Just nu i M3-nätverket
Gå till innehåll

IE7 Install Error Code 0x3F5


Sabelström

Rekommendera Poster

Har en dator med XP SP3 installerat på, men fick aldrig in IE7, får felmeddelandet 0x3F5.

 

Har läst på många forum om folk som har samma problem, men som inte fattar någon lösning, har ar kollat på microsofts hemsida o prövat det de har att säga.

 

Vissa saker jag kör får jag ju upp lite medelande om så skulle ju vara skönt om man hade någon att bolla med på svenska, ifall det är språket som gör att jag inte fixar det. Här kommer senaste loggen

 

 

[log]

================================================================================

0.234: 2009/01/08 21:13:44.031 (local)

0.234: c:\c250c3711bead4f83d10c9\update\update.exe (version 6.2.29.0)

0.250: Failed To Enable SE_SHUTDOWN_PRIVILEGE

0.265: Hotfix started with following command line: /quiet /norestart /er /log:C:\WINDOWS

0.265: IECUSTOM: Scanning for proper registry permissions...

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}\ProxyStubClsid

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}\ProxyStubClsid32

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}\TypeLib

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}\TypeLib

0.594: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

0.797: IECUSTOM: Scanning for proper registry permissions...

0.984: IECUSTOM: Scanning for proper registry permissions...

1.203: IECUSTOM: Unwriteable key HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

1.250: IECUSTOM: Backing up registry permissions...

1.250: IECUSTOM: Finished backing up registry permissions...

1.250: IECUSTOM: Setting new registry permissions...

1.250: IECUSTOM: Unable to clear DACLs HKCR\Interface\{34A715A0-6587-11D0-924A-0020AFC7AC4D}

1.250: IECUSTOM: Finished setting new registry permissions...

1.250: IECUSTOM: An error occured verifying registry permissions. ERROR: 0x80070534

1.250: DoInstallation: CustomizeCall Failed: 0x3f5

1.250: IECUSTOM: Restoring registry permissions...

1.250: IECUSTOM: Finished restoring registry permissions...

1.265: Registernyckeln för konfigurationen kan inte skrivas.

1.265: Installationen av Internet Explorer 7 slutfördes inte.

1.265: Update.exe extended error code = 0x3f5

[/log]

 

Hade virus för en vecka sen kan ju vara något sånt kanske, Hade något som hette W32.Spybot.Worm, som verkar varit inne i registret o härjat,

en hette Infostealer.Gamepass låg i en skärmsläckarde jag packade upp.

Sen klagade norton på de filer som hette dotnetfx.exe, netfxupdate.exe, qttask.exe, pythonservice.exe, sgvhost.exe, asussetup.exe, autorun.exe, nvuninst.exe pythonw.exe, re.exe, nwiz.exe

 

 

 

[inlägget ändrat 2009-01-13 09:25:27 av Sabelström]

Länk till kommentar
Dela på andra webbplatser

Loggen visar på problem med registret, troligen problem med att ha tillräckliga rättigheter att skriva där.

 

Sen klagade norton på de filer som hette dotnetfx.exe, netfxupdate.exe, qttask.exe, pythonservice.exe, sgvhost.exe, asussetup.exe, autorun.exe, nvuninst.exe pythonw.exe, re.exe, nwiz.exe
Vad har hänt med dessa filer? För en del ser ju ut som normala filer och en del som skadliga.

Har du kollat upp datorn med något annat säkerhetsprogram?

 

Länk till kommentar
Dela på andra webbplatser

Magnus Ralsgård

Kolla Microsofts lösning:

http://support.microsoft.com/kb/917925

Metod D: Återställ behörigheter för oskrivbara registerundernycklar

 

OBS!

Om du har svensk version av XP så måste du ändra gruppnamnen

Sedan kan det vara lite klurit med åäö i notepad, Jag använde wordpad och valde att spara filen som Text dokument - MSDos format

 

Administrators - Administratörer

Users - Användare

 

Lycka till

Magnus

 

 

Länk till kommentar
Dela på andra webbplatser

Vad har hänt med dessa filer? För en del ser ju ut som normala filer och en del som skadliga.

Har du kollat upp datorn med något annat säkerhetsprogram?

 

Om jag visste hur o var norton lägger upp loggar så skulle jag kunna lägga upp den.

 

Har inte kört med något annat förutom spybot, SUPERAntiSpyware och Malwarebytes' Anti-Malware.

 

Kanske skulle pröva med något annat virus program med.

 

På filerna står det: Affected Area: Windows Startup Settings, Recommended Actin: No Action Requierd, Detta står på filer som är nämda tidigare.

 

Trojaner, downloader och HSloader står det blocked på.

 

På alla virus o vissa trojaner o filen dotnetfx.exe står det removed på.

 

O sen står det protected på massa firewalls rules om program som updaterar sig mot nätet och som använs över nätet.

 

Länk till kommentar
Dela på andra webbplatser

Jag vet inte hur man hittar loggar i Norton heller.

 

Har Spybot, SUPERAntiSpyware eller Anti-Malware hittat något?

 

Du kan ju pröva med någon online-skanning mot virus:

http://usa.kaspersky.com/products_services/free-virus-scanner.php

 

Men det är ju möjligt att det inte finns något kvar i datorn efter att Norton har varit framme, men det är ju svårt att veta.

 

Länk till kommentar
Dela på andra webbplatser

Kolla Microsofts lösning:

http://support.microsoft.com/kb/917925

Metod D: Återställ behörigheter för oskrivbara registerundernycklar

 

Har prövat alla metoder, ingen funkar.

 

Men när jag kör D så hinner jag snappa upp detta: Last Failed: HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAI : 2 Det går inte att

LAst Failed: HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Windwos NT\CurrentVersin\Per sen får det inte plats mer i fönstret o hjälper ej att förstora det.

 

Och det slutar med att det står Failed 5.

 

Om det finns en log till det skulle man ju kunna se vilka fem det är.

 

Länk till kommentar
Dela på andra webbplatser

Har Spybot, SUPERAntiSpyware eller Anti-Malware hittat något?

 

Det ända som hittat något är Superantispyware, men det är ju det vanliga: Adware.Tracking Cookie och det mindre vanliga Adware.Vundo Variant.

 

Det senaste dom hänt i spybots teetimer är:

[log]2009-01-10 16:26:39 Denied (based on user blacklist) value "Video Driver" (new data: "sgvhost.exe") added in System Startup global entry!

2009-01-10 17:25:39 Allowed (based on user decision) value "MSConfig" (new data: "") deleted in System Startup global entry!

