcs (Whitelisted) ===================<br />
<br />
<br />
==================== One Month Created Files and Folders ========<br />
<br />
2013-05-30 22:56 - 2013-05-30 22:56 - 00000000 ____D C:&#092;FRST<br />
2013-05-30 12:22 - 2013-05-30 12:22 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-30 02:40 - 2013-05-30 02:40 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-29 17:47 - 2013-05-30 12:39 - 95023320 ___AT C:&#092;ProgramData&#092;eiw72.pad<br />
2013-05-29 17:47 - 2013-05-30 12:39 - 00000000 ____A C:&#092;ProgramData&#092;kjhy64.txt<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00116736 ____A (?????????? ??????????) C:&#092;Users&#092;Mirjana&#092;5911027.dll<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00116736 ____A (?????????? ??????????) C:&#092;ProgramData&#092;27wie.dat<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00044544 ____A (Microsoft Corporation) C:&#092;ProgramData&#092;rundll32.exe<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00002644 ____A C:&#092;ProgramData&#092;eiw72.js<br />
2013-05-27 03:44 - 2013-05-27 03:44 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-26 22:50 - 2013-05-26 22:50 - 00000000 ____D C:&#092;ProgramData&#092;?l?l<br />
2013-05-24 12:37 - 2013-05-24 12:44 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;vlc<br />
2013-05-24 12:36 - 2013-05-24 12:36 - 00000866 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;VLC media player.lnk<br />
2013-05-24 12:36 - 2013-05-24 12:36 - 00000000 ____D C:&#092;Program Files&#092;VideoLAN<br />
2013-05-24 12:35 - 2013-05-30 02:41 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Yontoo<br />
2013-05-24 12:35 - 2013-05-24 12:35 - 00000000 ____D C:&#092;Program Files&#092;Yontoo<br />
2013-05-24 12:31 - 2013-05-30 12:23 - 00000272 ____A C:&#092;Windows&#092;Tasks&#092;DriverScanner.job<br />
2013-05-24 12:31 - 2013-05-24 12:31 - 00000000 ____D C:&#092;ProgramData&#092;Uniblue<br />
2013-05-24 12:30 - 2013-05-30 12:23 - 00000332 ____A C:&#092;Windows&#092;Tasks&#092;dsmonitor.job<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000989 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;DriverScanner.lnk<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Uniblue<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;OpenCandy<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Program Files&#092;Uniblue<br />
2013-05-24 12:29 - 2013-05-24 12:29 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;CRE<br />
2013-05-22 21:42 - 2013-05-22 21:42 - 00000000 ____D C:&#092;ProgramData&#092;?C?C<br />
2013-05-21 22:48 - 2013-05-21 22:48 - 00000000 ____D C:&#092;ProgramData&#092;?Ï?Ï<br />
2013-05-20 06:20 - 2013-05-20 06:20 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-17 00:26 - 2013-05-17 00:26 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-15 22:16 - 2013-05-15 22:16 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-14 22:55 - 2013-05-14 22:55 - 00000000 ____D C:&#092;ProgramData&#092;?ﬂ?ﬂ<br />
2013-05-14 17:11 - 2013-05-05 11:25 - 12324864 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.dll<br />
2013-05-14 17:11 - 2013-05-05 11:12 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-05-14 17:01 - 2013-04-04 14:11 - 01800704 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jscript9.dll<br />
2013-05-14 17:01 - 2013-04-04 14:09 - 09738752 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieframe.dll<br />
2013-05-14 17:01 - 2013-04-04 14:02 - 01427968 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;inetcpl.cpl<br />
2013-05-14 17:01 - 2013-04-04 14:02 - 01129472 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;wininet.dll<br />
2013-05-14 17:01 - 2013-04-04 14:02 - 01104384 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;urlmon.dll<br />
2013-05-14 17:01 - 2013-04-04 14:01 - 00231936 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;url.dll<br />
2013-05-14 17:01 - 2013-04-04 13:59 - 00065024 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jsproxy.dll<br />
2013-05-14 17:01 - 2013-04-04 13:58 - 00717824 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jscript.dll<br />
2013-05-14 17:01 - 2013-04-04 13:58 - 00142848 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieUnatt.exe<br />
2013-05-14 17:01 - 2013-04-04 13:57 - 00420864 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;vbscript.dll<br />
2013-05-14 17:01 - 2013-04-04 13:56 - 00607744 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;msfeeds.dll<br />
2013-05-14 17:01 - 2013-04-04 13:55 - 01796096 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;iertutil.dll<br />
2013-05-14 17:01 - 2013-04-04 13:54 - 00073216 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtmled.dll<br />
2013-05-14 17:01 - 2013-04-04 13:50 - 00176640 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieui.dll<br />
2013-05-14 16:31 - 2013-05-14 16:31 - 00000000 ____D C:&#092;ProgramData&#092;?9?9<br />
2013-05-14 15:54 - 2013-04-15 06:20 - 00638328 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;Drivers&#092;dxgkrnl.sys<br />
2013-05-14 15:54 - 2013-04-13 02:56 - 00037376 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;cdd.dll<br />
2013-05-14 15:54 - 2013-04-08 17:36 - 02049024 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-05-14 02:34 - 2013-05-14 02:34 - 00000000 ____D C:&#092;ProgramData&#092;?a?a<br />
2013-05-13 22:01 - 2013-05-13 22:01 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-12 00:52 - 2013-05-12 00:52 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-10 23:55 - 2013-05-10 23:55 - 00000000 ____D C:&#092;ProgramData&#092;?€?€<br />
2013-05-03 10:49 - 2013-05-03 10:49 - 00000000 ____D C:&#092;ProgramData&#092;?t?t<br />
2013-05-03 07:44 - 2013-05-03 07:44 - 00000000 ____D C:&#092;ProgramData&#092;?A?A<br />
2013-05-03 02:53 - 2013-05-03 02:53 - 00000000 ____D C:&#092;ProgramData&#092;?©?©<br />
2013-05-02 23:12 - 2013-05-02 23:12 - 00000000 ____D C:&#092;ProgramData&#092;?I?I<br />
2013-05-01 12:16 - 2013-05-01 12:16 - 00000000 ___AH C:&#092;Windows&#092;System32&#092;Drivers&#092;Msft_Kernel_netaapl_01009.Wdf<br />
2013-05-01 08:28 - 2013-05-01 08:28 - 00000000 ____D C:&#092;ProgramData&#092;?œ?œ<br />
2013-04-30 02:01 - 2013-04-30 02:01 - 00000000 ____D C:&#092;ProgramData&#092;?.?<br />
<br />
==================== One Month Modified Files and Folders ========<br />
<br />
2013-05-30 22:56 - 2013-05-30 22:56 - 00000000 ____D C:&#092;FRST<br />
2013-05-30 12:39 - 2013-05-29 17:47 - 95023320 ___AT C:&#092;ProgramData&#092;eiw72.pad<br />
2013-05-30 12:39 - 2013-05-29 17:47 - 00000000 ____A C:&#092;ProgramData&#092;kjhy64.txt<br />
2013-05-30 12:23 - 2013-05-24 12:31 - 00000272 ____A C:&#092;Windows&#092;Tasks&#092;DriverScanner.job<br />
2013-05-30 12:23 - 2013-05-24 12:30 - 00000332 ____A C:&#092;Windows&#092;Tasks&#092;dsmonitor.job<br />
2013-05-30 12:23 - 2009-05-30 00:55 - 01693563 ____A C:&#092;Windows&#092;WindowsUpdate.log<br />
2013-05-30 12:23 - 2008-04-28 19:39 - 00000012 ____A C:&#092;Windows&#092;bthservsdp.dat<br />
2013-05-30 12:23 - 2006-11-02 04:58 - 00032538 ____A C:&#092;Windows&#092;Tasks&#092;SCHEDLGU.TXT<br />
2013-05-30 12:23 - 2006-11-02 04:58 - 00000006 ___AH C:&#092;Windows&#092;Tasks&#092;SA.DAT<br />
2013-05-30 12:22 - 2013-05-30 12:22 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-30 12:21 - 2011-02-11 02:56 - 00000000 ____D C:&#092;ProgramData&#092;MFAData<br />
2013-05-30 12:19 - 2012-05-07 01:48 - 00000868 ____A C:&#092;Windows&#092;Tasks&#092;Adobe Flash Player Updater.job<br />
2013-05-30 12:19 - 2010-03-14 02:59 - 00001012 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-3230649575-3308180912-329358592-1000UA.job<br />
2013-05-30 12:18 - 2006-11-02 04:45 - 00003616 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />
2013-05-30 12:18 - 2006-11-02 04:45 - 00003616 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />
2013-05-30 05:02 - 2013-02-23 03:49 - 00000268 ____A C:&#092;Windows&#092;Tasks&#092;RegClean Pro_DEFAULT.job<br />
2013-05-30 03:14 - 2012-01-16 17:17 - 00000680 ____A C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;d3d9caps.dat<br />
2013-05-30 02:41 - 2013-05-24 12:35 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Yontoo<br />
2013-05-30 02:40 - 2013-05-30 02:40 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-30 02:39 - 2013-02-23 10:10 - 00000438 ____A C:&#092;Windows&#092;Tasks&#092;ASOService.job<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00116736 ____A (?????????? ??????????) C:&#092;Users&#092;Mirjana&#092;5911027.dll<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00116736 ____A (?????????? ??????????) C:&#092;ProgramData&#092;27wie.dat<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00044544 ____A (Microsoft Corporation) C:&#092;ProgramData&#092;rundll32.exe<br />
2013-05-29 17:47 - 2013-05-29 17:47 - 00002644 ____A C:&#092;ProgramData&#092;eiw72.js<br />
2013-05-29 17:47 - 2009-08-10 06:34 - 00000000 ____D C:&#092;users&#092;Mirjana<br />
2013-05-29 02:56 - 2013-02-23 03:49 - 00000276 ____A C:&#092;Windows&#092;Tasks&#092;RegClean Pro_UPDATES.job<br />
2013-05-28 23:47 - 2008-04-28 20:33 - 00606138 ____A C:&#092;Windows&#092;System32&#092;perfh01D.dat<br />
2013-05-28 23:47 - 2008-04-28 20:33 - 00120508 ____A C:&#092;Windows&#092;System32&#092;perfc01D.dat<br />
2013-05-28 23:47 - 2006-11-02 02:33 - 01419232 ____A C:&#092;Windows&#092;System32&#092;PerfStringBackup.INI<br />
2013-05-27 03:44 - 2013-05-27 03:44 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-26 23:09 - 2010-03-14 02:59 - 00000960 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskUserS-1-5-21-3230649575-3308180912-329358592-1000Core.job<br />
2013-05-26 22:50 - 2013-05-26 22:50 - 00000000 ____D C:&#092;ProgramData&#092;?l?l<br />
2013-05-25 09:12 - 2013-02-23 10:12 - 00000440 ____A C:&#092;Windows&#092;Tasks&#092;ASO-AutoCheckUpdate7Days.job<br />
2013-05-25 03:44 - 2008-01-20 19:02 - 00213010 ____A C:&#092;Windows&#092;PFRO.log<br />
2013-05-24 12:44 - 2013-05-24 12:37 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;vlc<br />
2013-05-24 12:40 - 2009-08-10 10:42 - 00032256 ____A C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
2013-05-24 12:36 - 2013-05-24 12:36 - 00000866 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;VLC media player.lnk<br />
2013-05-24 12:36 - 2013-05-24 12:36 - 00000000 ____D C:&#092;Program Files&#092;VideoLAN<br />
2013-05-24 12:35 - 2013-05-24 12:35 - 00000000 ____D C:&#092;Program Files&#092;Yontoo<br />
2013-05-24 12:31 - 2013-05-24 12:31 - 00000000 ____D C:&#092;ProgramData&#092;Uniblue<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000989 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;DriverScanner.lnk<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;Uniblue<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Roaming&#092;OpenCandy<br />
2013-05-24 12:30 - 2013-05-24 12:30 - 00000000 ____D C:&#092;Program Files&#092;Uniblue<br />
2013-05-24 12:29 - 2013-05-24 12:29 - 00000000 ____D C:&#092;Users&#092;Mirjana&#092;AppData&#092;Local&#092;CRE<br />
2013-05-24 12:21 - 2006-11-02 04:49 - 00258676 ____A C:&#092;Windows&#092;setupact.log<br />
2013-05-22 21:42 - 2013-05-22 21:42 - 00000000 ____D C:&#092;ProgramData&#092;?C?C<br />
2013-05-21 22:48 - 2013-05-21 22:48 - 00000000 ____D C:&#092;ProgramData&#092;?Ï?Ï<br />
2013-05-21 10:30 - 2012-09-26 10:51 - 00000000 ____D C:&#092;Program Files&#092;AVG Secure Search<br />
2013-05-21 10:30 - 2012-09-04 04:07 - 00037664 ____A (AVG Technologies) C:&#092;Windows&#092;System32&#092;Drivers&#092;avgtpx86.sys<br />
2013-05-20 06:20 - 2013-05-20 06:20 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-17 00:26 - 2013-05-17 00:26 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-15 22:16 - 2013-05-15 22:16 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-15 04:40 - 2012-05-07 01:48 - 00692104 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;System32&#092;FlashPlayerApp.exe<br />
2013-05-15 04:40 - 2012-01-29 04:53 - 00071048 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;System32&#092;FlashPlayerCPLApp.cpl<br />
2013-05-14 23:55 - 2006-11-02 03:18 - 00000000 ____D C:&#092;Windows&#092;Microsoft.NET<br />
2013-05-14 22:55 - 2013-05-14 22:55 - 00000000 ____D C:&#092;ProgramData&#092;?ﬂ?ﬂ<br />
2013-05-14 17:32 - 2009-08-10 06:35 - 00045056 ____A C:&#092;Windows&#092;System32&#092;acovcnt.exe<br />
2013-05-14 17:30 - 2006-11-02 04:44 - 00444144 ____A C:&#092;Windows&#092;System32&#092;FNTCACHE.DAT<br />
2013-05-14 17:12 - 2009-05-30 01:02 - 00000000 ____D C:&#092;ProgramData&#092;Microsoft Help<br />
2013-05-14 17:02 - 2006-11-02 02:24 - 72607752 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mrt.exe<br />
2013-05-14 16:31 - 2013-05-14 16:31 - 00000000 ____D C:&#092;ProgramData&#092;?9?9<br />
2013-05-14 02:34 - 2013-05-14 02:34 - 00000000 ____D C:&#092;ProgramData&#092;?a?a<br />
2013-05-13 22:01 - 2013-05-13 22:01 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-12 00:52 - 2013-05-12 00:52 - 00000000 ____D C:&#092;ProgramData&#092;????<br />
2013-05-10 23:55 - 2013-05-10 23:55 - 00000000 ____D C:&#092;ProgramData&#092;?€?€<br />
2013-05-05 11:25 - 2013-05-14 17:11 - 12324864 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.dll<br />
2013-05-05 11:12 - 2013-05-14 17:11 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-05-03 10:49 - 2013-05-03 10:49 - 00000000 ____D C:&#092;ProgramData&#092;?t?t<br />
2013-05-03 07:44 - 2013-05-03 07:44 - 00000000 ____D C:&#092;ProgramData&#092;?A?A<br />
2013-05-03 02:53 - 2013-05-03 02:53 - 00000000 ____D C:&#092;ProgramData&#092;?©?©<br />
2013-05-02 23:12 - 2013-05-02 23:12 - 00000000 ____D C:&#092;ProgramData&#092;?I?I<br />
2013-05-01 12:16 - 2013-05-01 12:16 - 00000000 ___AH C:&#092;Windows&#092;System32&#092;Drivers&#092;Msft_Kernel_netaapl_01009.Wdf<br />
2013-05-01 08:28 - 2013-05-01 08:28 - 00000000 ____D C:&#092;ProgramData&#092;?œ?œ<br />
2013-04-30 02:01 - 2013-04-30 02:01 - 00000000 ____D C:&#092;ProgramData&#092;?.?<br />
<br />
Other Malware:<br />
===========<br />
C:&#092;ProgramData&#092;rundll32.exe<br />
C:&#092;Users&#092;Mirjana&#092;5911027.dll<br />
C:&#092;Users&#092;Mirjana&#092;taskmgr.exe<br />
C:&#092;ProgramData&#092;27wie.dat<br />
C:&#092;ProgramData&#092;eiw72.pad<br />
<br />
==================== Known DLLs (Whitelisted) ============<br />
<br />
<br />
==================== Bamital & volsnap Check =================<br />
<br />
C:&#092;Windows&#092;explorer.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;winlogon.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;wininit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;svchost.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;services.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;User32.dll =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;userinit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;volsnap.sys =&gt; MD5 is legit<br />
<br />
==================== EXE ASSOCIATION =====================<br />
<br />
HKLM&#092;...&#092;.exe: exefile =&gt; OK<br />
HKLM&#092;...&#092;exefile&#092;DefaultIcon: %1 =&gt; OK<br />
HKLM&#092;...&#092;exefile&#092;open&#092;command: "%1" %* =&gt; OK<br />
<br />
==================== Restore Points  =========================<br />
<br />
Restore point made on: 2013-05-17 01:26:06<br />
Restore point made on: 2013-05-18 03:32:10<br />
Restore point made on: 2013-05-19 06:18:27<br />
Restore point made on: 2013-05-20 07:46:45<br />
Restore point made on: 2013-05-21 01:12:43<br />
Restore point made on: 2013-05-21 23:24:54<br />
Restore point made on: 2013-05-22 22:29:06<br />
Restore point made on: 2013-05-23 22:56:55<br />
Restore point made on: 2013-05-24 12:31:07<br />
Restore point made on: 2013-05-25 05:58:20<br />
Restore point made on: 2013-05-26 06:26:02<br />
Restore point made on: 2013-05-26 23:54:32<br />
Restore point made on: 2013-05-28 06:18:16<br />
Restore point made on: 2013-05-29 00:50:54<br />
<br />
==================== Memory info =========================== <br />
<br />
Percentage of memory in use: 12%<br />
Total physical RAM: 4060.31 MB<br />
Available physical RAM: 3544.72 MB<br />
Total Pagefile: 3773.05 MB<br />
Available Pagefile: 3610.88 MB<br />
Total Virtual: 2047.88 MB<br />
Available Virtual: 1972.51 MB<br />
<br />
==================== Drives ================================<br />
<br />
Drive c: (VistaOS) (Fixed) (Total:116.44 GB) (Free:54.28 GB) NTFS ==&gt;[Drive with boot components (obtained from BCD)]<br />
Drive d: (DATA) (Fixed) (Total:104.73 GB) (Free:80.69 GB) NTFS<br />
Drive f: (USB MINNE) (Removable) (Total:3.81 GB) (Free:0.28 GB) FAT32<br />
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS<br />
<br />
==================== MBR & Partition Table ==================<br />
<br />
========================================================<br />
Disk: 0 (Size: 233 GB) (Disk ID: 97646C29)<br />
Partition 1: (Not Active) - (Size=12 GB) - (Type=1C)<br />
Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS)<br />
Partition 3: (Not Active) - (Size=105 GB) - (Type=OF Extended)<br />
<br />
========================================================<br />
Disk: 1 (Size: 4 GB) (Disk ID: 018D114A)<br />
Partition 1: (Active) - (Size=4 GB) - (Type=0C)<br />
<br />
<br />
Last Boot: 2013-05-30 02:47<br />
<br />
==================== End Of Log ============================]]></description>
		<pubDate>Thu, 30 May 2013 21:11:13 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341637-trojan-ukash/</guid>
	</item>
	<item>
		<title>chrome.Annonser dyker upp. Jimy är död!</title>
		<link>http://eforum.idg.se/topic/341630-chromeannonser-dyker-upp-jimy-ar-dod/</link>
		<description><![CDATA[I text finns det slumpvis ord med blå text. För jag muspekaren över ett sånt ord dyker det upp en annons för olika varor. Har sökt med MALWAREBYTES men det hjälpte inte. MSE hittar ingenting. Vad kan det vara?<br />
I dag hände något som hänt några gånger tidigare. När jag läser ett forum på google så försvinner texten plötsligt och skärmen blir blå och texten "Jimmy är död" och att det är något fel på chrome. Sen startar nedladdning av uppdateringar.]]></description>
		<pubDate>Thu, 30 May 2013 10:04:22 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341630-chromeannonser-dyker-upp-jimy-ar-dod/</guid>
	</item>
	<item>
		<title>MS Security Essentials - uppdateringar</title>
		<link>http://eforum.idg.se/topic/341627-ms-security-essentials-uppdateringar/</link>
		<description><![CDATA[Jag retar mig på att den inte uppdaterar automatiskt.<br />
Istället pockar den på uppmärksamhet med att ikonen byter färg nere vid klockan.<br />
<br />
Jag Googlade lite och hittade detta:<br />
Kör man följande i en commandoprompt så uppdaterar den.<br />
MpCmdRun.exe -SignatureUpdate -MMPC<br />
Filen ligger i c:&#092;Program Files&#092;Microsoft Security Client&#092;<br />
<br />
Så då borde det gå att lägga in detta som en schemalagd händelse.<br />
Har gjort det nu, och väntar på att se hur det kommer att fungera.<br />
<br />
Man ska tydligen även kunna använda detta program, men det behövs ju inte om ovanstående fungerar.<br />
<a href='http://www.addictivetips.com/windows-tips/mse-update-utility-addictivetips-apps/' class='bbc_url' title='Extern länk' rel='external'>http://www.addictivetips.com/windows-tips/mse-update-utility-addictivetips-apps/</a><br />
<br />
Sedan pockar den även på uppmärksamhet för att det var ett tag sen sista skanningen gjordes.<br />
Man kan då använda MpCmdRun.exe -Scan -ScanType 2<br />
2 står för Full Scan]]></description>
		<pubDate>Thu, 30 May 2013 07:23:42 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341627-ms-security-essentials-uppdateringar/</guid>
	</item>
	<item>
		<title>TrustPort Internet Security 2013</title>
		<link>http://eforum.idg.se/topic/341625-trustport-internet-security-2013/</link>
		<description><![CDATA[TrustPort Internet Security 2013 - <a href='https://portal.trustport.com/promo/plpcformat' class='bbc_url' title='Extern länk' rel='external'>de har inte uppdaterat sitt cert</a> - strunta i det helt enkelt - låt google översätta Polska om du inte pratar det språket  <img src='http://eforum.idg.se/public/style_emoticons/default/smile.gif' class='bbc_emoticon' alt=':)' /> <br />
<br />
Promo-koden<br />
PLPCFORMAT2013IS - rättat till felet i promo-koden - sorry<br />
<br />
TPIS 2013 använder 2 st antivirus-motorer AVG+Bitdefender<br />
<br />
<a href='https://www.virusbtn.com/vb100/RAP/RAP-quadrant-Oct12-Apr13-12.jpg' class='bbc_url' title='Extern länk' rel='external'>https://www.virusbtn.com/vb100/RAP/RAP-quadrant-Oct12-Apr13-12.jpg</a>]]></description>
		<pubDate>Wed, 29 May 2013 20:34:29 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341625-trustport-internet-security-2013/</guid>
	</item>
	<item>
		<title>Ukash-viruset - antivirus-program tog ej bort skadlig kod</title>
		<link>http://eforum.idg.se/topic/341623-ukash-viruset-antivirus-program-tog-ej-bort-skadlig-kod/</link>
		<description><![CDATA[Hej! <br />
<br />
Även jag har drabbats av Ukash-viruset som blockerar datorn helt. Försökte ta bort skadlig kod med antivirus-programmet "Malware bytes AntiMalware" men detta misslyckades. Kanske för att antivirusprogrammet inte var ordentligt uppdaterat.?<br />
<br />
Jag läste därför Cecilias råd till hur Eorl skulle göra, som drabbats av samma elände: Att ladda ner och köra programmet Farbar Recovery Scan Tool (FRST) som scannade igenom datorn och skapade en scanning-logg-fil. Det har jag gjort nu, och här följer textfilen från scanningen. <br />
<br />
Vore fantastiskt bra och jag skulle vara enormt tacksam om Cecilia eller någon annan kunde titta på textfilen och råda mig hur jag ska göra en"fixit-textfil" av den, köra FRST igen och få igång PC:n. Såg också att det finns en "addition.txt" fil från en tidigare scanning jag gjorde av PC:n, men som inte uppdaterades vid den här senaste scanningen. Är den filen av värde för er att titta på? / Hälsningar Gurra00!:<br />
<br />
<br />
<span style='color: #0000FF'>Logg borttagen pga personlig information. Logg utan personlig information finns längre ned i tråden.</span>]]></description>
		<pubDate>Wed, 29 May 2013 13:56:35 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341623-ukash-viruset-antivirus-program-tog-ej-bort-skadlig-kod/</guid>
