Just nu i M3-nätverket
Jump to content

Hijack this -logg


axel55

Recommended Posts

Hej, jag har lyckats med konststycket att bli infekterad av en/flera trojaner. Har tagit bort några av dem, men är övertygad om att det fortfarande ligger kvar några. därför postar jag en hijack this logg nedan.

 

Tacksam för att hjälp jag kan få. Antar att ni ser vilka virusprogram/anti-spyware program jag har i loggen nedan.

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 02:07:32, on 2008-11-26

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

C:\Program Files\Google\Gmail Notifier\gnotify.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Windows\System32\CTXFIHLP.EXE

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Windows\System32\CTXFISPI.EXE

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Users\Axel\AppData\Local\Temp\171A.tmp.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Trend Micro\HijackThis\axle.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\PROGRA~1\AVG\AVG8\aAvgApi.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXE

O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe" /r

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [HitmanPro3] "C:\Program Files\Hitman Pro 3\hitmanpro3.exe" -autocheck

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Cognac] C:\Users\Axel\AppData\Local\Temp\171A.tmp.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')

O4 - Global Startup: BankID säkerhetsprogram.lnk = C:\Program Files\Personal\bin\Personal.exe

O4 - Global Startup: D-Link REG Utility.lnk = C:\Program Files\DWL-G520M Wireless 108G MIMO PCI Adapter\Reg.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Windows\system32\acs.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe

O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe

O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe

O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

 

--

End of file - 9548 bytes[/log]

 

Link to comment
Share on other sites

Surfa till http://www.virustotal.com klistra in följande filnamn i rutan, tryck på Skicka Fil och vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in resultatet från de olika antivirusprogrammen (inte Övrig information) här.

C:\Users\Axel\AppData\Local\Temp\171A.tmp.exe

 

Link to comment
Share on other sites

Den filen finns inte. Gick in både i utforskaren (jag har visa dolda filer och mappar aktiverat). Testade även att skriva sökvägen i virustotalrutan men fick då svaret "0 bytes added" eller vad det stod. I väntan på svar installerade jag spy bot s/d. Den hittade några virus och därför lägger jag upp en ny logg. Tack för svaret

 

Kan passa på att säga att jag startade om datorn. Efter att den var uppstartad hade jag bara en svart skärm, inget annat. Startade aktivitetshanteraren (ctrl alt del) och tog bort "misstänkta" processer. Det var när jag tog bort en av dessa som windows plötsligt poppade upp. Använder mig av windows vista om det spelar någon roll.

 

/Axel

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 09:40:39, on 2008-11-26

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

C:\Program Files\Google\Gmail Notifier\gnotify.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Windows\System32\CTXFIHLP.EXE

C:\Windows\system32\wuauclt.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe

C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe

C:\Windows\System32\CTXFISPI.EXE

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Trend Micro\HijackThis\axle.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\PROGRA~1\AVG\AVG8\aAvgApi.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXE

O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe" /r

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [HitmanPro3] "C:\Program Files\Hitman Pro 3\hitmanpro3.exe" -autocheck

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJÄNST')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJÄNST')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NÄTVERKSTJÄNST')

O4 - Global Startup: BankID säkerhetsprogram.lnk = C:\Program Files\Personal\bin\Personal.exe

O4 - Global Startup: D-Link REG Utility.lnk = C:\Program Files\DWL-G520M Wireless 108G MIMO PCI Adapter\Reg.exe

O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

O9 - Extra button: Referensinformation - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Windows\system32\acs.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe

O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe

O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe

O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

 

--

End of file - 10025 bytes[/log]

 

 

Link to comment
Share on other sites

Ja. Som sagt var, när jag startade om datorn fick jag inte upp aktivitetsfältet utan endast en svart skärm. var tvungen att avsluta en process via aktivitetshanteraren för att få fram mitt skrivbord/verktygsfält/aktivitetsfällt. Dvs hela skärmen var svart, inget annat syntes.

 

Fanns det inget konstigt i den senaste loggen?

 

Mvh Axel

 

Link to comment
Share on other sites

Blir det likadant om du startar om datorn igen?

Vilken process tog du död på?

Långt ifrån allt skadligt syns i en HijackThis-logg så det kan tänkas att det behövs andra program.

 

Link to comment
Share on other sites

var klantig nog att inte tänka på vad processen hette, sry för det. Vet dock att så fort jag tog bort den kom allt tillbaka.

 

startade om datorn, och nu gick det bättre. Är dock väldigt rädd för att logga in på aktiedepåer/internetbanker online. Är det något man vågar göra?

 

/paradiod surfare

 

Link to comment
Share on other sites

Vi kan kolla lite till. Ladda ner OTViewIt till Skrivbordet:

http://oldtimer.geekstogo.com/OTViewIt.exe

 

Stäng alla program.

Kör OTViewIt.

Bocka för Scan all Users.

Välj 30 dagar för File Age om det inte redan är valt.

Tryck på Run Scan och låt programmet köra ostört.

 

När det är klart så skapas två loggfiler på Skrivbordet, OTViewIt.txt och Extras.txt, klistra in båda två i ditt svar (kom ihåg LOG-knappen).

 

Link to comment
Share on other sites

Här kommer loggarna:

 

[log]OTViewIt logfile created on: 2008-11-26 11:33:46 - Run

OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Users\Axel\Desktop

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

2,00 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 94,28% Memory free

4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free

Paging file location(s): ?:\pagefile.sys;

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 232,88 Gb Total Space | 45,04 Gb Free Space | 19,34% Space Free | Partition Type: NTFS

Drive D: | 637,02 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Drive E: | 465,76 Gb Total Space | 246,39 Gb Free Space | 52,90% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: AXEL-DATOR

Current User Name: Axel

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Whitelist: On

File Age = 30 Days

 

========== Processes ==========

 

[2008-01-19 08:33:37 | 00,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininit.exe

[2008-01-19 08:33:14 | 00,229,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lsm.exe

[2008-10-07 13:33:00 | 00,203,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe

[2008-04-30 09:35:20 | 00,425,984 | ---- | M] (Creative Technology Ltd) -- C:\Program\Creative\Shared Files\CTAudSvc.exe

[2008-01-19 08:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SLsvc.exe

[2008-07-07 07:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program\Lavasoft\Ad-Aware\aawservice.exe

[2006-11-02 10:45:37 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rundll32.exe

[2005-03-27 16:00:00 | 00,057,344 | ---- | M] (CANON INC.) -- C:\Windows\System32\CNAB4RPK.EXE

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

[2008-11-19 20:08:22 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgwdsvc.exe

[2008-08-29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe

[2004-07-30 15:47:36 | 00,069,632 | ---- | M] (Dantz Development Corporation) -- C:\Program\Dantz\Retrospect Express HD\retrorun.exe

[2008-05-27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe

[2008-07-07 09:42:02 | 00,809,296 | ---- | M] (Safer Networking Ltd.) -- C:\Program\Spybot - Search & Destroy\SDWinSec.exe

[2008-11-19 20:08:22 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgrsx.exe

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2008-01-19 08:33:08 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe

[2008-01-19 08:38:38 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Defender\MSASCui.exe

[2007-01-18 07:46:56 | 04,349,952 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe

[2005-07-15 22:48:33 | 00,479,232 | ---- | M] (Google Inc.) -- C:\Program\Google\Gmail Notifier\gnotify.exe

[2008-11-11 18:07:58 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program\Java\jre6\bin\jusched.exe

[2008-08-21 22:44:24 | 00,023,552 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CTXFIHLP.EXE

[2008-06-10 12:56:32 | 01,406,024 | ---- | M] (Microsoft Corporation) -- C:\Program\Microsoft IntelliPoint\ipoint.exe

[2006-11-02 10:45:37 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rundll32.exe

[2008-11-19 20:08:22 | 01,234,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgtray.exe

[2008-01-19 08:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnscfg.exe

[2008-01-19 08:33:33 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe

[2008-01-19 08:33:39 | 00,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\WmiPrvSE.exe

[2008-01-19 08:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnetwk.exe

[2007-12-13 17:43:30 | 00,416,280 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe

[2007-12-13 17:43:12 | 00,461,336 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe

[2007-12-13 17:43:02 | 00,481,304 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe

[2007-12-13 17:42:52 | 00,558,104 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe

[2008-08-21 22:40:38 | 01,225,216 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CTXFISPI.EXE

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2007-10-18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\usnsvc.exe

[2008-10-16 22:09:43 | 00,051,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe

[2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program\iPod\bin\iPodService.exe

[2008-11-20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program\iTunes\iTunesHelper.exe

[2008-01-19 08:33:12 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program\Internet Explorer\iexplore.exe

[2008-11-19 20:08:23 | 00,540,440 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\aAvgApi.exe

[2007-09-20 10:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program\Common Files\microsoft shared\Windows Live\WLLoginProxy.exe

[2008-01-05 12:21:39 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

[2008-05-27 06:18:16 | 00,184,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe

[2008-05-27 06:17:55 | 00,087,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe

[2008-11-26 11:33:17 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

 

========== (O23) Win32 Services ==========

 

[2008-07-07 07:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])

[2005-01-28 14:19:02 | 00,036,864 | ---- | M] () -- C:\Windows\System32\acs.exe -- (ACS [Auto | Stopped])

[2008-06-08 00:20:32 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])

[2008-11-19 20:08:22 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])

[2008-08-29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])

File not found -- -- (CertPropSvc [unknown | Stopped])

[2008-01-05 12:26:41 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

[2008-10-19 17:34:59 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\AL1Licensing.exe -- (Creative ALchemy AL1 Licensing Service [On_Demand | Stopped])

[2008-10-19 17:15:18 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service [On_Demand | Stopped])

[2008-07-09 12:57:55 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service [On_Demand | Stopped])

[2008-04-30 09:35:20 | 00,425,984 | ---- | M] (Creative Technology Ltd) -- C:\Program\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService [Auto | Running])

File not found -- -- (DcomLaunch [unknown | Running])

[2008-01-19 08:33:06 | 02,091,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dfsr.exe -- (DFSR [On_Demand | Stopped])

[2008-01-19 08:34:06 | 00,134,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dps.dll -- (DPS [unknown | Running])

[2008-01-19 08:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr [On_Demand | Stopped])

[2006-11-02 13:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])

[2008-08-31 11:34:48 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])

[2008-01-05 12:21:53 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])

[2008-01-19 08:34:25 | 00,574,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gpsvc.dll -- (gpsvc [unknown | Running])

[2004-10-22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

[2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])

[2006-11-02 14:04:14 | 00,000,000 | ---D | M] -- C:\Windows\System32\Msdtc -- (MSDTC [unknown | Stopped])

[2008-01-05 12:21:39 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])

[2008-10-07 13:33:00 | 00,203,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running])

[2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

[2004-07-30 15:47:36 | 00,069,632 | ---- | M] (Dantz Development Corporation) -- C:\Program\Dantz\Retrospect Express HD\retrorun.exe -- (RetroExpLauncher [Auto | Running])

[2008-01-19 08:36:17 | 00,547,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rpcss.dll -- (RpcSs [unknown | Running])

[2008-07-07 09:42:02 | 00,809,296 | ---- | M] (Safer Networking Ltd.) -- C:\Program\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService [Auto | Running])

[2008-01-19 08:36:19 | 00,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr [unknown | Stopped])

File not found -- -- (Schedule [unknown | Running])

File not found -- -- (SCPolicySvc [unknown | Stopped])

[2008-01-19 08:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SLsvc.exe -- (slsvc [Auto | Running])

[2006-11-02 10:45:46 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\snmptrap.exe -- (SNMPTRAP [On_Demand | Stopped])

[2008-11-22 11:47:10 | 00,104,944 | ---- | M] (Valve Corporation) -- C:\Program\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Stopped])

[2008-01-19 08:33:33 | 00,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UI0Detect.exe -- (UI0Detect [On_Demand | Stopped])

[2007-10-18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])

[2008-01-19 08:33:33 | 00,382,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vds.exe -- (vds [On_Demand | Stopped])

File not found -- -- (WdiServiceHost [unknown | Stopped])

File not found -- -- (WdiSystemHost [unknown | Running])

[2007-10-25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])

[2008-01-19 08:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])

[2008-05-27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe -- (WSearch [Auto | Running])

 

========== Driver Services ==========

 

[2006-11-02 10:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])

[2006-11-02 10:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])

[2006-11-02 10:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])

[2006-11-02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])

[2006-11-02 10:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\System32\drivers\aliide.sys -- (aliide [Disabled | Stopped])

[2006-11-02 10:49:59 | 00,054,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\AMDAGP.SYS -- (amdagp [On_Demand | Stopped])

[2006-11-02 10:49:26 | 00,015,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdide.sys -- (amdide [Disabled | Stopped])

[2006-11-02 09:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdk7.sys -- (AmdK7 [Disabled | Stopped])

[2008-01-19 06:27:20 | 00,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdk8.sys -- (AmdK8 [On_Demand | Running])

[2004-12-24 17:34:42 | 00,355,328 | ---- | M] (D-Link) -- C:\Windows\System32\drivers\ar5513.sys -- (AR5513 [On_Demand | Running])