2009-01-11 11:04:32 Allowed (based on user decision) value "scrnsave.exe" (new data: "C:\WINDOWS\system32\THE_LO~1.SCR") changed in Desktop settings!

2009-01-11 11:07:07 Allowed (based on user decision) value "scrnsave.exe" (new data: "C:\WINDOWS\Star_War.scr") changed in Desktop settings!

2009-01-11 11:08:15 Allowed (based on user decision) value "scrnsave.exe" (new data: "C:\WINDOWS\system32\THE_LO~1.SCR") changed in Desktop settings!

2009-01-11 12:57:00 Allowed (based on user whitelist) value "MSConfig" (new data: "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto") added in System Startup global entry!

2009-01-11 12:57:01 Allowed (based on user whitelist) value "MSConfig" (new data: "") deleted in System Startup global entry!

2009-01-11 22:26:00 Allowed (based on user decision) value "SpybotSD TeaTimer" (new data: "") deleted in System Startup user entry!

2009-01-11 22:26:02 Allowed (based on user decision) value "{53707962-6F74-2D53-2644-206D7942484F}" (new data: "") deleted in Browser Helper Object!

2009-01-12 09:42:53 Denied (based on user decision) value "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}" (new data: "") deleted in Internet Explorer searches!

2009-01-12 09:43:17 Allowed (based on user decision) value "!SASWinLogon" (new data: "") deleted in Winlogon Notifiers!

2009-01-12 09:43:25 Allowed (based on user decision) value "SUPERAntiSpyware" (new data: "C:\DOCUME~1\HANNAS~1\LOKALA~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware") changed in System Startup user entry!

2009-01-12 09:56:15 Allowed (based on user decision) value "SUPERAntiSpyware" (new data: "C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe") changed in System Startup user entry!

2009-01-12 11:25:17 Allowed (based on user decision) value "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}" (new data: "") deleted in Internet Explorer searches!

2009-01-13 08:12:55 Allowed (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\HANNAS~1\LOKALA~1\Temp\IXP000.TMP\"") added in System Startup global entry!

2009-01-13 08:13:57 Allowed (based on user decision) value "wextract_cleanup0" (new data: "") deleted in System Startup global entry!

2009-01-13 08:21:21 Denied (based on user decision) value "ctfmon.exe" (new data: "C:\WINDOWS\system32\ctfmon.exe") added in System Startup user entry!

2009-01-13 09:13:27 Allowed (based on user whitelist) value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\HANNAS~1\LOKALA~1\Temp\IXP000.TMP\"") added in System Startup global entry!

2009-01-13 12:16:31 Allowed (based on user whitelist) value "wextract_cleanup0" (new data: "") deleted in System Startup global entry!

2009-01-14 08:03:23 Allowed (based on lassh blacklist) value "{EFA24E64-B078-11D0-89E4-00C04FC9E26E}" (new data: "") added in User-specific browser toolbar!

2009-01-14 08:05:57 Allowed (based on user decision) value "CleanSetup" (new data: "cmd /C rmdir /S /Q "C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Temp\nro.tmp\"") added in System Startup global entry!

2009-01-14 08:07:43 Allowed (based on user decision) value "CloneCDTray" (new data: ""C:\Program\SlySoft\CloneCD\CloneCDTray.exe" /s") added in System Startup global entry!

2009-01-14 23:33:55 Allowed (based on user decision) value "CleanSetup" (new data: "") deleted in System Startup global entry!

2009-01-14 23:37:03 Allowed (based on user decision) value "CloneCDTray" (new data: "") deleted in System Startup global entry!

2009-01-15 10:15:18 Allowed (based on user whitelist) value "CleanSetup" (new data: "cmd /C rmdir /S /Q "C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Temp\nro.tmp\"") added in System Startup global entry!

2009-01-15 10:15:27 Denied (based on user decision) value "{32099AAC-C132-4136-9E9A-4E364A424E17}" (new data: "DAEMON Tools Toolbar") added in Global browser toolbar!

2009-01-15 10:15:48 Denied (based on user decision) value "{32099AAC-C132-4136-9E9A-4E364A424E17}" (new data: "hex:AC,9A,09,32,32,C1,36,41,9E,9A,4E,36,4A,42,4E,17") added in User-specific browser toolbar!

2009-01-16 00:05:20 Allowed (based on user decision) value "Malwarebytes' Anti-Malware" (new data: "C:\Program\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent") added in System Startup global entry!

[/log]

 

Fast innan det är det 2009-01-10 16:26:34 Denied (based on user blacklist) value "Video Driver" (new data: "sgvhost.exe") added in System Startup global entry! varannan sekund i loggen.

 

Länk till kommentar
Dela på andra webbplatser

Ahha, Vundo, det kan ställa till med mycket.

 

2009-01-11 11:07:07 Allowed (based on user decision) value "scrnsave.exe" (new data: "C:\WINDOWS\Star_War.scr") changed in Desktop settings!

Där ser du ut att ha godkänt Star_War.scr som ny skärmsläckare, du kan läsa om det här:

http://www.siteadvisor.com/sites/softpedia.com/downloads/11808015/

Det ser ut som att det är något du ska avinstallera.

 

Först så vill jag få en överblick med programmet HijackThis. Ladda ner från en av länkarna:

http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html

Installera, starta och välj "Do a system scan and save a logfile", kopiera loggen som kommer upp (inget annat).

 

I ditt svar bifogar du HijackThis-loggen på detta sätt:

Tryck på LOG-knappen i Besvara-fönstret

Klistra in loggen

Tryck igen på LOG-knappen

 

Länk till kommentar
Dela på andra webbplatser

Tror jag fick bort det, för har reagerat på det med, tror även något annat program reagerade på skärmsläckaren när jag installerade den, men lägger upp en log ändå.

 

[log]

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:09:26, on 2009-01-16

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

C:\Program\Windows Live\Messenger\MsnMsgr.Exe

C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program\Skype\Phone\Skype.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Spybot - Search & Destroy\TeaTimer.exe

C:\Program\Personal\bin\Personal.exe

C:\Program\Skype\Plugin Manager\skypePM.exe

C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

C:\Program\Mozilla Firefox\firefox.exe

C:\Program\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar

R3 - Default URLSearchHook is missing

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [osCheck] "C:\Program\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [Video Driver] sgvhost.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\RunServices: [Video Driver] sgvhost.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [skype] "C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231442855500

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\VAScanner\comHost.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE

O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

 

--

End of file - 6318 bytes

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Även om man tar bort skärmsläckaren så är det ju inte säkert att avinstallationen tar bort allt skadligt som kom med.