	</item>
	<item>
		<title>Ukash Virus felsäkert läge funkar inte. Hjälp!</title>
		<link>http://eforum.idg.se/topic/341621-ukash-virus-felsakert-lage-funkar-inte-hjalp/</link>
		<description><![CDATA[Hej jag har råkat ut för detta roliga virus igen! Förra gången kunde jag starta i felsäkert läge och fixa det själv denna gång går det inte lika bra.<br />
Jag kollade upp liknade trådar och laddade hem frst64 på min bärbara och gjorde en scan. Jag kanske naivt trodde kunde fixa det själv med:<br />
<br />
HKU&#092;Default.Default-dator&#092;...&#092;Winlogon: [Shell] explorer.exe,C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;skype.dat [102400 2011-11-16] () 2013-03-19 04:03 - 2013-03-19 05:03 - 00000004 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;skype.ini<br />
<br />
som fixlist.txt . Dock så kan jag starta datorn nu men efter 2-3 min så hoppas viruset igång igen och låser datorn, felsäkert läge funkar fortfarande inte.<br />
s¨jag ger upp och hoppas på hjälp. Här den senaste scan jag gjorde. Snälla hjälp mig!<br />
<br />
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-05-2013<br />
Ran by SYSTEM on 29-05-2013 09:50:21<br />
Running from F:&#092;<br />
Windows Vista &#153; Home Premium Service Pack 1 (X64) OS Language: Swedish<br />
Internet Explorer Version 9<br />
Boot Mode: Recovery<br />
The current controlset is ControlSet003<br />
<strong class='bbc'>ATTENTION!:=====&gt; FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.</strong><br />
<br />
==================== Registry (Whitelisted) ==================<br />
<br />
HKLM&#092;...&#092;Run: [RtHDVCpl] RAVCpl64.exe [x]<br />
HKLM&#092;...&#092;Run: [Skytel] Skytel.exe [x]<br />
HKLM&#092;...&#092;Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x]<br />
HKLM-x32&#092;...&#092;Winlogon: [Userinit] c:&#092;windows&#092;syswow64&#092;userinit.exe, [x]<br />
Winlogon&#092;Notify&#092;avldr: avldr64.dll (On-Access Anti-Malware Scanner Sync)<br />
HKLM-x32&#092;...&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe" [41208 2012-12-19] (Adobe Systems Incorporated)<br />
HKLM-x32&#092;...&#092;Run: [Adobe ARM] "C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)<br />
HKLM-x32&#092;...&#092;Run: [APVXDWIN] "C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;APVXDWIN.EXE" /s [1038192 2012-12-12] (Panda Security, S.L.)<br />
HKLM-x32&#092;...&#092;Run: [SCANINICIO] "C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;Inicio.exe" [70432 2012-11-08] (Panda Security, S.L.)<br />
HKU&#092;Default.Default-dator&#092;...&#092;Run: [msnmsgr] "C:&#092;Program Files (x86)&#092;Windows Live&#092;Messenger&#092;msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)<br />
HKU&#092;Default.Default-dator&#092;...&#092;Run: [ehTray.exe] C:&#092;Windows&#092;ehome&#092;ehTray.exe [138240 2008-01-21] (Microsoft Corporation)<br />
HKU&#092;Default.Default-dator&#092;...&#092;Run: [WMPNSCFG] C:&#092;Program Files (x86)&#092;Windows Media Player&#092;WMPNSCFG.exe [x]<br />
HKU&#092;Default.Default-dator&#092;...&#092;Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] C:&#092;Users&#092;Default.Default-dator&#092;Documents&#092;6113ae5e.exe [44544 2013-05-29] (Adobe Systems Incorporated)<br />
Startup: C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;Dropbox.lnk<br />
ShortcutTarget: Dropbox.lnk -&gt;  (No File)<br />
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:&#092;Windows&#092;System32&#092;webcheck.dll (Microsoft Corporation)<br />
<br />
==================== Services (Whitelisted) =================<br />
<br />
S3 LBTServ; C:&#092;Program Files&#092;Common Files&#092;Logitech&#092;Bluetooth&#092;LBTServ.exe [160272 2008-05-02] (Logitech, Inc.)<br />
S2 Panda Software Controller; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;PsCtrls.exe [177440 2012-11-19] (Panda Security, S.L.)<br />
S2 PAVFNSVR; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;PavFnSvr.exe [202016 2012-09-21] (Panda Security, S.L.)<br />
S2 PavPrSrv; C:&#092;Program Files (x86)&#092;Common Files&#092;Panda Security&#092;PavShld&#092;pavprsrv.exe [62768 2008-02-04] (Panda Security, S.L.)<br />
S2 PAVSRV; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;pavsrvx86.exe [313664 2011-04-13] (Panda Security, S.L.)<br />
S2 PSHost; c:&#092;program files (x86)&#092;panda security&#092;panda global protection 2013&#092;firewall&#092;PSHOST.EXE [226560 2009-11-26] (Panda Security International)<br />
S2 PSIMSVC; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;PsImSvc.exe [108288 2008-06-19] (Panda Security S.L.)<br />
S2 PskSvcRetail; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;PskSvc.exe [28992 2010-08-16] (Panda Security, S.L.)<br />
S2 TPSrv; C:&#092;Program Files (x86)&#092;Panda Security&#092;Panda Global Protection 2013&#092;TPSrvWow.exe [173344 2012-11-16] (Panda Security, S.L.)<br />
S3 usprserv; C:&#092;Windows&#092;SysWow64&#092;svchost.exe [21504 2008-01-21] (Microsoft Corporation)<br />
S3 msiserver; %systemroot%&#092;system32&#092;msiexec /V [x]<br />
S3 npggsvc; C:&#092;Windows&#092;system32&#092;GameMon.des -service [x]<br />
<br />
==================== Drivers (Whitelisted) ====================<br />
<br />
S2 AmFSM; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;amm6460.sys [71432 2012-03-26] (Panda Security, S.L.)<br />
S1 APPFLT; C:&#092;Windows&#092;system32&#092;Drivers&#092;APPFLT64.SYS [129096 2011-01-31] (Panda Security, S.L.)<br />
S2 atksgt; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;atksgt.sys [310728 2010-08-15] ()<br />
S2 ComFiltr; C:&#092;Windows&#092;system32&#092;DRIVERS&#092;COMFiltr.sys [15928 2013-05-10] ()<br />
S1 DSAFLT; C:&#092;Windows&#092;system32&#092;Drivers&#092;DSAFLT64.SYS [82952 2009-09-25] (Panda Security, S.L.)<br />
S1 FNETMON; C:&#092;Windows&#092;system32&#092;Drivers&#092;fnetm64.SYS [31752 2009-09-25] (Panda Security, S.L.)<br />
S3 gdrv; C:&#092;Windows&#092;gdrv.sys [20544 2008-08-27] (Windows &reg; Server 2003 DDK provider)<br />
S1 IDSFLT; C:&#092;Windows&#092;system32&#092;Drivers&#092;IDSFLT64.SYS [78920 2010-09-09] (Panda Security, S.L.)<br />
S2 lirsgt; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;lirsgt.sys [42696 2010-08-15] ()<br />
S1 NETFLTDI; C:&#092;Windows&#092;system32&#092;Drivers&#092;NETTDI64.SYS [170504 2009-09-25] (Panda Security, S.L.)<br />
S3 NETIMFLT01060044; C:&#092;Windows&#092;System32&#092;DRIVERS&#092;n64i1644.sys [216648 2010-09-01] (Panda Security, S.L.)<br />
S3 NPPTNT2; C:&#092;Windows&#092;SysWow64&#092;npptNT2.sys [4682 2005-01-01] (INCA Internet Co., Ltd.)<br />
S0 sptd; C:&#092;Windows&#092;System32&#092;Drivers&#092;sptd.sys [834544 2010-01-06] (Duplex Secure Ltd.)<br />
S1 WNMFLT; C:&#092;Windows&#092;system32&#092;Drivers&#092;WNMFLT64.SYS [74760 2009-09-25] (Panda Security, S.L.)<br />
S3 cpuz135; &#092;??&#092;C:&#092;Windows&#092;TEMP&#092;cpuz135&#092;cpuz135_x64.sys [x]<br />
S3 dump_wmimmc; &#092;??&#092;C:&#092;Spel&#092;Aion&#092;bin32&#092;GameGuard&#092;dump_wmimmc.sys [x]<br />
S3 IpInIp; system32&#092;DRIVERS&#092;ipinip.sys [x]<br />
S3 NwlnkFlt; system32&#092;DRIVERS&#092;nwlnkflt.sys [x]<br />
S3 NwlnkFwd; system32&#092;DRIVERS&#092;nwlnkfwd.sys [x]<br />
S0 pavboot; system32&#092;Drivers&#092;pavboot64.sys [x]<br />
S3 PavTPK.sys; &#092;??&#092;C:&#092;Windows&#092;system32&#092;PavTPK.sys [x]<br />
S3 Prot6Flt; system32&#092;DRIVERS&#092;Prot6Flt.sys [x]<br />
S1 ShldFlt; System32&#092;DRIVERS&#092;ShldFlt.sys [x]<br />
<br />
==================== NetSvcs (Whitelisted) ===================<br />
<br />
<br />
==================== One Month Created Files and Folders ========<br />
<br />
2013-05-29 08:35 - 2013-05-29 08:35 - 00000000 ____D C:&#092;FRST<br />
2013-05-29 08:07 - 2013-05-29 08:07 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{51FD656E-A793-436B-99A5-0F75502E918E}<br />
2013-05-29 07:27 - 2013-05-29 07:27 - 00281984 ____A C:&#092;Windows&#092;Minidump&#092;Mini052913-01.dmp<br />
2013-05-29 07:26 - 2013-05-29 07:26 - 457820035 ____A C:&#092;Windows&#092;MEMORY.DMP<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00117254 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;2433f433<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00117169 ____A C:&#092;ProgramData&#092;2433f433<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00044544 ____A (Adobe Systems Incorporated) C:&#092;Users&#092;Default.Default-dator&#092;Documents&#092;6113ae5e.exe<br />
2013-05-19 00:48 - 2013-05-19 00:48 - 00011634 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;ouji)] Haruhi no Uzuki [Haruhi’s Ache] (Suzumiya Haruhi no Yuuutsu [The Melancholy of Haruhi Suzumiya]) [English] [Strange Gray Cat].zip.torrent<br />
2013-05-15 12:22 - 2013-05-15 12:23 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{4B91FFC8-D6C9-4D5C-9ABE-648BC272A897}<br />
2013-05-15 12:10 - 2013-04-05 02:19 - 10926080 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieframe.dll<br />
2013-05-15 12:10 - 2013-04-05 02:08 - 02312704 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jscript9.dll<br />
2013-05-15 12:10 - 2013-04-05 02:01 - 01346560 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;urlmon.dll<br />
2013-05-15 12:10 - 2013-04-05 02:00 - 01392128 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;wininet.dll<br />
2013-05-15 12:10 - 2013-04-05 01:59 - 01494528 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;inetcpl.cpl<br />
2013-05-15 12:10 - 2013-04-05 01:58 - 00237056 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;url.dll<br />
2013-05-15 12:10 - 2013-04-05 01:57 - 00085504 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jsproxy.dll<br />
2013-05-15 12:10 - 2013-04-05 01:56 - 00173056 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieUnatt.exe<br />
2013-05-15 12:10 - 2013-04-05 01:55 - 00816640 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;jscript.dll<br />
2013-05-15 12:10 - 2013-04-05 01:55 - 00599040 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;vbscript.dll<br />
2013-05-15 12:10 - 2013-04-05 01:54 - 02147840 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;iertutil.dll<br />
2013-05-15 12:10 - 2013-04-05 01:54 - 00729088 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;msfeeds.dll<br />
2013-05-15 12:10 - 2013-04-05 01:51 - 00096768 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtmled.dll<br />
2013-05-15 12:10 - 2013-04-05 01:46 - 00248320 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ieui.dll<br />
2013-05-15 12:10 - 2013-04-04 23:11 - 01800704 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;jscript9.dll<br />
2013-05-15 12:10 - 2013-04-04 23:09 - 09738752 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;ieframe.dll<br />
2013-05-15 12:10 - 2013-04-04 23:02 - 01427968 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;inetcpl.cpl<br />
2013-05-15 12:10 - 2013-04-04 23:02 - 01129472 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;wininet.dll<br />
2013-05-15 12:10 - 2013-04-04 23:02 - 01104384 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;urlmon.dll<br />
2013-05-15 12:10 - 2013-04-04 23:01 - 00231936 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;url.dll<br />
2013-05-15 12:10 - 2013-04-04 22:59 - 00065024 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;jsproxy.dll<br />
2013-05-15 12:10 - 2013-04-04 22:58 - 00717824 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;jscript.dll<br />
2013-05-15 12:10 - 2013-04-04 22:58 - 00142848 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;ieUnatt.exe<br />
2013-05-15 12:10 - 2013-04-04 22:57 - 00420864 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;vbscript.dll<br />
2013-05-15 12:10 - 2013-04-04 22:56 - 00607744 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;msfeeds.dll<br />
2013-05-15 12:10 - 2013-04-04 22:55 - 01796096 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;iertutil.dll<br />
2013-05-15 12:10 - 2013-04-04 22:54 - 00073216 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mshtmled.dll<br />
2013-05-15 12:10 - 2013-04-04 22:50 - 00176640 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;ieui.dll<br />
2013-05-15 11:59 - 2013-05-05 22:36 - 17818624 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.dll<br />
2013-05-15 11:59 - 2013-05-05 22:16 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-05-15 11:59 - 2013-05-05 20:25 - 12324864 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mshtml.dll<br />
2013-05-15 11:59 - 2013-05-05 20:12 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mshtml.tlb<br />
2013-05-15 11:57 - 2013-04-15 15:17 - 00901496 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;Drivers&#092;dxgkrnl.sys<br />
2013-05-15 11:57 - 2013-04-13 04:34 - 00047104 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;cdd.dll<br />
2013-05-15 11:57 - 2013-04-09 02:55 - 02774016 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-05-15 10:02 - 2013-05-22 12:50 - 00000089 ____A C:&#092;Users&#092;Default.Default-dator&#092;Desktop&#092;Spel.txt<br />
2013-05-10 10:52 - 2013-05-10 10:52 - 00001069 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;Panda Cloud Cleaner.lnk<br />
2013-05-10 10:32 - 2013-05-10 10:34 - 00474430 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;dd_vcredistMSI2A37.txt<br />
2013-05-10 10:32 - 2013-05-10 10:34 - 00012770 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;dd_vcredistUI2A37.txt<br />
2013-05-10 10:29 - 2013-03-11 14:33 - 04691304 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;ntoskrnl.exe<br />
2013-05-10 10:29 - 2013-03-09 05:16 - 00085504 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;csrsrv.dll<br />
2013-05-10 10:29 - 2013-03-09 02:48 - 00075264 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;smss.exe<br />
2013-05-10 10:29 - 2013-03-08 05:18 - 00451072 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;winsrv.dll<br />
2013-05-10 10:29 - 2013-03-08 05:17 - 02425344 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mstscax.dll<br />
2013-05-10 10:29 - 2013-03-08 04:52 - 02067968 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mstscax.dll<br />
2013-05-10 10:29 - 2013-03-03 20:13 - 01513320 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;Drivers&#092;ntfs.sys<br />
2013-05-10 10:17 - 2013-05-29 08:31 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;WnmFlt.cfg.bck<br />
2013-05-10 10:17 - 2013-05-29 08:31 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;WnmFlt.cfg<br />
2013-05-10 10:17 - 2013-05-29 08:31 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.cfg.bck<br />
2013-05-10 10:17 - 2013-05-29 08:31 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.cfg<br />
2013-05-10 10:15 - 2013-05-29 08:31 - 00000252 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;IdsFlt.cfg.bck<br />
2013-05-10 10:15 - 2013-05-29 08:31 - 00000252 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;IdsFlt.cfg<br />
2013-05-10 10:15 - 2013-05-29 08:31 - 00000068 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetFlt.cfg.bck<br />
2013-05-10 10:15 - 2013-05-29 08:31 - 00000068 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetFlt.cfg<br />
2013-05-10 10:14 - 2013-05-29 08:31 - 00000060 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAR.wlt.bck<br />
2013-05-10 10:14 - 2013-05-29 08:31 - 00000060 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAR.wlt<br />
2013-05-10 10:06 - 2013-05-29 08:31 - 00001132 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFLTR.CFG.bck<br />
2013-05-10 10:06 - 2013-05-29 08:31 - 00001132 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFLTR.CFG<br />
2013-05-10 10:06 - 2013-05-26 16:57 - 00447324 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.rls.bck<br />
2013-05-10 10:06 - 2013-05-26 16:57 - 00447324 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.rls<br />
2013-05-10 10:06 - 2013-05-26 16:53 - 00251144 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFCONT.DAT.bck<br />
2013-05-10 10:06 - 2013-05-26 16:53 - 00251144 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFCONT.DAT<br />
2013-05-10 10:06 - 2013-05-10 10:06 - 00015928 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;COMFiltr.sys<br />
2013-05-10 10:06 - 2013-05-10 10:06 - 00000274 ____A C:&#092;Windows&#092;System32&#092;PavCPL64.dat<br />
2013-05-10 10:06 - 2010-09-09 14:23 - 00078920 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;idsflt64.sys<br />
2013-05-10 10:06 - 2009-09-25 12:54 - 00082952 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;dsaflt64.sys<br />
2013-05-10 10:06 - 2009-09-25 12:54 - 00074760 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;wnmflt64.sys<br />
2013-05-10 10:06 - 2009-08-13 17:07 - 00729424 ____A (WeOnlyDo Software) C:&#092;Windows&#092;SysWOW64&#092;wodSFTP.dll<br />
2013-05-10 10:06 - 2009-08-13 17:07 - 00672024 ____A (WeOnlyDo! COM) C:&#092;Windows&#092;SysWOW64&#092;wodKeys.dll<br />
2013-05-10 10:04 - 2013-05-24 23:00 - 00000522 ____A C:&#092;Windows&#092;Tasks&#092;Grundrensning.job<br />
2013-05-10 10:04 - 2011-01-31 14:41 - 00129096 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFLT64.SYS<br />
2013-05-10 10:04 - 2010-06-22 16:20 - 00030792 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;pavboot64.sys<br />
2013-05-10 10:04 - 2009-09-25 12:54 - 00170504 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;NETTDI64.SYS<br />
2013-05-10 10:04 - 2009-09-25 12:54 - 00031752 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;fnetm64.sys<br />
2013-05-10 10:04 - 2007-03-15 17:38 - 00046640 ____A (Panda Software) C:&#092;Windows&#092;System32&#092;pavcpl64.cpl<br />
2013-05-10 10:03 - 2013-05-10 10:03 - 00000000 ____D C:&#092;Windows&#092;SysWOW64&#092;PAV<br />
2013-05-10 10:03 - 2012-11-20 10:20 - 00545056 ____A (Panda Security, S.L.) C:&#092;Windows&#092;SysWOW64&#092;PavSHookWow.dll<br />
2013-05-10 10:03 - 2012-11-16 10:08 - 00837920 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;PavSHook64.dll<br />
2013-05-10 10:03 - 2012-05-22 13:54 - 00087328 ____A (Panda Security, S.L.) C:&#092;Windows&#092;SysWOW64&#092;PavLspHookWow.dll<br />
2013-05-10 10:03 - 2012-05-22 13:52 - 00117024 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;PavLspHook64.dll<br />
2013-05-10 10:03 - 2012-04-20 11:42 - 00024064 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;sysHelper64.dll<br />
2013-05-10 10:03 - 2012-03-26 16:57 - 00071432 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;amm6460.sys<br />
2013-05-10 10:03 - 2010-06-21 15:02 - 00323392 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;TpUtil64.dll<br />
2013-05-10 10:03 - 2010-06-21 15:02 - 00202048 ____A (Panda Security, S.L.) C:&#092;Windows&#092;SysWOW64&#092;TpUtilWow.dll<br />
2013-05-10 10:03 - 2010-06-21 15:01 - 00090944 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;PavIpc64.dll<br />
2013-05-10 10:03 - 2010-06-21 15:01 - 00066880 ____A (Panda Security, S.L.) C:&#092;Windows&#092;SysWOW64&#092;PavIpcWow.dll<br />
2013-05-10 10:03 - 2010-03-24 10:56 - 00064768 ____A (On-Access Anti-Malware Scanner Sync) C:&#092;Windows&#092;System32&#092;avldr64.dll<br />
2013-05-10 10:03 - 2009-10-27 10:07 - 00048136 ____A (Panda Security, S.L.) C:&#092;Windows&#092;System32&#092;Drivers&#092;ShldFlt.sys<br />
2013-05-10 10:03 - 2009-08-10 11:46 - 00025344 ____A (Panda Security, S.L.) C:&#092;Windows&#092;SysWOW64&#092;sysHelper32.dll<br />
2013-05-09 10:03 - 2013-05-09 10:03 - 00009307 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;rmite (Nohito)] Full Dive Human Farm ~If One Could Make a Human Farm Using Cheats~ Download Edition (Sword Art Online) [English] =LWB=.zip.torrent<br />
2013-05-08 21:01 - 2013-05-08 21:01 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{53408C3C-CB7D-4135-AC8D-4EF6820E7A3F}<br />
2013-05-05 08:07 - 2013-05-05 08:07 - 00011002 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;[Minion] Binkan â˜† boli Torisu Ch. 1 [English] {bfrost}.zip.torrent<br />
2013-05-05 07:54 - 2013-05-05 07:54 - 00011766 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;) [Karakishi Youhei-dan Shinka (Kanenomori Sentarou, Sunahara Wataru)] Go Tesei Ikka [Handmade Family] (Naruto) [English] {Decensored}.zip.torrent<br />
2013-05-04 02:07 - 2013-05-04 02:07 - 00041888 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;)] Futanari Euphemia x Kyonyuu Cornelia   Futanari Euphemia and Big-Breasted Cornelia (Code Geass  Lelouch of the Rebellion) [English].zip.torrent<br />
2013-05-04 02:07 - 2013-05-04 02:07 - 00039687 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;(C72) [FANGS (Higashimadou Hisagi)] Futanari Kallen x Kyonyuu Milly   Huge-Rack Milly X Futanari Kallen (Code Geass) [English].zip.torrent<br />
2013-05-01 17:40 - 2013-05-01 17:40 - 00049952 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;GDIPFONTCACHEV1.DAT<br />
<br />
==================== One Month Modified Files and Folders =======<br />
<br />
2013-05-29 08:35 - 2013-05-29 08:35 - 00000000 ____D C:&#092;FRST<br />
2013-05-29 08:34 - 2012-04-20 10:31 - 01934706 ____A C:&#092;Windows&#092;WindowsUpdate.log<br />
2013-05-29 08:31 - 2013-05-10 10:17 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;WnmFlt.cfg.bck<br />
2013-05-29 08:31 - 2013-05-10 10:17 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;WnmFlt.cfg<br />
2013-05-29 08:31 - 2013-05-10 10:17 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.cfg.bck<br />
2013-05-29 08:31 - 2013-05-10 10:17 - 00000056 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.cfg<br />
2013-05-29 08:31 - 2013-05-10 10:15 - 00000252 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;IdsFlt.cfg.bck<br />
2013-05-29 08:31 - 2013-05-10 10:15 - 00000252 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;IdsFlt.cfg<br />
2013-05-29 08:31 - 2013-05-10 10:15 - 00000068 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetFlt.cfg.bck<br />
2013-05-29 08:31 - 2013-05-10 10:15 - 00000068 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetFlt.cfg<br />
2013-05-29 08:31 - 2013-05-10 10:14 - 00000060 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAR.wlt.bck<br />
2013-05-29 08:31 - 2013-05-10 10:14 - 00000060 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAR.wlt<br />
2013-05-29 08:31 - 2013-05-10 10:06 - 00001132 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFLTR.CFG.bck<br />