[2006-11-02 10:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arc.sys -- (arc [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])

[2008-11-19 20:08:27 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys -- (AvgLdx86 [system | Running])

[2008-11-19 20:08:27 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys -- (AvgMfx86 [system | Running])

[2008-01-19 06:28:26 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bowser.sys -- (bowser [On_Demand | Running])

[2006-11-02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltLo.sys -- (BrFiltLo [On_Demand | Stopped])

[2006-11-02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltUp.sys -- (BrFiltUp [On_Demand | Stopped])

[2006-11-02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerId.sys -- (Brserid [Disabled | Stopped])

[2006-11-02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerWdm.sys -- (BrSerWdm [Disabled | Stopped])

[2006-11-02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbMdm.sys -- (BrUsbMdm [Disabled | Stopped])

[2006-11-02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbSer.sys -- (BrUsbSer [On_Demand | Stopped])

[2006-11-02 09:55:23 | 00,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bthmodem.sys -- (BTHMODEM [Disabled | Stopped])

[2006-11-02 09:55:08 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\circlass.sys -- (circlass [Disabled | Stopped])

[2008-01-19 08:42:58 | 00,247,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clfs.sys -- (CLFS [unknown | Running])

[2006-11-02 10:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\System32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])

[2006-11-02 10:49:43 | 00,022,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk [boot | Running])

[2006-11-02 09:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\crusoe.sys -- (Crusoe [Disabled | Stopped])

[2008-08-22 02:08:32 | 00,171,032 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CT20XUT.DLL -- (CT20XUT.DLL [On_Demand | Running])

[2008-08-22 02:09:04 | 00,511,000 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTAC32K.SYS -- (ctac32k [On_Demand | Stopped])

[2008-08-22 02:09:14 | 00,527,768 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTAUD2K.SYS -- (ctaud2k [On_Demand | Running])

[2008-08-22 02:08:54 | 01,324,568 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL [On_Demand | Running])

[2008-08-22 02:08:42 | 00,072,728 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CTHWIUT.DLL -- (CTHWIUT.DLL [On_Demand | Running])

[2008-08-22 02:09:28 | 00,014,360 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTPRXY2K.SYS -- (ctprxy2k [On_Demand | Running])

[2008-08-22 02:09:34 | 00,158,744 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTSFM2K.SYS -- (ctsfm2k [On_Demand | Running])

[2008-01-19 06:28:20 | 00,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dfsc.sys -- (DfsC [system | Running])

[2008-08-02 02:01:23 | 00,625,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgkrnl.sys -- (DXGKrnl [On_Demand | Running])

[2006-11-02 08:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])

[2008-01-19 08:42:11 | 00,143,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ecache.sys -- (Ecache [boot | Running])

[2006-11-02 10:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\System32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])

[2008-08-22 02:09:42 | 00,095,768 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\EMUPIA2K.SYS -- (emupia [On_Demand | Running])

[2008-01-19 06:28:01 | 00,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\exfat.sys -- (exfat [On_Demand | Stopped])

[2008-01-19 08:42:31 | 00,058,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\fileinfo.sys -- (FileInfo [boot | Running])

[2008-01-19 06:30:23 | 00,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\filetrace.sys -- (Filetrace [On_Demand | Stopped])

[2006-11-02 10:50:04 | 00,058,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\GAGP30KX.SYS -- (gagp30kx [On_Demand | Stopped])

[2007-12-25 14:43:06 | 00,014,656 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\gdrv.sys -- (gdrv [On_Demand | Stopped])

[2008-04-17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])

[2008-08-22 02:09:54 | 01,178,136 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\HA20X2K.SYS -- (ha20x2k [On_Demand | Running])

[2006-11-02 08:36:49 | 00,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService [On_Demand | Stopped])

[2008-01-19 05:30:49 | 00,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])

[2006-11-02 09:55:22 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidbth.sys -- (HidBth [Disabled | Stopped])

[2006-11-02 09:55:01 | 00,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidir.sys -- (HidIr [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\System32\drivers\HpCISSs.sys -- (HpCISSs [Disabled | Stopped])

[2006-11-02 10:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorV.sys -- (iaStorV [Disabled | Stopped])

[2006-11-02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\System32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])

[2007-01-18 11:56:56 | 01,729,632 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService [On_Demand | Running])

[2006-11-02 09:42:03 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\IPMIDrv.sys -- (IPMIDRV [Disabled | Stopped])

[2008-01-19 08:42:35 | 00,181,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msiscsi.sys -- (iScsiPrt [On_Demand | Running])

[2006-11-02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])

[2006-11-02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])

[2008-01-19 06:49:17 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\kbdhid.sys -- (kbdhid [system | Running])

[2008-01-19 06:55:03 | 00,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\lltdio.sys -- (lltdio [Auto | Running])

[2006-11-02 10:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])

[2006-11-02 10:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])

[2008-01-19 06:30:36 | 00,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\luafv.sys -- (luafv [Auto | Running])

[2006-11-02 10:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\System32\drivers\megasas.sys -- (megasas [Disabled | Stopped])

[2008-01-19 06:52:19 | 00,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\monitor.sys -- (monitor [On_Demand | Running])

[2006-11-02 10:50:16 | 00,078,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mpio.sys -- (mpio [Disabled | Stopped])

[2008-01-19 06:54:46 | 00,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mpsdrv.sys -- (mpsdrv [On_Demand | Running])

[2006-11-02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\System32\drivers\Mraid35x.sys -- (Mraid35x [Disabled | Stopped])

[2008-08-27 02:05:41 | 00,212,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys -- (mrxsmb10 [On_Demand | Running])

[2008-01-19 06:28:37 | 00,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys -- (mrxsmb20 [On_Demand | Running])

[2006-11-02 10:49:44 | 00,023,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msahci.sys -- (msahci [Disabled | Stopped])

[2006-11-02 10:50:17 | 00,080,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msdsm.sys -- (msdsm [Disabled | Stopped])

[2008-01-19 08:41:14 | 00,016,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msisadrv.sys -- (msisadrv [boot | Running])

[2008-01-19 08:42:29 | 00,163,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC [On_Demand | Stopped])

[2004-10-07 10:21:22 | 00,015,360 | ---- | M] (Maxtor Corp.) -- C:\Windows\System32\drivers\mxopswd.sys -- (MXOPSWD [On_Demand | Stopped])

[2008-05-20 03:07:31 | 00,148,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\nwifi.sys -- (NativeWifiP [On_Demand | Running])

[2006-11-02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\System32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])

[2008-01-19 06:55:50 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\nsiproxy.sys -- (nsiproxy [system | Running])

[2006-11-02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])

[2007-11-18 02:39:50 | 01,040,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD [On_Demand | Running])

[2008-10-07 13:33:00 | 07,380,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])

[2006-11-02 10:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])

[2007-01-05 21:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys -- (nvstor [boot | Running])

[2007-08-09 18:12:30 | 00,110,624 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32 [boot | Running])

[2006-11-02 10:50:40 | 00,106,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\NV_AGP.SYS -- (nv_agp [On_Demand | Stopped])

[2008-08-22 02:09:20 | 00,129,560 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\drivers\CTOSS2K.SYS -- (ossrv [On_Demand | Running])

[2006-11-02 10:04:35 | 00,878,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\PEAuth.sys -- (PEAUTH [Auto | Running])

[2008-06-10 13:04:28 | 00,033,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\point32k.sys -- (Point32 [On_Demand | Running])

[2008-04-05 02:21:42 | 00,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\pacer.sys -- (PSched [system | Running])

[2006-11-02 10:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\System32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\System32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])

[2008-01-19 06:56:07 | 00,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\qwavedrv.sys -- (QWAVEdrv [On_Demand | Stopped])

[2008-01-19 06:56:43 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\rassstp.sys -- (RasSstp [On_Demand | Running])

[2008-01-19 07:01:09 | 00,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\RDPENCDD.sys -- (RDPENCDD [system | Running])

[2008-01-19 06:55:03 | 00,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\rspndr.sys -- (rspndr [Auto | Running])

[2007-04-03 12:57:42 | 00,083,336 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116bus.sys -- (s116bus [On_Demand | Stopped])

[2007-04-03 12:57:48 | 00,015,112 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mdfl.sys -- (s116mdfl [On_Demand | Stopped])

[2007-04-03 12:57:48 | 00,108,680 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mdm.sys -- (s116mdm [On_Demand | Stopped])

[2007-04-03 12:57:50 | 00,100,488 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mgmt.sys -- (s116mgmt [On_Demand | Stopped])

[2007-04-03 12:57:52 | 00,023,176 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116nd5.sys -- (s116nd5 [On_Demand | Stopped])

[2007-04-03 12:57:52 | 00,098,696 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116obex.sys -- (s116obex [On_Demand | Stopped])

[2007-04-03 12:57:54 | 00,099,080 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116unic.sys -- (s116unic [On_Demand | Stopped])

[2006-11-02 10:50:16 | 00,076,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sbp2port.sys -- (sbp2port [Disabled | Stopped])

[2006-11-02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])

[2008-01-19 06:49:16 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sermouse.sys -- (sermouse [Disabled | Stopped])

[2006-11-02 09:51:38 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffdisk.sys -- (sffdisk [Disabled | Stopped])

[2006-11-02 09:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffp_mmc.sys -- (sffp_mmc [On_Demand | Stopped])

[2006-11-02 09:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffp_sd.sys -- (sffp_sd [On_Demand | Stopped])

[2006-11-02 10:49:51 | 00,053,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\SISAGP.SYS -- (sisagp [On_Demand | Stopped])

[2006-11-02 10:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\System32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])

[2006-11-02 10:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\System32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])

[2008-01-19 06:55:27 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\smb.sys -- (Smb [system | Running])

[2008-01-19 08:41:30 | 00,021,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\spldr.sys -- (spldr [boot | Running])

[2008-01-19 06:29:15 | 00,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys -- (srv2 [On_Demand | Running])

[2008-01-19 06:29:12 | 00,098,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srvnet.sys -- (srvnet [On_Demand | Running])

[2006-11-02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])

[2006-11-02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])

[2006-11-02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])

[2008-01-19 06:56:07 | 00,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tcpipreg.sys -- (tcpipreg [Auto | Running])

[2008-01-19 06:55:58 | 00,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tdx.sys -- (tdx [system | Running])

[2008-01-19 07:01:15 | 00,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tssecsrv.sys -- (tssecsrv [On_Demand | Stopped])

[2008-01-19 06:55:41 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\TUNMP.SYS -- (tunmp [On_Demand | Running])

[2008-01-19 06:55:50 | 00,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tunnel.sys -- (tunnel [On_Demand | Running])

[2006-11-02 10:49:59 | 00,056,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UAGP35.SYS -- (uagp35 [On_Demand | Stopped])

[2006-11-02 10:50:04 | 00,058,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ULIAGPKX.SYS -- (uliagpkx [On_Demand | Stopped])

[2006-11-02 10:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\System32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\System32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])

[2006-11-02 10:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\System32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])

[2008-01-19 06:53:40 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\umbus.sys -- (umbus [On_Demand | Running])

[2007-07-11 09:40:18 | 00,012,416 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus [On_Demand | Stopped])

[2006-11-02 09:55:09 | 00,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbcir.sys -- (usbcir [Disabled | Stopped])

[2007-07-11 14:51:48 | 00,019,840 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag [On_Demand | Stopped])

[2007-07-11 09:45:00 | 00,021,632 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem [On_Demand | Stopped])

[2006-11-02 09:53:56 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\vgapnp.sys -- (vga [On_Demand | Stopped])

[2006-11-02 09:30:19 | 00,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\viac7.sys -- (ViaC7 [Disabled | Stopped])

[2006-11-02 10:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\System32\drivers\viaide.sys -- (viaide [Disabled | Stopped])

[2008-01-19 08:42:18 | 00,052,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\volmgr.sys -- (volmgr [boot | Running])

[2008-01-19 08:43:03 | 00,294,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\volmgrx.sys -- (volmgrx [boot | Running])

[2006-11-02 10:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\System32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])

[2006-11-02 09:52:52 | 00,020,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wacompen.sys -- (WacomPen [Disabled | Stopped])

[2006-11-02 10:49:38 | 00,019,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wd.sys -- (Wd [Disabled | Stopped])

[2008-01-19 08:43:27 | 00,503,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\Wdf01000.sys -- (Wdf01000 [boot | Running])

[2006-11-02 09:35:03 | 00,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wmiacpi.sys -- (WmiAcpi [Disabled | Stopped])

[2008-01-19 06:56:49 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl [Disabled | Stopped])

 

========== (R ) Internet Explorer ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]

"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157

"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896

"Default_Secondary_Page_URL"=

"Extensions Off Page"=about:NoAdd-ons

"Local Page"=%SystemRoot%\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Security Risk Page"=about:SecurityRisk

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]

"Local Page"=C:\Windows\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

"StartPageCache"=

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Internet Explorer\Main]

"Local Page"=C:\Windows\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

"StartPageCache"=

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

========== (O1) Hosts File ==========

 

HOSTS File = (942 bytes) - C:\Windows\System32\drivers\etc\Hosts

First 25 entries...