 

Ladda ner OTViewIt till Skrivbordet:

http://oldtimer.geekstogo.com/OTViewIt.exe

 

Stäng alla program.

Kör OTViewIt (i Vista högerklicka och Kör som administratör).

Bocka för Scan all Users.

Välj 30 dagar för File Age om det inte redan är valt.

Tryck på Run Scan och låt programmet köra ostört.

 

När det är klart så skapas två loggfiler på Skrivbordet, OTViewIt.txt och Extras.txt, klistra in båda två i ditt svar (kom ihåg LOG-knappen).

 

Länk till kommentar
Dela på andra webbplatser

Ok, men hur stänger man av norton?, om jag visste vad processen hette kunde jag ju stänga av den.

 

Kaspersky hittade inget i alla fall.

 

[inlägget ändrat 2009-01-17 10:03:15 av Sabelström]

Länk till kommentar
Dela på andra webbplatser

Får upp detta felmedelande när jag försöker lägga upp loggarna.

 

Request object error 'ASP 0104 : 80004005'

 

Operation not Allowed

 

/Globalincludes/medlem_commerce/ErrorLog/InsertErrorIntoDB.asp, line 17

 

Länk till kommentar
Dela på andra webbplatser

Här är den lilla loggen:

 

[log]

OTViewIt Extras logfile created on: 2009-01-17 09:34:38 - Run 2

OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Hanna Smilla Leon\Skrivbord

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

2,00 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 74,89% Memory free

3,85 Gb Paging File | 3,53 Gb Available in Paging File | 91,68% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program

Drive C: | 48,83 Gb Total Space | 32,89 Gb Free Space | 67,37% Space Free | Partition Type: NTFS

Drive D: | 137,47 Gb Total Space | 41,43 Gb Free Space | 30,14% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HANNA

Current User Name: Hanna Smilla Leon

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Whitelist: On

File Age = 30 Days

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled"=1

"AntiVirusDisableNotify"=0

"FirewallDisableNotify"=0

"UpdatesDisableNotify"=0

"AntiVirusOverride"=0

"FirewallOverride"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

"DisableMonitoring"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

"DisableMonitoring"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

"EnableFirewall"=0

"DoNotAllowExceptions"=0

"DisableNotifications"=0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[2008-04-14 17:05:18 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019

[2008-04-13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[2007-10-18 11:35:08 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

[2007-10-02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[2008-11-20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program\iTunes\iTunes.exe:*:Enabled:iTunes

[2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour

[2008-04-13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[2007-10-18 11:35:08 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

[2009-01-09 15:27:18 | 00,270,128 | ---- | M] (BitTorrent, Inc.) -- C:\Program\uTorrent\uTorrent.exe:*:Enabled:µTorrent

[2008-04-14 17:05:18 | 00,141,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019

[2007-10-02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\livecall.exe:*:Disabled:Windows Live Messenger (Phone)

[2008-11-07 14:31:38 | 21,633,320 | R--- | M] (Skype Technologies S.A.) -- C:\Program\Skype\Phone\Skype.exe:*:Enabled:Skype

 

========== (O10) Winsock2 Catalogs ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]

NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program\Bonjour\mdnsNSP.dll (Apple Inc.)

 

========== (O18) Protocol Handlers ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

ipp: [HKLM - No CLSID value]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers

[2005-09-20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-10-18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

msdaipp: [HKLM - No CLSID value]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers

[2005-09-20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers

[2005-09-20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2000-04-19 18:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-10-18 11:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2007-05-10 13:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]

[2008-07-23 14:11:34 | 01,942,864 | R--- | M] (Skype Technologies) C:\Program\Delade filer\Skype\Skype4COM.dll (skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} (HKLM) [iEProtocolHandler Class])

 

========== (O18) Protocol Filters ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters

[2007-04-19 13:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program\Delade filer\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}"=Adobe AIR

"{07287123-B8AC-41CE-8346-3D777245C35B}"=Bonjour

"{0EF65F3C-18D6-42C6-A0F2-F7795B964731}"=SymNet

"{17014473-0098-4DF0-827D-7D582697C78C}"=Microsoft .NET Framework 2.0 Language Pack - SVE

"{1A2A15C2-6780-49c1-B296-503230E9DE00}"=The Sims™ 2 Herrgård och trädgård Prylpaket

"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}"=Cool & Quiet

"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}"=Google Earth

"{20503DFE-E5B2-491E-B2C5-8BCB5BF5B9E9}"=Windows Live Messenger

"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java 6 Update 11

"{2DD388FF-6422-43C9-86A1-C7A99C83E946}"=ASUS nVidia Driver

"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}"=Component Framework

"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes

"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java 6 Update 7

"{350C941d-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP

"{3921A67A-5AB1-4E48-9444-C71814CF3027}"=VCRedistSetup

"{4817189D-1785-4627-A33C-39FD90919300}"=The Sims™ 2 Djurliv

"{4E3AD5BB-1CD4-4F9A-9C87-34FA8E7DDFB7}"=Hitta Nemo

"{55A6283C-638A-4EE0-B491-51118554BDA2}"=Norton Confidential Core

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}"=neroxml

"{587178E7-B1DF-494E-9838-FA4DD36E873C}"=ASUSUpdate

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}"=Skype™ 3.8

"{62120008-8E1E-4807-860D-A8B48F8552DB}"=Norton Protection Center

"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}"=The Sims™ 2 Kök & badrum Heminredning Prylpaket

"{65483F1B-BE75-4FD7-B970-E1F36C76ED0F}"=Halvan Här kommer bärgningsbilen

"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update

"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}"=The Sims 2

"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable

"{77772678-817F-4401-9301-ED1D01A8DA56}"=SPBBC 32bit

"{77DCDCE3-2DED-62F3-8154-05E745472D07}"=Acrobat.com

"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}"=Norton AntiVirus

"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}"=The Sims 2 Arbetsliv

"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}"=The Sims™ 2 H&M® Fashion Prylpaket

"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}"=The Sims™ 2 Fritid

"{9011041D-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003

"{924EB80F-C2BB-4B9F-8412-88BBA937393F}"=MobileMe Control Panel

"{992A2DB1-4ABC-4738-BD71-045C5FFE00D1}"=Microsoft .NET Framework 1.1 Swedish Language Pack

"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}"=The Sims™ 2 Glitter & Glamour Prylpaket