2013-05-29 08:31 - 2013-05-10 10:06 - 00001132 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFLTR.CFG<br />
2013-05-29 08:31 - 2011-06-09 22:33 - 00000152 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetLoc.wlt.bck<br />
2013-05-29 08:31 - 2011-06-09 22:33 - 00000152 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetLoc.wlt<br />
2013-05-29 08:31 - 2011-06-09 22:32 - 00000136 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAdapt.cfg.bck<br />
2013-05-29 08:31 - 2011-06-09 22:32 - 00000136 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;NetAdapt.cfg<br />
2013-05-29 08:30 - 2011-08-27 20:12 - 00000992 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineCore.job<br />
2013-05-29 08:30 - 2006-11-02 16:42 - 00032618 ____A C:&#092;Windows&#092;Tasks&#092;SCHEDLGU.TXT<br />
2013-05-29 08:30 - 2006-11-02 16:42 - 00000006 ___AH C:&#092;Windows&#092;Tasks&#092;SA.DAT<br />
2013-05-29 08:30 - 2006-11-02 16:22 - 00003840 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />
2013-05-29 08:30 - 2006-11-02 16:22 - 00003840 ___AH C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />
2013-05-29 08:15 - 2011-08-27 20:12 - 00000996 ____A C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineUA.job<br />
2013-05-29 08:07 - 2013-05-29 08:07 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{51FD656E-A793-436B-99A5-0F75502E918E}<br />
2013-05-29 08:06 - 2012-12-30 12:40 - 00000000 ___RD C:&#092;Users&#092;Default.Default-dator&#092;Dropbox<br />
2013-05-29 08:06 - 2012-12-30 12:37 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;Dropbox<br />
2013-05-29 08:05 - 2008-10-12 04:51 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;Tracing<br />
2013-05-29 07:55 - 2013-04-09 23:58 - 00003356 ____A C:&#092;Windows&#092;setupact.log<br />
2013-05-29 07:27 - 2013-05-29 07:27 - 00281984 ____A C:&#092;Windows&#092;Minidump&#092;Mini052913-01.dmp<br />
2013-05-29 07:27 - 2010-01-13 18:25 - 00000000 ____D C:&#092;Windows&#092;Minidump<br />
2013-05-29 07:26 - 2013-05-29 07:26 - 457820035 ____A C:&#092;Windows&#092;MEMORY.DMP<br />
2013-05-29 05:51 - 2009-10-17 17:48 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;uTorrent<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00117254 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;2433f433<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00117169 ____A C:&#092;ProgramData&#092;2433f433<br />
2013-05-29 05:46 - 2013-05-29 05:46 - 00044544 ____A (Adobe Systems Incorporated) C:&#092;Users&#092;Default.Default-dator&#092;Documents&#092;6113ae5e.exe<br />
2013-05-28 15:46 - 2010-05-11 12:34 - 00008627 ____A C:&#092;Windows&#092;SysWOW64&#092;PAV_FOG.OPC<br />
2013-05-28 09:57 - 2010-09-19 06:17 - 00000000 ____D C:&#092;Program Files (x86)&#092;Steam<br />
2013-05-27 05:16 - 2009-05-11 06:37 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;DC++<br />
2013-05-27 05:16 - 2009-05-11 06:37 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;DC++<br />
2013-05-26 16:57 - 2013-05-10 10:06 - 00447324 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.rls.bck<br />
2013-05-26 16:57 - 2013-05-10 10:06 - 00447324 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;etc&#092;DsaFlt.rls<br />
2013-05-26 16:53 - 2013-05-10 10:06 - 00251144 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFCONT.DAT.bck<br />
2013-05-26 16:53 - 2013-05-10 10:06 - 00251144 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;APPFCONT.DAT<br />
2013-05-24 23:00 - 2013-05-10 10:04 - 00000522 ____A C:&#092;Windows&#092;Tasks&#092;Grundrensning.job<br />
2013-05-24 22:53 - 2013-03-20 19:05 - 00001992 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;Google Chrome.lnk<br />
2013-05-22 12:50 - 2013-05-15 10:02 - 00000089 ____A C:&#092;Users&#092;Default.Default-dator&#092;Desktop&#092;Spel.txt<br />
2013-05-19 01:03 - 2012-03-29 00:37 - 00204800 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />
2013-05-19 00:48 - 2013-05-19 00:48 - 00011634 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;ouji)] Haruhi no Uzuki [Haruhiâ€™s Ache] (Suzumiya Haruhi no Yuuutsu [The Melancholy of Haruhi Suzumiya]) [English] [Strange Gray Cat].zip.torrent<br />
2013-05-16 16:38 - 2013-01-10 00:05 - 00000362 ____A C:&#092;Users&#092;Default.Default-dator&#092;Desktop&#092;att se på så smånigom.txt<br />
2013-05-15 12:26 - 2008-01-21 11:17 - 01667518 ____A C:&#092;Windows&#092;System32&#092;PerfStringBackup.INI<br />
2013-05-15 12:26 - 2008-01-21 11:16 - 00692866 ____A C:&#092;Windows&#092;System32&#092;perfh01D.dat<br />
2013-05-15 12:26 - 2008-01-21 11:16 - 00161354 ____A C:&#092;Windows&#092;System32&#092;perfc01D.dat<br />
2013-05-15 12:23 - 2013-05-15 12:22 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{4B91FFC8-D6C9-4D5C-9ABE-648BC272A897}<br />
2013-05-15 12:19 - 2013-03-19 18:14 - 00230312 ____A C:&#092;Windows&#092;System32&#092;FNTCACHE.DAT<br />
2013-05-15 12:05 - 2006-11-02 13:35 - 75016696 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mrt.exe<br />
2013-05-10 10:52 - 2013-05-10 10:52 - 00001069 ____A C:&#092;Users&#092;Public&#092;Desktop&#092;Panda Cloud Cleaner.lnk<br />
2013-05-10 10:51 - 2008-08-29 15:50 - 00000000 ____D C:&#092;Program Files (x86)&#092;Panda Security<br />
2013-05-10 10:34 - 2013-05-10 10:32 - 00474430 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;dd_vcredistMSI2A37.txt<br />
2013-05-10 10:34 - 2013-05-10 10:32 - 00012770 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;dd_vcredistUI2A37.txt<br />
2013-05-10 10:13 - 2013-04-08 07:07 - 00005792 ____A C:&#092;Windows&#092;PFRO.log<br />
2013-05-10 10:07 - 2011-06-09 22:28 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;Panda Security<br />
2013-05-10 10:06 - 2013-05-10 10:06 - 00015928 ____A C:&#092;Windows&#092;System32&#092;Drivers&#092;COMFiltr.sys<br />
2013-05-10 10:06 - 2013-05-10 10:06 - 00000274 ____A C:&#092;Windows&#092;System32&#092;PavCPL64.dat<br />
2013-05-10 10:05 - 2008-08-27 15:45 - 00000000 ____D C:&#092;users&#092;Default.Default-dator<br />
2013-05-10 10:03 - 2013-05-10 10:03 - 00000000 ____D C:&#092;Windows&#092;SysWOW64&#092;PAV<br />
2013-05-10 10:03 - 2011-06-09 22:25 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Roaming&#092;Panda Security<br />
2013-05-10 10:03 - 2011-04-27 05:23 - 00000000 ____D C:&#092;ProgramData&#092;Panda Security<br />
2013-05-10 10:03 - 2008-08-27 16:08 - 00000000 ___HD C:&#092;Program Files (x86)&#092;InstallShield Installation Information<br />
2013-05-09 10:03 - 2013-05-09 10:03 - 00009307 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;rmite (Nohito)] Full Dive Human Farm ~If One Could Make a Human Farm Using Cheats~ Download Edition (Sword Art Online) [English] =LWB=.zip.torrent<br />
2013-05-08 21:01 - 2013-05-08 21:01 - 00000000 ____D C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;{53408C3C-CB7D-4135-AC8D-4EF6820E7A3F}<br />
2013-05-05 22:36 - 2013-05-15 11:59 - 17818624 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.dll<br />
2013-05-05 22:16 - 2013-05-15 11:59 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-05-05 20:25 - 2013-05-15 11:59 - 12324864 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mshtml.dll<br />
2013-05-05 20:12 - 2013-05-15 11:59 - 02382848 ____A (Microsoft Corporation) C:&#092;Windows&#092;SysWOW64&#092;mshtml.tlb<br />
2013-05-05 08:07 - 2013-05-05 08:07 - 00011002 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;[Minion] Binkan â˜† Torisu Ch. 1 [English] {bfrost}.zip.torrent<br />
2013-05-05 07:54 - 2013-05-05 07:54 - 00011766 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;) [Karakishi Youhei-dan Shinka (Kanenomori Sentarou, Sunahara Wataru)] Go Tesei Ikka [Handmade Family] (Naruto) [English] {Decensored}.zip.torrent<br />
2013-05-04 02:07 - 2013-05-04 02:07 - 00041888 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;)] Futanari Euphemia x Kyonyuu Cornelia   Futanari Euphemia and Big-Breasted Cornelia (Code Geass  Lelouch of the Rebellion) [English].zip.torrent<br />
2013-05-04 02:07 - 2013-05-04 02:07 - 00039687 ____A C:&#092;Users&#092;Default.Default-dator&#092;Downloads&#092;(C72) [FANGS (Higashimadou Hisagi)] Futanari Kallen x Kyonyuu Milly   Huge-Rack Milly X Futanari Kallen (Code Geass) [English].zip.torrent<br />
2013-05-03 20:07 - 2012-05-11 02:02 - 00012458 ____A C:&#092;Users&#092;Default.Default-dator&#092;Desktop&#092;musik.txt<br />
2013-05-02 21:47 - 2012-04-17 18:30 - 00691592 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;SysWOW64&#092;FlashPlayerApp.exe<br />
2013-05-02 21:47 - 2011-09-16 17:32 - 00071048 ____A (Adobe Systems Incorporated) C:&#092;Windows&#092;SysWOW64&#092;FlashPlayerCPLApp.cpl<br />
2013-05-02 21:47 - 2008-09-14 19:18 - 00000000 ____D C:&#092;ProgramData&#092;Adobe<br />
2013-05-02 21:41 - 2012-10-28 21:24 - 00000000 ____D C:&#092;Program Files (x86)&#092;uTorrent<br />
2013-05-02 01:06 - 2010-01-06 19:02 - 00278800 ____N (Microsoft Corporation) C:&#092;Windows&#092;System32&#092;MpSigStub.exe<br />
2013-05-01 17:40 - 2013-05-01 17:40 - 00049952 ____A C:&#092;Users&#092;Default.Default-dator&#092;AppData&#092;Local&#092;GDIPFONTCACHEV1.DAT<br />
2013-05-01 17:18 - 2011-10-25 09:37 - 00000550 ____A C:&#092;Users&#092;Default.Default-dator&#092;Desktop&#092;ekonomi.txt<br />
<br />
==================== Known DLLs (Whitelisted) ================<br />
<br />
<br />
==================== Bamital & volsnap Check =================<br />
<br />
C:&#092;Windows&#092;System32&#092;winlogon.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;wininit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;SysWOW64&#092;wininit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;explorer.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;SysWOW64&#092;explorer.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;svchost.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;SysWOW64&#092;svchost.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;services.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;User32.dll =&gt; MD5 is legit<br />
C:&#092;Windows&#092;SysWOW64&#092;User32.dll =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;userinit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;SysWOW64&#092;userinit.exe =&gt; MD5 is legit<br />
C:&#092;Windows&#092;System32&#092;Drivers&#092;volsnap.sys =&gt; MD5 is legit<br />
<br />
==================== EXE ASSOCIATION =====================<br />
<br />
HKLM&#092;...&#092;.exe: exefile =&gt; OK<br />
HKLM&#092;...&#092;exefile&#092;DefaultIcon: %1 =&gt; OK<br />
HKLM&#092;...&#092;exefile&#092;open&#092;command: "%1" %* =&gt; OK<br />
<br />
==================== Restore Points  =========================<br />
<br />
Restore point made on: 2013-04-19 06:14:43<br />
Restore point made on: 2013-04-19 23:00:05<br />
Restore point made on: 2013-04-20 23:00:18<br />
Restore point made on: 2013-04-22 13:07:50<br />
Restore point made on: 2013-04-23 23:00:27<br />
Restore point made on: 2013-04-24 23:00:23<br />
Restore point made on: 2013-04-25 23:00:28<br />
Restore point made on: 2013-04-27 03:34:53<br />
Restore point made on: 2013-04-27 23:00:34<br />
Restore point made on: 2013-05-02 23:11:10<br />
Restore point made on: 2013-05-03 23:00:43<br />
Restore point made on: 2013-05-05 02:40:35<br />
Restore point made on: 2013-05-08 22:18:02<br />
Restore point made on: 2013-05-09 23:00:27<br />
Restore point made on: 2013-05-10 10:05:49<br />
Restore point made on: 2013-05-10 10:30:44<br />
Restore point made on: 2013-05-10 23:00:25<br />
Restore point made on: 2013-05-11 23:00:33<br />
Restore point made on: 2013-05-13 15:32:25<br />
Restore point made on: 2013-05-14 23:06:57<br />
Restore point made on: 2013-05-15 11:58:50<br />
Restore point made on: 2013-05-16 10:55:45<br />
Restore point made on: 2013-05-16 23:00:32<br />
Restore point made on: 2013-05-17 23:00:23<br />
Restore point made on: 2013-05-19 06:47:16<br />
Restore point made on: 2013-05-24 22:53:08<br />
Restore point made on: 2013-05-25 23:00:27<br />
<br />
==================== Memory info =========================== <br />
<br />
Percentage of memory in use: 14%<br />
Total physical RAM: 4093.58 MB<br />
Available physical RAM: 3490.48 MB<br />
Total Pagefile: 3821 MB<br />
Available Pagefile: 3459.49 MB<br />
Total Virtual: 8192 MB<br />
Available Virtual: 8191.89 MB<br />
<br />
==================== Drives ================================<br />
<br />
Drive c: (Windows) (Fixed) (Total:698.63 GB) (Free:91.2 GB) NTFS (Disk=0 Partition=1) ==&gt;[Drive with boot components (obtained from BCD)]<br />
Drive d: (Data) (Fixed) (Total:698.63 GB) (Free:51.63 GB) NTFS (Disk=1 Partition=1)<br />
Drive e: (FRMCxFRE_SV_DVD) (CDROM) (Total:3.54 GB) (Free:0 GB) UDF<br />
Drive f: (SCII CE USB) (Removable) (Total:1.96 GB) (Free:0.72 GB) FAT (Disk=2 Partition=1)<br />
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS<br />
<br />
==================== MBR & Partition Table ==================<br />
<br />
========================================================<br />
Disk: 0 (MBR Code: Windows Vista) (Size: 699 GB) (Disk ID: 0770BCAC)<br />
Partition 1: (Active) - (Size=699 GB) - (Type=07 NTFS)<br />
<br />
========================================================<br />
Disk: 1 (MBR Code: Windows Vista) (Size: 699 GB) (Disk ID: 9DF45DCE)<br />
Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS)<br />
<br />
========================================================<br />
Disk: 2 (Size: 2 GB) (Disk ID: 6F20736B)<br />
Partition 1: (Not Active) - (Size=544 GB) - (Type=72)<br />
Partition 2: (Not Active) - (Size=923 GB) - (Type=65)<br />
Partition 3: (Not Active) - (Size=923 GB) - (Type=79)<br />
Partition 4: (Not Active) - (Size=-336763289600) - (Type=0D)<br />
<br />
<br />
Last Boot: 2013-05-29 08:38<br />
<br />
==================== End Of Log ============================<br />
<br />
]]></description>
		<pubDate>Wed, 29 May 2013 08:05:34 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341621-ukash-virus-felsakert-lage-funkar-inte-hjalp/</guid>
	</item>
	<item>
		<title><![CDATA[Drabbats av Ukash ( &#34;Polisviruset&#34; )]]></title>
		<link>http://eforum.idg.se/topic/341612-drabbats-av-ukash-polisviruset/</link>
		<description><![CDATA[Hej. <br />
<br />
Igår drabbades vi av Ukash-viruset på vår bärbara dator. Det kom upp en stor ruta där det stod att Rikspolisstyrelsen krävde betalning pga att man varit inne på olagliga sidor, och det gick inte att få bort denna sida.<br />
<br />
Tillslut lyckades vi starta datorn i felsäkert läge och därefter installera ett antivirusprogram som heter "Malware bytes AntiMalware". Detta program skannade igenom hela datorn och hittade 2 st objekt - Trojaner som togs bort. Efter det gick det att starta datorn och komma fram till vanliga startbilden. När vi kört en genomskanning med Malware-programmet nu igen så står det att 0 objekt är funna och att hela datorn har genomsökts. <br />
<br />
Min fråga är nu, kan man lita på att viruset är helt och hållet borta eftersom det står att 0 objekt är funna, eller behöver vi kontakta vår internetoperatör, Telia, och be dem att formatera hela vår dator?? Eller kan vi själva formatera datorn på ett enkelt sätt? Vi kan i stort sätt ingenting om datorer. <br />
<br />
En sista fråga... om vi ber Telia att formatera datorn, försvinner då alla våra bilder (fotografier) som vi har i mappen "Bilder" eller berörs de ej av formateringen?<br />
<br />
Stort tack på förhand!<br />
Mvh Jossan]]></description>
		<pubDate>Tue, 28 May 2013 06:48:15 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341612-drabbats-av-ukash-polisviruset/</guid>
	</item>
	<item>
		<title>Microsoft Security Essentials Alert (Fake)</title>
		<link>http://eforum.idg.se/topic/341594-microsoft-security-essentials-alert-fake/</link>
		<description><![CDATA[Jag har dabbat mig och (troligen) laddat ner en falskt "Microsoft Security Essentials Alert" "Potentials thret details.....".<br />
<br />
Jag förstod efter en sekund mitt misstag och gjorde genast en fullständig scan av datorn med mitt antivirusprogram<strong class='bbc'> Telia Säker surf</strong>. Scannade också med <strong class='bbc'>Trend Micro</strong>, <strong class='bbc'>Panda </strong>och <strong class='bbc'>Spybot</strong>. Inget malware blev funnet. <strong class='bbc'>Panda</strong> hade ett antal "Unknown Files & Suspicious Policies" som togs bort. <strong class='bbc'>Spybot</strong> hade fyra "Tracking cookies" som togs bort.<br />
<br />
Är det något mer jag bör och kan göra? <br />
<br />
Känner någon till <strong class='bbc'>utanvirus.se</strong>? Där har man ett program som man anser tar bort faket "Microsoft Security Essentials Alert" och dess skadliga effekter.<br />
<br />
Tacksam för synpunkter!]]></description>
		<pubDate>Mon, 27 May 2013 09:04:24 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341594-microsoft-security-essentials-alert-fake/</guid>
	</item>
	<item>
		<title>Polisvirus</title>
		<link>http://eforum.idg.se/topic/341591-polisvirus/</link>
		<description><![CDATA[Hej,<br />
I lördags var jag inne och kollade på en film och råkade klicka på en banner, det var på en fri sida så det var väl bara otur - det flashade upp Polis - sen var datorn låst. Så ledsen - hela mitt liv finns i den datorn och nu kommer jag inte åt något.<br />
<br />
Kan inget mer om datorer än som vanlig användare och hittade den här siten - verkar finnas många som kan tipsa mig här <img src='http://eforum.idg.se/public/style_emoticons/default/rolleyes.gif' class='bbc_emoticon' alt=':rolleyes:' /> .<br />
<br />
Har skrivit ut en manual från nätet men vet inte om jag vågar använda den då den kanske är gjord av virusskaparna - man blir ju lite schizo..<br />
<br />
Kan någon hjälpa mig och förklara på så enkelt språk att jag - en "not so skilled" dataperson kan förstå!<br />
<br />
Jag tackar på förhand - hoppas att jag kan komma åt allt i datorn igen!<img src='http://eforum.idg.se/public/style_emoticons/default/blush.gif' class='bbc_emoticon' alt=':blush:' /> <img src='http://eforum.idg.se/public/style_emoticons/default/blush.gif' class='bbc_emoticon' alt=':blush:' /> <img src='http://eforum.idg.se/public/style_emoticons/default/blush.gif' class='bbc_emoticon' alt=':blush:' /> <br />
<br />
<br />
Monique]]></description>
		<pubDate>Mon, 27 May 2013 07:46:36 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341591-polisvirus/</guid>
	</item>
	<item>
		<title>Vilket virusprogram?</title>
		<link>http://eforum.idg.se/topic/341589-vilket-virusprogram/</link>
		<description><![CDATA[OM man läser lite så verkar det som Essential är det man bör ha. Hur länge har det funnits?<br />
Jag har ju bara använt AVG Norton m.m.]]></description>
		<pubDate>Mon, 27 May 2013 07:31:20 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341589-vilket-virusprogram/</guid>
	</item>
	<item>
		<title>Karantän</title>
		<link>http://eforum.idg.se/topic/341550-karantan/</link>
		<description><![CDATA[Hej!<br />
Har en fråga om karantän.När jag skannade datorn så hittade programmet, yontoo, Qvo6.com, och en del annat.<br />
Det jag undrar över,varför sätts det i karantän,varför tas det inte bort på en gång]]></description>
		<pubDate>Thu, 23 May 2013 12:02:12 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341550-karantan/</guid>
	</item>
	<item>
		<title>Ännu en  polistrojan</title>
		<link>http://eforum.idg.se/topic/341546-annu-en-polistrojan/</link>
		<description><![CDATA[Hej igen Cecilia!<br />
Postar min  log här nedan.<br />
Det var  inget  negativt i det jag  sa  om  "datanördar".<br />
2 av mina  bästa kompisar  är  bäst i landet på  sina områden- men de  jobbar  mer med att  laga nätverk och haverrerade servers -  sen vill jag inte  störa dem   om jag  tror  mig kunna greja det  själv, men jag  körde fast  som sagt- trots Dina fina råd.<br />
Du har  inte  tänkt  att  bli kommersiell och ta betalt för att  hjälpa folk med sånt här?? Kaching!!<br />
<br />
Så här ser  min logg ut:<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade filer</h4>
	<ul>
		
			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17482" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17482" title="Ladda ner bilaga">txt.txt</a> <span class='desc'><strong>(31,97Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 4</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 22 May 2013 13:00:01 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341546-annu-en-polistrojan/</guid>
	</item>
	<item>
		<title>Hur tänker man hos Norton/Symantec?</title>
		<link>http://eforum.idg.se/topic/341515-hur-tanker-man-hos-nortonsymantec/</link>
		<description><![CDATA[Har haft min HP Pavilion G6 drygt ett år. Norton Internet Security fanns med som prov-version från start. Funkade utmärkt, omärkligt och utan problem under hela provperioden, så jag köpte en årsprenumeration à 599 kr när prövotiden gick ut eftersom Norton skötte jobbet snyggt och jag var nöjd.<br />
<br />
Nåväl, prenumerationåret har gått snabbt och det är åter dags att förnya prenumerationen, enkelt och smidigt via elektronisk uppdatering med registrerat konto och dito kontokort. Ytterligare 599 kr för ett år.<br />
<br />
Men vad nu? Surfar lite på nätet och upptäcker att jag kan köpa Norton Internet Security 2013 nytt i kartong, med vidhängande  CD/DVD-skiva, för mindre än en tredjedel av det pris som en fortsatt elektronisk prenumeration via Norton Update skulle kosta. 18 pund (182 kr) från Amazon mot 599 kr.<br />
<br />
Klart förhandlingsläge tänker jag och ringer Norton/Symantec support. Men där blir det nobben och kalla handen direkt. Någon rabatt för att matcha marknadspriset hos Amazon är inte att tänka på, meddelar en supportfröken tämligen ampert. <br />
<br />
"Vi tar 599 kr för en årsprenumeration", blir svaret.<br />
<br />
"Men jag får ju samma produkt med både kartong och programskiva för bara en tredjedel av priset hos Amazon. Varför är det mycket dyrare om man köper direkt av tillverkaren, dessutom en uppdatering utan fysiska media", undrar jag.<br />
<br />
"Marknaden och våra partners är fria att sätta vilka priser de vill, det kan inte vi göra något åt. Men vi tar 599 kr för ett år" blir det föga upplysande svaret.<br />
<br />
Så nu har jag köpt en kartong. Men jag undrar hur man tänker hos Norton/Symantec.<br />