127.0.0.1 localhost

::1 localhost

127.0.0.1 www.mininova.org

127.0.0.1 www.mininova.com

127.0.0.1 www.thepiratebay.org

127.0.0.1 www.suprbay.org

127.0.0.1 mininova.org

127.0.0.1 mininova.com

127.0.0.1 thepiratebay.org

127.0.0.1 suprbay.org

 

========== (O2) BHO's ==========

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

{A057A204-BACC-4D26-9990-79A187E2698E} (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

 

========== (O3) Toolbars ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

========== (O4) Run Keys ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)

"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)

"CTxfiHlp"=CTXFIHLP.EXE (Creative Technology Ltd)

"HitmanPro3"="C:\Program Files\Hitman Pro 3\hitmanpro3.exe" -autocheck ()

"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)

"Launch LCDMon"="C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" (Logitech Inc.)

"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE (Logitech Inc.)

"NvCplDaemon"=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)

"NvMediaCenter"=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)

"RtHDVCpl"=RtHDVCpl.exe (Realtek Semiconductor)

"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)

"UpdReg"=C:\Windows\UpdReg.EXE (Creative Technology Ltd.)

"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)

"VolPanel"="C:\Program Files\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe" /r (Creative Technology Ltd)

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)

"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)

"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)

"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)

"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

 

========== (O6 & O7) Current Version Policies ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]

"ConsentPromptBehaviorAdmin"=2

"ConsentPromptBehaviorUser"=1

"EnableInstallerDetection"=1

"EnableLUA"=0

"EnableSecureUIAPaths"=1

"EnableVirtualization"=1

"PromptOnSecureDesktop"=1

"ValidateAdminCodeSignatures"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"scforceoption"=0

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

"FilterAdministratorToken"=0

"EnableUIADesktopToggle"=0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]

"CF_TEXT"=1

"CF_BITMAP"=2

"CF_OEMTEXT"=7

"CF_DIB"=8

"CF_PALETTE"=9

"CF_UNICODETEXT"=13

"CF_DIBV5"=17

 

========== (O8) IE Context Menu Extensions ==========

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

 

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

========== (O9) IE Extensions ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Referensinformation -- %SystemDrive%\Program\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007-04-19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %SystemDrive%\Program\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)

 

========== (O12) Internet Explorer Plugins ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]

PluginsPage: "" = http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s

PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

 

========== (O13) Default Prefixes ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]

""=http://

 

========== (O15) Trusted Sites ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

49 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

49 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

========== (O16) DPF ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]

{0CCA191D-13A6-4E29-B746-314DEE697D83}: http://upload.facebook.com/controls/FacebookPhotoUploader5.cab -- Facebook Photo Uploader 5

{20A60F0D-9AFA-4515-A0FD-83BD84642501}: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab -- Checkers Class

{5C051655-FCD5-4969-9182-770EA5AA5565}: http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab -- Solitaire Showdown Class

{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{B8BE5E93-A60C-4D26-A2DC-220313175592}: http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab -- MSN Games - Installer

{C3F79A2B-B9B4-4A66-B012-3EE46475B072}: http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab -- MessengerStatsClient Class

{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab -- Java Plug-in 1.6.0_03

{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab -- Java Plug-in 1.6.0_05

{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07

{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object

{D8089245-3211-40F6-819B-9E5E92CD61A2}: https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab -- FlashXControl Object

{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}: http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab -- Minesweeper Flags Class

 

========== (O17) DNS Name Servers ==========

 

{9FCDC34E-88DC-4FD7-82C9-5888F413F71C} (Servers: | Description: NVIDIA nForce Networking Controller)

{A63C7D22-A5B8-4549-A40F-A9CAA3C4D25A} (Servers: | Description: Sony Ericsson Device 116 USB Ethernet Emulation (NDIS 5))

{C0B32F68-1CA9-4ECB-863E-C1BF17E6EB37} (Servers: | Description: DWL-G520M Wireless 108G MIMO PCI Adapter)

 

========== (O20) AppInit_DLLs ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_Dlls"=avgrsstx.dll

>[2008-11-19 20:08:28 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

 

========== HKLM *SecurityProviders* ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]

"SecurityProviders"=credssp.dll

>[2008-01-19 08:33:59 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll

 

========== LSA *Security Packages* ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]

"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,

>[2008-01-19 08:36:42 | 00,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TSpkg.dll

 

========== Safeboot Options ==========

 

"AlternateShell"=cmd.exe

 

========== CDRom AutoRun Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]

"AutoRun" = 1

 

========== Autorun Files on Drives ==========

 

autoexec.bat [REM Dummy file for NTVDM | ]

[2006-09-18 22:43:36 | 00,000,024 | ---- | M] () -- C:\autoexec.bat -- [ NTFS ]

 

AUTORUN.INF [[autorun] | OPEN=SETUP.EXE | ICON=SC.ICO | ]

[1998-01-09 04:06:18 | 00,000,040 | R--- | M] () -- D:\AUTORUN.INF -- [ CDFS ]

 

========== MountPoints2 ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{355a527c-b3b0-11dc-8369-806e6f6e6963}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{355a527c-b3b0-11dc-8369-806e6f6e6963}\Shell\AutoRun\command]

""=D:\SETUP.EXE -- [1998-01-14 08:11:20 | 00,025,088 | R--- | M] ()

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7fee77-b2e8-11dc-b28d-806e6f6e6963}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7fee77-b2e8-11dc-b28d-806e6f6e6963}\Shell\AutoRun\command]

""=D:\autorun.exe -- File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e005f95-e159-11dc-b59c-0013464cdcf9}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e005f95-e159-11dc-b59c-0013464cdcf9}\Shell\AutoRun\command]

""=F:\LaunchU3.exe -- File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]

""=E:\LaunchU3.exe -- File not found

 

========== Files/Folders - Created Within 30 Days ==========

 

[1 C:\Windows\*.tmp files]

[2008-11-26 11:32:06 | 00,422,400 | ---- | C] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

[2008-11-26 02:15:51 | 00,001,097 | ---- | C] () -- C:\Users\Axel\Desktop\Spybot - Search & Destroy.lnk

[2008-11-26 01:38:09 | 00,001,882 | ---- | C] () -- C:\Users\Axel\Desktop\HijackThis.lnk

[2008-11-26 01:38:08 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2008-11-26 01:34:39 | 00,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro

[2008-11-26 01:34:30 | 00,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Hitman Pro 3.lnk

[2008-11-26 01:34:28 | 00,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3

[2008-11-26 01:34:27 | 00,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro 3

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At9.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At8.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At24.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At23.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At22.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At21.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At20.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At19.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At18.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At17.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At16.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At15.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At14.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At13.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At12.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At11.job

[2008-11-26 01:19:57 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At10.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At7.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At6.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At5.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At4.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At3.job

[2008-11-26 01:19:56 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At2.job

[2008-11-26 01:19:55 | 00,040,964 | ---- | C] () -- C:\Windows\System32\3xe3DgDU.exe

[2008-11-26 01:19:55 | 00,000,348 | ---- | C] () -- C:\Windows\tasks\At1.job

[2008-11-26 01:19:55 | 00,000,000 | ---- | C] () -- C:\Windows\System32\3xe3DgDU.exe.a_a

[2008-11-26 01:18:14 | 00,000,000 | ---D | C] -- C:\Windows\Easy Decrypter

[2008-11-26 01:18:14 | 00,000,000 | ---D | C] -- C:\Program Files\Easy Decrypter

[2008-11-25 08:42:20 | 00,000,000 | ---D | C] -- C:\Program Files\iPod

[2008-11-25 08:42:19 | 00,000,000 | ---D | C] -- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

[2008-11-25 08:42:19 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes

[2008-11-25 08:25:40 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple

[2008-11-25 08:25:34 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime

[2008-11-25 08:25:17 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update

[2008-11-25 07:59:38 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Local\Temp

[2008-11-24 16:36:44 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up

[2008-11-22 20:32:08 | 00,259,571 | ---- | C] () -- C:\Users\Axel\Desktop\axle1.jpg

[2008-11-20 22:17:06 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$

[2008-11-19 20:08:31 | 00,001,689 | ---- | C] () -- C:\Users\Public\Desktop\AVG Free 8.0.lnk

[2008-11-19 20:08:28 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

[2008-11-19 20:08:27 | 30,355,197 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm

[2008-11-19 20:08:27 | 00,334,743 | ---- | C] () -- C:\Windows\System32\drivers\Avg\miniavi.avg

[2008-11-19 20:08:27 | 00,097,928 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys

[2008-11-19 20:08:27 | 00,050,685 | ---- | C] () -- C:\Windows\System32\drivers\Avg\microavi.avg

[2008-11-19 20:08:25 | 06,061,540 | ---- | C] () -- C:\Windows\System32\drivers\Avg\avi7.avg

[2008-11-19 20:08:25 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg

[2008-11-19 20:08:22 | 00,000,000 | ---D | C] -- C:\Program Files\AVG

[2008-11-19 20:08:21 | 00,000,000 | ---D | C] -- C:\ProgramData\avg8

[2008-11-17 23:05:33 | 00,000,000 | ---D | C] -- C:\ProgramData\NCH Software

[2008-11-17 23:05:15 | 00,000,000 | ---D | C] -- C:\Program Files\NCH Software

[2008-11-17 23:00:06 | 00,000,156 | ---- | C] () -- C:\Windows\Twunk001.MTX

[2008-11-17 23:00:06 | 00,000,002 | ---- | C] () -- C:\Windows\Twain001.Mtx

[2008-11-17 23:00:06 | 00,000,000 | ---- | C] () -- C:\Windows\Twunk002.MTX

[2008-11-14 14:08:44 | 00,133,905 | ---- | C] () -- C:\Users\Axel\Desktop\sensation.jpg

[2008-11-14 12:22:38 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll

[2008-11-14 12:22:37 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuaueng.dll

[2008-11-14 12:22:37 | 01,524,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll

[2008-11-14 12:22:37 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe

[2008-11-14 12:22:11 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll

[2008-11-14 12:22:11 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll

[2008-11-14 12:22:11 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll

[2008-11-14 12:22:07 | 00,162,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll

[2008-11-14 12:22:07 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe

[2008-11-13 21:34:59 | 00,000,000 | ---D | C] -- C:\Windows\Minidump

[2008-11-13 09:10:23 | 00,212,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys

[2008-11-13 09:10:22 | 01,191,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3.dll

[2008-11-13 09:10:19 | 01,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll

[2008-11-12 15:32:35 | 00,000,000 | ---D | C] -- C:\Windows\System32\AGEIA

[2008-11-12 15:32:35 | 00,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies

[2008-11-12 15:24:19 | 00,002,032 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Mouse.lnk

[2008-11-12 15:24:14 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliPoint

[2008-11-11 18:13:40 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Roaming\Personal

[2008-11-11 18:13:18 | 00,001,872 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk

[2008-11-11 18:13:17 | 00,000,000 | ---D | C] -- C:\Program Files\Personal

[2008-11-10 15:15:34 | 00,001,929 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk

[2008-11-07 13:51:03 | 00,000,000 | ---D | C] -- C:\Program Files\Domain Tools

[2008-10-30 01:32:42 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Local\Native Instruments

[2008-10-30 01:31:22 | 00,000,000 | ---D | C] -- C:\Users\Axel\Documents\Traktor3

[2008-10-30 01:31:09 | 00,000,000 | ---D | C] -- C:\Program Files\Native Instruments

[2008-10-29 11:37:18 | 00,443,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32spl.dll

[2008-10-29 11:33:52 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll

[2008-10-29 11:33:52 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wersvc.dll

 

========== Files - Modified Within 30 Days ==========

 

[1 C:\Windows\*.tmp files]

[2008-11-26 11:33:17 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

[2008-11-26 11:11:33 | 00,000,544 | ---- | M] () -- C:\Users\Axel\Documents\Mina delade mappar.lnk

[2008-11-26 11:08:34 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At11.job

[2008-11-26 11:08:34 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2008-11-26 11:08:30 | 00,004,080 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2008-11-26 11:08:30 | 00,004,080 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2008-11-26 11:08:21 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2008-11-26 11:06:53 | 00,054,740 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:53 | 00,054,740 | ---- | M] () -- C:\Windows\System32\BMXState-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:53 | 00,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:41 | 03,877,323 | -H-- | M] () -- C:\Users\Axel\AppData\Local\IconCache.db

[2008-11-26 11:00:21 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At12.job

[2008-11-26 02:15:51 | 00,001,097 | ---- | M] () -- C:\Users\Axel\Desktop\Spybot - Search & Destroy.lnk

[2008-11-26 02:06:26 | 30,355,197 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At9.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At8.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At7.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At6.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At5.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At4.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At3.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At24.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At23.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At22.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At21.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At20.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At2.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At19.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At18.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At17.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At16.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At15.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At14.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At13.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At10.job

[2008-11-26 02:04:57 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\At1.job