"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}"=ImagXpress

"{AC54E544-3E42-443C-A91D-A00A6974C592}"=NVIDIA PhysX v8.10.13

"{AC76BA86-7AD7-1033-7B44-A90000000001}"=Adobe Reader 9

"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}"=ccCommon

"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy

"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1

"{B6F5B704-06D3-4687-90F3-6195304AD755}"=The Sims™ 2 Livet i lägenhet

"{C151CE54-E7EA-4804-854B-F515368B0798}"=AMD Processor Driver

"{C1C185CA-C531-49F5-A6FA-B838405A049D}"=Norton Internet Security

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1

"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}"=SUPERAntiSpyware Free Edition

"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}"=Windows Resource Kit Tools - SubInAcl.exe

"{D642E38E-0D24-486C-9A2D-E316DD696F4B}"=Microsoft XML Parser

"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}"=Symantec Real Time Storage Protection Component

"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}"=The Sims™ 2 Året runt

"{E17F76BE-50E9-4E7C-ADF6-6D8F44A9C6F3}"=Windows Live installer

"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}"=Norton AntiVirus Help

"{E80F62FF-5D3C-4A19-8409-9721F2928206}"=LiveUpdate (Symantec Corporation)

"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}"=The Sims™ 2 Fest & bröllop! Prylpaket

"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support

"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}"=AppCore

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver

"{F248ADFA-64E0-4b03-8A83-059078BED6A0}"=The Sims™ 2 Jorden runt

"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime

"{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}"=Windows Resource Kit Tools

"Adobe AIR"=Adobe AIR

"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin

"Adobe Shockwave Player"=Adobe Shockwave Player 11

"Barbie som Rapunzel"=Barbie som Rapunzel

"CEP - Colour Enable Packages_is1"=CEP - Color Enable Package

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"=Acrobat.com

"DAEMON Tools Toolbar"=DAEMON Tools Toolbar

"EPSON Printer and Utilities"=EPSON Skrivarprogramvara

"EVEREST Ultimate Edition_is1"=EVEREST Ultimate Edition v4.60

"GameWiz32"=GameWiz32

"HijackThis"=HijackThis 2.0.2

"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs

"InstallShield_{4E3AD5BB-1CD4-4F9A-9C87-34FA8E7DDFB7}"=Hitta Nemo

"Julens hjältar"=Julens hjältar

"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware

"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1

"Microsoft .NET Framework 2.0 Language Pack - SVE"=Microsoft .NET Framework 2.0 Language Pack - SVE

"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)

"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP

"MTK3"=Mitt Djursjukhus i Australien

"Nero - Burning Rom!UninstallKey"=Ahead Nero 6 Demo

"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs

"NVIDIA Drivers"=NVIDIA Drivers

"Personal"=Personal 4.9.3

"Pettson1"=Pettson1

"Pettson3"=Pettson3

"PsuedoLiveUpdate"=LiveUpdate (Symantec Corporation)

"Registry Easy_is1"=Registry Easy v4.7

"Star Wars "=Star Wars

"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}"=Norton Internet Security (Symantec Corporation)

"The Lost Watch 3D Screensaver_is1"=The Lost Watch 3D Screensaver 1.0

"Windows Media Format Runtime"=Windows Media Format 11 runtime

"Windows Media Player"=Windows Media Player 11

"Windows XP Service Pack"=Windows XP Service Pack 3

"WinRAR archiver"=WinRAR archiver

"Vintergatan - Fifunernas återkomst"=Vintergatan - Fifunernas återkomst

"Vintergatan - Rädda Jorden!"=Vintergatan - Rädda Jorden!

"VLC media player"=VideoLAN VLC media player 0.8.6i

"WMFDist11"=Windows Media Format 11 runtime

"wmp11"=Windows Media Player 11

"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent"=µTorrent

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent"=µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 2009-01-12 06:24:35 | Computer Name = HANNA | Source = Spybot - Search & Destroy | ID = 0

Description =

 

Error - 2009-01-12 06:28:40 | Computer Name = HANNA | Source = Application Hang | ID = 1002

Description = Stoppat program firefox.exe, version 1.9.0.3257, stoppad modul hungapp,

version 0.0.0.0, stoppad adress 0x00000000.

 

Error - 2009-01-12 06:28:40 | Computer Name = HANNA | Source = Application Hang | ID = 1002

Description = Stoppat program firefox.exe, version 1.9.0.3257, stoppad modul hungapp,

version 0.0.0.0, stoppad adress 0x00000000.

 

Error - 2009-01-12 06:30:09 | Computer Name = HANNA | Source = Application Hang | ID = 1001

Description = Fel-bucket 1037228563.

 

Error - 2009-01-12 06:30:34 | Computer Name = HANNA | Source = Application Hang | ID = 1001

Description = Fel-bucket 1037228563.

 

Error - 2009-01-13 02:57:02 | Computer Name = HANNA | Source = Internet Explorer 7 Disk | ID = 921877

Description =

 

Error - 2009-01-13 03:36:01 | Computer Name = HANNA | Source = Internet Explorer 7 Disk | ID = 921877

Description =

 

Error - 2009-01-13 03:45:59 | Computer Name = HANNA | Source = Internet Explorer 7 Disk | ID = 921877

Description =

 

Error - 2009-01-13 04:10:31 | Computer Name = HANNA | Source = Internet Explorer 7 Disk | ID = 921877

Description =

 

Error - 2009-01-17 04:34:14 | Computer Name = HANNA | Source = Application Hang | ID = 1002

Description = Stoppat program OTViewIt.exe, version 1.0.21.0, stoppad modul hungapp,

version 0.0.0.0, stoppad adress 0x00000000.

 

[ System Events ]

Error - 2009-01-13 03:38:40 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1084 vid försök att starta tjänsten StiSvc med argumenten

för att köra servern: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

 

Error - 2009-01-13 03:38:46 | Computer Name = HANNA | Source = Service Control Manager | ID = 7026

Description = Följande start- eller systemstartdrivrutin(er) avbröts på grund av

fel under start: AmdK8 AsIO eeCtrl Fips SASDIFSV SASKUTIL SPBBCDrv SRTSP SRTSPX SYMTDI

 

Error - 2009-01-13 03:39:20 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1084 vid försök att starta tjänsten StiSvc med argumenten

för att köra servern: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

 

Error - 2009-01-13 03:44:18 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1084 vid försök att starta tjänsten wuauserv med

argumenten för att köra servern: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

 

Error - 2009-01-13 03:47:03 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1084 vid försök att starta tjänsten EventSystem med

argumenten för att köra servern: {1BE1F766-5536-11D1-B726-00C04FB926AF}

 

Error - 2009-01-13 04:10:39 | Computer Name = HANNA | Source = Windows Update Agent | ID = 20

Description = Installationsfel: Det gick inte att installera följande uppdatering

på grund av fel 0x80070643: Windows Internet Explorer 7 för Windows XP.