<br />
Mitt råd till alla uppgraderare in spe är att kolla kartongpriset vs det elektroniska direktpriset, inte bara på Norton/Symantecs produkter.]]></description>
		<pubDate>Sun, 19 May 2013 18:17:40 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341515-hur-tanker-man-hos-nortonsymantec/</guid>
	</item>
	<item>
		<title>Ucash</title>
		<link>http://eforum.idg.se/topic/341484-ucash/</link>
		<description><![CDATA[En av mina datorer har drabbats av virus och jag kan i princip ingenting om datorer, men har lyckats googla mig till att det rör sig om ett ucash-virus, det ser likadant ut som det som visas i en tråd här på forumet om ucash-virus från mars. Jag har försökt lista ut hur jag ska gå tillväga för att bli av med det, och det verkar som att flera har fått hjälp av snälla människor här så jag hoppas på det jag också.<br />
<br />
Datorn i fråga har ett par år på nacken och rymmer hela mitt liv så jag vill gärna slippa blåsa hela hårddisken. Det rör sig om ett Vista business, men mer än så vet jag inte och det finns ingen installationsskiva till operativsystemet heller.<br />
<br />
Blir outsägligt glad om någon vill hjälpa mig. Tack på förhand!]]></description>
		<pubDate>Thu, 16 May 2013 08:21:08 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341484-ucash/</guid>
	</item>
	<item>
		<title><![CDATA[Efter omstart blev datorn &#34;gammal&#34;]]></title>
		<link>http://eforum.idg.se/topic/341468-efter-omstart-blev-datorn-gammal/</link>
		<description><![CDATA[<div class="bbc_log">
				<input type="button" class="bbc_log_show" value="+" />
				<div class="bbc_log_wrapper">
					<div class="bbc_log_short_content" id="bbc_log_short_content">DDS (Ver_2012-11-20.01) - NTFS_x86 </div>
					<div class="bbc_log_content" id="bbc_log_content" style="display:none;">DDS (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 8.0.6001.19412<br />
Run by xx at 19:45:47 on 2013-05-14<br />
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.46.1053.18.3068.934 [GMT 2:00]<br />
.<br />
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}<br />
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}<br />
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}<br />
.<br />
============== Running Processes ================<br />
.<br />
C:&#092;Windows&#092;system32&#092;wininit.exe<br />
C:&#092;Windows&#092;system32&#092;lsm.exe<br />
C:&#092;Windows&#092;system32&#092;Ati2evxx.exe<br />
C:&#092;Windows&#092;system32&#092;SLsvc.exe<br />
C:&#092;Windows&#092;system32&#092;Hpservice.exe<br />
C:&#092;Windows&#092;system32&#092;WLANExt.exe<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Windows&#092;System32&#092;spoolsv.exe<br />
C:&#092;Windows&#092;system32&#092;Ati2evxx.exe<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Windows&#092;system32&#092;Dwm.exe<br />
C:&#092;Windows&#092;Explorer.EXE<br />
C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;armsvc.exe<br />
C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;stwrt.inf_52c73ccb&#092;aestsrv.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;AppleMobileDeviceService.exe<br />
C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />
C:&#092;Program Files&#092;Norton 360&#092;Engine&#092;20.3.1.22&#092;ccSvcHst.exe<br />
C:&#092;Program Files&#092;Sony Ericsson&#092;Sony Ericsson PC Suite&#092;SupServ.exe<br />
C:&#092;Program Files&#092;Sony&#092;PMB&#092;PMBDeviceInfoProvider.exe<br />
c:&#092;Program Files&#092;Common Files&#092;Protexis&#092;License Service&#092;PsiService_2.exe<br />
C:&#092;Program Files&#092;SMINST&#092;BLService.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;TouchSmart&#092;Media&#092;TSMAgent.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;TouchSmart&#092;Media&#092;Kernel&#092;CLML&#092;CLMLSvc.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Wireless Assistant&#092;HPWAMain.exe<br />
C:&#092;Program Files&#092;IDT&#092;WDM&#092;sttray.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP MediaSmart&#092;SmartMenu.exe<br />
C:&#092;Program Files&#092;CyberLink&#092;Shared files&#092;RichVideo.exe<br />
C:&#092;Program Files&#092;Secunia&#092;PSI&#092;PSIA.exe<br />
C:&#092;Program Files&#092;Elaborate Bytes&#092;VirtualCloneDrive&#092;VCDDaemon.exe<br />
C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;Program Files&#092;Sony&#092;PMB&#092;PMBVolumeWatcher.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;Media&#092;TV&#092;Kernel&#092;TV&#092;TVCapSvc.exe<br />
C:&#092;Users&#092;xx&#092;AppData&#092;Local&#092;Akamai&#092;netsession_win.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;Media&#092;TV&#092;Kernel&#092;TV&#092;TVSched.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSVC.EXE<br />
C:&#092;Users&#092;xx&#092;AppData&#092;Roaming&#092;Spotify&#092;Data&#092;SpotifyWebHelper.exe<br />
C:&#092;Windows&#092;system32&#092;SearchIndexer.exe<br />
C:&#092;Program Files&#092;Skype&#092;Phone&#092;Skype.exe<br />
C:&#092;Program Files&#092;ATI Technologies&#092;ATI.ACE&#092;Core-Static&#092;MOM.exe<br />
C:&#092;Program Files&#092;Windows Media Player&#092;wmpnscfg.exe<br />
C:&#092;Windows&#092;System32&#092;WUDFHost.exe<br />
C:&#092;Program Files&#092;Personal&#092;bin&#092;Personal.exe<br />
C:&#092;Program Files&#092;Secunia&#092;PSI&#092;psi_tray.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSvcM.exe<br />
C:&#092;Program Files&#092;Norton 360&#092;Engine&#092;20.3.1.22&#092;ccSvcHst.exe<br />
C:&#092;Program Files&#092;Windows Media Player&#092;wmpnetwk.exe<br />
C:&#092;Windows&#092;system32&#092;DllHost.exe<br />
C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
C:&#092;Users&#092;xx&#092;AppData&#092;Local&#092;Akamai&#092;netsession_win.exe<br />
C:&#092;Program Files&#092;Secunia&#092;PSI&#092;sua.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPHelper.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;Shared&#092;hpqwmiex.exe<br />
C:&#092;Program Files&#092;ATI Technologies&#092;ATI.ACE&#092;Core-Static&#092;CCC.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;Shared&#092;hpqToaster.exe<br />
C:&#092;Windows&#092;system32&#092;conime.exe<br />
C:&#092;Windows&#092;Microsoft.Net&#092;Framework&#092;v3.0&#092;WPF&#092;PresentationFontCache.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;Program Files&#092;Mozilla Firefox&#092;plugin-container.exe<br />
C:&#092;Windows&#092;system32&#092;Macromed&#092;Flash&#092;FlashPlayerPlugin_11_7_700_169.exe<br />
C:&#092;Windows&#092;system32&#092;Macromed&#092;Flash&#092;FlashPlayerPlugin_11_7_700_169.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Internet Services&#092;ApplePhotoStreams.exe<br />
C:&#092;Windows&#092;system32&#092;SearchProtocolHost.exe<br />
C:&#092;Windows&#092;system32&#092;SearchFilterHost.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k DcomLaunch<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k rpcss<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalServiceNetworkRestricted<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalSystemNetworkRestricted<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k netsvcs<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k GPSvcGroup<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalService<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkService<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceNoNetwork<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k Akamai<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k hpdevmgmt<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkServiceNetworkRestricted<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k imgsvc<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k WerSvcGroup<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceAndNoImpersonation<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://search.babylon.com/?affID=109217&tt=300912_TORP_4012_2&babsrc=HP_ss&mntrId=3f670521000000000000002556718ef3<br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sv_se&c=91&bd=Pavilion&pf=cnnb<br />
uProxyOverride = &lt;local&gt;;*.local<br />
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:&#092;program files&#092;utorrentcontrol2&#092;prxtbuTor.dll<br />
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:&#092;program files&#092;utorrentcontrol2&#092;prxtbuTor.dll<br />
mWinlogon: Userinit = Userinit.exe,<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:&#092;program files&#092;common files&#092;adobe&#092;acrobat&#092;activex&#092;AcroIEHelperShim.dll<br />
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:&#092;program files&#092;norton 360&#092;engine&#092;20.3.1.22&#092;coieplg.dll<br />
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:&#092;program files&#092;utorrentcontrol2&#092;prxtbuTor.dll<br />
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:&#092;program files&#092;norton 360&#092;engine&#092;20.3.1.22&#092;ips&#092;ipsbho.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:&#092;program files&#092;common files&#092;microsoft shared&#092;windows live&#092;WindowsLiveLogin.dll<br />
TB: uTorrentControl2 Toolbar: {687578B9-7132-4A7A-80E4-30EE31099E03} - c:&#092;program files&#092;utorrentcontrol2&#092;prxtbuTor.dll<br />
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:&#092;program files&#092;norton 360&#092;engine&#092;20.3.1.22&#092;coieplg.dll<br />
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:&#092;program files&#092;utorrentcontrol2&#092;prxtbuTor.dll<br />
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:&#092;program files&#092;norton 360&#092;engine&#092;20.3.1.22&#092;coieplg.dll<br />
uRun: [Akamai NetSession Interface] "c:&#092;users&#092;xx&#092;appdata&#092;local&#092;akamai&#092;netsession_win.exe"<br />
uRun: [Spotify Web Helper] "c:&#092;users&#092;xx&#092;appdata&#092;roaming&#092;spotify&#092;data&#092;SpotifyWebHelper.exe"<br />
uRun: [Skype] "c:&#092;program files&#092;skype&#092;phone&#092;Skype.exe" /minimized /regrun<br />
uRun: [WMPNSCFG] c:&#092;program files&#092;windows media player&#092;WMPNSCFG.exe<br />
mRun: [StartCCC] "c:&#092;program files&#092;ati technologies&#092;ati.ace&#092;core-static&#092;CLIStart.exe" MSRun<br />
mRun: [SynTPEnh] c:&#092;program files&#092;synaptics&#092;syntp&#092;SynTPEnh.exe<br />
mRun: [TSMAgent] "c:&#092;program files&#092;hewlett-packard&#092;touchsmart&#092;media&#092;TSMAgent.exe"<br />
mRun: [CLMLServer for HP TouchSmart] "c:&#092;program files&#092;hewlett-packard&#092;touchsmart&#092;media&#092;kernel&#092;clml&#092;CLMLSvc.exe"<br />
mRun: [UCam_Menu] "c:&#092;program files&#092;hewlett-packard&#092;media&#092;webcam&#092;muitransfer&#092;muistartmenu.exe" "c:&#092;program files&#092;hewlett-packard&#092;media&#092;webcam" update "software&#092;hewlett-packard&#092;media&#092;Webcam"<br />
mRun: [UpdateLBPShortCut] "c:&#092;program files&#092;cyberlink&#092;labelprint&#092;muitransfer&#092;muistartmenu.exe" "c:&#092;program files&#092;cyberlink&#092;labelprint" updatewithcreateonce "software&#092;cyberlink&#092;labelprint&#092;2.5"<br />
mRun: [UpdateP2GoShortCut] "c:&#092;program files&#092;cyberlink&#092;power2go&#092;muitransfer&#092;muistartmenu.exe" "c:&#092;program files&#092;cyberlink&#092;power2go" updatewithcreateonce "software&#092;cyberlink&#092;power2go&#092;6.0"<br />
mRun: [WirelessAssistant] c:&#092;program files&#092;hewlett-packard&#092;hp wireless assistant&#092;HPWAMain.exe<br />
mRun: [SysTrayApp] c:&#092;program files&#092;idt&#092;wdm&#092;sttray.exe<br />
mRun: [ATICustomerCare] "c:&#092;program files&#092;ati&#092;aticustomercare&#092;ATICustomerCare.exe"<br />
mRun: [SmartMenu] c:&#092;program files&#092;hewlett-packard&#092;hp mediasmart&#092;SmartMenu.exe<br />
mRun: [UpdatePDRShortCut] "c:&#092;program files&#092;cyberlink&#092;powerdirector&#092;muitransfer&#092;muistartmenu.exe" "c:&#092;program files&#092;cyberlink&#092;powerdirector" updatewithcreateonce "software&#092;cyberlink&#092;powerdirector&#092;8.0"<br />
mRun: [APSDaemon] "c:&#092;program files&#092;common files&#092;apple&#092;apple application support&#092;APSDaemon.exe"<br />
mRun: [QuickTime Task] "c:&#092;program files&#092;quicktime&#092;QTTask.exe" -atboottime<br />
mRun: [VirtualCloneDrive] "c:&#092;program files&#092;elaborate bytes&#092;virtualclonedrive&#092;VCDDaemon.exe" /s<br />
mRun: [iTunesHelper] "c:&#092;program files&#092;itunes&#092;iTunesHelper.exe"<br />
mRun: [PMBVolumeWatcher] c:&#092;program files&#092;sony&#092;pmb&#092;PMBVolumeWatcher.exe<br />
mRun: [Adobe ARM] "c:&#092;program files&#092;common files&#092;adobe&#092;arm&#092;1.0&#092;AdobeARM.exe"<br />
StartupFolder: c:&#092;progra~2&#092;micros~1&#092;windows&#092;startm~1&#092;programs&#092;startup&#092;bankid~1.lnk - c:&#092;program files&#092;personal&#092;bin&#092;Personal.exe<br />
StartupFolder: c:&#092;progra~2&#092;micros~1&#092;windows&#092;startm~1&#092;programs&#092;startup&#092;secuni~1.lnk - c:&#092;program files&#092;secunia&#092;psi&#092;psi_tray.exe<br />
uPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0<br />
mPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: E&xportera till Microsoft Excel - c:&#092;progra~1&#092;micros~2&#092;office12&#092;EXCEL.EXE/3000<br />
IE: Search the Web - c:&#092;program files&#092;sweetim&#092;toolbars&#092;internet explorer&#092;resources&#092;menuext.html<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:&#092;program files&#092;microsoft office&#092;office12&#092;ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}<br />
TCP: NameServer = 83.255.245.11 193.150.193.150<br />
TCP: Interfaces&#092;{50AB8F99-77D3-48AE-B70F-41C2F4C8C36B} : DHCPNameServer = 83.255.245.11 193.150.193.150<br />
TCP: Interfaces&#092;{F4F15961-03E9-43E1-AECC-90D86FA2518E} : DHCPNameServer = 195.54.122.211 195.54.122.221<br />
Handler: mcataloguer - {FECF9894-CCCF-4DE3-B994-AEE32E70B341} - c:&#092;program files&#092;mcataloguer&#092;MCatProt.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:&#092;program files&#092;common files&#092;skype&#092;Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:&#092;program files&#092;windows live&#092;photo gallery&#092;AlbumDownloadProtocolHandler.dll<br />
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:&#092;program files&#092;common files&#092;lightscribe&#092;LSRunOnce.exe"<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:&#092;users&#092;xx&#092;appdata&#092;roaming&#092;mozilla&#092;firefox&#092;profiles&#092;d4iqibzp.default&#092;<br />
FF - prefs.js: browser.search.defaulturl - <br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.aftonbladet.se/<br />
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109217&tt=300912_TORP_4012_2&babsrc=KW_ss&mntrId=3f670521000000000000002556718ef3&q=<br />
FF - plugin: c:&#092;program files&#092;adobe&#092;reader 11.0&#092;reader&#092;air&#092;nppdf32.dll<br />
FF - plugin: c:&#092;program files&#092;microsoft silverlight&#092;5.1.20125.0&#092;npctrlui.dll<br />
FF - plugin: c:&#092;program files&#092;personal&#092;bin&#092;np_prsnl.dll<br />
FF - plugin: c:&#092;program files&#092;sony&#092;media go&#092;npmediago.dll<br />
FF - plugin: c:&#092;program files&#092;windows live&#092;photo gallery&#092;NPWLPG.dll<br />
FF - plugin: c:&#092;users&#092;xx&#092;appdata&#092;roaming&#092;mozilla&#092;firefox&#092;profiles&#092;d4iqibzp.default&#092;extensions&#092;2020player_ikea@2020technologies.com&#092;plugins&#092;NP_2020Player_IKEA.dll<br />
FF - plugin: c:&#092;windows&#092;system32&#092;macromed&#092;flash&#092;NPSWF32_11_7_700_169.dll<br />
FF - plugin: c:&#092;windows&#092;system32&#092;npdeployJava1.dll<br />
FF - plugin: c:&#092;windows&#092;system32&#092;npmproxy.dll<br />
.<br />
---- FIREFOX POLICIES ----<br />
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=3f670521000000000000002556718ef3&q=<br />
FF - user.js: extensions.BabylonToolbar.id - 3f670521000000000000002556718ef3<br />
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}<br />
FF - user.js: extensions.BabylonToolbar.instlDay - 15614<br />
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.0.7<br />
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.0.7<br />
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.0.78:30:54<br />
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon<br />
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar<br />
FF - user.js: extensions.BabylonToolbar.aflt - babsst<br />
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none<br />
FF - user.js: extensions.BabylonToolbar.tlbrId - base<br />
FF - user.js: extensions.BabylonToolbar.instlRef - sst<br />
FF - user.js: extensions.BabylonToolbar.dfltLng - en<br />
FF - user.js: extensions.BabylonToolbar.excTlbr - false<br />
FF - user.js: extensions.BabylonToolbar.admin - false<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 SymDS;Symantec Data Store;c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symds.sys [2013-4-16 367704]<br />
R0 SymEFA;Symantec Extended File Attributes;c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symefa.sys [2013-4-16 934488]<br />
R1 BHDrvx86;BHDrvx86;c:&#092;programdata&#092;norton&#092;{0c55c096-0f1d-4f28-aaa2-85ef591126e7}&#092;n360_20.1.1.2&#092;definitions&#092;bashdefs&#092;20130502.001&#092;BHDrvx86.sys [2013-5-7 1000024]<br />
R1 ccSet_N360;Norton 360 Settings Manager;c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;ccsetx86.sys [2013-4-16 134304]<br />
R1 IDSVix86;IDSVix86;c:&#092;programdata&#092;norton&#092;{0c55c096-0f1d-4f28-aaa2-85ef591126e7}&#092;n360_20.1.1.2&#092;definitions&#092;ipsdefs&#092;20130511.001&#092;IDSvix86.sys [2013-5-14 386720]<br />
R1 SymIRON;Symantec Iron Driver;c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;ironx86.sys [2013-4-16 175264]<br />
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symtdiv.sys [2013-4-16 350368]<br />
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/06/15 03:57:14];c:&#092;program files&#092;hewlett-packard&#092;media&#092;dvd&#092;000.fcl [2008-11-29 87536]<br />
R2 AESTFilters;Andrea ST Filters Service;c:&#092;windows&#092;system32&#092;driverstore&#092;filerepository&#092;stwrt.inf_52c73ccb&#092;AEstSrv.exe [2009-6-15 77824]<br />
R2 Akamai;Akamai NetSession Interface;c:&#092;windows&#092;system32&#092;svchost.exe -k Akamai [2008-1-21 21504]<br />
R2 ezSharedSvc;Easybits Shared Services for Windows;c:&#092;windows&#092;system32&#092;svchost.exe -k netsvcs [2008-1-21 21504]<br />
R2 FontCache;Windows Font Cache Service;c:&#092;windows&#092;system32&#092;svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]<br />
R2 hpsrv;HP Service;c:&#092;windows&#092;system32&#092;hpservice.exe [2008-3-19 19456]<br />
R2 N360;Norton 360;c:&#092;program files&#092;norton 360&#092;engine&#092;20.3.1.22&#092;ccsvchst.exe [2013-4-16 144520]<br />
R2 OMSI download service;Sony Ericsson OMSI download service;c:&#092;program files&#092;sony ericsson&#092;sony ericsson pc suite&#092;SupServ.exe [2010-5-11 90112]<br />
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:&#092;program files&#092;sony&#092;pmb&#092;PMBDeviceInfoProvider.exe [2009-10-24 360224]<br />
R2 Recovery Service for Windows;Recovery Service for Windows;c:&#092;program files&#092;sminst&#092;BLService.exe [2009-2-8 365952]<br />
R2 Secunia PSI Agent;Secunia PSI Agent;c:&#092;program files&#092;secunia&#092;psi&#092;psia.exe [2011-1-5 988216]<br />
R2 Secunia Update Agent;Secunia Update Agent;c:&#092;program files&#092;secunia&#092;psi&#092;sua.exe [2011-1-5 399416]<br />
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:&#092;program files&#092;hewlett-packard&#092;media&#092;tv&#092;kernel&#092;tv&#092;TVCapSvc.exe [2009-2-9 296320]<br />
R2 TVSched;TV Task Scheduler (TVTS);c:&#092;program files&#092;hewlett-packard&#092;media&#092;tv&#092;kernel&#092;tv&#092;TVSched.exe [2009-2-9 116096]<br />
R3 appliandMP;appliandMP;c:&#092;windows&#092;system32&#092;drivers&#092;appliand.sys [2010-6-24 28256]<br />
R3 enecir;ENE CIR Receiver;c:&#092;windows&#092;system32&#092;drivers&#092;enecir.sys [2008-9-4 54784]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:&#092;program files&#092;common files&#092;symantec shared&#092;eengine&#092;EraserUtilRebootDrv.sys [2012-8-13 106656]<br />
R3 JMCR;JMCR;c:&#092;windows&#092;system32&#092;drivers&#092;jmcr.sys [2008-10-23 107360]<br />
R3 PSI;PSI;c:&#092;windows&#092;system32&#092;drivers&#092;psi_mf.sys [2010-9-1 15544]<br />
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;vcsvad.sys [2010-11-1 17792]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:&#092;windows&#092;microsoft.net&#092;framework&#092;v4.0.30319&#092;mscorsvw.exe [2010-3-18 130384]<br />
S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:&#092;windows&#092;system32&#092;drivers&#092;Apowersoft_AudioDevice.sys [2012-2-14 16640]<br />
S3 appliand;Applian Network Service;c:&#092;windows&#092;system32&#092;drivers&#092;appliand.sys [2010-6-24 28256]<br />
S3 ASPI;Advanced SCSI Programming Interface Driver;c:&#092;windows&#092;system32&#092;drivers&#092;ASPI32.SYS [2010-12-6 84832]<br />
S3 Com4QLBEx;Com4QLBEx;c:&#092;program files&#092;hewlett-packard&#092;hp quick launch buttons&#092;Com4QLBEx.exe [2009-2-8 222512]<br />
S3 Netaapl;Apple Mobile Device Ethernet Service;c:&#092;windows&#092;system32&#092;drivers&#092;netaapl.sys [2011-5-10 18432]<br />
S3 PACSPTISVR-Sound_Organizer;PACSPTISVR-Sound_Organizer;c:&#092;program files&#092;sony&#092;sound organizer&#092;sony.earth&#092;PACSPTISVR.exe [2010-11-19 157024]<br />
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s0017bus.sys [2010-5-11 86824]<br />
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:&#092;windows&#092;system32&#092;drivers&#092;s0017mdfl.sys [2010-5-11 15016]<br />
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:&#092;windows&#092;system32&#092;drivers&#092;s0017mdm.sys [2010-5-11 114600]<br />
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s0017mgmt.sys [2010-5-11 108328]<br />
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:&#092;windows&#092;system32&#092;drivers&#092;s0017nd5.sys [2010-5-11 26024]<br />
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:&#092;windows&#092;system32&#092;drivers&#092;s0017obex.sys [2010-5-11 104616]<br />
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s0017unic.sys [2010-5-11 109736]<br />