[2008-11-26 01:39:46 | 00,001,882 | ---- | M] () -- C:\Users\Axel\Desktop\HijackThis.lnk

[2008-11-26 01:34:30 | 00,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Hitman Pro 3.lnk

[2008-11-26 01:19:55 | 00,000,000 | ---- | M] () -- C:\Windows\System32\3xe3DgDU.exe.a_a

[2008-11-26 01:19:54 | 00,040,964 | ---- | M] () -- C:\Windows\System32\3xe3DgDU.exe

[2008-11-25 14:08:45 | 00,236,032 | ---- | M] () -- C:\Users\Axel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2008-11-24 20:51:15 | 00,050,685 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg

[2008-11-23 21:50:57 | 01,513,870 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI

[2008-11-23 21:50:57 | 00,642,212 | ---- | M] () -- C:\Windows\System32\perfh01D.dat

[2008-11-23 21:50:57 | 00,628,782 | ---- | M] () -- C:\Windows\System32\perfh009.dat

[2008-11-23 21:50:57 | 00,133,192 | ---- | M] () -- C:\Windows\System32\perfc01D.dat

[2008-11-23 21:50:57 | 00,114,218 | ---- | M] () -- C:\Windows\System32\perfc009.dat

[2008-11-22 20:32:08 | 00,259,571 | ---- | M] () -- C:\Users\Axel\Desktop\axle1.jpg

[2008-11-20 01:57:41 | 00,334,743 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg

[2008-11-19 20:08:31 | 00,001,689 | ---- | M] () -- C:\Users\Public\Desktop\AVG Free 8.0.lnk

[2008-11-19 20:08:28 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

[2008-11-19 20:08:27 | 06,061,540 | ---- | M] () -- C:\Windows\System32\drivers\Avg\avi7.avg

[2008-11-19 20:08:27 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys

[2008-11-19 20:08:27 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys

[2008-11-18 00:06:59 | 00,000,316 | ---- | M] () -- C:\Users\Axel\Documents\Setting.ini

[2008-11-17 23:00:06 | 00,000,156 | ---- | M] () -- C:\Windows\Twunk001.MTX

[2008-11-17 23:00:06 | 00,000,002 | ---- | M] () -- C:\Windows\Twain001.Mtx

[2008-11-17 23:00:06 | 00,000,000 | ---- | M] () -- C:\Windows\Twunk002.MTX

[2008-11-14 14:08:46 | 00,133,905 | ---- | M] () -- C:\Users\Axel\Desktop\sensation.jpg

[2008-11-12 15:24:19 | 00,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Mouse.lnk

[2008-11-11 18:13:18 | 00,001,872 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk

[2008-11-10 15:15:34 | 00,001,929 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk

[2008-11-04 01:10:25 | 17,318,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe

< End of report >

[/log]

 

och den andra

 

[log]OTViewIt Extras logfile created on: 2008-11-26 11:33:46 - Run

OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Users\Axel\Desktop

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

2,00 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 94,28% Memory free

4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free

Paging file location(s): ?:\pagefile.sys;

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 232,88 Gb Total Space | 45,04 Gb Free Space | 19,34% Space Free | Partition Type: NTFS

Drive D: | 637,02 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Drive E: | 465,76 Gb Total Space | 246,39 Gb Free Space | 52,90% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: AXEL-DATOR

Current User Name: Axel

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Whitelist: On

File Age = 30 Days

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride"=0

"AntiSpywareOverride"=0

"FirewallOverride"=0

"VistaSp1"=V¾y;

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2903967537-112725781-1445369304-1000]

"EnableNotifications"=0

"EnableNotificationsRef"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

"DisableNotifications"=0

"EnableFirewall"=1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

 

========== (O10) Winsock2 Catalogs ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]

NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] -- C:\Windows\System32\nlaapi.dll (Microsoft Corporation)

NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] -- C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)

NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] -- C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] -- C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] -- C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)

 

========== HKEY_LOCAL_MACHINE Protocol Defaults ==========

 

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default Protocols

ldap -- 4 = Restricted sites (Not a Default Protocol)

news -- 4 = Restricted sites (Not a Default Protocol)

nntp -- 4 = Restricted sites (Not a Default Protocol)

oecmd -- 4 = Restricted sites (Not a Default Protocol)

snews -- 4 = Restricted sites (Not a Default Protocol)

 

========== HKEY_USERS Protocol Defaults ==========

 

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols

@ivt -- @ivt protocol not assigned

file -- file protocol not assigned

ftp -- ftp protocol not assigned

http -- http protocol not assigned

https -- https protocol not assigned

shell -- shell protocol not assigned

 

========== HKEY_USERS Protocol Defaults ==========

 

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols

@ivt -- @ivt protocol not assigned

file -- file protocol not assigned

ftp -- ftp protocol not assigned

http -- http protocol not assigned

https -- https protocol not assigned

shell -- shell protocol not assigned

 

========== (O18) Protocol Handlers ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2008-11-19 20:08:23 | 00,079,128 | ---- | M] (AVG Technologies CZ, s.r.o.) C:\Program\AVG\AVG8\avgpp.dll (linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} (HKLM) [XPLPPFilter Class])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-10-18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

msdaipp: [HKLM - No CLSID value]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers

[2005-09-20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers

[2005-09-20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-10-18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-05-10 13:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program\Common Files\microsoft shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2008-04-03 15:48:26 | 01,934,672 | R--- | M] (Skype Technologies) C:\Program\Common Files\Skype\Skype4COM.dll (skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} (HKLM) [iEProtocolHandler Class])

 

========== (O18) Protocol Filters ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters

[2007-04-19 13:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=Google Gmail Notifier

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}"=Steam

"{04AF207D-9A77-465A-8B76-991F6AB66245}"=Adobe Help Viewer CS3

"{0523EAF4-402C-4435-A0DA-13C40193D811}"=Logitech GamePanel Software 2.02

"{08B32819-6EEF-4057-AEDA-5AB681A36A23}"=Adobe Bridge Start Meeting

"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}"=Windows Installer Clean Up

"{13515135-48BB-4184-8C1F-2FAE0138E200}"=TBS WMP Plug-in

"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}"=Adobe WinSoft Linguistics Plugin

"{1E88F516-C8AA-4D17-9A54-8AB0768F34C1}"=Retrospect Express HD 1.0

"{20503DFE-E5B2-491E-B2C5-8BCB5BF5B9E9}"=Windows Live Messenger

"{20E98A60-BE95-4B45-A51F-10F9C0514D77}"=DWL-G520M Wireless 108G MIMO PCI Adapter

"{231F68F4-70E4-41A6-BEDA-7E7934169B54}"=Maxtor OneTouch

"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}"=Adobe ExtendScript Toolkit 2

"{26A24AE4-039D-4CA4-87B4-2F83216010FF}"=Java 6 Update 10

"{2770CB13-5093-4C94-A318-F103857E18B1}"=Smarta menyer (Windows Live Toolbar)

"{29E5EA97-5F74-4A57-B8B2-D4F169117183}"=Adobe Stock Photos CS3

"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes

"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java 6 Update 3

"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java 6 Update 5

"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java 6 Update 7

"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}"=Adobe Photoshop CS3

"{51846830-E7B2-4218-8968-B77F0FF475B8}"=Adobe Color EU Extra Settings

"{54793AA1-5001-42F4-ABB6-C364617C6078}"=Adobe Linguistics CS3

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}"=Skype™ 3.6

"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}"=Adobe Setup

"{64E09E82-610D-4FB9-8722-1D2D1CD65A6B}"=Windows Live Toolbar Extension (Windows Live Toolbar)

"{66A9D30D-1464-4C7F-B2F3-507DADAF2595}"=Microsoft IntelliPoint 6.3

"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}"=Windows Media Player Firefox Plugin

"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}"=Adobe Fonts All

"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}"=Adobe Color Common Settings

"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}"=Adobe Asset Services CS3

"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable

"{786C5747-1437-443D-B06E-79A00FE45110}"=Adobe Stock Photos 1.0

"{789289CA-F73A-4A16-A331-54D498CE069F}"=Ventrilo Client

"{802771A9-A856-4A41-ACF7-1450E523C923}"=Adobe XMP Panels CS3

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}"=Microsoft Silverlight

"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour

"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}"=Adobe Device Central CS3

"{8DC42D05-680B-41B0-8878-6C14D24602DB}"=QuickTime

"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}"=Adobe Type Support

"{8EDBA74D-0686-4C99-BFDD-F894678E5102}"=Adobe Common File Installer

"{8FFC924C-ED06-44CB-8867-3CA778ECE903}"=Adobe Help Center 2.0

"{90120000-0020-0409-0000-0000000FF1CE}"=Compatibility Pack for the 2007 Office system

"{90176341-0A8B-4CCC-A78D-F862228A6B95}"=Adobe Anchor Service CS3

"{9112041D-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Standard Edition 2003

"{95120000-00B9-0409-0000-0000000FF1CE}"=Microsoft Application Error Reporting

"{95655ED4-7CA5-46DF-907F-7144877A32E5}"=Adobe Color NA Recommended Settings

"{993960EE-CA4D-443F-8F88-E24260DD5FD2}"=LG PC Suite

"{9C9824D9-9000-4373-A6A5-D0E5D4831394}"=Adobe Bridge CS3

"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}"=Adobe CMaps

"{A2D81E70-2A98-4A08-A628-94388B063C5E}"=Adobe Color - Photoshop Specific

"{A5FB086B-B602-4452-8FE9-DF6BFBCE3D09}"=Steinberg Cubase Studio 4

"{A7E07C2B-2220-4415-87E3-784D5814BC93}"=NVIDIA PhysX v8.09.04

"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}"=PDF Settings

"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3

"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}"=Adobe Bridge 1.0

"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}"=Windows Live inloggningsassistenten

"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}"=Adobe Camera Raw 4.0

"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}"=Adobe Setup

"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy

"{B74D4E10-0000-0000-0000-EDED00000102}"=Adobe ExtendScript Toolkit 1.0

"{B8E8C8EC-5C22-4B02-9C02-D851262F574C}"=Sony Vegas Movie Studio Platinum 8.0

"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}"=Adobe Default Language CS3

"{C3ABE126-2BB2-4246-BFE1-6797679B3579}"=LG USB Modem driver

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1

"{D052C16B-1290-41CF-8EFB-79337027B2F7}"=Sökmarkeringsfönstret (Windows Live Toolbar)

"{D0DFF92A-492E-4C40-B862-A74A173C25C5}"=Adobe Version Cue CS3 Client

"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}"=Adobe PDF Library Files

"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}"=Nikon Message Center

"{DA7D5E4A-7AEA-45BE-AA03-3748282DFB09}"=Auzen X-Fi Prelude 7.1

"{DD362256-A7A2-4524-9457-213DDC2AFC2A}"=Adobe After Effects 7.0

"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}"=Adobe Color JA Extra Settings

"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware

"{E17F76BE-50E9-4E7C-ADF6-6D8F44A9C6F3}"=Windows Live installer

"{E69AE897-9E0B-485C-8552-7841F48D42D8}"=Adobe Update Manager CS3

"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}"=Microsoft SQL Server 2005 Compact Edition [ENU]

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver

"{F1A14CB2-A048-45A6-AFDA-3571296E1D76}"=Creative Media Toolbox 6

"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}"=Adobe Setup

"Adobe After Effects 7.0"=Adobe After Effects 7.0

"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX

"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin

"Adobe Shockwave Player"=Adobe Shockwave Player

"Adobe_3e054d2218e7aa282c2369d939e58ff"=Adobe ExtendScript Toolkit 2

"Adobe_6c8e2cb4fd241c55406016127a6ab2e"=Adobe Color Common Settings

"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1"=Adobe Photoshop CS3

"AVG8Uninstall"=AVG Free 8.0

"Azureus Vuze"=Azureus Vuze

"Canon LBP2900"=Canon LBP2900

"CCleaner"=CCleaner (remove only)

"Collab"=Collab

"Dolby Digital Live Pack"=Dolby Digital Live Pack

"DTS Connect Pack"=DTS Connect Pack

"Easy Decrypter1.12"=Easy Decrypter

"FL Studio 8"=FL Studio 8

"FLAC"=FLAC 1.2.1b (remove only)

"Fraps"=Fraps (remove only)

"HijackThis"=HijackThis 2.0.2

"HitmanPro3"=Hitman Pro 3

"IL Download Manager"=IL Download Manager

"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}"=TBS WMP Plug-in

"InstallShield_{231F68F4-70E4-41A6-BEDA-7E7934169B54}"=Maxtor OneTouch

"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1

"mIRC"=mIRC

"Mozilla Firefox (3.0.4)"=Mozilla Firefox (3.0.4)