 

Error - 2009-01-14 09:17:02 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1058 vid försök att starta tjänsten usnjsvc med argumenten

för att köra servern: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

 

Error - 2009-01-14 09:17:13 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1058 vid försök att starta tjänsten usnjsvc med argumenten

för att köra servern: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

 

Error - 2009-01-14 09:17:23 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1058 vid försök att starta tjänsten usnjsvc med argumenten

för att köra servern: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

 

Error - 2009-01-14 09:17:34 | Computer Name = HANNA | Source = DCOM | ID = 10005

Description = DCOM fick felet %1058 vid försök att starta tjänsten usnjsvc med argumenten

för att köra servern: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

 

 

< End of report >

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Här är del 1 av den stora loggen:

 

[log]

OTViewIt logfile created on: 2009-01-17 09:34:38 - Run 2

OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Hanna Smilla Leon\Skrivbord

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

 

2,00 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 74,89% Memory free

3,85 Gb Paging File | 3,53 Gb Available in Paging File | 91,68% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program

Drive C: | 48,83 Gb Total Space | 32,89 Gb Free Space | 67,37% Space Free | Partition Type: NTFS

Drive D: | 137,47 Gb Total Space | 41,43 Gb Free Space | 30,14% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: HANNA

Current User Name: Hanna Smilla Leon

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Whitelist: On

File Age = 30 Days

 

========== Processes ==========

 

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

[2008-02-09 18:06:00 | 00,238,968 | ---- | M] (Symantec Corporation) -- C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe

[2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe

[2009-01-08 21:01:34 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program\Java\jre6\bin\jqs.exe

[2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE

[2008-08-01 14:48:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe

[2008-04-14 17:05:18 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE

[2009-01-08 18:26:12 | 01,245,064 | ---- | M] () -- C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe

[2009-01-17 09:32:15 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\OTViewIt.exe

 

========== (O23) Win32 Services ==========

 

[2008-11-07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])

[2007-10-24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

[2008-02-09 18:06:00 | 00,238,968 | ---- | M] (Symantec Corporation) -- C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running])

[2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE -- (ccEvtMgr [Auto | Running])

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE -- (ccSetMgr [Auto | Running])

[2007-10-24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE -- (CLTNetCnService [Auto | Running])

[2007-08-22 02:21:00 | 00,055,640 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\VAScanner\comHost.exe -- (comHost [On_Demand | Stopped])

[2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

[2008-11-20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])

[2009-01-08 21:01:34 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

[2008-09-05 11:52:32 | 03,220,856 | ---- | M] (Symantec Corporation) -- C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate [On_Demand | Stopped])

[2008-10-17 15:52:10 | 00,149,352 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\CCSVCHST.EXE -- (LiveUpdate Notice [Auto | Running])

[2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])

[2008-08-01 14:48:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])

[2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program\Delade filer\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

[2009-01-08 18:26:12 | 01,245,064 | ---- | M] () -- C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [On_Demand | Running])

[2007-10-18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [Disabled | Stopped])

[2007-10-25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])

[2006-11-15 10:49:34 | 00,912,384 | ---- | M] (Microsoft Corporation) -- C:\Program\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Disabled | Stopped])

 

========== Driver Services ==========

 

[2006-07-01 23:21:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8 [system | Running])

[2007-12-17 17:14:00 | 00,012,400 | ---- | M] () -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO [system | Running])

[2008-07-30 17:42:12 | 00,023,888 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon [On_Demand | Stopped])

[2007-08-08 18:39:00 | 00,036,056 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\CO_Mon.sys -- (CO_Mon [Auto | Running])

[2008-12-17 08:43:48 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [system | Running])

[2008-12-17 08:43:48 | 00,099,376 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])

[2008-04-17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])

[2008-04-13 17:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus [On_Demand | Running])

[2008-10-31 11:38:08 | 04,942,336 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])

[2004-08-13 19:56:20 | 00,005,810 | R--- | M] () -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor [On_Demand | Running])

[2008-12-17 08:43:48 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\VirusDefs\20090116.025\NAVENG.SYS -- (NAVENG [On_Demand | Running])

[2008-12-17 08:43:48 | 00,876,112 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\VirusDefs\20090116.025\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])

[2009-01-10 12:47:01 | 00,042,512 | ---- | M] (CACE Technologies) -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF [On_Demand | Stopped])

[2008-08-01 14:48:00 | 06,555,104 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])

[2008-08-01 11:36:20 | 00,054,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD [On_Demand | Running])

[2008-08-01 11:36:26 | 00,022,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus [On_Demand | Running])

[2006-03-02 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])

[2001-08-17 23:05:16 | 00,028,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\OVCD.sys -- (QCDonner [On_Demand | Running])

[2008-05-28 10:33:36 | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV [system | Running])

[2008-05-28 10:33:38 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Running])

[2008-05-28 10:33:36 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL [system | Running])

[2008-04-13 17:39:17 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])

[2008-09-05 14:31:42 | 00,447,024 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [system | Running])

[2009-01-10 11:01:05 | 00,717,296 | ---- | M] () -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd [boot | Running])

[2008-01-31 19:51:00 | 00,279,088 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP [system | Running])

[2008-01-31 19:51:00 | 00,317,616 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL [On_Demand | Stopped])

[2008-01-31 19:51:00 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX [system | Running])

[2008-06-13 14:13:38 | 00,013,616 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symdns.sys -- (SYMDNS [On_Demand | Running])

[2009-01-08 18:55:41 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])

[2008-06-13 14:13:38 | 00,096,432 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symfw.sys -- (SYMFW [On_Demand | Running])

[2008-06-13 14:13:38 | 00,038,576 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symids.sys -- (SYMIDS [On_Demand | Running])

[2009-01-02 21:53:44 | 00,250,224 | ---- | M] (Symantec Corporation) -- C:\Program\Delade filer\Symantec Shared\SymcData\ipsdefs\20090113.002\SymIDSCo.sys -- (SYMIDSCO [On_Demand | Running])

[2008-06-13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM [On_Demand | Stopped])

[2008-06-13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP [On_Demand | Running])

[2008-06-13 14:13:38 | 00,037,424 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symndis.sys -- (SYMNDIS [On_Demand | Running])

[2008-06-13 14:13:38 | 00,022,320 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Running])

[2008-06-13 14:13:40 | 00,184,240 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [system | Running])

[2008-04-13 19:36:38 | 00,008,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [system | Running])

[2006-03-02 13:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [Disabled | Stopped])

 

========== (R ) Internet Explorer ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]

"Default_Page_URL"=

"Default_Search_URL"=

"Search Page"=

"Start Page"=about:blank

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]

"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]

"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

"Start Page"=about:blank

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]

"provider"=

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main]

"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

"Start Page"=about:blank

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\Software\Microsoft\Internet Explorer\SearchURL]

"provider"=

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"ProxyEnable" = 0

"ProxyOverride" = *.local

 

========== (O1) Hosts File ==========

 

HOSTS File = (290890 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

First 25 entries...