S3 s1029bus;Sony Ericsson Device 1029 driver (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s1029bus.sys [2010-5-11 90280]<br />
S3 s1029mdfl;Sony Ericsson Device 1029 USB WMC Modem Filter;c:&#092;windows&#092;system32&#092;drivers&#092;s1029mdfl.sys [2010-5-11 15016]<br />
S3 s1029mdm;Sony Ericsson Device 1029 USB WMC Modem Driver;c:&#092;windows&#092;system32&#092;drivers&#092;s1029mdm.sys [2010-5-11 122280]<br />
S3 s1029mgmt;Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s1029mgmt.sys [2010-5-11 115880]<br />
S3 s1029nd5;Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS);c:&#092;windows&#092;system32&#092;drivers&#092;s1029nd5.sys [2010-5-11 26024]<br />
S3 s1029obex;Sony Ericsson Device 1029 USB WMC OBEX Interface;c:&#092;windows&#092;system32&#092;drivers&#092;s1029obex.sys [2010-5-11 111912]<br />
S3 s1029unic;Sony Ericsson Device 1029 USB Ethernet Emulation (WDM);c:&#092;windows&#092;system32&#092;drivers&#092;s1029unic.sys [2010-5-11 116904]<br />
S3 TdsNordecr;Nordea NCR1 SmartCard Reader;c:&#092;windows&#092;system32&#092;drivers&#092;nordecr.sys [2007-10-30 24064]<br />
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:&#092;windows&#092;microsoft.net&#092;framework&#092;v4.0.30319&#092;wpf&#092;WPFFontCache_v0400.exe [2010-3-18 753504]<br />
.<br />
=============== File Associations ===============<br />
.<br />
FileExt: .js: Applications&#092;wordpad.exe="c:&#092;program files&#092;windows nt&#092;accessories&#092;WORDPAD.EXE" "%1" [UserChoice]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-04-16 01:24:26	934488	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symefa.sys<br />
2013-04-16 01:24:26	602712	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;srtsp.sys<br />
2013-04-16 01:24:26	367704	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symds.sys<br />
2013-04-16 01:24:26	350368	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symtdiv.sys<br />
2013-04-16 01:24:26	338592	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symnets.sys<br />
2013-04-16 01:24:26	32344	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;srtspx.sys<br />
2013-04-16 01:24:26	21400	----a-r-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symelam.sys<br />
2013-04-16 01:24:26	175264	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;ironx86.sys<br />
2013-04-16 01:24:26	134304	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;ccsetx86.sys<br />
2013-04-16 01:23:50	14818	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016&#092;symvtcer.dat<br />
2013-04-16 01:23:50	--------	d-----w-	c:&#092;windows&#092;system32&#092;drivers&#092;n360&#092;1403010.016<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-12 17:06:02	3766	--sha-w-	c:&#092;programdata&#092;KGyGaAvL.sys<br />
2013-04-17 16:32:26	71048	----a-w-	c:&#092;windows&#092;system32&#092;FlashPlayerCPLApp.cpl<br />
2013-04-17 16:32:26	691592	----a-w-	c:&#092;windows&#092;system32&#092;FlashPlayerApp.exe<br />
2013-04-04 12:50:32	22856	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;mbam.sys<br />
2013-03-11 13:25:50	3603816	----a-w-	c:&#092;windows&#092;system32&#092;ntkrnlpa.exe<br />
2013-03-11 13:25:50	3551080	----a-w-	c:&#092;windows&#092;system32&#092;ntoskrnl.exe<br />
2013-03-09 03:45:04	49152	----a-w-	c:&#092;windows&#092;system32&#092;csrsrv.dll<br />
2013-03-09 01:28:08	64000	----a-w-	c:&#092;windows&#092;system32&#092;smss.exe<br />
2013-03-08 07:17:20	861088	----a-w-	c:&#092;windows&#092;system32&#092;npdeployJava1.dll<br />
2013-03-08 07:17:20	782240	----a-w-	c:&#092;windows&#092;system32&#092;deployJava1.dll<br />
2013-03-08 03:53:50	376320	----a-w-	c:&#092;windows&#092;system32&#092;winsrv.dll<br />
2013-03-08 03:52:22	2067968	----a-w-	c:&#092;windows&#092;system32&#092;mstscax.dll<br />
2013-03-05 01:40:56	2049024	----a-w-	c:&#092;windows&#092;system32&#092;win32k.sys<br />
2013-03-03 19:07:52	1082232	----a-w-	c:&#092;windows&#092;system32&#092;drivers&#092;ntfs.sys<br />
2013-03-01 12:23:51	916480	----a-w-	c:&#092;windows&#092;system32&#092;wininet.dll<br />
2013-03-01 12:18:29	43520	----a-w-	c:&#092;windows&#092;system32&#092;licmgr10.dll<br />
2013-03-01 12:17:59	1469440	----a-w-	c:&#092;windows&#092;system32&#092;inetcpl.cpl<br />
2013-03-01 12:17:42	71680	----a-w-	c:&#092;windows&#092;system32&#092;iesetup.dll<br />
2013-03-01 12:17:42	109056	----a-w-	c:&#092;windows&#092;system32&#092;iesysprep.dll<br />
2013-03-01 10:37:25	385024	----a-w-	c:&#092;windows&#092;system32&#092;html.iec<br />
2013-03-01 08:52:50	133632	----a-w-	c:&#092;windows&#092;system32&#092;ieUnatt.exe<br />
2013-03-01 08:50:31	1638912	----a-w-	c:&#092;windows&#092;system32&#092;mshtml.tlb<br />
2011-08-23 16:42:54	332144	----a-w-	c:&#092;program files&#092;common files&#092;MediaOrganizer.dll<br />
2011-08-23 16:35:38	33136	----a-w-	c:&#092;program files&#092;common files&#092;FlickrProvider.dll<br />
2011-08-23 16:35:14	402800	----a-w-	c:&#092;program files&#092;common files&#092;facebook.dll<br />
2011-08-23 16:35:14	130416	----a-w-	c:&#092;program files&#092;common files&#092;PluginCommon.dll<br />
2011-08-23 16:34:26	465264	----a-w-	c:&#092;program files&#092;common files&#092;AppFramework.dll<br />
.<br />
============= FINISH: 19:52:10,26 ===============<br /></div>
				</div>
			</div>Nått mycket besynnerligt har hänt! Jag körde en Liveupdate och ombads att starta om datorn, som f.ö. varit på i över en månad. Hur som helst efter omstarten märkte jag först att själva fältet längst ner på skrivbordet (till höger om start) var vit (genomskinlig). Outlook fick plötsligt det utseendet som det haft på min gamla dator (5 år sedan)... Nu undrar jag ju då natuuligt vad som hänt!? Jag har kört en malware och allt verkar ok. Jag har kört Norton allt ok. Secunia 100% . Men nått är fel...Kör Vista och Firefox, datorn är en HP. t.o.m. start menyn (allt som är ovanför startknappen, alla program etc. i vänster stapel) är förändrat...Även program jag för över 2 år sedan tagit bort från "uppstart" startades upp idag vid omstarten....?<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade filer</h4>
	<ul>
		
			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17420" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17420" title="Ladda ner bilaga">attach.txt</a> <span class='desc'><strong>(11,78Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 3</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Tue, 14 May 2013 17:32:39 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341468-efter-omstart-blev-datorn-gammal/</guid>
	</item>
	<item>
		<title>SPAMfighter 7.6.39 gratis</title>
		<link>http://eforum.idg.se/topic/341466-spamfighter-7639-gratis/</link>
		<description><![CDATA[<a href='http://www.spamfighter.com/SPAMfighter/Lang_DA/Product_Info.asp' class='bbc_url' title='Extern länk' rel='external'>http://www.spamfighter.com/SPAMfighter/Lang_DA/Product_Info.asp</a>]]></description>
		<pubDate>Tue, 14 May 2013 11:18:46 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341466-spamfighter-7639-gratis/</guid>
	</item>
	<item>
		<title>Hupigon backdoor hittas bara av MBAM! Varför?</title>
		<link>http://eforum.idg.se/topic/341452-hupigon-backdoor-hittas-bara-av-mbam-varfor/</link>
		<description><![CDATA[Haft problem ett tag med att MBAM hittar "Hupigon Backdoor" i "c:/downloads/secheot.exe".<br />
Försökt ta bort det med mbam utan resultat.<br />
Valde då att testa "msert" som ska kunna ta bort denna, men msert hittar ingen infektion!<br />
<br />
Drog då igenom hela registret av av´s etc i felsäkert läge;<br />
Hitman pro, Kaspersky security scan, SAS, Spybot etc.<br />
Körde även flera rescuediscs; Kaspersky, comodo, F-secure, DrWeb, Bitdefender samt Avira utan tecken till infektioner.<br />
<br />
Så nu lutar jag nästan åt att detta är falsepos men vill gärna ha en "Second Opinion"!<br />
<br />
Loggar:<br />
MBAM:<br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
www.malwarebytes.org<br />
<br />
Databasversion: v2013.05.11.05<br />
<br />
Windows 7 Service Pack 1 x64 NTFS<br />
Internet Explorer 9.0.8112.16421<br />
Henrik :: HENRIK-DATOR [administratör]<br />
<br />
2013-05-13 10:02:22<br />
MBAM-log-2013-05-13 (12-22-27).txt<br />
<br />
Skanningstyp: Fullständig skanning (C:&#092;|E:&#092;|F:&#092;|G:&#092;|H:&#092;|I:&#092;|J:&#092;|K:&#092;|)<br />
Aktiverade skanningsalternativ: Minne | Start | Register | Filsystem | Heuristik/Extra | Heuristik/Shuriken | PUP | PUM<br />
Inaktiverade skanningsalternativ: P2P<br />
Antal skannade objekt: 486164<br />
Förfluten tid: 34 minut(er), 5 sekund(er)<br />
<br />
Upptäckta minnesprocesser: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta minnesmoduler: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta registernycklar: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta registervärden: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta registerdataposter: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta mappar: 0<br />
(Inga skadliga poster hittades)<br />
<br />
Upptäckta filer: 1<br />
c:&#092;downloads&#092;secheot.exe (Backdoor.Hupigon) -&gt; Ingen åtgärd.<br />
<br />
(klar)<br />
<br />
DDS:<br />
<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17410" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17410" title="Ladda ner bilaga">Attach.txt</a> <span class='desc'><strong>(8Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 1</span><br />
<br />
<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 9.0.8112.16476  BrowserJavaVersion: 10.21.2<br />
Run by Henrik at 12:27:39 on 2013-05-13<br />
.<br />
============== Running Processes ===============<br />
.<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uProxyOverride = &lt;local&gt;<br />
mWinlogon: Userinit = userinit.exe,<br />
BHO: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;orbitcth.dll<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - E:&#092;Spybot S&D&#092;Spybot - Search & Destroy 2&#092;SDHelper.dll<br />
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;ssv.dll<br />
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:&#092;Program Files (x86)&#092;Microsoft Office&#092;Office14&#092;URLREDIR.DLL<br />
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;jp2ssv.dll<br />
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;GrabPro.dll<br />
uRun: [Sidebar] C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe /autoRun<br />
mRun: [NUSB3MON] "C:&#092;Program Files (x86)&#092;Renesas Electronics&#092;USB 3.0 Host Controller Driver&#092;Application&#092;nusb3mon.exe"<br />
mRun: [WinPatrol] C:&#092;Program Files (x86)&#092;BillP Studios&#092;WinPatrol&#092;winpatrol.exe -expressboot<br />
mRun: [VMonitorVMUVC] "C:&#092;Program Files (x86)&#092;Vimicro Corporation&#092;VMUVC&#092;VMonitor.exe" VMUVC<br />
mRun: [BrMfcWnd] C:&#092;Program Files (x86)&#092;Brother&#092;Brmfcmon&#092;BrMfcWnd.exe /AUTORUN<br />
mRun: [ControlCenter3] C:&#092;Program Files (x86)&#092;Brother&#092;ControlCenter3&#092;brctrcen.exe /autorun<br />
mRun: [JMB36X IDE Setup] C:&#092;Windows&#092;RaidTool&#092;xInsIDE.exe<br />
mRun: [SunJavaUpdateSched] "C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe"<br />
mRun: [avgnt] "C:&#092;Program Files (x86)&#092;Avira&#092;AntiVir Desktop&#092;avgnt.exe" /min<br />
StartupFolder: C:&#092;PROGRA~3&#092;MICROS~1&#092;Windows&#092;STARTM~1&#092;Programs&#092;Startup&#092;BANKID~1.LNK - C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;Personal.exe<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: &Download by Orbit - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;orbitmxt.dll/201<br />
IE: &Grab video by Orbit - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;orbitmxt.dll/204<br />
IE: Do&wnload selected by Orbit - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;orbitmxt.dll/203<br />
IE: Down&load all by Orbit - C:&#092;Program Files (x86)&#092;Orbitdownloader&#092;orbitmxt.dll/202<br />
IE: E&xportera till Microsoft Excel - C:&#092;PROGRA~1&#092;MICROS~2&#092;Office14&#092;EXCEL.EXE/3000<br />
IE: Ski&cka till OneNote - C:&#092;PROGRA~1&#092;MICROS~2&#092;Office14&#092;ONBttnIE.dll/105<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:&#092;Program Files (x86)&#092;Microsoft Office&#092;Office14&#092;ONBttnIE.dll<br />
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:&#092;Program Files (x86)&#092;Microsoft Office&#092;Office14&#092;ONBttnIELinkedNotes.dll<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - E:&#092;Spybot S&D&#092;Spybot - Search & Destroy 2&#092;SDHelper.dll<br />
LSP: %windir%&#092;system32&#092;vsocklib.dll<br />
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB<br />
TCP: NameServer = 192.168.0.1<br />
TCP: Interfaces&#092;{B25707D2-0D1A-40F4-B492-0A763F60E7B7} : NameServer = 8.26.56.26,156.154.70.22<br />
TCP: Interfaces&#092;{B25707D2-0D1A-40F4-B492-0A763F60E7B7} : DHCPNameServer = 192.168.0.1<br />
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:&#092;Program Files (x86)&#092;Common Files&#092;Microsoft Shared&#092;OFFICE14&#092;MSOXMLMF.DLL<br />
Notify: SDWinLogon - SDWinLogon.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;26.0.1410.64&#092;Installer&#092;chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:&#092;Program Files&#092;Microsoft Office&#092;Office14&#092;URLREDIR.DLL<br />
x64-Run: [WinPatrol] C:&#092;Program Files (x86)&#092;BillP Studios&#092;WinPatrol&#092;WinPatrol.exe -expressboot<br />
x64-Run: [FG_Monitor] E:&#092;Folderguard&#092;Folder Guard&#092;FGKey64.exe /Start<br />
x64-Run: [Cmaudio8788] C:&#092;Windows&#092;syswow64&#092;RunDll32.exe C:&#092;Windows&#092;Syswow64&#092;cmicnfgp.dll,CMICtrlWnd<br />
x64-Run: [Cmaudio8788GX] C:&#092;Windows&#092;syswow64&#092;HsMgr.exe Envoke<br />
x64-Run: [Cmaudio8788GX64] C:&#092;Windows&#092;system&#092;HsMgr64.exe Envoke<br />
x64-Run: [RTHDVCPL] C:&#092;Program Files&#092;Realtek&#092;Audio&#092;HDA&#092;RtkNGUI64.exe -s<br />
x64-Run: [COMODO Internet Security] C:&#092;Program Files&#092;COMODO&#092;COMODO Internet Security&#092;cistray.exe<br />
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:&#092;Program Files&#092;Microsoft Office&#092;Office14&#092;ONBttnIE.dll<br />
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:&#092;Program Files&#092;Microsoft Office&#092;Office14&#092;ONBttnIELinkedNotes.dll<br />
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;OFFICE14&#092;MSOXMLMF.DLL<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:&#092;Users&#092;Henrik&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;mbgak97j.default&#092;<br />
FF - prefs.js: browser.startup.homepage - google.se<br />
FF - plugin: C:&#092;PROGRA~2&#092;MICROS~2&#092;Office14&#092;NPAUTHZ.DLL<br />
FF - plugin: C:&#092;PROGRA~2&#092;MICROS~2&#092;Office14&#092;NPSPWRAP.DLL<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 11.0&#092;Reader&#092;AIR&#092;nppdf32.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Battlelog Web Plugins&#092;2.1.2&#092;npesnlaunch.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Battlelog Web Plugins&#092;Sonar&#092;0.70.4&#092;npesnsonar.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Google&#092;Update&#092;1.3.21.145&#092;npGoogleUpdate3.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;plugin2&#092;npjp2.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;NVIDIA Corporation&#092;3D Vision&#092;npnv3dv.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;NVIDIA Corporation&#092;3D Vision&#092;npnv3dvstreaming.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;np_prsnl.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;np_prsnl64.dll<br />
FF - plugin: C:&#092;Windows&#092;SysWOW64&#092;Macromed&#092;Flash&#092;NPSWF32_11_7_700_169.dll<br />
FF - plugin: E:&#092;VLC&#092;npvlc.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
.<br />
=============== File Associations ===============<br />
.<br />
ShellExec: PortraitProfessional.exe: open="E:&#092;Portrait Professional studio v10&#092;Programmet&#092;Portrait Professional Studio 10&#092;PortraitProfessionalStudio.exe" /P "%1"<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-11 16:19:29	--------	d-----w-	C:&#092;Users&#092;Henrik&#092;AppData&#092;Local&#092;CrashDumps<br />
2013-05-07 19:18:16	--------	d-----w-	C:&#092;Users&#092;Henrik&#092;AppData&#092;Local&#092;NPE<br />
2013-05-07 16:00:57	83160	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;avnetflt.sys<br />
2013-04-29 14:16:25	--------	d-----w-	C:&#092;Users&#092;Henrik&#092;AppData&#092;Roaming&#092;Avira<br />
2013-04-29 14:11:11	28600	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;avkmgr.sys<br />
2013-04-29 14:11:10	100712	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;avgntflt.sys<br />
2013-04-29 14:11:10	--------	d-----w-	C:&#092;ProgramData&#092;Avira<br />
2013-04-29 14:11:10	--------	d-----w-	C:&#092;Program Files (x86)&#092;Avira<br />
2013-04-29 13:34:18	1656680	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;ntfs.sys<br />
2013-04-29 13:33:07	9317456	----a-w-	C:&#092;ProgramData&#092;Microsoft&#092;Windows Defender&#092;Definition Updates&#092;{C5B2F4AB-5F29-4A92-8184-1EA815C6E769}&#092;mpengine.dll<br />
2013-04-21 18:41:42	--------	d-----w-	C:&#092;Users&#092;Henrik&#092;AppData&#092;Local&#092;Freelancer<br />
2013-04-18 16:46:47	--------	d-----r-	C:&#092;Users&#092;Henrik&#092;AppData&#092;Roaming&#092;Brother<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-13 07:14:37	16152	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;SWDUMon.sys<br />
2013-04-23 14:04:10	437176	----a-w-	C:&#092;Windows&#092;System32&#092;guard64.dll<br />
2013-04-23 14:04:10	348048	----a-w-	C:&#092;Windows&#092;SysWow64&#092;guard32.dll<br />
2013-04-17 16:54:03	71048	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerCPLApp.cpl<br />
2013-04-17 16:54:03	691592	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerApp.exe<br />
2013-04-15 17:38:52	48360	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;cmdhlp.sys<br />
2013-04-15 17:38:51	706560	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;cmdguard.sys<br />
2013-04-15 17:38:51	23168	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;cmderd.sys<br />
2013-04-15 17:38:38	43216	----a-w-	C:&#092;Windows&#092;System32&#092;cmdcsr.dll<br />
2013-04-15 17:38:29	343760	----a-w-	C:&#092;Windows&#092;System32&#092;cmdvrt64.dll<br />
2013-04-15 17:38:28	45776	----a-w-	C:&#092;Windows&#092;System32&#092;cmdkbd64.dll<br />
2013-04-15 17:38:25	276688	----a-w-	C:&#092;Windows&#092;SysWow64&#092;cmdvrt32.dll<br />
2013-04-15 17:38:24	40656	----a-w-	C:&#092;Windows&#092;SysWow64&#092;cmdkbd32.dll<br />
2013-04-09 14:26:53	861088	----a-w-	C:&#092;Windows&#092;SysWow64&#092;npDeployJava1.dll<br />
2013-04-09 14:26:53	782240	----a-w-	C:&#092;Windows&#092;SysWow64&#092;deployJava1.dll<br />
2013-04-04 12:50:32	25928	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;mbam.sys<br />
2013-04-04 03:35:05	95648	----a-w-	C:&#092;Windows&#092;SysWow64&#092;WindowsAccessBridge-32.dll<br />
2013-03-21 12:42:17	1700352	----a-w-	C:&#092;Windows&#092;SysWow64&#092;gdiplus.dll<br />
2013-03-19 06:04:06	5550424	----a-w-	C:&#092;Windows&#092;System32&#092;ntoskrnl.exe<br />
2013-03-19 05:46:56	43520	----a-w-	C:&#092;Windows&#092;System32&#092;csrsrv.dll<br />
2013-03-19 05:04:13	3968856	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntoskrnl.exe<br />
2013-03-19 04:47:50	6656	----a-w-	C:&#092;Windows&#092;SysWow64&#092;apisetschema.dll<br />
2013-03-19 03:06:33	112640	----a-w-	C:&#092;Windows&#092;System32&#092;smss.exe<br />
2013-03-15 04:16:18	3477280	----a-w-	C:&#092;Windows&#092;System32&#092;nvsvc64.dll<br />
2013-03-15 04:16:17	6398240	----a-w-	C:&#092;Windows&#092;System32&#092;nvcpl.dll<br />
2013-03-15 04:16:10	877856	----a-w-	C:&#092;Windows&#092;System32&#092;nvvsvc.exe<br />
2013-03-15 04:16:10	63776	----a-w-	C:&#092;Windows&#092;System32&#092;nvshext.dll<br />
2013-03-15 04:16:10	2555680	----a-w-	C:&#092;Windows&#092;System32&#092;nvsvcr.dll<br />
2013-03-15 04:16:10	237856	----a-w-	C:&#092;Windows&#092;System32&#092;nvmctray.dll<br />
2013-03-14 21:07:52	559904	----a-w-	C:&#092;Windows&#092;SysWow64&#092;nvStreaming.exe<br />
2013-03-13 16:24:01	3065455	----a-w-	C:&#092;Windows&#092;System32&#092;nvcoproc.bin<br />
2013-03-11 23:10:56	282744	------w-	C:&#092;Windows&#092;System32&#092;MpSigStub.exe<br />
2013-03-06 23:33:21	65336	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;aswRvrt.sys<br />
2013-03-06 23:33:21	178624	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;aswVmm.sys<br />
2013-03-01 03:36:04	3153408	----a-w-	C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-02-22 06:27:49	2312704	----a-w-	C:&#092;Windows&#092;System32&#092;jscript9.dll<br />
2013-02-22 06:20:51	1392128	----a-w-	C:&#092;Windows&#092;System32&#092;wininet.dll<br />
2013-02-22 06:19:37	1494528	----a-w-	C:&#092;Windows&#092;System32&#092;inetcpl.cpl<br />
2013-02-22 06:15:48	173056	----a-w-	C:&#092;Windows&#092;System32&#092;ieUnatt.exe<br />
2013-02-22 06:15:23	599040	----a-w-	C:&#092;Windows&#092;System32&#092;vbscript.dll<br />
2013-02-22 06:12:41	2382848	----a-w-	C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-02-22 03:46:00	1800704	----a-w-	C:&#092;Windows&#092;SysWow64&#092;jscript9.dll<br />
2013-02-22 03:38:00	1129472	----a-w-	C:&#092;Windows&#092;SysWow64&#092;wininet.dll<br />
2013-02-22 03:37:50	1427968	----a-w-	C:&#092;Windows&#092;SysWow64&#092;inetcpl.cpl<br />
2013-02-22 03:34:17	142848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ieUnatt.exe<br />
2013-02-22 03:34:03	420864	----a-w-	C:&#092;Windows&#092;SysWow64&#092;vbscript.dll<br />
2013-02-22 03:31:46	2382848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;mshtml.tlb<br />
2013-02-15 06:08:40	44032	----a-w-	C:&#092;Windows&#092;System32&#092;tsgqec.dll<br />
2013-02-15 06:06:11	3717632	----a-w-	C:&#092;Windows&#092;System32&#092;mstscax.dll<br />
2013-02-15 06:02:26	158720	----a-w-	C:&#092;Windows&#092;System32&#092;aaclient.dll<br />
2013-02-15 04:37:10	3217408	----a-w-	C:&#092;Windows&#092;SysWow64&#092;mstscax.dll<br />
2013-02-15 04:34:10	131584	----a-w-	C:&#092;Windows&#092;SysWow64&#092;aaclient.dll<br />
2013-02-15 03:25:51	36864	----a-w-	C:&#092;Windows&#092;SysWow64&#092;tsgqec.dll<br />
.<br />
============= FINISH: 12:28:19,92 ===============<br />