"Native Instruments Service Center"=Native Instruments Service Center

"Native Instruments Traktor DJ Studio 3"=Native Instruments Traktor DJ Studio 3

"NVIDIA Drivers"=NVIDIA Drivers

"OpenAL"=OpenAL

"Personal"=BankID säkerhetsprogram 4.10

"PoiZone"=PoiZone

"Prism"=Prism Video Converter

"ProjectWhois"=ProjectWhois

"SimCity 3000"=SimCity 3000

"SopCast"=SopCast 3.0.3

"Starcraft"=Starcraft

"Steam App 10"=Counter-Strike

"Steam App 17500"=Zombie Panic! Source

"Steam App 17510"=Age of Chivalry

"Steam App 17520"=Synergy

"Steam App 17530"=D.I.P.R.I.P. Warm Up

"Steam App 17700"=Insurgency

"Steam App 20"=Team Fortress Classic

"Steam App 220"=Half-Life 2

"Toxic Biohazard"=Toxic Biohazard

"Uninstaller_B4736000_Creative Media Toolbox 6"=Creative Media Toolbox 6 (Shared Components)

"Winamp"=Winamp

"WinRAR archiver"=WinRAR archiver

"VLC media player"=VideoLAN VLC media player 0.8.6f

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"NoNameScript"=NNScript

"Octoshape add-in for Adobe Flash Player"=Octoshape add-in for Adobe Flash Player

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"NoNameScript"=NNScript

"Octoshape add-in for Adobe Flash Player"=Octoshape add-in for Adobe Flash Player

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 2008-11-24 11:39:49 | Computer Name = Axel-dator | Source = VBRuntime | ID = 1

Description = The VB Application identified by the event source logged this Application

MSICUU: Thread ID: 4808 ,Logged: Success: C:\Program Files\Windows Installer Clean

Up\msizap.exe TW! {EC4455AB-F155-4CC1-A4C5-88F3777F9886}

 

Error - 2008-11-24 11:39:57 | Computer Name = Axel-dator | Source = VBRuntime | ID = 1

Description = The VB Application identified by the event source logged this Application

MSICUU: Thread ID: 4808 ,Logged: Success: C:\Program Files\Windows Installer Clean

Up\msizap.exe TW! {6956856F-B6B3-4BE0-BA0B-8F495BE32033}

 

Error - 2008-11-24 11:40:03 | Computer Name = Axel-dator | Source = VBRuntime | ID = 1

Description = The VB Application identified by the event source logged this Application

MSICUU: Thread ID: 4808 ,Logged: Success: C:\Program Files\Windows Installer Clean

Up\msizap.exe TW! {8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}

 

Error - 2008-11-25 20:11:51 | Computer Name = Axel-dator | Source = Windows Search Service | ID = 3013

Description =

 

Error - 2008-11-25 20:12:01 | Computer Name = Axel-dator | Source = Windows Search Service | ID = 3013

Description =

 

Error - 2008-11-25 20:12:06 | Computer Name = Axel-dator | Source = Windows Search Service | ID = 3013

Description =

 

Error - 2008-11-25 20:12:06 | Computer Name = Axel-dator | Source = Windows Search Service | ID = 3013

Description =

 

Error - 2008-11-25 20:12:57 | Computer Name = Axel-dator | Source = Windows Search Service | ID = 3013

Description =

 

Error - 2008-11-25 20:20:29 | Computer Name = Axel-dator | Source = VSS | ID = 8194

Description =

 

Error - 2008-11-25 21:08:04 | Computer Name = Axel-dator | Source = VSS | ID = 8194

Description =

 

[ System Events ]

Error - 2008-11-25 03:43:35 | Computer Name = Axel-dator | Source = DCOM | ID = 10010

Description =

 

Error - 2008-11-25 16:10:35 | Computer Name = Axel-dator | Source = HTTP | ID = 15016

Description =

 

Error - 2008-11-25 20:21:14 | Computer Name = Axel-dator | Source = WinDefend | ID = 3006

Description = Realtidsskyddet från %%827 har påträffat ett fel under åtgärder mot

spionprogram eller annan oönskad programvara. Mer information finns här: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:Win32/Renos.FH&threatid=131738'>http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:Win32/Renos.FH&threatid=131738'>http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:Win32/Renos.FH&threatid=131738

 

Sök-ID:

{6E178770-C93B-4A52-8B7C-02A8D9378139} Användare: Axel-dator\Axel Namn: TrojanDownloader:Win32/Renos.FH

 

ID:

131738 Allvarlighets-ID: 4 Kategori-ID: 4 Sökväg: Aviseringstyp: %%805 Åtgärd: %%811

 

Felkod:

0x80508022 Felbeskrivning: Slutför borttagningen av spionprogram och annan oönskad

programvara genom att starta om datorn.

 

Error - 2008-11-25 20:27:35 | Computer Name = Axel-dator | Source = WinDefend | ID = 3006

Description = Realtidsskyddet från %%827 har påträffat ett fel under åtgärder mot

spionprogram eller annan oönskad programvara. Mer information finns här: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:Win32/Renos.FH&threatid=131738

 

Sök-ID:

{2DE1C300-57EE-44F2-8475-AD584D38CF2D} Användare: Axel-dator\Axel Namn: TrojanDownloader:Win32/Renos.FH

 

ID:

131738 Allvarlighets-ID: 4 Kategori-ID: 4 Sökväg: Aviseringstyp: %%805 Åtgärd: %%811

 

Felkod:

0x80508022 Felbeskrivning: Slutför borttagningen av spionprogram och annan oönskad

programvara genom att starta om datorn.

 

Error - 2008-11-25 20:35:47 | Computer Name = Axel-dator | Source = WinDefend | ID = 1008

Description = Ett fel påträffades av %%827 när åtgärder vidtogs mot spionprogram

eller annan oönskad programvara. Mer information finns här: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDownloader:Win32/Renos.FH&threatid=131738

 

Sök-ID:

{5537704A-B62A-489A-ADBF-52EAD463FA3E} Söktyp: %%802 Användare: Axel-dator\Axel Namn:

TrojanDownloader:Win32/Renos.FH ID: 131738 Allvarlighets-ID: 4 Kategori-ID: 4 Sökväg:

Åtgärd: %%811 Felkod: 0x80508022 Felbeskrivning: Slutför borttagningen av spionprogram

och annan oönskad programvara genom att starta om datorn.

 

Error - 2008-11-25 21:04:57 | Computer Name = Axel-dator | Source = HTTP | ID = 15016

Description =

 

Error - 2008-11-26 04:24:18 | Computer Name = Axel-dator | Source = HTTP | ID = 15016

Description =

 

Error - 2008-11-26 04:32:37 | Computer Name = Axel-dator | Source = Service Control Manager | ID = 7034

Description =

 

Error - 2008-11-26 04:32:42 | Computer Name = Axel-dator | Source = Service Control Manager | ID = 7031

Description =

 

Error - 2008-11-26 06:08:34 | Computer Name = Axel-dator | Source = HTTP | ID = 15016

Description =

 

 

< End of report >

[/log]

 

Link to comment
Share on other sites

I mappen C:\Windows\tasks ta bort alla de schemalagda aktiviterna som börjar på At.

 

Ta bort filen C:\Windows\System32\3xe3DgDU.exe.a_a

 

Ta bort mapparna:

C:\Windows\Easy Decrypter

C:\Program Files\Easy Decrypter

Det ser ut som att det var det programmet som infekterade datorn.

 

Surfa till http://www.virustotal.com klistra in ett av följande filnamn i rutan, tryck på Skicka Fil och vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in resultatet från de olika antivirusprogrammen (inte Övrig information) här. Upprepa med nästa filnamn.

C:\Windows\System32\3xe3DgDU.exe

 

Avinstallera följande, det är gamla versioner med säkerhetshål:

"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java™ 6 Update 3

"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java™ 6 Update 5

"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7

 

 

Link to comment
Share on other sites

Det är garanterat det programmet som infekterade datorn. skönt att hitta det.

 

Jag laddade upp: C:\Windows\System32\3xe3DgDU.exe och fick följande resultat:

 

[log]Antivirus Version Senaste Uppdatering Resultat

AhnLab-V3 2008.11.24.3 2008.11.26 -

AntiVir 7.9.0.35 2008.11.26 TR/Crypt.ULPM.Gen

Authentium 5.1.0.4 2008.11.25 -

Avast 4.8.1281.0 2008.11.25 -

AVG 8.0.0.199 2008.11.25 -

BitDefender 7.2 2008.11.26 Trojan.Adclicker.HB

CAT-QuickHeal 10.00 2008.11.26 -

ClamAV 0.94.1 2008.11.26 -

DrWeb 4.44.0.09170 2008.11.26 Trojan.DownLoad.23514

eSafe 7.0.17.0 2008.11.25 Suspicious File

eTrust-Vet 31.6.6228 2008.11.26 -

Ewido 4.0 2008.11.25 -

F-Prot 4.4.4.56 2008.11.25 -

F-Secure 8.0.14332.0 2008.11.26 -

Fortinet 3.117.0.0 2008.11.25 -

GData 19 2008.11.26 Trojan.Adclicker.HB

Ikarus T3.1.1.45.0 2008.11.26 -

K7AntiVirus 7.10.533 2008.11.25 -

Kaspersky 7.0.0.125 2008.11.26 -

McAfee 5445 2008.11.25 New Malware.bl

McAfee+Artemis 5445 2008.11.25 New Malware.bl

Microsoft 1.4104 2008.11.26 TrojanDownloader:Win32/Obvod.C

NOD32 3641 2008.11.26 a variant of Win32/TrojanClicker.Agent.NEB

Norman 5.80.02 2008.11.25 -

Panda 9.0.0.4 2008.11.25 Suspicious file

PCTools 4.4.2.0 2008.11.25 -

Prevx1 V2 2008.11.26 -

Rising 21.05.12.00 2008.11.25 Trojan.Win32.Undef.jrw

SecureWeb-Gateway 6.7.6 2008.11.25 Trojan.Crypt.ULPM.Gen

Sophos 4.35.0 2008.11.25 Mal/HckPk-A

Sunbelt 3.1.1830.2 2008.11.26 -

Symantec 10 2008.11.26 -

TheHacker 6.3.1.1.163 2008.11.25 -

TrendMicro 8.700.0.1004 2008.11.26 PAK_Generic.001

VBA32 3.12.8.9 2008.11.26 Trojan-Downloader.Win32.Agent.aoyp

ViRobot 2008.11.26.1486 2008.11.26 -

VirusBuster 4.5.11.0 2008.11.25 -

[/log]

 

förstod inte riktigt vilka filer du syftade på med:

"Upprepa med nästa filnamn."

 

/Axel

 

Link to comment
Share on other sites

förstod inte riktigt vilka filer du syftade på med:

"Upprepa med nästa filnamn."

Förlåt, det var två filer först som jag tänkte att du skulle skanna men sedan såg jag att den andra var tom så jag tog bort det filnamnet men glömde ta bort Upprepa-meningen.

 

Kan du ladda upp C:\Windows\System32\3xe3DgDU.exe på http://www.skickafilen.se/ och som e-postadress så skriver du in min som du ser när du trycker på Anv.info här under. Då kan jag skicka den vidare till de antivirusföretag som inte känner till den.

 

Link to comment
Share on other sites

Skickade vidare filen, Finns det något jag kan göra åt den, vad händer nu?

 

Jag antar att jag inte kan ta bort den, och mitt virusprogram (AVG) hittade den ju inte på onlinesökningen.

 

Jag vågar inte gå in på några som helst onlinekonton när jag har det här viruset/virusen på min dator.

 

Link to comment
Share on other sites

Ladda ner OTMoveIt till Skrivbordet:

http://oldtimer.geekstogo.com/OTMoveIt3.exe

Starta programmet

Kopiera alla dessa rader (använd markera kod):

:Files
C:\Windows\System32\3xe3DgDU.exe

Klistra in dem i rutan Paste Instructions for Items to be Moved

Tryck på MoveIt!

Om du blir tillfrågad om att starta om datorn så gör det.

Gå till mappen c:\_OTMoveIt\MovedFiles och öppna loggfilen som skapades med dagens datum och klockslag. Kopiera innehållet och klistra in här liksom en ny OTViewIt.txt.

 

Link to comment
Share on other sites

Här är logfilen:

 

[log]

========== FILES ==========

C:\Windows\System32\3xe3DgDU.exe moved successfully.

 

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11262008_153123[/log]

 

"Kopiera innehållet och klistra in här liksom en ny OTViewIt.txt."

Är inte helt säker på vad du menar. Ser i alla fall den flyttade filen i en mapp med samma namn som logfilen (tid och datum).