127.0.0.1 localhost

127.0.0.1 www.007guard.com

127.0.0.1 007guard.com

127.0.0.1 008i.com

127.0.0.1 www.008k.com

127.0.0.1 008k.com

127.0.0.1 www.00hq.com

127.0.0.1 00hq.com

127.0.0.1 010402.com

127.0.0.1 www.032439.com

127.0.0.1 032439.com

127.0.0.1 www.0scan.com

127.0.0.1 0scan.com

127.0.0.1 1000gratisproben.com

127.0.0.1 www.1000gratisproben.com

127.0.0.1 www.1001namen.com

127.0.0.1 1001namen.com

127.0.0.1 www.100888290cs.com

127.0.0.1 100888290cs.com

127.0.0.1 www.100sexlinks.com

127.0.0.1 100sexlinks.com

127.0.0.1 www.10sek.com

127.0.0.1 10sek.com

127.0.0.1 www.1-2005-search.com

127.0.0.1 1-2005-search.com

10085 more lines...

 

========== (O2) BHO's ==========

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]

{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} (HKLM) -- C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

{6D53EC84-6AAE-4787-AEEE-F4628F01010C} (HKLM) -- C:\Program\Delade filer\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

 

========== (O3) Toolbars ==========

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (HKLM) -- C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" (HKLM) -- C:\Program\Delade filer\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)

 

========== (O4) Run Keys ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Alcmtr"=ALCMTR.EXE (Realtek Semiconductor Corp.)

"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" (Symantec Corporation)

"EPSON Stylus D68 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68" (SEIKO EPSON CORPORATION)

"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)

"nwiz"=nwiz.exe /install ()

"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)

"osCheck"="C:\Program\Norton Internet Security\osCheck.exe" (Symantec Corporation)

"RTHDCPL"=RTHDCPL.EXE (Realtek Semiconductor Corp.)

"Video Driver"=sgvhost.exe File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)

"Skype"="C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)

"SpybotSD TeaTimer"=C:\Program\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

"SUPERAntiSpyware"=C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)

"Skype"="C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)

"SpybotSD TeaTimer"=C:\Program\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

"SUPERAntiSpyware"=C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

 

========== (O4) RunServices Keys ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

"Video Driver"=sgvhost.exe File not found

 

========== (O4) Startup Folders ==========

 

[2009-01-08 20:11:02 | 00,910,864 | ---- | M] (Technology Nexus AB) -- C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Personal.lnk = C:\Program\Personal\bin\Personal.exe

 

========== (O6 & O7) Current Version Policies ==========

 

[HKEY_CURRENT_USER\Software\policies\microsoft\internet explorer\Restrictions]

"NoViewSource"=0

"NoBrowserContextMenu"=0

"NoBrowserClose"=0

"NoBrowserOptions"=0

"NoBrowserSaveAs"=0

"NoFavorites"=0

"NoFileNew"=0

"NoFileOpen"=0

"NoFindFiles"=0

"NoSelectDownloadDir"=0

"NoTheaterMode"=0

"NoAddressBar"=0

"NoToolBar"=0

"NoLinksBar"=0

 

[HKEY_USERS\.DEFAULT\Software\policies\microsoft\internet explorer\Control Pan]

"homepage"=0

 

[HKEY_USERS\S-1-5-18\Software\policies\microsoft\internet explorer\Control Pan]

"homepage"=0

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\Software\policies\microsoft\internet explorer\Restrictions]

"NoViewSource"=0

"NoBrowserContextMenu"=0

"NoBrowserClose"=0

"NoBrowserOptions"=0

"NoBrowserSaveAs"=0

"NoFavorites"=0

"NoFileNew"=0

"NoFileOpen"=0

"NoFindFiles"=0

"NoSelectDownloadDir"=0

"NoTheaterMode"=0

"NoAddressBar"=0

"NoToolBar"=0

"NoLinksBar"=0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoFolderOptions"= [binary data]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

"NoDesktop"=0

"NoFolderOptions"=0

"RestrictRun"=0

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]

"DisableRegistryTools"=0

"NoSecCPL"=0

"NoDispCPL"=0

"NoDispBackgroundPage"=0

"NoDispScrSavPage"=0

"NoDispAppearancePage"=0

"NoDispSettingsPage"=0

"NoDevMgrPage"=0

"NoConfigPage"=0

"NoVirtMemPage"=0

"NoFileSysPage"=0

"NoNetSetup"=0

"NoNetSetupIDPage"=0

"NoNetSetupSecurityPage"=0

"NoWorkgroupContents"=0

"NoEntireNetwork"=0

"NoFileSharingControl"=0

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

"NoRun"=0

"NoLogOff"=0

"NoFind"=0

"NoClose"=0

"NoSetFolders"=0

"NoFavoritesMenu"=0

"NoStartBanner"=0

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

"NoRun"=0

"NoLogOff"=0

"NoFind"=0

"NoClose"=0

"NoSetFolders"=0

"NoFavoritesMenu"=0

"NoStartBanner"=0

 

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]

"NoDriveTypeAutoRun"=145

"NoDesktop"=0

"NoFolderOptions"=0

"RestrictRun"=0

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]

"DisableRegistryTools"=0

"NoSecCPL"=0

"NoDispCPL"=0

"NoDispBackgroundPage"=0

"NoDispScrSavPage"=0

"NoDispAppearancePage"=0

"NoDispSettingsPage"=0

"NoDevMgrPage"=0

"NoConfigPage"=0

"NoVirtMemPage"=0

"NoFileSysPage"=0

"NoNetSetup"=0

"NoNetSetupIDPage"=0

"NoNetSetupSecurityPage"=0

"NoWorkgroupContents"=0

"NoEntireNetwork"=0

"NoFileSharingControl"=0

 

========== (O9) IE Extensions ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found

CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found

CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found

CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Extensions\]

CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found

CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found

 

========== (O12) Internet Explorer Plugins ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]

PluginsPage: "" = http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s

PluginsPageFriendlyName: "" = Microsoft ActiveX-galleri

 

========== (O13) Default Prefixes ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]

""=http://

 

========== (O15) Trusted Sites ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

49 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

48 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

48 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

48 domain(s) and sub-domain(s) not assigned to a zone.