<br />
<br />
Åsikter??]]></description>
		<pubDate>Mon, 13 May 2013 10:43:28 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341452-hupigon-backdoor-hittas-bara-av-mbam-varfor/</guid>
	</item>
	<item>
		<title>10 gratisverktyg för säkert nät</title>
		<link>http://eforum.idg.se/topic/341430-10-gratisverktyg-for-sakert-nat/</link>
		<description><![CDATA[10 gratisverktyg för säkert nät<br />
<br />
<a href='http://www.idg.se/2.1085/1.506603/10-gratisverktyg-for-sakert-nat' class='bbc_url' title='Extern länk' rel='external'>http://www.idg.se/2.1085/1.506603/10-gratisverktyg-for-sakert-nat</a>]]></description>
		<pubDate>Sat, 11 May 2013 10:09:33 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341430-10-gratisverktyg-for-sakert-nat/</guid>
	</item>
	<item>
		<title>AV-TEST får kritik av Eugene Kaspersky</title>
		<link>http://eforum.idg.se/topic/341429-av-test-far-kritik-av-eugene-kaspersky/</link>
		<description><![CDATA[AV-TEST får kritik av Eugene Kaspersky<br />
<br />
<a href='http://eugene.kaspersky.com/2013/05/09/av-test-certification-devalued/#more-5166' class='bbc_url' title='Extern länk' rel='external'>http://eugene.kasper...lued/#more-5166</a> <br />
<br />
<br />
<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade bilder</h4>
	<ul>
		
			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_05_2013/post-71662-0-86469000-1368213560.png" class='bbc_img linked-image' alt="Bifogad bild: monthly_05_2013/post-71662-0-86469000-1368213560.png" />
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Fri, 10 May 2013 19:20:03 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341429-av-test-far-kritik-av-eugene-kaspersky/</guid>
	</item>
	<item>
		<title>adware yontoo</title>
		<link>http://eforum.idg.se/topic/341423-adware-yontoo/</link>
		<description>Hej .använder både MAM som inte hittar nåt.Super anti spyware hittar detta och tar bort det.Problemet är att det kommer tillbaka hela tiden.Hur gör jag och vad är detta för nåt:::fler som har dessa problem.</description>
		<pubDate>Fri, 10 May 2013 14:33:58 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341423-adware-yontoo/</guid>
	</item>
	<item>
		<title>How Strong is Your Password?</title>
		<link>http://eforum.idg.se/topic/341421-how-strong-is-your-password/</link>
		<description><![CDATA[<a href='https://www-ssl.intel.com/content/www/us/en/forms/passwordwin.html' class='bbc_url' title='Extern länk' rel='external'>https://www-ssl.intel.com/content/www/us/en/forms/passwordwin.html</a>]]></description>
		<pubDate>Fri, 10 May 2013 10:00:42 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341421-how-strong-is-your-password/</guid>
	</item>
	<item>
		<title>Jag vann!</title>
		<link>http://eforum.idg.se/topic/341409-jag-vann/</link>
		<description><![CDATA[Jag vann!  <img src='http://eforum.idg.se/public/style_emoticons/default/smile.gif' class='bbc_emoticon' alt=':)' /><div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade bilder</h4>
	<ul>
		
			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_05_2013/post-71662-0-36497800-1368038058.jpg" class='bbc_img linked-image' alt="Bifogad bild: monthly_05_2013/post-71662-0-36497800-1368038058.jpg" />
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 08 May 2013 18:34:52 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341409-jag-vann/</guid>
	</item>
	<item>
		<title>Hjälp med att ta bort: Delta search</title>
		<link>http://eforum.idg.se/topic/341347-hjalp-med-att-ta-bort-delta-search/</link>
		<description><![CDATA[Hej, vore väldigt tacksam om ni ville hjälpa mig med att få bort Delta search. Jag försöker och försöker, men verkar vara förgäves.<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 10.0.9200.16537  BrowserJavaVersion: 10.21.2<br />
Run by Josefin at 19:07:05 on 2013-05-02<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.46.1053.18.6092.3375 [GMT 2:00]<br />
.<br />
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}<br />
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:&#092;Windows&#092;system32&#092;lsm.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k DcomLaunch<br />
C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;TrueSuiteService.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k RPCSS<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalServiceNetworkRestricted<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalSystemNetworkRestricted<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalService<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k netsvcs<br />
C:&#092;Program Files&#092;IDT&#092;WDM&#092;STacSV64.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k GPSvcGroup<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkService<br />
C:&#092;Windows&#092;System32&#092;spoolsv.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceNoNetwork<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;armsvc.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;AppleMobileDeviceService.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgidsagent.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgwdsvc.exe<br />
C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />
C:&#092;Windows&#092;SysWOW64&#092;ezSharedSvcHost.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalServiceAndNoImpersonation<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Client Services&#092;HPClientServices.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Shared&#092;HPDrvMntSvc.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPWMISVC.exe<br />
C:&#092;Program Files (x86)&#092;Realtek&#092;Realtek PCIE Card Reader&#092;RIconMan.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Services&#092;IPT&#092;jhi_service.exe<br />
C:&#092;Program Files (x86)&#092;Microsoft&#092;BingBar&#092;SeaPort.EXE<br />
C:&#092;Program Files (x86)&#092;Microsoft Application Virtualization Client&#092;sftvsa.exe<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k LocalSystemNetworkRestricted<br />
C:&#092;Program Files (x86)&#092;voddler&#092;service&#092;voddler.exe<br />
C:&#092;Windows&#092;SysWOW64&#092;cmd.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;AVG Secure Search&#092;vToolbarUpdater&#092;14.2.0&#092;ToolbarUpdater.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgnsa.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgemca.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSVC.EXE<br />
C:&#092;Program Files (x86)&#092;Microsoft Application Virtualization Client&#092;sftlist.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WLIDSvcM.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Microsoft Shared&#092;Virtualization Handler&#092;CVHSVC.EXE<br />
C:&#092;Windows&#092;system32&#092;svchost.exe -k NetworkServiceNetworkRestricted<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;hpsa_service.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Rapid Storage Technology&#092;IAStorDataMgrSvc.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Management Engine Components&#092;LMS&#092;LMS.exe<br />
C:&#092;Program Files&#092;Windows Media Player&#092;wmpnetwk.exe<br />
C:&#092;Windows&#092;system32&#092;SearchIndexer.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Management Engine Components&#092;UNS&#092;UNS.exe<br />
C:&#092;Windows&#092;system32&#092;taskhost.exe<br />
C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;TouchControl.exe<br />
C:&#092;Windows&#092;system32&#092;Dwm.exe<br />
C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;BioMonitor.exe<br />
C:&#092;Windows&#092;Explorer.EXE<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;unsecapp.exe<br />
C:&#092;Windows&#092;System32&#092;hkcmd.exe<br />
C:&#092;Windows&#092;System32&#092;igfxpers.exe<br />
C:&#092;Program Files&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
C:&#092;Program Files&#092;IDT&#092;WDM&#092;sttray64.exe<br />
C:&#092;Program Files&#092;Microsoft IntelliPoint&#092;ipoint.exe<br />
C:&#092;Program Files&#092;Microsoft IntelliType Pro&#092;itype.exe<br />
C:&#092;Program Files&#092;Common Files&#092;Common Desktop Agent&#092;CDASrv.exe<br />
C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Spotify&#092;Data&#092;SpotifyWebHelper.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP LaunchBox&#092;HPTaskBar1.exe<br />
C:&#092;Program Files (x86)&#092;FileHippo.com&#092;UpdateChecker.exe<br />
C:&#092;Program Files&#092;Hewlett-Packard&#092;HP LaunchBox&#092;HPTaskBar2.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Drive&#092;googledrivesync.exe<br />
C:&#092;Program Files&#092;Microsoft IntelliType Pro&#092;dpupdchk.exe<br />
C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;Personal.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Rapid Storage Technology&#092;IAStorIcon.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP QuickWeb&#092;hpqwutils.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPMSGSVC.exe<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP On Screen Display&#092;HPOSD.exe<br />
C:&#092;Program Files (x86)&#092;voddler&#092;service&#092;VNetManager.exe<br />
C:&#092;Program Files (x86)&#092;ekort&#092;ekort.exe<br />
C:&#092;Program Files (x86)&#092;AVG Secure Search&#092;vprot.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgui.exe<br />
C:&#092;Program Files (x86)&#092;Sony&#092;ReaderDesktop&#092;appHelper&#092;ReaderAppHelper.exe<br />
C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe<br />
C:&#092;Windows&#092;SysWOW64&#092;OBroker.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe<br />
C:&#092;PROGRAM FILES&#092;SYNAPTICS&#092;SYNTP&#092;SYNTPHELPER.EXE<br />
C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Shared&#092;hpqWmiEx.exe<br />
C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k LocalServicePeerNet<br />
C:&#092;Program Files (x86)&#092;Google&#092;Drive&#092;googledrivesync.exe<br />
C:&#092;Windows&#092;system32&#092;taskeng.exe<br />
C:&#092;Program Files (x86)&#092;CyberLink&#092;YouCam&#092;YCMMirage.exe<br />
C:&#092;Windows&#092;System32&#092;svchost.exe -k secsvcs<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgcfgex.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgrsa.exe<br />
C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgcsrva.exe<br />
C:&#092;PROGRA~1&#092;ENIGMA~1&#092;SPYHUN~1&#092;SH4SER~1.EXE<br />
C:&#092;Program Files&#092;Enigma Software Group&#092;SpyHunter&#092;SpyHunter4.exe<br />
C:&#092;Program Files (x86)&#092;IObit&#092;IObit SmartDefrag&#092;IObit SmartDefrag.exe<br />
C:&#092;Windows&#092;system32&#092;AUDIODG.EXE<br />
C:&#092;Program Files (x86)&#092;Mozilla Firefox&#092;firefox.exe<br />
C:&#092;Program Files (x86)&#092;Mozilla Firefox&#092;plugin-container.exe<br />
C:&#092;Program Files (x86)&#092;Mozilla Firefox&#092;plugin-container.exe<br />
C:&#092;Windows&#092;SysWOW64&#092;Macromed&#092;Flash&#092;FlashPlayerPlugin_11_7_700_169.exe<br />
C:&#092;Windows&#092;SysWOW64&#092;Macromed&#092;Flash&#092;FlashPlayerPlugin_11_7_700_169.exe<br />
C:&#092;Windows&#092;system32&#092;SearchProtocolHost.exe<br />
C:&#092;Windows&#092;system32&#092;SearchFilterHost.exe<br />
C:&#092;Windows&#092;system32&#092;wbem&#092;wmiprvse.exe<br />
C:&#092;Windows&#092;System32&#092;cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.se/<br />
mWinlogon: Userinit = userinit.exe<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - &lt;orphaned&gt;<br />
BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;ssv.dll<br />
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;IEBHO.dll<br />
BHO: Inloggningshjälp för Microsoft-konto: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files (x86)&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />
BHO: e-kort Helper Class: {9065E913-4F23-4B47-9B5D-B055D32DB1F3} - C:&#092;Program Files (x86)&#092;ekort&#092;EKortHelper.dll<br />
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:&#092;Program Files (x86)&#092;AVG Secure Search&#092;14.2.0.1&#092;AVG Secure Search_toolbar.dll<br />
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files (x86)&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll<br />
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - <br />
BHO: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;jp2ssv.dll<br />
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;Resources&#092;HPNetworkCheck&#092;HPNetworkCheckPlugin.dll<br />
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:&#092;Program Files (x86)&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll<br />
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - <br />
TB: e-kort Toolbar: {8DB2B2E8-579F-48A8-A496-18FEFCF8F4DF} - C:&#092;Program Files (x86)&#092;ekort&#092;EKortToolbar.dll<br />
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:&#092;Program Files (x86)&#092;AVG Secure Search&#092;14.2.0.1&#092;AVG Secure Search_toolbar.dll<br />
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files (x86)&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll<br />
uRun: [Spotify Web Helper] "C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Spotify&#092;Data&#092;SpotifyWebHelper.exe"<br />
uRun: [swg] "C:&#092;Program Files (x86)&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe"<br />
uRun: [FileHippo.com] "C:&#092;Program Files (x86)&#092;FileHippo.com&#092;UpdateChecker.exe" /background<br />
uRun: [GoogleDriveSync] "C:&#092;Program Files (x86)&#092;Google&#092;Drive&#092;googledrivesync.exe" /autostart<br />
mRun: [IAStorIcon] C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Rapid Storage Technology&#092;IAStorIcon.exe<br />
mRun: [HPQuickWebProxy] "C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP QuickWeb&#092;hpqwutils.exe"<br />
mRun: [HP Quick Launch] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPMSGSVC.exe<br />
mRun: [HPOSD] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP On Screen Display&#092;HPOSD.exe<br />
mRun: [Easybits Recovery] C:&#092;Program Files (x86)&#092;EasyBits For Kids&#092;ezRecover.exe<br />
mRun: [VoddlerNet Manager] C:&#092;Program Files (x86)&#092;voddler&#092;service&#092;VNetManager.exe<br />
mRun: [e-kort] C:&#092;PROGRA~2&#092;ekort&#092;ekort.exe  /dontopenmycards /Autostart<br />
mRun: [vProt] "C:&#092;Program Files (x86)&#092;AVG Secure Search&#092;vprot.exe"<br />
mRun: [AVG_UI] "C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgui.exe" /TRAYONLY<br />
mRun: [APSDaemon] "C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Apple Application Support&#092;APSDaemon.exe"<br />
mRun: [Adobe ARM] "C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;ARM&#092;1.0&#092;AdobeARM.exe"<br />
mRun: [Reader Application Helper] C:&#092;Program Files (x86)&#092;Sony&#092;ReaderDesktop&#092;appHelper&#092;ReaderAppHelper.exe<br />
mRun: [iTunesHelper] "C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe"<br />
mRun: [QuickTime Task] "C:&#092;Program Files (x86)&#092;QuickTime&#092;QTTask.exe" -atboottime<br />
mRun: [SunJavaUpdateSched] "C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe"<br />
StartupFolder: C:&#092;PROGRA~3&#092;MICROS~1&#092;Windows&#092;STARTM~1&#092;Programs&#092;Startup&#092;BANKID~1.LNK - C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;Personal.exe<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-Explorer: EnableShellExecuteHooks = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
mPolicies-System: HideFastUserSwitching = dword:0<br />
IE: Add to Evernote 4.0 - C:&#092;Program Files (x86)&#092;Evernote&#092;Evernote&#092;EvernoteIE.dll/204<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Writer&#092;WriterBrowserExtension.dll<br />
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;Resources&#092;HPNetworkCheck&#092;NCLauncherFromIE.exe<br />
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:&#092;Program Files (x86)&#092;Evernote&#092;Evernote&#092;EvernoteIE.dll/204<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
TCP: NameServer = 192.168.1.1<br />
TCP: Interfaces&#092;{4CE9F2EA-92AC-4310-95B2-AE47AAA580E3} : DHCPNameServer = 192.168.1.1<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - &lt;orphaned&gt;<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;Program Files (x86)&#092;Common Files&#092;Skype&#092;Skype4COM.dll<br />
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:&#092;Program Files (x86)&#092;Common Files&#092;AVG Secure Search&#092;ViProtocolInstaller&#092;14.2.0&#092;ViProtocol.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:&#092;Program Files (x86)&#092;Windows Live&#092;Photo Gallery&#092;AlbumDownloadProtocolHandler.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:&#092;Windows&#092;SysWOW64&#092;ezUPBHook.dll<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;26.0.1410.64&#092;Installer&#092;chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
x64-BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - &lt;orphaned&gt;<br />
x64-BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre7&#092;bin&#092;ssv.dll<br />
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;x64&#092;IEBHO.dll<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files (x86)&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_64.dll<br />
x64-BHO: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre7&#092;bin&#092;jp2ssv.dll<br />
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files (x86)&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_64.dll<br />
x64-Run: [IgfxTray] C:&#092;Windows&#092;System32&#092;igfxtray.exe<br />
x64-Run: [HotKeysCmds] C:&#092;Windows&#092;System32&#092;hkcmd.exe<br />
x64-Run: [Persistence] C:&#092;Windows&#092;System32&#092;igfxpers.exe<br />
x64-Run: [SynTPEnh] C:&#092;Program Files (x86)&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
x64-Run: [SysTrayApp] C:&#092;Program Files&#092;IDT&#092;WDM&#092;sttray64.exe<br />
x64-Run: [SetDefault] C:&#092;Program Files&#092;Hewlett-Packard&#092;HP LaunchBox&#092;SetDefault.exe<br />
x64-Run: [IntelliPoint] "c:&#092;Program Files&#092;Microsoft IntelliPoint&#092;ipoint.exe"<br />
x64-Run: [itype] "c:&#092;Program Files&#092;Microsoft IntelliType Pro&#092;itype.exe"<br />
x64-Run: [CDAServer] C:&#092;Program Files&#092;Common Files&#092;Common Desktop Agent&#092;CDASrv.exe<br />
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - &lt;orphaned&gt;<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - &lt;orphaned&gt;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-Notify: igfxcui - igfxdev.dll<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;wyzrzv8k.default&#092;<br />
FF - prefs.js: browser.startup.homepage - hxxp://isearch.avg.com?pid=avg&sg=&cid=%7B261a783c-f3c2-4c21-8ba6-22e291ee7ab6%7D&mid=04e22e4a561347d1bea79557e705fe07-2d4eac95cfd82a5f2dca92b3e73a7137201daaa6&ds=AVG&v=14.2.0.1&lang=en&pr=fr&d=2012-09-26%2018%3A52%3A06&sap=hp<br />
FF - plugin: C:&#092;PROGRA~2&#092;MICROS~1&#092;Office14&#092;NPSPWRAP.DLL<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 11.0&#092;Reader&#092;AIR&#092;nppdf32.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Common Files&#092;AVG Secure Search&#092;SiteSafetyInstaller&#092;14.2.0&#092;npsitesafety.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Google&#092;Update&#092;1.3.21.135&#092;npGoogleUpdate3.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Java&#092;jre7&#092;bin&#092;plugin2&#092;npjp2.dll<br />
FF - plugin: c:&#092;Program Files (x86)&#092;Microsoft Silverlight&#092;5.1.20125.0&#092;npctrlui.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;np_prsnl.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Personal&#092;bin&#092;np_prsnl64.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Sony&#092;ReaderDesktop&#092;npreaderdetectmoz.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;WildTangent Games&#092;App&#092;BrowserIntegration&#092;Registered&#092;0&#092;NP_wtapp.dll<br />
FF - plugin: C:&#092;Program Files (x86)&#092;Windows Live&#092;Photo Gallery&#092;NPWLPG.dll<br />
FF - plugin: C:&#092;Windows&#092;SysWOW64&#092;Macromed&#092;Flash&#092;NPSWF32_11_7_700_169.dll<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=10588&tl=gkn468967&tt=180312_cp2<br />
FF - user.js: extensions.BabylonToolbar_i.babExt - <br />
FF - user.js: extensions.BabylonToolbar_i.srcExt - def<br />
FF - user.js: extensions.BabylonToolbar_i.id - 9ab7b123000000000000441ea1e117f4<br />
FF - user.js: extensions.BabylonToolbar_i.hardId - 9ab7b123000000000000441ea1e117f4<br />
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15460<br />
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17<br />
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17<br />
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1717:32:20<br />
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon<br />
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar<br />
FF - user.js: extensions.BabylonToolbar_i.aflt - babclient<br />
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none<br />
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base<br />
FF - user.js: extensions.BabylonToolbar_i.instlRef - std<br />
FF - user.js: extensions.delta.tlbrSrchUrl - <br />
FF - user.js: extensions.delta.id - 9ab7b123000000000000441ea1e117f4<br />
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}<br />
FF - user.js: extensions.delta.instlDay - 15826<br />
FF - user.js: extensions.delta.vrsn - 1.8.16.16<br />
FF - user.js: extensions.delta.vrsni - 1.8.16.16<br />
FF - user.js: extensions.delta.vrsnTs - 1.8.16.1611:37:07<br />
FF - user.js: extensions.delta.prtnrId - delta<br />
FF - user.js: extensions.delta.prdct - delta<br />
FF - user.js: extensions.delta.aflt - babsst<br />
FF - user.js: extensions.delta.smplGrp - none<br />
FF - user.js: extensions.delta.tlbrId - base<br />
FF - user.js: extensions.delta.instlRef - sst<br />
FF - user.js: extensions.delta.dfltLng - en<br />
FF - user.js: extensions.delta.excTlbr - false<br />
FF - user.js: extensions.delta.ffxUnstlRst - true<br />
FF - user.js: extensions.delta.admin - false<br />
FF - user.js: extensions.delta.autoRvrt - false<br />
FF - user.js: extensions.delta.rvrt - false<br />
FF - user.js: extensions.delta.newTab - false<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 AVGIDSHA;AVGIDSHA;C:&#092;Windows&#092;System32&#092;drivers&#092;avgidsha.sys [2012-10-15 63328]<br />