 

/Axel

 

 

Link to comment
Share on other sites

Läste fel. Försökte redigera mitt inlägg men det gick inte, så jag gör ett nytt istället. Här kommer den nya loggen

 

[log]

OTViewIt logfile created on: 2008-11-26 15:38:04 - Run 2

OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Users\Axel\Desktop

Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation

Internet Explorer (Version = 7.0.6001.18000)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

2,00 Gb Total Physical Memory | 1,48 Gb Available Physical Memory | 73,75% Memory free

4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free

Paging file location(s): ?:\pagefile.sys;

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 232,88 Gb Total Space | 51,83 Gb Free Space | 22,26% Space Free | Partition Type: NTFS

Drive D: | 637,02 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Drive E: | 465,76 Gb Total Space | 246,39 Gb Free Space | 52,90% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: AXEL-DATOR

Current User Name: Axel

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Whitelist: On

File Age = 30 Days

 

========== Processes ==========

 

[2008-01-19 08:33:37 | 00,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininit.exe

[2008-01-19 08:33:14 | 00,229,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lsm.exe

[2008-10-07 13:33:00 | 00,203,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe

[2008-04-30 09:35:20 | 00,425,984 | ---- | M] (Creative Technology Ltd) -- C:\Program\Creative\Shared Files\CTAudSvc.exe

[2008-01-19 08:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SLsvc.exe

[2008-07-07 07:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program\Lavasoft\Ad-Aware\aawservice.exe

[2006-11-02 10:45:37 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rundll32.exe

[2005-03-27 16:00:00 | 00,057,344 | ---- | M] (CANON INC.) -- C:\Windows\System32\CNAB4RPK.EXE

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

[2008-11-19 20:08:22 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgwdsvc.exe

[2008-08-29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe

[2004-07-30 15:47:36 | 00,069,632 | ---- | M] (Dantz Development Corporation) -- C:\Program\Dantz\Retrospect Express HD\retrorun.exe

[2008-05-27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe

[2008-07-07 09:42:02 | 00,809,296 | ---- | M] (Safer Networking Ltd.) -- C:\Program\Spybot - Search & Destroy\SDWinSec.exe

[2008-11-19 20:08:22 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgrsx.exe

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2008-01-19 08:33:08 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe

[2008-01-19 08:38:38 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Defender\MSASCui.exe

[2007-01-18 07:46:56 | 04,349,952 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe

[2005-07-15 22:48:33 | 00,479,232 | ---- | M] (Google Inc.) -- C:\Program\Google\Gmail Notifier\gnotify.exe

[2008-08-21 22:44:24 | 00,023,552 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CTXFIHLP.EXE

[2008-06-10 12:56:32 | 01,406,024 | ---- | M] (Microsoft Corporation) -- C:\Program\Microsoft IntelliPoint\ipoint.exe

[2006-11-02 10:45:37 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rundll32.exe

[2008-11-19 20:08:22 | 01,234,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgtray.exe

[2008-01-19 08:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnscfg.exe

[2008-01-19 08:33:33 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe

[2008-01-19 08:33:39 | 00,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\WmiPrvSE.exe

[2008-01-19 08:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnetwk.exe

[2007-12-13 17:43:30 | 00,416,280 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe

[2007-12-13 17:43:12 | 00,461,336 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe

[2007-12-13 17:43:02 | 00,481,304 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe

[2007-12-13 17:42:52 | 00,558,104 | ---- | M] (Logitech Inc.) -- C:\Program\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe

[2008-08-21 22:40:38 | 01,225,216 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CTXFISPI.EXE

[2008-01-19 08:33:32 | 00,169,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe

[2007-10-18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\usnsvc.exe

[2008-10-16 22:09:43 | 00,051,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe

[2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program\iPod\bin\iPodService.exe

[2008-11-20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program\iTunes\iTunesHelper.exe

[2008-01-19 08:33:12 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program\Internet Explorer\iexplore.exe

[2008-11-19 20:08:23 | 00,540,440 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\aAvgApi.exe

[2007-09-20 10:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program\Common Files\microsoft shared\Windows Live\WLLoginProxy.exe

File not found -- C:\Windows\system32\3xe3DgDU.exe

[2008-01-19 08:33:12 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\Program\Internet Explorer\iexplore.exe

[2008-11-19 20:08:23 | 00,540,440 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\aAvgApi.exe

[2007-09-20 10:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program\Common Files\microsoft shared\Windows Live\WLLoginProxy.exe

[2008-04-23 17:19:18 | 01,189,104 | ---- | M] (Piriform Ltd) -- C:\Program\CCleaner\CCleaner.exe

[2008-11-11 18:07:58 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program\Java\jre6\bin\jusched.exe

[2008-04-01 23:41:10 | 00,095,744 | ---- | M] () -- C:\Program\VideoLAN\VLC\vlc.exe

[2008-11-26 11:33:17 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

 

========== (O23) Win32 Services ==========

 

[2008-07-07 07:15:18 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])

[2005-01-28 14:19:02 | 00,036,864 | ---- | M] () -- C:\Windows\System32\acs.exe -- (ACS [Auto | Stopped])

[2008-06-08 00:20:32 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])

[2008-11-19 20:08:22 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])

[2008-08-29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])

File not found -- -- (CertPropSvc [unknown | Stopped])

[2008-01-05 12:26:41 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

[2008-10-19 17:34:59 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\AL1Licensing.exe -- (Creative ALchemy AL1 Licensing Service [On_Demand | Stopped])

[2008-10-19 17:15:18 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service [On_Demand | Stopped])

[2008-07-09 12:57:55 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service [On_Demand | Stopped])

[2008-04-30 09:35:20 | 00,425,984 | ---- | M] (Creative Technology Ltd) -- C:\Program\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService [Auto | Running])

File not found -- -- (DcomLaunch [unknown | Running])

[2008-01-19 08:33:06 | 02,091,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dfsr.exe -- (DFSR [On_Demand | Stopped])

[2008-01-19 08:34:06 | 00,134,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dps.dll -- (DPS [unknown | Running])

[2008-01-19 08:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr [On_Demand | Stopped])

[2006-11-02 13:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])

[2008-08-31 11:34:48 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])

[2008-01-05 12:21:53 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])

[2008-01-19 08:34:25 | 00,574,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gpsvc.dll -- (gpsvc [unknown | Running])

[2004-10-22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

[2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])

[2006-11-02 14:04:14 | 00,000,000 | ---D | M] -- C:\Windows\System32\Msdtc -- (MSDTC [unknown | Stopped])

[2008-01-05 12:21:39 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])

[2008-10-07 13:33:00 | 00,203,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running])

[2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

[2004-07-30 15:47:36 | 00,069,632 | ---- | M] (Dantz Development Corporation) -- C:\Program\Dantz\Retrospect Express HD\retrorun.exe -- (RetroExpLauncher [Auto | Running])

[2008-01-19 08:36:17 | 00,547,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rpcss.dll -- (RpcSs [unknown | Running])

[2008-07-07 09:42:02 | 00,809,296 | ---- | M] (Safer Networking Ltd.) -- C:\Program\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService [Auto | Running])

[2008-01-19 08:36:19 | 00,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr [unknown | Stopped])

File not found -- -- (Schedule [unknown | Running])

File not found -- -- (SCPolicySvc [unknown | Stopped])

[2008-01-19 08:33:22 | 02,623,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SLsvc.exe -- (slsvc [Auto | Running])

[2006-11-02 10:45:46 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\snmptrap.exe -- (SNMPTRAP [On_Demand | Stopped])

[2008-11-22 11:47:10 | 00,104,944 | ---- | M] (Valve Corporation) -- C:\Program\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Stopped])

[2008-01-19 08:33:33 | 00,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\UI0Detect.exe -- (UI0Detect [On_Demand | Stopped])

[2007-10-18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])

[2008-01-19 08:33:33 | 00,382,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vds.exe -- (vds [On_Demand | Stopped])

File not found -- -- (WdiServiceHost [unknown | Stopped])

File not found -- -- (WdiSystemHost [unknown | Running])

[2007-10-25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])

[2008-01-19 08:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])

[2008-05-27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe -- (WSearch [Auto | Running])

 

========== Driver Services ==========

 

[2006-11-02 10:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])

[2006-11-02 10:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])

[2006-11-02 10:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])

[2006-11-02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])

[2006-11-02 10:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\System32\drivers\aliide.sys -- (aliide [Disabled | Stopped])

[2006-11-02 10:49:59 | 00,054,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\AMDAGP.SYS -- (amdagp [On_Demand | Stopped])

[2006-11-02 10:49:26 | 00,015,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdide.sys -- (amdide [Disabled | Stopped])

[2006-11-02 09:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdk7.sys -- (AmdK7 [Disabled | Stopped])

[2008-01-19 06:27:20 | 00,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\amdk8.sys -- (AmdK8 [On_Demand | Running])

[2004-12-24 17:34:42 | 00,355,328 | ---- | M] (D-Link) -- C:\Windows\System32\drivers\ar5513.sys -- (AR5513 [On_Demand | Running])

[2006-11-02 10:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arc.sys -- (arc [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])

[2008-11-19 20:08:27 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys -- (AvgLdx86 [system | Running])

[2008-11-19 20:08:27 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys -- (AvgMfx86 [system | Running])

[2008-01-19 06:28:26 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bowser.sys -- (bowser [On_Demand | Running])

[2006-11-02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltLo.sys -- (BrFiltLo [On_Demand | Stopped])

[2006-11-02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltUp.sys -- (BrFiltUp [On_Demand | Stopped])

[2006-11-02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerId.sys -- (Brserid [Disabled | Stopped])

[2006-11-02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerWdm.sys -- (BrSerWdm [Disabled | Stopped])

[2006-11-02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbMdm.sys -- (BrUsbMdm [Disabled | Stopped])

[2006-11-02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbSer.sys -- (BrUsbSer [On_Demand | Stopped])

[2006-11-02 09:55:23 | 00,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bthmodem.sys -- (BTHMODEM [Disabled | Stopped])

[2006-11-02 09:55:08 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\circlass.sys -- (circlass [Disabled | Stopped])

[2008-01-19 08:42:58 | 00,247,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clfs.sys -- (CLFS [unknown | Running])

[2006-11-02 10:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\System32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])

[2006-11-02 10:49:43 | 00,022,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\crcdisk.sys -- (crcdisk [boot | Running])

[2006-11-02 09:30:18 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\crusoe.sys -- (Crusoe [Disabled | Stopped])

[2008-08-22 02:08:32 | 00,171,032 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CT20XUT.DLL -- (CT20XUT.DLL [On_Demand | Running])

[2008-08-22 02:09:04 | 00,511,000 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTAC32K.SYS -- (ctac32k [On_Demand | Stopped])

[2008-08-22 02:09:14 | 00,527,768 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTAUD2K.SYS -- (ctaud2k [On_Demand | Running])

[2008-08-22 02:08:54 | 01,324,568 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL [On_Demand | Running])

[2008-08-22 02:08:42 | 00,072,728 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\CTHWIUT.DLL -- (CTHWIUT.DLL [On_Demand | Running])

[2008-08-22 02:09:28 | 00,014,360 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTPRXY2K.SYS -- (ctprxy2k [On_Demand | Running])

[2008-08-22 02:09:34 | 00,158,744 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\CTSFM2K.SYS -- (ctsfm2k [On_Demand | Running])

[2008-01-19 06:28:20 | 00,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dfsc.sys -- (DfsC [system | Running])

[2008-08-02 02:01:23 | 00,625,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgkrnl.sys -- (DXGKrnl [On_Demand | Running])

[2006-11-02 08:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])

[2008-01-19 08:42:11 | 00,143,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ecache.sys -- (Ecache [boot | Running])

[2006-11-02 10:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\System32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])

[2008-08-22 02:09:42 | 00,095,768 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\EMUPIA2K.SYS -- (emupia [On_Demand | Running])

[2008-01-19 06:28:01 | 00,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\exfat.sys -- (exfat [On_Demand | Stopped])

[2008-01-19 08:42:31 | 00,058,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\fileinfo.sys -- (FileInfo [boot | Running])

[2008-01-19 06:30:23 | 00,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\filetrace.sys -- (Filetrace [On_Demand | Stopped])

[2006-11-02 10:50:04 | 00,058,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\GAGP30KX.SYS -- (gagp30kx [On_Demand | Stopped])

[2007-12-25 14:43:06 | 00,014,656 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\gdrv.sys -- (gdrv [On_Demand | Stopped])

[2008-04-17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])

[2008-08-22 02:09:54 | 01,178,136 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\drivers\HA20X2K.SYS -- (ha20x2k [On_Demand | Running])

[2006-11-02 08:36:49 | 00,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService [On_Demand | Stopped])

[2008-01-19 05:30:49 | 00,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])

[2006-11-02 09:55:22 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidbth.sys -- (HidBth [Disabled | Stopped])

[2006-11-02 09:55:01 | 00,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidir.sys -- (HidIr [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\System32\drivers\HpCISSs.sys -- (HpCISSs [Disabled | Stopped])

[2006-11-02 10:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\System32\drivers\iaStorV.sys -- (iaStorV [Disabled | Stopped])

[2006-11-02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\System32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])

[2007-01-18 11:56:56 | 01,729,632 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService [On_Demand | Running])

[2006-11-02 09:42:03 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\IPMIDrv.sys -- (IPMIDRV [Disabled | Stopped])

[2008-01-19 08:42:35 | 00,181,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msiscsi.sys -- (iScsiPrt [On_Demand | Running])

[2006-11-02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])

[2006-11-02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])

[2008-01-19 06:49:17 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\kbdhid.sys -- (kbdhid [system | Running])

[2008-01-19 06:55:03 | 00,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\lltdio.sys -- (lltdio [Auto | Running])

[2006-11-02 10:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])

[2006-11-02 10:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])

[2006-11-02 10:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])

[2008-01-19 06:30:36 | 00,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\luafv.sys -- (luafv [Auto | Running])