 

[HKEY_USERS\S-1-5-21-220523388-299502267-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]

48 domain(s) and sub-domain(s) not assigned to a zone.

 

========== (O16) DPF ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]

{166B1BCA-3F9C-11CF-8075-444553540000}: http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab -- Shockwave ActiveX Control

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}: http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231442855500 -- MUWebControl Class

{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab'>http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11

{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.

{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07

{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11

 

========== (O17) DNS Name Servers ==========

 

{08C761E5-954D-4B5E-BCF3-6326882CA7A2} (Servers: | Description: NVIDIA nForce 10/100/1000 Mbps Ethernet )

{68CF06B4-746F-4B84-AC2B-DD50C51909FD} (Servers: | Description: )

 

========== Shell Execute Hooks ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)

 

========== Safeboot Options ==========

 

"AlternateShell"=cmd.exe

 

========== CDRom AutoRun Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]

"AutoRun" = 1

 

========== Autorun Files on Drives ==========

 

AUTOEXEC.BAT []

[2009-01-08 18:16:57 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

 

========== Files/Folders - Created Within 30 Days ==========

 

[1 C:\WINDOWS\System32\*.tmp files]

[9 C:\WINDOWS\*.tmp files]

[2009-01-17 09:32:14 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\OTViewIt.exe

[2009-01-17 00:31:41 | 00,031,744 | -HS- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Thumbs.db

@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Thumbs.db:encryptable

[2009-01-17 00:27:19 | 00,076,489 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bf0f5.jpg

[2009-01-17 00:25:14 | 00,075,047 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bea01.jpg

[2009-01-17 00:22:33 | 00,089,290 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bdfd6.jpg

[2009-01-16 22:39:45 | 00,057,472 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\biiindaaa.jpg

[2009-01-16 21:09:13 | 00,000,000 | ---D | C] -- C:\Program\Trend Micro

[2009-01-16 16:56:27 | 00,057,462 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\1023468.jpg

[2009-01-16 16:48:27 | 00,026,057 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\sx8ee7cf448.jpg

[2009-01-16 16:40:02 | 00,569,344 | ---- | C] (Pegasus Software,LLC) -- C:\WINDOWS\System32\imagr5.dll

[2009-01-16 16:40:02 | 00,544,768 | ---- | C] (Pegasus Software, LLC) -- C:\WINDOWS\System32\imagx5.dll

[2009-01-16 16:40:02 | 00,283,920 | ---- | C] (Pegasus Software, LLC) -- C:\WINDOWS\System32\ImagXpr5.dll

[2009-01-16 16:40:02 | 00,155,648 | ---- | C] (Ahead Software Gmbh) -- C:\WINDOWS\System32\NeroCheck.exe

[2009-01-16 16:40:02 | 00,038,912 | ---- | C] (Pegasus Imaging Corp.) -- C:\WINDOWS\System32\picn20.dll

[2009-01-16 16:40:02 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Ahead

[2009-01-16 16:39:58 | 00,000,000 | ---D | C] -- C:\Program\Ahead

[2009-01-16 07:00:24 | 00,290,890 | R--- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090116-070024.backup

[2009-01-15 12:15:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokument\EA Games

[2009-01-15 12:12:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\EA Games

[2009-01-15 11:10:52 | 00,000,000 | ---D | C] -- C:\Program\EA GAMES

[2009-01-15 10:15:17 | 00,000,000 | ---D | C] -- C:\Program\DAEMON Tools Toolbar

[2009-01-15 10:15:06 | 00,000,000 | ---D | C] -- C:\Program\DAEMON Tools Lite

[2009-01-15 10:14:55 | 00,000,000 | -HSD | C] -- C:\Config.Msi

[2009-01-14 23:54:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\EA Games 2

[2009-01-14 19:43:41 | 00,018,406 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\huuusvagn.jpg

[2009-01-14 19:43:19 | 00,116,027 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\vagnahus.jpg

[2009-01-14 12:03:10 | 00,049,938 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\n618847606_1308412_3302.jpg

[2009-01-14 08:07:58 | 00,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib

[2009-01-14 08:07:30 | 00,000,000 | ---D | C] -- C:\Program\SlySoft

[2009-01-13 21:28:48 | 00,013,824 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-01-13 10:06:44 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\GkSui18.EXE

[2009-01-13 10:06:43 | 00,000,000 | ---D | C] -- C:\Program\GameWiz32

[2009-01-13 09:36:00 | 00,737,280 | ---- | C] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe

[2009-01-13 08:48:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution

[2009-01-13 08:21:34 | 00,003,371 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\install.rtf

[2009-01-13 08:16:17 | 00,000,769 | ---- | C] () -- C:\fix_reg.cmd

[2009-01-13 08:11:46 | 00,379,392 | ---- | C] () -- C:\WINDOWS\System32\subinacl.msi

[2009-01-13 08:10:17 | 00,379,392 | ---- | C] () -- C:\WINDOWS\System32\subinacl.exe

[2009-01-12 11:23:58 | 00,290,890 | R--- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090112-112358.backup

[2009-01-12 09:34:02 | 00,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat

[2009-01-11 13:33:52 | 00,288,612 | R--- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090111-133352.backup

[2009-01-11 12:14:02 | 00,000,000 | ---D | C] -- C:\Program\Windows Resource Kits

[2009-01-11 11:58:36 | 00,068,663 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\917925.htm

[2009-01-11 11:58:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\917925-filer

[2009-01-11 11:54:30 | 00,000,000 | ---D | C] -- C:\Program\MSXML 4.0

[2009-01-11 11:14:29 | 00,000,335 | ---- | C] () -- C:\WINDOWS\Julens hjältar.ini

[2009-01-11 11:06:53 | 00,231,445 | ---- | C] () -- C:\WINDOWS\uninstall Star_War.exe

[2009-01-11 11:06:45 | 30,359,902 | ---- | C] () -- C:\WINDOWS\Star_War.scr

[2009-01-11 11:04:15 | 03,034,624 | ---- | C] (3Planesoft) -- C:\WINDOWS\System32\The Lost Watch 3D Screensaver.exe

[2009-01-11 11:04:14 | 00,855,552 | ---- | C] (3Planesoft) -- C:\WINDOWS\System32\The_Lost_Watch_3D_Screensaver.scr

[2009-01-11 11:04:14 | 00,000,000 | ---D | C] -- C:\Program\The Lost Watch 3D Screensaver

[2009-01-11 11:03:29 | 05,745,270 | ---- | C] (3Planesoft ) -- C:\WINDOWS\System32\xa63536421.exe