R0 Avgloga;AVG Logging Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;avgloga.sys [2012-9-21 225120]<br />
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:&#092;Windows&#092;System32&#092;drivers&#092;avgmfx64.sys [2012-11-16 111968]<br />
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;avgrkx64.sys [2012-9-14 40800]<br />
R1 AVGIDSDriver;AVGIDSDriver;C:&#092;Windows&#092;System32&#092;drivers&#092;avgidsdrivera.sys [2012-10-22 154464]<br />
R1 Avgldx64;AVG AVI Loader Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;avgldx64.sys [2012-10-2 185696]<br />
R1 Avgtdia;AVG TDI Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;avgtdia.sys [2012-9-21 200032]<br />
R1 avgtp;avgtp;C:&#092;Windows&#092;System32&#092;drivers&#092;avgtpx64.sys [2012-9-3 39768]<br />
R2 AVGIDSAgent;AVGIDSAgent;C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgidsagent.exe [2012-11-16 5814904]<br />
R2 avgwd;AVG WatchDog;C:&#092;Program Files (x86)&#092;AVG&#092;AVG2013&#092;avgwdsvc.exe [2012-10-22 196664]<br />
R2 cvhsvc;Client Virtualization Handler;C:&#092;Program Files (x86)&#092;Common Files&#092;microsoft shared&#092;Virtualization Handler&#092;CVHSVC.EXE [2012-1-4 822624]<br />
R2 ezSharedSvc;Easybits Services for Windows;C:&#092;Windows&#092;System32&#092;ezSharedSvcHost.exe --&gt; C:&#092;Windows&#092;System32&#092;ezSharedSvcHost.exe [?]<br />
R2 FPLService;TrueSuiteService;C:&#092;Program Files (x86)&#092;HP SimplePass 2011&#092;TrueSuiteService.exe [2011-5-6 263496]<br />
R2 HP Support Assistant Service;HP Support Assistant Service;C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Support Framework&#092;HPSA_Service.exe [2012-9-27 86528]<br />
R2 HPClientSvc;HP Client Services;C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Client Services&#092;HPClientServices.exe [2010-10-11 346168]<br />
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Shared&#092;HPDrvMntSvc.exe [2012-8-10 197536]<br />
R2 HPWMISVC;HPWMISVC;C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch&#092;HPWMISVC.exe [2011-4-8 26680]<br />
R2 IAStorDataMgrSvc;Intel&reg; Rapid Storage Technology;C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Rapid Storage Technology&#092;IAStorDataMgrSvc.exe [2012-3-25 13592]<br />
R2 IconMan_R;IconMan_R;C:&#092;Program Files (x86)&#092;Realtek&#092;Realtek PCIE Card Reader&#092;RIconMan.exe [2012-3-25 2372096]<br />
R2 jhi_service;Intel&reg; Identity Protection Technology Host Interface Service;C:&#092;Program Files (x86)&#092;Intel&#092;Services&#092;IPT&#092;jhi_service.exe [2011-2-24 212944]<br />
R2 sftlist;Application Virtualization Client;C:&#092;Program Files (x86)&#092;Microsoft Application Virtualization Client&#092;sftlist.exe [2011-10-1 508776]<br />
R2 SpyHunter 4 Service;SpyHunter 4 Service;C:&#092;PROGRA~1&#092;ENIGMA~1&#092;SPYHUN~1&#092;SH4SER~1.EXE [2013-1-14 1024384]<br />
R2 SSPORT;SSPORT;C:&#092;Windows&#092;System32&#092;drivers&#092;SSPORT.SYS [2012-2-15 11576]<br />
R2 UNS;Intel&reg; Management and Security Application User Notification Service;C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Management Engine Components&#092;UNS&#092;UNS.exe [2012-3-25 2656280]<br />
R2 VoddlerNet;VoddlerNet;C:&#092;Program Files (x86)&#092;voddler&#092;service&#092;voddler.exe [2011-11-30 2175304]<br />
R2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;C:&#092;Program Files (x86)&#092;Common Files&#092;AVG Secure Search&#092;vToolbarUpdater&#092;14.2.0&#092;ToolbarUpdater.exe [2013-2-19 968880]<br />
R3 clwvd;CyberLink WebCam Virtual Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;clwvd.sys [2010-7-28 31088]<br />
R3 esgiguard;esgiguard;C:&#092;Program Files&#092;Enigma Software Group&#092;SpyHunter&#092;esgiguard.sys [2011-3-2 13088]<br />
R3 IntcDAud;Intel&reg; Display Audio;C:&#092;Windows&#092;System32&#092;drivers&#092;IntcDAud.sys [2011-5-10 317440]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;Rt64win7.sys [2011-6-10 539240]<br />
R3 Sftfs;Sftfs;C:&#092;Windows&#092;System32&#092;drivers&#092;Sftfslh.sys [2011-10-1 764264]<br />
R3 Sftplay;Sftplay;C:&#092;Windows&#092;System32&#092;drivers&#092;Sftplaylh.sys [2011-10-1 268648]<br />
R3 Sftredir;Sftredir;C:&#092;Windows&#092;System32&#092;drivers&#092;Sftredirlh.sys [2011-10-1 25960]<br />
R3 Sftvol;Sftvol;C:&#092;Windows&#092;System32&#092;drivers&#092;Sftvollh.sys [2011-10-1 22376]<br />
R3 sftvsa;Application Virtualization Service Agent;C:&#092;Program Files (x86)&#092;Microsoft Application Virtualization Client&#092;sftvsa.exe [2011-10-1 219496]<br />
R3 WSDScan;WSD Scan Support via UMB;C:&#092;Windows&#092;System32&#092;drivers&#092;WSDScan.sys [2009-7-14 25088]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v4.0.30319&#092;mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:&#092;Windows&#092;Microsoft.NET&#092;Framework64&#092;v4.0.30319&#092;mscorsvw.exe [2010-3-18 138576]<br />
S2 SkypeUpdate;Skype Updater;C:&#092;Program Files (x86)&#092;Skype&#092;Updater&#092;Updater.exe [2013-2-28 161384]<br />
S3 BBSvc;Bing Bar Update Service;C:&#092;Program Files (x86)&#092;Microsoft&#092;BingBar&#092;BBSvc.EXE [2011-3-2 183560]<br />
S3 EsgScanner;EsgScanner;C:&#092;Windows&#092;System32&#092;drivers&#092;EsgScanner.sys [2013-5-2 22704]<br />
S3 fssfltr;fssfltr;C:&#092;Windows&#092;System32&#092;drivers&#092;fssfltr.sys [2012-9-30 57280]<br />
S3 fsssvc;Windows Live Family Safety Service;C:&#092;Program Files (x86)&#092;Windows Live&#092;Family Safety&#092;fsssvc.exe [2012-7-28 1511872]<br />
S3 GamesAppService;GamesAppService;C:&#092;Program Files (x86)&#092;WildTangent Games&#092;App&#092;GamesAppService.exe [2010-10-12 206072]<br />
S3 Netaapl;Apple Mobile Device Ethernet Service;C:&#092;Windows&#092;System32&#092;drivers&#092;netaapl64.sys [2012-3-26 22528]<br />
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;rdpvideominiport.sys [2012-11-4 19456]<br />
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;RtsPStor.sys [2012-3-25 335464]<br />
S3 SrvHsfHDA;SrvHsfHDA;C:&#092;Windows&#092;System32&#092;drivers&#092;VSTAZL6.SYS [2009-7-14 292864]<br />
S3 SrvHsfV92;SrvHsfV92;C:&#092;Windows&#092;System32&#092;drivers&#092;VSTDPV6.SYS [2009-7-14 1485312]<br />
S3 SrvHsfWinac;SrvHsfWinac;C:&#092;Windows&#092;System32&#092;drivers&#092;VSTCNXT6.SYS [2009-7-14 740864]<br />
S3 TsUsbFlt;TsUsbFlt;C:&#092;Windows&#092;System32&#092;drivers&#092;TsUsbFlt.sys [2012-11-4 57856]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:&#092;Windows&#092;System32&#092;drivers&#092;TsUsbGD.sys [2012-11-4 30208]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:&#092;Windows&#092;System32&#092;drivers&#092;usbaapl64.sys [2012-12-13 54784]<br />
S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:&#092;Windows&#092;System32&#092;Wat&#092;WatAdminSvc.exe [2011-12-27 1255736]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-02 15:58:58	--------	d-----w-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;IObit<br />
2013-05-02 15:58:58	--------	d-----w-	C:&#092;Program Files (x86)&#092;IObit<br />
2013-05-02 15:47:50	--------	d-----w-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Glarysoft<br />
2013-05-02 15:47:50	--------	d-----w-	C:&#092;Program Files (x86)&#092;Glary Utilities<br />
2013-05-02 15:30:46	22704	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;EsgScanner.sys<br />
2013-05-02 15:30:40	110080	----a-r-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Microsoft&#092;Installer&#092;{6B6C4C46-1B7E-4A41-9E70-ACFBB22B1D81}&#092;IconF7A21AF7.exe<br />
2013-05-02 15:30:40	110080	----a-r-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Microsoft&#092;Installer&#092;{6B6C4C46-1B7E-4A41-9E70-ACFBB22B1D81}&#092;IconD7F16134.exe<br />
2013-05-02 15:30:40	110080	----a-r-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Microsoft&#092;Installer&#092;{6B6C4C46-1B7E-4A41-9E70-ACFBB22B1D81}&#092;Icon1226A4C5.exe<br />
2013-05-02 15:30:39	--------	d-----w-	C:&#092;sh4ldr<br />
2013-05-02 15:30:39	--------	d-----w-	C:&#092;Program Files&#092;Enigma Software Group<br />
2013-05-02 15:29:58	--------	d-----w-	C:&#092;Windows&#092;6B6C4C461B7E4A419E70ACFBB22B1D81.TMP<br />
2013-05-02 15:29:57	--------	d-----w-	C:&#092;Program Files (x86)&#092;Common Files&#092;Wise Installation Wizard<br />
2013-05-02 15:05:40	69000	----a-w-	C:&#092;ProgramData&#092;Microsoft&#092;Windows Defender&#092;Definition Updates&#092;{5B414623-976D-4F5C-B949-CE6325AAC864}&#092;offreg.dll<br />
2013-05-02 14:18:41	--------	d-----w-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;NCH Software<br />
2013-05-01 21:55:49	95648	----a-w-	C:&#092;Windows&#092;SysWow64&#092;WindowsAccessBridge-32.dll<br />
2013-05-01 09:36:42	--------	d-----w-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;Babylon<br />
2013-05-01 09:36:42	--------	d-----w-	C:&#092;ProgramData&#092;Babylon<br />
2013-04-29 12:53:46	--------	d-----w-	C:&#092;Users&#092;Josefin&#092;AppData&#092;Roaming&#092;PerformerSoft<br />
2013-04-29 12:53:45	19632	----a-w-	C:&#092;Windows&#092;System32&#092;roboot64.exe<br />
2013-04-29 12:53:45	--------	d-----w-	C:&#092;ProgramData&#092;IBUpdaterService<br />
2013-04-29 12:52:54	--------	d-----w-	C:&#092;Program Files (x86)&#092;VideoLAN<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin7.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin6.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin5.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin4.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin3.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin2.dll<br />
2013-04-24 17:33:31	159744	----a-w-	C:&#092;Program Files (x86)&#092;Internet Explorer&#092;Plugins&#092;npqtplugin.dll<br />
2013-04-24 17:06:23	1656680	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;ntfs.sys<br />
2013-04-10 16:10:04	--------	d-----w-	C:&#092;Program Files&#092;Diablo II<br />
2013-04-10 16:10:04	--------	d-----w-	C:&#092;Program Files (x86)&#092;Common Files&#092;Blizzard Entertainment<br />
2013-04-10 15:44:13	3153408	----a-w-	C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-04-10 15:44:12	223752	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;fvevol.sys<br />
2013-04-10 15:44:04	5550424	----a-w-	C:&#092;Windows&#092;System32&#092;ntoskrnl.exe<br />
2013-04-10 15:44:03	3913560	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntoskrnl.exe<br />
2013-04-10 15:44:02	6656	----a-w-	C:&#092;Windows&#092;SysWow64&#092;apisetschema.dll<br />
2013-04-10 15:44:02	43520	----a-w-	C:&#092;Windows&#092;System32&#092;csrsrv.dll<br />
2013-04-10 15:44:02	3968856	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntkrnlpa.exe<br />
2013-04-10 15:44:02	112640	----a-w-	C:&#092;Windows&#092;System32&#092;smss.exe<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-02 09:02:52	71048	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerCPLApp.cpl<br />
2013-05-02 09:02:52	691592	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerApp.exe<br />
2013-03-26 05:38:29	861088	----a-w-	C:&#092;Windows&#092;SysWow64&#092;npDeployJava1.dll<br />
2013-03-26 05:38:29	782240	----a-w-	C:&#092;Windows&#092;SysWow64&#092;deployJava1.dll<br />
2013-03-13 16:45:09	16486616	----a-w-	C:&#092;Windows&#092;SysWow64&#092;FlashPlayerInstaller.exe<br />
2013-03-02 18:22:05	1085344	----a-w-	C:&#092;Windows&#092;System32&#092;npDeployJava1.dll<br />
2013-03-02 18:22:05	108448	----a-w-	C:&#092;Windows&#092;System32&#092;WindowsAccessBridge-64.dll<br />
2013-03-02 18:22:04	963488	----a-w-	C:&#092;Windows&#092;System32&#092;deployJava1.dll<br />
2013-02-19 08:28:10	39768	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;avgtpx64.sys<br />
2013-02-12 05:45:24	135168	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcXtrnal.dll<br />
2013-02-12 05:45:22	350208	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcLayers.dll<br />
2013-02-12 05:45:22	308736	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcGenral.dll<br />
2013-02-12 05:45:22	111104	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;acspecfc.dll<br />
2013-02-12 04:48:31	474112	----a-w-	C:&#092;Windows&#092;apppatch&#092;AcSpecfc.dll<br />
2013-02-12 04:48:26	2176512	----a-w-	C:&#092;Windows&#092;apppatch&#092;AcGenral.dll<br />
2013-02-12 04:12:05	19968	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;usb8023.sys<br />
.<br />
============= FINISH: 19:07:34,66 ===============<br />
<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP & ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: &#092;Device&#092;HarddiskVolume1<br />
Install Date: 2011-12-26 21:02:46<br />
System Uptime: 2013-05-02 16:44:47 (3 hours ago)<br />
.<br />
Motherboard: Hewlett-Packard |  | 166F<br />
Processor: Intel&reg; Core&#153; i5-2430M CPU @ 2.40GHz | CPU1 | 2401/1333mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 676 GiB total, 416,062 GiB free.<br />
D: is FIXED (NTFS) - 19 GiB total, 1,964 GiB free.<br />
E: is FIXED (FAT32) - 4 GiB total, 1,082 GiB free.<br />
F: is CDROM (CDFS)<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP136: 2013-04-30 00:44:34 - Windows Update<br />
RP137: 2013-05-01 23:54:51 - Installed Java 7 Update 21<br />
RP138: 2013-05-02 16:28:01 - Återställningsåtgärd<br />
RP139: 2013-05-02 17:30:06 - Installed SpyHunter<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe Digital Editions 2.0<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader XI (11.0.02)<br />
Adobe Shockwave Player 11.5<br />
Agatha Christie - Peril at End House<br />
Apple-programstöd<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
Atheros Driver Installation Program<br />
µTorrent<br />
AuthenTec TrueAPI<br />
AVG 2013<br />
AVG Security Toolbar<br />
BankID säkerhetsprogram<br />
Bejeweled 3<br />
Bing Bar<br />
Blackhawk Striker 2<br />
Blasterball 3<br />
Bloodline Champions<br />
Bonjour<br />
Bounce Symphony<br />
Cake Mania<br />
CCleaner<br />
Chronicles of Albian<br />
Chuzzle Deluxe<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Common Desktop Agent<br />
Cradle of Rome 2<br />
CyberLink YouCam<br />
D3DX10<br />
Diablo II<br />
e-kort<br />
EclipseCrossword<br />
ESU for Microsoft Windows 7 SP1<br />
Evernote v. 4.5.10<br />
Farm Frenzy<br />
FATE<br />
FileHippo.com Update Checker<br />
Final Drive: Nitro<br />
Fotogalleriet<br />
Glary Utilities 2.54.0.1759<br />
Google Chrome<br />
Google Drive<br />
Google Toolbar for Internet Explorer<br />
Google Update Helper<br />
Governor of Poker 2 Premium Edition<br />
Hewlett-Packard ACLM.NET v1.2.1.1<br />
HP Auto<br />
HP Client Services<br />
HP Customer Experience Enhancements<br />
HP Documentation<br />
HP Games<br />
HP Launch Box<br />
HP On Screen Display<br />
HP Power Manager<br />
HP Quick Launch<br />
HP QuickWeb<br />
HP Setup<br />
HP Setup Manager<br />
HP SimplePass PE 2011<br />
HP Software Framework<br />
iCloud<br />
IDT Audio<br />
Intel&reg; Control Center<br />
Intel&reg; Identity Protection Technology 1.1.2.0<br />
Intel&reg; Management Engine Components<br />
Intel&reg; Processor Graphics<br />
Intel&reg; Rapid Storage Technology<br />
iTunes<br />
Java 7 Update 15 (64-bit)<br />
Java 7 Update 21<br />
Java Auto Updater<br />
Java&#153; 6 Update 31<br />
Jewel Quest: The Sleepless Star - Collector's Edition<br />
Junk Mail filter update<br />
Korsordsskaparen 3.2<br />
League of Legends<br />
Magic Desktop<br />
Mah Jong Medley<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft .NET Framework 4 Client Profile Language Pack - SVE<br />
Microsoft .NET Framework 4 Client Profile SVE Language Pack<br />
Microsoft Application Error Reporting<br />
Microsoft IntelliPoint 8.2<br />
Microsoft IntelliType Pro 8.2<br />
Microsoft Office 2010<br />
Microsoft Office Klicka-och-kör 2010<br />
Microsoft Office Starter 2010 - svenska<br />
Microsoft PowerPoint Viewer<br />
Microsoft Silverlight<br />
Microsoft SkyDrive<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft SQL Server Compact 3.5 SP1 English<br />
Microsoft SQL Server Compact 3.5 SP1 x64 English<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2005 Redistributable (x64)<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219<br />
Microsoft WSE 3.0 Runtime<br />
Microsoft XNA Framework Redistributable 3.1<br />
Movie Maker<br />
Mozilla Firefox 20.0.1 (x86 sv-SE)<br />
Mozilla Maintenance Service<br />
MSVCRT<br />
MSVCRT_amd64<br />
MSVCRT110<br />
MSVCRT110_amd64<br />
MusicStation<br />
Mystery of Mortlake Mansion<br />
Namco All-Stars: PAC-MAN<br />
Origin<br />
Penguins!<br />
Photo Common<br />
Photo Gallery<br />
Plants vs. Zombies - Game of the Year<br />
Poker Superstars III<br />
Polar Bowler<br />
Polar Golfer<br />
QuickTime<br />
Reader for PC<br />
Realtek Ethernet Controller Driver<br />
Realtek PCIE Card Reader<br />
Recovery Manager<br />
Samsung Easy Document Creator<br />
Samsung Easy Printer Manager<br />
Samsung Printer Live Update<br />
Samsung Scan Process Machine<br />
Samsung SCX-3400 Series<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Client Profile Language Pack - SVE (KB2518870)<br />
Skype™ 6.3<br />
Slingo Supreme<br />
Smart Defrag<br />
SNS Upload for Easy Document Creator<br />
Spotify<br />
SpyHunter<br />
Synaptics TouchPad Driver<br />
The Sims™ 3<br />
The Sims™ 3 Drömjobb<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update Installer for WildTangent Games App<br />
Vacation Quest - The Hawaiian Islands<br />
Warcraft III<br />
Warcraft III: All Products<br />
WildTangent Games App<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Family Safety<br />
Windows Live Fotogalleri<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Mail<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
Windows Liven asennustyökalu<br />
Windows Liven sähköposti<br />
Windows Liven valokuvavalikoima<br />
Windows Media Player Firefox Plugin<br />
WinRAR 4.20 (32-bit)<br />
VIP Access SDK (1.0.1.2) <br />
Virtual Villagers 5 - New Believers<br />
Visual Studio 2008 x64 Redistributables<br />
Visual Studio 2010 x64 Redistributables<br />
Voddler<br />
Zuma Deluxe<br />
.<br />
==== End Of File ===========================]]></description>
		<pubDate>Thu, 02 May 2013 17:19:00 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341347-hjalp-med-att-ta-bort-delta-search/</guid>
	</item>
	<item>
		<title>Att ta bort virus</title>
		<link>http://eforum.idg.se/topic/341338-att-ta-bort-virus/</link>
		<description><![CDATA[<span style='font-size: 17px;'>Hej<br />
<span style='font-size: 17px;'>Bifogar en bild från Spybot Search och Destroy   <br />
<span style='font-size: 17px;'>Vid skanning får jag <span style='font-size: 17px;'>det som syns på bilden och lite till  <br />
<span style='font-size: 17px;'>Men när jag försöker ta bort det så får jag medde<span style='font-size: 17px;'>lande att jag inte är administratör<br />
<span style='font-size: 17px;'>Har kollat via kontrollpanel<span style='font-size: 17px;'>en och användarkonton att jag är administratör vad det nu skall<br />
<span style='font-size: 17px;'>vara bra för när jag är enda <span style='font-size: 17px;'>användaren av min dator<br />
<span style='font-size: 17px;'>Jag körde även Ad <span style='font-size: 17px;'>Awere men det programmet hittade ingenting   <br />
<span style='font-size: 17px;'>Toolbar Babylon är ett elende att klistra sig fast på många ställen <br />
<span style='font-size: 17px;'>Många andra spyboots <span style='font-size: 17px;'>ser jag inte i datorn men förmodar dom ligger <span style='font-size: 17px;'>på något ställe och kollar<br />
<span style='font-size: 17px;'>Tacksam för tips och råd</span><br />
</span></span></span></span></span></span><br />
</span></span></span></span></span></span></span></span></span></span><div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade bilder</h4>
	<ul>
		
			<li class=''>
				<img src="http://eforum.idg.se/uploads/monthly_05_2013/post-127767-0-35656400-1367424966.png" class='bbc_img linked-image' alt="Bifogad bild: monthly_05_2013/post-127767-0-35656400-1367424966.png" />
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 01 May 2013 16:23:28 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341338-att-ta-bort-virus/</guid>
	</item>
	<item>
		<title>Ad-Aware utan Antivirus</title>
		<link>http://eforum.idg.se/topic/341337-ad-aware-utan-antivirus/</link>
		<description><![CDATA[Hej.<br />
Tycker att Ad.aware är bra som komlement till virusskydd.Det tar kraft.Kan man stänga av virusskyddet på det eller finns det nån bra verision utan antivirus???]]></description>
		<pubDate>Wed, 01 May 2013 16:02:03 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341337-ad-aware-utan-antivirus/</guid>
	</item>
	<item>
		<title>Adserverplus.com Hur bli av med det?</title>
		<link>http://eforum.idg.se/topic/341336-adserverpluscom-hur-bli-av-med-det/</link>
		<description><![CDATA[Det här är inget kul!  Tacksam för hjälp med att få bort den här inkräktaren. Olika typer av popup-fönster förpestar min dator när jag är ute på Internet.<br />
En  del helt blanka fönster som glider in och lägger sig för det jag håller  på med. Eller så blir jag uppmanad att ladda ner senaste version av  Flash-player, fast jag har den.senaste redan.<br />
<br />
Stora meddelanden med varningar om förestående datorkrasch, dataspel mm.<br />
Eländes elände!!! och mina antivirus- och spamprogram upptäcker inte inkräktaren.<br />
Jag kan inte vara ensam om detta. åtminstone medlem melissa186 har drabbats av samma sak, troligen 1000-tals fler.<br />
Vet någon hur jag ska få bort dem?<br />
<br />
Bifogar de 2 filerna som jag skulle - hoppas jag gjort rätt:<br />
<br />
/Svenne Strulputt<div id='attach_wrap' class='rounded clearfix'>
	<h4>Bifogade filer</h4>
	<ul>
		
			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17372" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/txt.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17372" title="Ladda ner bilaga">DDS.txt</a> <span class='desc'><strong>(20,45Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 2</span>
			</li>
		

			<li class='clear'>
				<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17373" title="Ladda ner bilaga"><img src="http://eforum.idg.se/public/style_extra/mime_types/zip.gif" alt="Bifogad fil" /></a>