[2006-11-02 10:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\System32\drivers\megasas.sys -- (megasas [Disabled | Stopped])

[2008-01-19 06:52:19 | 00,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\monitor.sys -- (monitor [On_Demand | Running])

[2006-11-02 10:50:16 | 00,078,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mpio.sys -- (mpio [Disabled | Stopped])

[2008-01-19 06:54:46 | 00,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mpsdrv.sys -- (mpsdrv [On_Demand | Running])

[2006-11-02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\System32\drivers\Mraid35x.sys -- (Mraid35x [Disabled | Stopped])

[2008-08-27 02:05:41 | 00,212,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys -- (mrxsmb10 [On_Demand | Running])

[2008-01-19 06:28:37 | 00,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys -- (mrxsmb20 [On_Demand | Running])

[2006-11-02 10:49:44 | 00,023,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msahci.sys -- (msahci [Disabled | Stopped])

[2006-11-02 10:50:17 | 00,080,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msdsm.sys -- (msdsm [Disabled | Stopped])

[2008-01-19 08:41:14 | 00,016,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msisadrv.sys -- (msisadrv [boot | Running])

[2008-01-19 08:42:29 | 00,163,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC [On_Demand | Stopped])

[2004-10-07 10:21:22 | 00,015,360 | ---- | M] (Maxtor Corp.) -- C:\Windows\System32\drivers\mxopswd.sys -- (MXOPSWD [On_Demand | Stopped])

[2008-05-20 03:07:31 | 00,148,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\nwifi.sys -- (NativeWifiP [On_Demand | Running])

[2006-11-02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\System32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])

[2008-01-19 06:55:50 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\nsiproxy.sys -- (nsiproxy [system | Running])

[2006-11-02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])

[2007-11-18 02:39:50 | 01,040,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD [On_Demand | Running])

[2008-10-07 13:33:00 | 07,380,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])

[2006-11-02 10:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])

[2007-01-05 21:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys -- (nvstor [boot | Running])

[2007-08-09 18:12:30 | 00,110,624 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32 [boot | Running])

[2006-11-02 10:50:40 | 00,106,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\NV_AGP.SYS -- (nv_agp [On_Demand | Stopped])

[2008-08-22 02:09:20 | 00,129,560 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\System32\drivers\CTOSS2K.SYS -- (ossrv [On_Demand | Running])

[2006-11-02 10:04:35 | 00,878,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\PEAuth.sys -- (PEAUTH [Auto | Running])

[2008-06-10 13:04:28 | 00,033,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\point32k.sys -- (Point32 [On_Demand | Running])

[2008-04-05 02:21:42 | 00,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\pacer.sys -- (PSched [system | Running])

[2006-11-02 10:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\System32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\System32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])

[2008-01-19 06:56:07 | 00,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\qwavedrv.sys -- (QWAVEdrv [On_Demand | Stopped])

[2008-01-19 06:56:43 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\rassstp.sys -- (RasSstp [On_Demand | Running])

[2008-01-19 07:01:09 | 00,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\RDPENCDD.sys -- (RDPENCDD [system | Running])

[2008-01-19 06:55:03 | 00,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\rspndr.sys -- (rspndr [Auto | Running])

[2007-04-03 12:57:42 | 00,083,336 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116bus.sys -- (s116bus [On_Demand | Stopped])

[2007-04-03 12:57:48 | 00,015,112 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mdfl.sys -- (s116mdfl [On_Demand | Stopped])

[2007-04-03 12:57:48 | 00,108,680 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mdm.sys -- (s116mdm [On_Demand | Stopped])

[2007-04-03 12:57:50 | 00,100,488 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116mgmt.sys -- (s116mgmt [On_Demand | Stopped])

[2007-04-03 12:57:52 | 00,023,176 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116nd5.sys -- (s116nd5 [On_Demand | Stopped])

[2007-04-03 12:57:52 | 00,098,696 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116obex.sys -- (s116obex [On_Demand | Stopped])

[2007-04-03 12:57:54 | 00,099,080 | ---- | M] (MCCI Corporation) -- C:\Windows\System32\drivers\s116unic.sys -- (s116unic [On_Demand | Stopped])

[2006-11-02 10:50:16 | 00,076,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sbp2port.sys -- (sbp2port [Disabled | Stopped])

[2006-11-02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])

[2008-01-19 06:49:16 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sermouse.sys -- (sermouse [Disabled | Stopped])

[2006-11-02 09:51:38 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffdisk.sys -- (sffdisk [Disabled | Stopped])

[2006-11-02 09:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffp_mmc.sys -- (sffp_mmc [On_Demand | Stopped])

[2006-11-02 09:51:40 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\sffp_sd.sys -- (sffp_sd [On_Demand | Stopped])

[2006-11-02 10:49:51 | 00,053,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\SISAGP.SYS -- (sisagp [On_Demand | Stopped])

[2006-11-02 10:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\System32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])

[2006-11-02 10:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\System32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])

[2008-01-19 06:55:27 | 00,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\smb.sys -- (Smb [system | Running])

[2008-01-19 08:41:30 | 00,021,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\spldr.sys -- (spldr [boot | Running])

[2008-01-19 06:29:15 | 00,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys -- (srv2 [On_Demand | Running])

[2008-01-19 06:29:12 | 00,098,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srvnet.sys -- (srvnet [On_Demand | Running])

[2006-11-02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])

[2006-11-02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])

[2006-11-02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\System32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])

[2008-01-19 06:56:07 | 00,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tcpipreg.sys -- (tcpipreg [Auto | Running])

[2008-01-19 06:55:58 | 00,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tdx.sys -- (tdx [system | Running])

[2008-01-19 07:01:15 | 00,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tssecsrv.sys -- (tssecsrv [On_Demand | Stopped])

[2008-01-19 06:55:41 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\TUNMP.SYS -- (tunmp [On_Demand | Running])

[2008-01-19 06:55:50 | 00,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tunnel.sys -- (tunnel [On_Demand | Running])

[2006-11-02 10:49:59 | 00,056,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UAGP35.SYS -- (uagp35 [On_Demand | Stopped])

[2006-11-02 10:50:04 | 00,058,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ULIAGPKX.SYS -- (uliagpkx [On_Demand | Stopped])

[2006-11-02 10:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\System32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])

[2006-11-02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\System32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])

[2006-11-02 10:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\System32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])

[2008-01-19 06:53:40 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\umbus.sys -- (umbus [On_Demand | Running])

[2007-07-11 09:40:18 | 00,012,416 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus [On_Demand | Stopped])

[2006-11-02 09:55:09 | 00,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbcir.sys -- (usbcir [Disabled | Stopped])

[2007-07-11 14:51:48 | 00,019,840 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag [On_Demand | Stopped])

[2007-07-11 09:45:00 | 00,021,632 | ---- | M] (LG Electronics Inc.) -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem [On_Demand | Stopped])

[2006-11-02 09:53:56 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\vgapnp.sys -- (vga [On_Demand | Stopped])

[2006-11-02 09:30:19 | 00,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\viac7.sys -- (ViaC7 [Disabled | Stopped])

[2006-11-02 10:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\System32\drivers\viaide.sys -- (viaide [Disabled | Stopped])

[2008-01-19 08:42:18 | 00,052,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\volmgr.sys -- (volmgr [boot | Running])

[2008-01-19 08:43:03 | 00,294,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\volmgrx.sys -- (volmgrx [boot | Running])

[2006-11-02 10:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\System32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])

[2006-11-02 09:52:52 | 00,020,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wacompen.sys -- (WacomPen [Disabled | Stopped])

[2006-11-02 10:49:38 | 00,019,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wd.sys -- (Wd [Disabled | Stopped])

[2008-01-19 08:43:27 | 00,503,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\Wdf01000.sys -- (Wdf01000 [boot | Running])

[2006-11-02 09:35:03 | 00,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\wmiacpi.sys -- (WmiAcpi [Disabled | Stopped])

[2008-01-19 06:56:49 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl [Disabled | Stopped])

 

========== (R ) Internet Explorer ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]

"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157

"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896

"Default_Secondary_Page_URL"=

"Extensions Off Page"=about:NoAdd-ons

"Local Page"=%SystemRoot%\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Security Risk Page"=about:SecurityRisk

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]

"Local Page"=C:\Windows\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

"StartPageCache"=

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Internet Explorer\Main]

"Local Page"=C:\Windows\system32\blank.htm

"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896

"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

"StartPageCache"=

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\System32\ieframe.dll (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

========== (O1) Hosts File ==========

 

HOSTS File = (942 bytes) - C:\Windows\System32\drivers\etc\Hosts

First 25 entries...

127.0.0.1 localhost

::1 localhost

127.0.0.1 www.mininova.org

127.0.0.1 www.mininova.com

127.0.0.1 www.thepiratebay.org

127.0.0.1 www.suprbay.org

127.0.0.1 mininova.org

127.0.0.1 mininova.com

127.0.0.1 thepiratebay.org

127.0.0.1 suprbay.org

 

========== (O2) BHO's ==========

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

{A057A204-BACC-4D26-9990-79A187E2698E} (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

 

========== (O3) Toolbars ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )

 

========== (O4) Run Keys ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)

"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)

"CTxfiHlp"=CTXFIHLP.EXE (Creative Technology Ltd)

"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)

"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)

"Launch LCDMon"="C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" (Logitech Inc.)

"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE (Logitech Inc.)

"NvCplDaemon"=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)

"NvMediaCenter"=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)

"RtHDVCpl"=RtHDVCpl.exe (Realtek Semiconductor)

"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)

"UpdReg"=C:\Windows\UpdReg.EXE (Creative Technology Ltd.)

"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)

"VolPanel"="C:\Program Files\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe" /r (Creative Technology Ltd)

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)

"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)

"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)

"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)

"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

 

========== (O6 & O7) Current Version Policies ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]

"ConsentPromptBehaviorAdmin"=2

"ConsentPromptBehaviorUser"=1

"EnableInstallerDetection"=1

"EnableLUA"=0

"EnableSecureUIAPaths"=1

"EnableVirtualization"=1

"PromptOnSecureDesktop"=1

"ValidateAdminCodeSignatures"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"scforceoption"=0

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

"FilterAdministratorToken"=0

"EnableUIADesktopToggle"=0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]

"CF_TEXT"=1

"CF_BITMAP"=2

"CF_OEMTEXT"=7

"CF_DIB"=8

"CF_PALETTE"=9

"CF_UNICODETEXT"=13

"CF_DIBV5"=17

 

========== (O8) IE Context Menu Extensions ==========

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

 

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\Software\Microsoft\Internet Explorer\MenuExt\]

E&xportera till Microsoft Excel: C:\Program\Microsoft Office\OFFICE11\EXCEL.EXE [2008-08-04 15:12:50 | 10,354,176 | ---- | M] (Microsoft Corporation)

 

========== (O9) IE Extensions ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Referensinformation -- %SystemDrive%\Program\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007-04-19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %SystemDrive%\Program\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)

 

========== (O12) Internet Explorer Plugins ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]

PluginsPage: "" = http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s

PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

 

========== (O13) Default Prefixes ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]

""=http://

 

========== (O15) Trusted Sites ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

49 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

49 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-21-2903967537-112725781-1445369304-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

44 domain(s) and sub-domain(s) not assigned to a zone.