&nbsp;<a href="http://eforum.idg.se/index.php?app=core&module=attach&section=attach&attach_id=17373" title="Ladda ner bilaga">Attach.zip</a> <span class='desc'><strong>(2,77Kb)</strong></span>
<br /><span class="desc info">Antal nedladdningar: 1</span>
			</li>
		
	</ul>
</div>]]></description>
		<pubDate>Wed, 01 May 2013 14:32:03 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341336-adserverpluscom-hur-bli-av-med-det/</guid>
	</item>
	<item>
		<title>Få bort toolbars</title>
		<link>http://eforum.idg.se/topic/341402-fa-bort-toolbars/</link>
		<description><![CDATA[Jag har fortfarande inte fått det till o fungera.<br />
<br />
Körde en DDS och fick fram detta:<br />
<br />
<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 9.0.8112.16476<br />
Run by Kattas at 23:51:02 on 2013-04-29<br />
.<br />
============== Running Processes ================<br />
.<br />
C:&#092;Prey&#092;platform&#092;windows&#092;cronsvc.exe<br />
C:&#092;Program Files (x86)&#092;Launch Manager&#092;dsiwmis.exe<br />
C:&#092;Program Files (x86)&#092;Acer&#092;Registration&#092;GREGsvc.exe<br />
C:&#092;Program Files (x86)&#092;Launch Manager&#092;LMworker.exe<br />
C:&#092;Program Files (x86)&#092;Launch Manager&#092;LMutilps32.exe<br />
C:&#092;Program Files (x86)&#092;Acer&#092;clear.fi&#092;MVP&#092;clear.fiAgent.exe<br />
C:&#092;Program Files (x86)&#092;Acer&#092;clear.fi&#092;MVP&#092;.&#092;Kernel&#092;DMR&#092;DMREngine.exe<br />
C:&#092;ProgramData&#092;IBUpdaterService&#092;ibsvc.exe<br />
C:&#092;Program Files&#092;Acer&#092;Acer Updater&#092;UpdaterService.exe<br />
C:&#092;ProgramData&#092;MobileBrServ&#092;mbbservice.exe<br />
C:&#092;Program Files (x86)&#092;NTI&#092;Acer Backup Manager&#092;IScheduleSvc.exe<br />
C:&#092;ProgramData&#092;Skype&#092;Toolbars&#092;Skype C2C Service&#092;c2c_service.exe<br />
C:&#092;Program Files (x86)&#092;TeamViewer&#092;Version8&#092;TeamViewer_Service.exe<br />
C:&#092;Program Files (x86)&#092;Yontoo&#092;Y2Desktop.Updater.exe<br />
C:&#092;Program Files (x86)&#092;TeamViewer&#092;Version8&#092;TeamViewer.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Update&#092;1.3.21.135&#092;GoogleCrashHandler.exe<br />
C:&#092;Program Files (x86)&#092;TeamViewer&#092;Version8&#092;tv_w32.exe<br />
C:&#092;Program Files (x86)&#092;uTorrent&#092;uTorrent.exe<br />
C:&#092;Users&#092;Kattas&#092;AppData&#092;Roaming&#092;Yontoo&#092;YontooDesktop.exe<br />
C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Smartbar&#092;Application&#092;QuickShare.exe<br />
C:&#092;Program Files (x86)&#092;NTI&#092;Acer Backup Manager&#092;BackupManagerTray.exe<br />
C:&#092;Program Files (x86)&#092;OpenOffice.org 3&#092;program&#092;soffice.exe<br />
C:&#092;Program Files (x86)&#092;OpenOffice.org 3&#092;program&#092;soffice.bin<br />
C:&#092;Program Files (x86)&#092;Launch Manager&#092;LManager.exe<br />
C:&#092;Program Files (x86)&#092;Acer&#092;clear.fi&#092;Movie&#092;clear.fiMovieService.exe<br />
C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe<br />
C:&#092;Program Files (x86)&#092;Notification Tool&#092;PC_assistant.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Rapid Storage Technology&#092;IAStorDataMgrSvc.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Management Engine Components&#092;LMS&#092;LMS.exe<br />
C:&#092;Program Files (x86)&#092;Intel&#092;Intel&reg; Management Engine Components&#092;UNS&#092;UNS.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Sony&#092;Sony PC Companion&#092;PCCompanion.exe<br />
C:&#092;Program Files (x86)&#092;Sony&#092;Sony PC Companion&#092;PCCompanionInfo.exe<br />
C:&#092;Program Files (x86)&#092;Sony&#092;Sony PC Companion&#092;PCCService.exe<br />
C:&#092;Program Files (x86)&#092;Skype&#092;Phone&#092;Skype.exe<br />
C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Temp&#092;F929.tmp<br />
C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Temp&#092;restorer1.0.0.1.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;chrome.exe<br />
c:&#092;program files (x86)&#092;teamviewer&#092;version8&#092;TeamViewer_Desktop.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3220468<br />
uDefault_Page_URL = hxxp://acer.msn.com<br />
mStart Page = hxxp://searchab.com/?aff=7&uid=2c61d0bd-51dc-11e2-8610-582c80139263<br />
mDefault_Page_URL = hxxp://acer.msn.com<br />
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:&#092;Program Files (x86)&#092;uTorrentControl_v2&#092;prxtbuTor.dll<br />
mURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:&#092;Program Files (x86)&#092;uTorrentControl_v2&#092;prxtbuTor.dll<br />
mWinlogon: Userinit = userinit.exe<br />
BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} - <br />
BHO: Search-Results Toolbar: {3ec1a45c-8bc3-4bfe-b226-4051c5d3d068} - <br />
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:&#092;Program Files (x86)&#092;uTorrentControl_v2&#092;prxtbuTor.dll<br />
BHO: Java&#153; Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files (x86)&#092;Java&#092;jre6&#092;bin&#092;ssv.dll<br />
BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - <br />
BHO: Zoomex: {8924C01B-14CE-17A7-7D3F-3FE9D7F6FE94} - C:&#092;ProgramData&#092;Zoomex&#092;50df2b50bdba0.dll<br />
BHO: Smiley Bar for Facebook: {944FEDFD-C4FD-441D-8275-9C651A9FFBDE} - C:&#092;Program Files (x86)&#092;Smiley Bar for Facebook&#092;ScriptHost.dll<br />
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer&#092;skypeieplugin.dll<br />
BHO: SpecialSavings.Addon: {bb184e6d-26d1-461a-9226-b93ca8da2af9} - <br />
BHO: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files (x86)&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll<br />
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:&#092;Program Files (x86)&#092;Yontoo&#092;YontooIEClient.dll<br />
TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:&#092;Program Files (x86)&#092;uTorrentControl_v2&#092;prxtbuTor.dll<br />
TB: Search-Results Toolbar: {3ec1a45c-8bc3-4bfe-b226-4051c5d3d068} - <br />
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:&#092;Program Files (x86)&#092;uTorrentControl_v2&#092;prxtbuTor.dll<br />
TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} - <br />
uRun: [uTorrent] "C:&#092;Program Files (x86)&#092;uTorrent&#092;uTorrent.exe"  /MINIMIZED<br />
uRun: [Sony PC Companion] "C:&#092;Program Files (x86)&#092;Sony&#092;Sony PC Companion&#092;PCCompanion.exe" /Background<br />
uRun: [Yontoo Desktop] "C:&#092;Users&#092;Kattas&#092;AppData&#092;Roaming&#092;Yontoo&#092;YontooDesktop.exe"<br />
uRun: [Facebook Update] "C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Facebook&#092;Update&#092;FacebookUpdate.exe" /c /nocrashserver<br />
uRun: [Browser Infrastructure Helper] C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Smartbar&#092;Application&#092;QuickShare.exe startup<br />
uRun: [msnmsgr] "C:&#092;Program Files (x86)&#092;Windows Live&#092;Messenger&#092;msnmsgr.exe" /background<br />
mRun: [BackupManagerTray] "C:&#092;Program Files (x86)&#092;NTI&#092;Acer Backup Manager&#092;BackupManagerTray.exe" -h -k<br />
mRun: [LManager] C:&#092;Program Files (x86)&#092;Launch Manager&#092;LManager.exe<br />
mRun: [SuiteTray] "C:&#092;Program Files (x86)&#092;EgisTec MyWinLockerSuite&#092;x86&#092;SuiteTray.exe"<br />
mRun: [ArcadeMovieService] "C:&#092;Program Files (x86)&#092;Acer&#092;clear.fi&#092;Movie&#092;clear.fiMovieService.exe"<br />
mRun: [SunJavaUpdateSched] "C:&#092;Program Files (x86)&#092;Common Files&#092;Java&#092;Java Update&#092;jusched.exe"<br />
mRun: [PC Assistant] C:&#092;Program Files (x86)&#092;Notification Tool&#092;PC_Assistant.exe<br />
mRun: [PrivitizeVPN] C:&#092;Program Files (x86)&#092;PrivitizeVPN&#092;PrivitizeVPN.exe /autorun<br />
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer&#092;skypeieplugin.dll<br />
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:&#092;Program Files (x86)&#092;Evernote&#092;Evernote&#092;EvernoteIE.dll/204<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
TCP: NameServer = 192.168.1.1 192.168.1.1<br />
TCP: Interfaces&#092;{4544B149-1FFE-4784-BC3E-B01D84A9BE1A} : DHCPNameServer = 192.168.1.250<br />
TCP: Interfaces&#092;{539A14BF-114F-4E3A-8C24-1719F4205F8C} : DHCPNameServer = 192.168.1.1 192.168.1.1<br />
TCP: Interfaces&#092;{60CAECBD-AF52-4418-B5B3-C77EECAE9A94} : DHCPNameServer = 192.168.1.1 192.168.1.1<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer&#092;skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;Program Files (x86)&#092;Common Files&#092;Skype&#092;Skype4COM.dll<br />
AppInit_DLLs= c:&#092;progra~3&#092;browse~1&#092;261095~1.52&#092;{c16c1~1&#092;browse~1.dll c:&#092;progra~2&#092;zoomex&#092;sprote~1.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:&#092;Program Files (x86)&#092;Google&#092;Chrome&#092;Application&#092;26.0.1410.64&#092;Installer&#092;chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
x64-mStart Page = hxxp://acer.msn.com<br />
x64-mDefault_Page_URL = hxxp://acer.msn.com<br />
x64-BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} - <br />
x64-BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - <br />
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer x64&#092;skypeieplugin.dll<br />
x64-TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} - <br />
x64-Run: [AmIcoSinglun64] C:&#092;Program Files (x86)&#092;AmIcoSingLun&#092;AmIcoSinglun64.exe<br />
x64-Run: [IgfxTray] C:&#092;Windows&#092;System32&#092;igfxtray.exe<br />
x64-Run: [HotKeysCmds] C:&#092;Windows&#092;System32&#092;hkcmd.exe<br />
x64-Run: [Persistence] C:&#092;Windows&#092;System32&#092;igfxpers.exe<br />
x64-Run: [SynTPEnh] C:&#092;Program Files (x86)&#092;Synaptics&#092;SynTP&#092;SynTPEnh.exe<br />
x64-Run: [RTHDVCPL] C:&#092;Program Files&#092;Realtek&#092;Audio&#092;HDA&#092;RAVCpl64.exe -s<br />
x64-Run: [Power Management] C:&#092;Program Files&#092;Acer&#092;Acer ePower Management&#092;ePowerTray.exe<br />
x64-Run: [MSC] "c:&#092;Program Files&#092;Microsoft Security Client&#092;msseces.exe" -hide -runkey<br />
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer x64&#092;skypeieplugin.dll<br />
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:&#092;Program Files (x86)&#092;Skype&#092;Toolbars&#092;Internet Explorer x64&#092;skypeieplugin.dll<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Notify: igfxcui - igfxdev.dll<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R? AmUStor;AM USB Stroage Driver<br />
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86<br />
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64<br />
R? EgisTec Ticket Service;EgisTec Ticket Service<br />
R? GamesAppService;GamesAppService<br />
R? ggflt;SEMC USB Flash Driver Filter<br />
R? seu3bus;Sony Ericsson MD400g Mobile Broadband Composite Device driver (WDM)<br />
R? seu3card;Sony Ericsson MD400g Device Mgmt<br />
R? seu3mdfl;Sony Ericsson MD400g Mobile Broadband Modem Filter<br />
R? seu3mdfl2;Sony Ericsson MD400g Mobile Broadband Data Modem Filter<br />
R? seu3mdm;Sony Ericsson MD400g Mobile Broadband Modem Driver<br />
R? seu3mdm2;Sony Ericsson MD400g Mobile Broadband Data Modem Driver<br />
R? seu3nd5;Sony Ericsson MD400g Mobile Broadband Network Adapter (NDIS)<br />
R? seu3unic;Sony Ericsson MD400g Mobile Broadband Network Adapter (WDM)<br />
R? SkypeUpdate;Skype Updater<br />
R? Sony_EricssonWWSC;Sony Ericsson PC SC Port<br />
R? TsUsbFlt;TsUsbFlt<br />
R? TsUsbGD;Remote Desktop Generic USB Device<br />
R? WatAdminSvc;Aktiveringsteknologier f”r Windows-tj„nst<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-04-29 20:11:27	9317456	----a-w-	C:&#092;ProgramData&#092;Microsoft&#092;Microsoft Antimalware&#092;Definition Updates&#092;{CCF9A3F9-B6DC-4C3D-98D1-5AB85B3B2CEF}&#092;mpengine.dll<br />
2013-04-29 12:34:10	905296	------w-	C:&#092;ProgramData&#092;Microsoft&#092;Microsoft Antimalware&#092;Definition Updates&#092;{B898E782-43D8-47A0-9ED0-F4265EBB972F}&#092;gapaengine.dll<br />
2013-04-29 12:32:16	9317456	------w-	C:&#092;ProgramData&#092;Microsoft&#092;Microsoft Antimalware&#092;Definition Updates&#092;Backup&#092;mpengine.dll<br />
2013-04-11 12:51:15	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Smartbar<br />
2013-04-10 09:31:46	3717632	----a-w-	C:&#092;Windows&#092;System32&#092;mstscax.dll<br />
2013-04-09 22:33:59	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;AppData&#092;Roaming&#092;File Scout<br />
2013-04-08 18:31:38	48648	----a-w-	C:&#092;ProgramData&#092;Microsoft&#092;eHome&#092;Packages&#092;MCEClientUX&#092;UpdateableMarkup&#092;Markup.dll<br />
2013-04-08 18:31:33	346960	----a-w-	C:&#092;ProgramData&#092;Microsoft&#092;eHome&#092;Packages&#092;MCESpotlight&#092;MCESpotlight&#092;SpotlightResources.dll<br />
2013-04-08 16:45:43	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;Tracing<br />
2013-04-08 16:09:01	77656	----a-w-	C:&#092;Windows&#092;System32&#092;XAPOFX1_5.dll<br />
2013-04-08 16:09:01	74072	----a-w-	C:&#092;Windows&#092;SysWow64&#092;XAPOFX1_5.dll<br />
2013-04-08 16:09:01	527192	----a-w-	C:&#092;Windows&#092;SysWow64&#092;XAudio2_7.dll<br />
2013-04-08 16:09:01	518488	----a-w-	C:&#092;Windows&#092;System32&#092;XAudio2_7.dll<br />
2013-04-08 16:09:00	2526056	----a-w-	C:&#092;Windows&#092;System32&#092;D3DCompiler_43.dll<br />
2013-04-08 16:09:00	2106216	----a-w-	C:&#092;Windows&#092;SysWow64&#092;D3DCompiler_43.dll<br />
2013-04-08 16:08:59	276832	----a-w-	C:&#092;Windows&#092;System32&#092;d3dx11_43.dll<br />
2013-04-08 16:08:59	248672	----a-w-	C:&#092;Windows&#092;SysWow64&#092;d3dx11_43.dll<br />
2013-04-08 16:07:10	--------	d-----w-	C:&#092;Program Files (x86)&#092;Microsoft SkyDrive<br />
2013-04-08 16:07:10	--------	d-----r-	C:&#092;Users&#092;Kattas&#092;SkyDrive<br />
2013-04-08 16:06:43	--------	d-----w-	C:&#092;ProgramData&#092;Microsoft SkyDrive<br />
2013-04-08 16:02:48	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Windows Live<br />
2013-04-04 18:56:14	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;AppData&#092;Local&#092;Facebook<br />
2013-04-04 16:07:25	--------	d-----w-	C:&#092;Users&#092;Kattas&#092;jagexcache<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-04-29 21:06:01	31	----a-w-	C:&#092;Windows&#092;SysWow64&#092;TempWmicBatchFile.bat<br />
2013-04-02 10:34:28	282744	------w-	C:&#092;Windows&#092;System32&#092;MpSigStub.exe<br />
2013-03-19 06:04:06	5550424	----a-w-	C:&#092;Windows&#092;System32&#092;ntoskrnl.exe<br />
2013-03-19 05:46:56	43520	----a-w-	C:&#092;Windows&#092;System32&#092;csrsrv.dll<br />
2013-03-19 05:04:13	3968856	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ntoskrnl.exe<br />
2013-03-19 04:47:50	6656	----a-w-	C:&#092;Windows&#092;SysWow64&#092;apisetschema.dll<br />
2013-03-19 03:06:33	112640	----a-w-	C:&#092;Windows&#092;System32&#092;smss.exe<br />
2013-03-02 06:04:53	1655656	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;ntfs.sys<br />
2013-03-01 03:36:04	3153408	----a-w-	C:&#092;Windows&#092;System32&#092;win32k.sys<br />
2013-02-22 06:27:49	2312704	----a-w-	C:&#092;Windows&#092;System32&#092;jscript9.dll<br />
2013-02-22 06:20:51	1392128	----a-w-	C:&#092;Windows&#092;System32&#092;wininet.dll<br />
2013-02-22 06:19:37	1494528	----a-w-	C:&#092;Windows&#092;System32&#092;inetcpl.cpl<br />
2013-02-22 06:15:48	173056	----a-w-	C:&#092;Windows&#092;System32&#092;ieUnatt.exe<br />
2013-02-22 06:15:23	599040	----a-w-	C:&#092;Windows&#092;System32&#092;vbscript.dll<br />
2013-02-22 06:12:41	2382848	----a-w-	C:&#092;Windows&#092;System32&#092;mshtml.tlb<br />
2013-02-22 03:46:00	1800704	----a-w-	C:&#092;Windows&#092;SysWow64&#092;jscript9.dll<br />
2013-02-22 03:38:00	1129472	----a-w-	C:&#092;Windows&#092;SysWow64&#092;wininet.dll<br />
2013-02-22 03:37:50	1427968	----a-w-	C:&#092;Windows&#092;SysWow64&#092;inetcpl.cpl<br />
2013-02-22 03:34:17	142848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;ieUnatt.exe<br />
2013-02-22 03:34:03	420864	----a-w-	C:&#092;Windows&#092;SysWow64&#092;vbscript.dll<br />
2013-02-22 03:31:46	2382848	----a-w-	C:&#092;Windows&#092;SysWow64&#092;mshtml.tlb<br />
2013-02-15 06:08:40	44032	----a-w-	C:&#092;Windows&#092;System32&#092;tsgqec.dll<br />
2013-02-15 06:02:26	158720	----a-w-	C:&#092;Windows&#092;System32&#092;aaclient.dll<br />
2013-02-15 04:37:10	3217408	----a-w-	C:&#092;Windows&#092;SysWow64&#092;mstscax.dll<br />
2013-02-15 04:34:10	131584	----a-w-	C:&#092;Windows&#092;SysWow64&#092;aaclient.dll<br />
2013-02-15 03:25:51	36864	----a-w-	C:&#092;Windows&#092;SysWow64&#092;tsgqec.dll<br />
2013-02-12 05:45:24	135168	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcXtrnal.dll<br />
2013-02-12 05:45:22	350208	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcLayers.dll<br />
2013-02-12 05:45:22	308736	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;AcGenral.dll<br />
2013-02-12 05:45:22	111104	----a-w-	C:&#092;Windows&#092;apppatch&#092;AppPatch64&#092;acspecfc.dll<br />
2013-02-12 04:48:31	474112	----a-w-	C:&#092;Windows&#092;apppatch&#092;AcSpecfc.dll<br />
2013-02-12 04:48:26	2176512	----a-w-	C:&#092;Windows&#092;apppatch&#092;AcGenral.dll<br />
2013-02-12 04:12:06	19968	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;usb8023x.sys<br />
2013-02-12 04:12:05	19968	----a-w-	C:&#092;Windows&#092;System32&#092;drivers&#092;usb8023.sys<br />
.<br />
============= FINISH: 23:52:29,18 ===============<br />
<br />
<br />
vbscript.dll finns iaf  där..<br />
<br />
Någon som har något förslag på hur jag löser problemet? <img src='http://eforum.idg.se/public/style_emoticons/default/smile.gif' class='bbc_emoticon' alt=':)' /><br />
<br />
Mvh Jesse]]></description>
		<pubDate>Tue, 30 Apr 2013 15:50:44 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341402-fa-bort-toolbars/</guid>
	</item>
	<item>
		<title>Ukash virus - felsäkert läge fungerar ej</title>
		<link>http://eforum.idg.se/topic/341319-ukash-virus-felsakert-lage-fungerar-ej/</link>
		<description><![CDATA[Hej,<br />
<br />
En kompis till mig har för andra gången drabbats av Ukash. Förra gången fungerade felsäkert läge med nätverksåtkomst och det gick att bli av med eländet enligt instruktioner. Men denna gång fungerar inget. Eller jo, datorn startar och läser in och sedan sitter han där med den "fina vita bild som talar om att han måste betala pengar till polisen".<br />
<br />
Det finns ingen Windows skiva. <span style='font-size: 13px;'>Hur går jag vidare? D</span>et Windows Vista Home som är installerat.<br />
 <span style='font-size: 13px;'>Han är hopplös på datorer, jag är något bättre men skulle verkligen behöva lite hjälp. Hur blir jag av med det eländiga Ukash?? </span><br />
 <br />
<span style='font-size: 13px;'>Tack på förhand!</span><br />
<br />
Kiwifågeln]]></description>
		<pubDate>Mon, 29 Apr 2013 18:11:45 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341319-ukash-virus-felsakert-lage-fungerar-ej/</guid>
	</item>
	<item>
		<title>Fsecure Internet Security 12013 hjälp</title>
		<link>http://eforum.idg.se/topic/341300-fsecure-internet-security-12013-hjalp/</link>
		<description><![CDATA[Hej, jag använder Internet Download manager för nedladdning av filer. I inställningarna för nedladdningen kan man mata in att man vill att antivirusprogrammet automatiskt ska söka av den nedladdade filen. Vilken fil i Fsecure ska man peka ut? Hade förut Norton IS och där hittade jag filen.<br />
<br />
Tacksam för tips <img src='http://eforum.idg.se/public/style_emoticons/default/smile.gif' class='bbc_emoticon' alt=':)' />]]></description>
		<pubDate>Sun, 28 Apr 2013 08:44:05 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341300-fsecure-internet-security-12013-hjalp/</guid>
	</item>
	<item>
		<title>Virus som heter Qvo6.com</title>
		<link>http://eforum.idg.se/topic/341280-virus-som-heter-qvo6com/</link>
		<description><![CDATA[Hej!<br />
<br />
Jag har fått något som heter Qvo6.com som byter ut min startsida till sin egen!<img src='http://eforum.idg.se/public/style_emoticons/default/thumbsdown.gif' class='bbc_emoticon' alt=':thumbsdown:' /> <br />
<br />
Kollade upp namnet och Hitachi ingår i adressen nu har jag en Hitachi HD som fanns i datorn vid leveransen.<br />
<br />
Men med 2 brandväggar i Routern och Norton 360 i datorn (både brandvägg och antivirusprogram) och så finner man detta virus i datorn ändå!<br />
<br />
Nu var jag tvungen att ladda ner Java när jag körde igång NASen  Kan det ha haft någon betydelse?<br />
<br />
Jag var tveksam till att göra det men var tvungen för att kunna ladda upp musiken till HDn i NASen.<br />
<br />
Det konstiga är att om jag lägger ner IE sidan i aktivitetsfältet och sedan trycker på knappen för att starta IE 64 Bits versionen så finns min <br />
<br />
rätta startsida på denna version så tydligen (tror jag) är det bara IE av 32 Bits versionen som är kapad.(Rätta mig om jag har fel)<img src='http://eforum.idg.se/public/style_emoticons/default/biggrin.gif' class='bbc_emoticon' alt=':D' /> <br />
<br />
Men det konstoga är att datorn var igång fråm onsdag 24/4 till torsdag 25/5 i 24 timmar 45 minuter och 30 sekunder när jag laddade upp musiken <br />
<br />
totalt 318 GB.Utan att datorn visade något utan det har hänt i em. Bara varit inne på mina vanliga sidor som är säkra enligt Norton.<br />
<br />
Kör med W7 på en HP Notebook .]]></description>
		<pubDate>Fri, 26 Apr 2013 17:24:48 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341280-virus-som-heter-qvo6com/</guid>
	</item>
	<item>
		<title>PUP Funmood</title>
		<link>http://eforum.idg.se/topic/341272-pup-funmood/</link>
		<description><![CDATA[<span style='font-family: Comic Sans MS'>Hej   När jag scannade med Maleware anti male så upptäckes många förmodade spyware som heter PUP Funmood<br />
Närjag försökete ta bort dom fick jag meddelande att det inte gick och sedan slutade datorn att fungera korrekt<br />
Fick igång den dock med systemåterställning<br />
Mitt fråga är om det är skadligt med PUP Funmood och hur jag i så fall får bort det <br />
Har scannat datorn med Avasti och Spybot search och destroy men kan inte se om de programmen hittat viruset   Det är <br />
ofta så konstiga namn på saker som dyker upp efter scanning<br />
Jag märker inga problem direkt i datorn men det känns inte bra att ha någon som spionerar i min dator<br />
Tacksam för tips och råd<br />
</span>]]></description>
		<pubDate>Fri, 26 Apr 2013 05:03:23 +0000</pubDate>
		<guid>http://eforum.idg.se/topic/341272-pup-funmood/</guid>
	</item>
</channel>
</rss>