 

========== (O16) DPF ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]

{0CCA191D-13A6-4E29-B746-314DEE697D83}: http://upload.facebook.com/controls/FacebookPhotoUploader5.cab -- Facebook Photo Uploader 5

{20A60F0D-9AFA-4515-A0FD-83BD84642501}: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab -- Checkers Class

{5C051655-FCD5-4969-9182-770EA5AA5565}: http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab -- Solitaire Showdown Class

{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{B8BE5E93-A60C-4D26-A2DC-220313175592}: http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab -- MSN Games - Installer

{C3F79A2B-B9B4-4A66-B012-3EE46475B072}: http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab -- MessengerStatsClient Class

{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab -- Java Plug-in 1.6.0_10

{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object

{D8089245-3211-40F6-819B-9E5E92CD61A2}: https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab -- FlashXControl Object

{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}: http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab -- Minesweeper Flags Class

 

========== (O17) DNS Name Servers ==========

 

{9FCDC34E-88DC-4FD7-82C9-5888F413F71C} (Servers: | Description: NVIDIA nForce Networking Controller)

{A63C7D22-A5B8-4549-A40F-A9CAA3C4D25A} (Servers: | Description: Sony Ericsson Device 116 USB Ethernet Emulation (NDIS 5))

{C0B32F68-1CA9-4ECB-863E-C1BF17E6EB37} (Servers: | Description: DWL-G520M Wireless 108G MIMO PCI Adapter)

 

========== (O20) AppInit_DLLs ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_Dlls"=avgrsstx.dll

>[2008-11-19 20:08:28 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

 

========== HKLM *SecurityProviders* ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]

"SecurityProviders"=credssp.dll

>[2008-01-19 08:33:59 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll

 

========== LSA *Security Packages* ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]

"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,

>[2008-01-19 08:36:42 | 00,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TSpkg.dll

 

========== Safeboot Options ==========

 

"AlternateShell"=cmd.exe

 

========== CDRom AutoRun Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]

"AutoRun" = 1

 

========== Autorun Files on Drives ==========

 

autoexec.bat [REM Dummy file for NTVDM | ]

[2006-09-18 22:43:36 | 00,000,024 | ---- | M] () -- C:\autoexec.bat -- [ NTFS ]

 

AUTORUN.INF [[autorun] | OPEN=SETUP.EXE | ICON=SC.ICO | ]

[1998-01-09 04:06:18 | 00,000,040 | R--- | M] () -- D:\AUTORUN.INF -- [ CDFS ]

 

========== MountPoints2 ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{355a527c-b3b0-11dc-8369-806e6f6e6963}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{355a527c-b3b0-11dc-8369-806e6f6e6963}\Shell\AutoRun\command]

""=D:\SETUP.EXE -- [1998-01-14 08:11:20 | 00,025,088 | R--- | M] ()

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7fee77-b2e8-11dc-b28d-806e6f6e6963}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e7fee77-b2e8-11dc-b28d-806e6f6e6963}\Shell\AutoRun\command]

""=D:\autorun.exe -- File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e005f95-e159-11dc-b59c-0013464cdcf9}\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e005f95-e159-11dc-b59c-0013464cdcf9}\Shell\AutoRun\command]

""=F:\LaunchU3.exe -- File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell]

""=AutoRun

 

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]

""=E:\LaunchU3.exe -- File not found

 

========== Files/Folders - Created Within 30 Days ==========

 

[1 C:\Windows\*.tmp files]

[2008-11-26 15:31:23 | 00,000,000 | ---D | C] -- C:\_OTMoveIt

[2008-11-26 15:30:00 | 00,349,696 | ---- | C] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTMoveIt3.exe

[2008-11-26 11:32:06 | 00,422,400 | ---- | C] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

[2008-11-26 02:15:51 | 00,001,097 | ---- | C] () -- C:\Users\Axel\Desktop\Spybot - Search & Destroy.lnk

[2008-11-26 01:38:09 | 00,001,882 | ---- | C] () -- C:\Users\Axel\Desktop\HijackThis.lnk

[2008-11-26 01:38:08 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2008-11-26 01:34:39 | 00,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro

[2008-11-26 01:34:30 | 00,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Hitman Pro 3.lnk

[2008-11-26 01:34:28 | 00,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3

[2008-11-26 01:34:27 | 00,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro 3

[2008-11-25 08:42:20 | 00,000,000 | ---D | C] -- C:\Program Files\iPod

[2008-11-25 08:42:19 | 00,000,000 | ---D | C] -- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

[2008-11-25 08:42:19 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes

[2008-11-25 08:25:40 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple

[2008-11-25 08:25:34 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime

[2008-11-25 08:25:17 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update

[2008-11-25 07:59:38 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Local\Temp

[2008-11-24 16:36:44 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up

[2008-11-22 20:32:08 | 00,259,571 | ---- | C] () -- C:\Users\Axel\Desktop\axle1.jpg

[2008-11-20 22:17:06 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$

[2008-11-19 20:08:31 | 00,001,689 | ---- | C] () -- C:\Users\Public\Desktop\AVG Free 8.0.lnk

[2008-11-19 20:08:28 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

[2008-11-19 20:08:27 | 30,355,197 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm

[2008-11-19 20:08:27 | 00,334,743 | ---- | C] () -- C:\Windows\System32\drivers\Avg\miniavi.avg

[2008-11-19 20:08:27 | 00,097,928 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys

[2008-11-19 20:08:27 | 00,050,685 | ---- | C] () -- C:\Windows\System32\drivers\Avg\microavi.avg

[2008-11-19 20:08:25 | 06,061,540 | ---- | C] () -- C:\Windows\System32\drivers\Avg\avi7.avg

[2008-11-19 20:08:25 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg

[2008-11-19 20:08:22 | 00,000,000 | ---D | C] -- C:\Program Files\AVG

[2008-11-19 20:08:21 | 00,000,000 | ---D | C] -- C:\ProgramData\avg8

[2008-11-17 23:05:33 | 00,000,000 | ---D | C] -- C:\ProgramData\NCH Software

[2008-11-17 23:05:15 | 00,000,000 | ---D | C] -- C:\Program Files\NCH Software

[2008-11-17 23:00:06 | 00,000,156 | ---- | C] () -- C:\Windows\Twunk001.MTX

[2008-11-17 23:00:06 | 00,000,002 | ---- | C] () -- C:\Windows\Twain001.Mtx

[2008-11-17 23:00:06 | 00,000,000 | ---- | C] () -- C:\Windows\Twunk002.MTX

[2008-11-14 14:08:44 | 00,133,905 | ---- | C] () -- C:\Users\Axel\Desktop\sensation.jpg

[2008-11-14 12:22:38 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll

[2008-11-14 12:22:37 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuaueng.dll

[2008-11-14 12:22:37 | 01,524,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll

[2008-11-14 12:22:37 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe

[2008-11-14 12:22:11 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll

[2008-11-14 12:22:11 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll

[2008-11-14 12:22:11 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll

[2008-11-14 12:22:07 | 00,162,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll

[2008-11-14 12:22:07 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe

[2008-11-13 21:34:59 | 00,000,000 | ---D | C] -- C:\Windows\Minidump

[2008-11-13 09:10:23 | 00,212,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys

[2008-11-13 09:10:22 | 01,191,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3.dll

[2008-11-13 09:10:19 | 01,334,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll

[2008-11-12 15:32:35 | 00,000,000 | ---D | C] -- C:\Windows\System32\AGEIA

[2008-11-12 15:32:35 | 00,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies

[2008-11-12 15:24:19 | 00,002,032 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Mouse.lnk

[2008-11-12 15:24:14 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft IntelliPoint

[2008-11-11 18:13:40 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Roaming\Personal

[2008-11-11 18:13:18 | 00,001,872 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk

[2008-11-11 18:13:17 | 00,000,000 | ---D | C] -- C:\Program Files\Personal

[2008-11-10 15:15:34 | 00,001,929 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk

[2008-11-07 13:51:03 | 00,000,000 | ---D | C] -- C:\Program Files\Domain Tools

[2008-10-30 01:32:42 | 00,000,000 | ---D | C] -- C:\Users\Axel\AppData\Local\Native Instruments

[2008-10-30 01:31:22 | 00,000,000 | ---D | C] -- C:\Users\Axel\Documents\Traktor3

[2008-10-30 01:31:09 | 00,000,000 | ---D | C] -- C:\Program Files\Native Instruments

[2008-10-29 11:37:18 | 00,443,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32spl.dll

[2008-10-29 11:33:52 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Faultrep.dll

[2008-10-29 11:33:52 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wersvc.dll

 

========== Files - Modified Within 30 Days ==========

 

[1 C:\Windows\*.tmp files]

[2008-11-26 15:30:22 | 00,349,696 | ---- | M] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTMoveIt3.exe

[2008-11-26 15:08:25 | 00,004,080 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2008-11-26 15:08:25 | 00,004,080 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2008-11-26 11:33:17 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Users\Axel\Desktop\OTViewIt.exe

[2008-11-26 11:11:33 | 00,000,544 | ---- | M] () -- C:\Users\Axel\Documents\Mina delade mappar.lnk

[2008-11-26 11:08:34 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2008-11-26 11:08:21 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2008-11-26 11:06:53 | 00,054,740 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:53 | 00,054,740 | ---- | M] () -- C:\Windows\System32\BMXState-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:53 | 00,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000001-00000000-00000007-00001102-00000005-0034415A}.rfx

[2008-11-26 11:06:41 | 03,877,323 | -H-- | M] () -- C:\Users\Axel\AppData\Local\IconCache.db

[2008-11-26 02:15:51 | 00,001,097 | ---- | M] () -- C:\Users\Axel\Desktop\Spybot - Search & Destroy.lnk

[2008-11-26 02:06:26 | 30,355,197 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm

[2008-11-26 01:39:46 | 00,001,882 | ---- | M] () -- C:\Users\Axel\Desktop\HijackThis.lnk

[2008-11-26 01:34:30 | 00,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Hitman Pro 3.lnk

[2008-11-25 14:08:45 | 00,236,032 | ---- | M] () -- C:\Users\Axel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2008-11-24 20:51:15 | 00,050,685 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg

[2008-11-23 21:50:57 | 01,513,870 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI

[2008-11-23 21:50:57 | 00,642,212 | ---- | M] () -- C:\Windows\System32\perfh01D.dat

[2008-11-23 21:50:57 | 00,628,782 | ---- | M] () -- C:\Windows\System32\perfh009.dat

[2008-11-23 21:50:57 | 00,133,192 | ---- | M] () -- C:\Windows\System32\perfc01D.dat

[2008-11-23 21:50:57 | 00,114,218 | ---- | M] () -- C:\Windows\System32\perfc009.dat

[2008-11-22 20:32:08 | 00,259,571 | ---- | M] () -- C:\Users\Axel\Desktop\axle1.jpg

[2008-11-20 01:57:41 | 00,334,743 | ---- | M] () -- C:\Windows\System32\drivers\Avg\miniavi.avg

[2008-11-19 20:08:31 | 00,001,689 | ---- | M] () -- C:\Users\Public\Desktop\AVG Free 8.0.lnk

[2008-11-19 20:08:28 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll

[2008-11-19 20:08:27 | 06,061,540 | ---- | M] () -- C:\Windows\System32\drivers\Avg\avi7.avg

[2008-11-19 20:08:27 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys

[2008-11-19 20:08:27 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys

[2008-11-18 00:06:59 | 00,000,316 | ---- | M] () -- C:\Users\Axel\Documents\Setting.ini

[2008-11-17 23:00:06 | 00,000,156 | ---- | M] () -- C:\Windows\Twunk001.MTX

[2008-11-17 23:00:06 | 00,000,002 | ---- | M] () -- C:\Windows\Twain001.Mtx

[2008-11-17 23:00:06 | 00,000,000 | ---- | M] () -- C:\Windows\Twunk002.MTX

[2008-11-14 14:08:46 | 00,133,905 | ---- | M] () -- C:\Users\Axel\Desktop\sensation.jpg

[2008-11-12 15:24:19 | 00,002,032 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Mouse.lnk

[2008-11-11 18:13:18 | 00,001,872 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk

[2008-11-10 15:15:34 | 00,001,929 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk

[2008-11-04 01:10:25 | 17,318,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe

< End of report >

[/log]

 

Link to comment
Share on other sites

On topic:

jag märker inte av något nu. Ska ta en scan med alla program jag har (spy bot s/d, adaware, avg, ccleaner, osv).

 

Tror du att man vågar logga in på online depåer nu? Väldigt rädd för detta efter att jag hört om trojaner som snott inloggningar och rensat konton.

 

Off-topic:

Jag måste bara fråga, hur har du lärt dig att analysera hijackthis-loggar osv, Jobbar du med antivirus eller?

 

Tack för all hjälp också, det är priceless att ha kunniga människor som dig, som kan hjälpa till när man har fått problem med virus.

 

Mvh Axel

 

Link to comment
Share on other sites

Ja, det ska inte vara något problem. Men byt gärna lösenord för säkerhets skull.

 

Här är några program som jag rekommenderar för att minska risken att drabbas http://ceblstockholm.googlepages.com/home och de kan vara bra även för att kolla upp datorn nu.

 

Jag har lärt mig rensa datorer på fritiden genom att följa hur andra gör och läsa artiklar om det. :)

 

Link to comment
Share on other sites

Idag skulle jag gå in på piratebay och ladda ner en snowboardfilm, ponytale (freeware). När jag försöker gå in där får jag istället för hemsidan upp en länkad bild där det står IIS7. Först tror jag att sidan är nere tillfälligt. Jag ber en bekant att testa sidan och han kommer in direkt, jag testar igen men samma problem. Testar då om sidan mininova.org fungerar, och det är samma sak med den. Därför misstänker jag att jag fortfarande har någon typ av virus på datorn som begränsar tillgängligheten till vissa hemsidor.

 

Jag skaffade zonealarm igår, och när jag går in på piratebay eller mininova får jag en anslutningsvarning att "IIS Worker Process is trying to access the trusted zone" application: w3wp.exe.

När jag nekar den tillgång kommer det upp "HTTP ERROR 404.0 - not found" på sidan, om jag tillåter den kommer IIS7 bilden upp. Har scannat mappen med avg, spybot s/d och malwarebytes, även laddat upp w3wp.exe till virustotal utan resultat.

 

Har du något tips?

 

Link to comment
Share on other sites

w3wp.exe är en Windowsfil.

 

Att du inte kan komma till de webbsidorna beror på att datorns hosts-fil är spärrad för det. Jag såg det i någon logg men antog att det var för att skydda datorn. Se http://ceblstockholm.googlepages.com/home avsnittet om Hosts-fil för att installera en hosts-fil som skyddar datorn men ändå ger tillgång till mininova och piratebay.

 

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.



×
×
  • Create New...