[2009-01-11 11:03:28 | 05,745,270 | ---- | C] (3Planesoft ) -- C:\WINDOWS\System32\xa63534890.exe

[2009-01-10 15:52:29 | 00,000,885 | ---- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090110-155229.backup

[2009-01-10 14:45:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Adobe

[2009-01-10 14:44:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss

[2009-01-10 14:16:08 | 00,962,612 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc42d.dll

[2009-01-10 14:16:08 | 00,434,252 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSVCRTD.DLL

[2009-01-10 14:16:07 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll

[2009-01-10 14:16:07 | 00,012,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys

[2009-01-10 14:16:06 | 00,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys

[2009-01-10 14:16:06 | 00,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys

[2009-01-10 14:16:05 | 00,000,000 | ---D | C] -- C:\Program\ASUS

[2009-01-10 14:12:22 | 01,684,736 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys

[2009-01-10 14:09:19 | 00,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2009-01-10 14:09:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\skypePM

[2009-01-10 14:06:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\NV816836.TMP

[2009-01-10 14:00:25 | 00,006,045 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu

[2009-01-10 13:50:50 | 00,001,746 | ---- | C] () -- C:\WINDOWS\Language_trs.ini

[2009-01-10 13:33:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Nero

[2009-01-10 13:13:20 | 00,000,000 | ---D | C] -- C:\Program\directx

[2009-01-10 13:01:32 | 00,086,016 | ---- | C] (MindVision Software) -- C:\WINDOWS\unvise32.exe

[2009-01-10 12:56:40 | 00,000,000 | ---D | C] -- C:\Program\Nero

[2009-01-10 12:56:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero

[2009-01-10 12:56:07 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Nero

[2009-01-10 12:47:01 | 00,240,240 | ---- | C] (CACE Technologies) -- C:\WINDOWS\System32\wpcap.dll

[2009-01-10 12:47:01 | 00,088,704 | ---- | C] (CACE Technologies) -- C:\WINDOWS\System32\packet.dll

[2009-01-10 12:47:01 | 00,042,512 | ---- | C] (CACE Technologies) -- C:\WINDOWS\System32\drivers\npf.sys

[2009-01-10 12:47:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP

@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:466F9D5D

[2009-01-10 12:45:07 | 00,000,082 | ---- | C] () -- C:\WINDOWS\ka.ini

[2009-01-10 12:44:48 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Knowledge Adventure

[2009-01-10 12:21:46 | 00,442,368 | R--- | C] (On2.com) -- C:\WINDOWS\System32\vp6vfw.dll

[2009-01-10 12:14:25 | 00,000,035 | ---- | C] () -- C:\WINDOWS\vg5aloc.ini

[2009-01-10 12:08:37 | 00,000,035 | ---- | C] () -- C:\WINDOWS\vg5bloc.ini

[2009-01-10 12:01:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\DAEMON Tools Pro

[2009-01-10 12:01:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\DAEMON Tools

[2009-01-10 12:00:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

[2009-01-10 11:11:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\GetRight Pro

[2009-01-10 11:11:10 | 00,000,000 | ---D | C] -- C:\Program\GetRight

[2009-01-10 11:03:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Downloads

[2009-01-10 11:03:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\GetRightToGo

[2009-01-10 11:01:05 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-01-10 11:01:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\DAEMON Tools Lite

[2009-01-09 18:32:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\AGEIA

[2009-01-09 18:32:22 | 00,000,000 | ---D | C] -- C:\Program\AGEIA Technologies

[2009-01-09 18:32:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\NV18324084.TMP

[2009-01-09 18:31:21 | 00,000,000 | ---D | C] -- C:\NVIDIA

[2009-01-09 18:26:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\WinRAR

[2009-01-09 17:27:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun

[2009-01-09 17:22:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Smajlies

[2009-01-09 16:54:57 | 00,009,349 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\the_devil.jpg

[2009-01-09 16:35:02 | 00,290,748 | R--- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090109-163502.backup

[2009-01-09 16:26:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Kiwee Toolbar

[2009-01-09 16:26:20 | 02,117,632 | ---- | C] (Python Software Foundation) -- C:\WINDOWS\System32\python25.dll

[2009-01-09 16:26:20 | 00,339,968 | ---- | C] () -- C:\WINDOWS\System32\pythoncom25.dll

[2009-01-09 16:26:20 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\pywintypes25.dll

[2009-01-09 16:26:19 | 01,332,197 | ---- | C] () -- C:\WINDOWS\System32\pythondll.zip

[2009-01-09 16:17:36 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2009-01-09 16:17:36 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2009-01-09 16:17:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe

[2009-01-09 15:42:49 | 00,013,511 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\toilet04.gif

[2009-01-09 15:27:18 | 00,000,000 | ---D | C] -- C:\Program\uTorrent

[2009-01-09 15:27:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\uTorrent

[2009-01-09 13:34:28 | 00,000,268 | -H-- | C] () -- C:\sqmdata03.sqm

[2009-01-09 13:34:28 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt03.sqm

[2009-01-09 12:36:28 | 00,268,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll

[2009-01-09 12:36:28 | 00,027,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui

[2009-01-09 07:06:04 | 00,290,748 | R--- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090109-070604.backup

[2009-01-08 22:02:10 | 00,000,268 | -H-- | C] () -- C:\sqmdata02.sqm

[2009-01-08 22:02:10 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt02.sqm

[2009-01-08 21:49:36 | 00,000,146 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\fusioncache.dat

[2009-01-08 21:49:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\ApplicationHistory

[2009-01-08 21:42:50 | 00,000,268 | -H-- | C] () -- C:\sqmdata01.sqm

[2009-01-08 21:42:50 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt01.sqm

[2009-01-08 21:16:51 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvapps.nvb

[2009-01-08 21:16:43 | 00,000,000 | ---D | C] -- C:\WINDOWS\NV22081308.TMP

[2009-01-08 21:13:47 | 00,000,099 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Felsök Internet Explorer.url

[2009-01-08 21:13:40 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$

[2009-01-08 21:13:29 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$

[2009-01-08 21:12:16 | 20,853,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe

[2009-01-08 21:10:38 | 00,018,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll

[2009-01-08 21:10:21 | 00,000,000 | ---D | C] -- C:\Program\Windows Media Connect 2

[2009-01-08 21:09:17 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2009-01-08 21:09:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles

[2009-01-08 21:09:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF

[2009-01-08 21:04:40 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly

[2009-01-08 21:04:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET

[2009-01-08 21:04:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp

[2009-01-08 21:00:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Sun

[2009-01-08 20:59:37 | 00,138,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\afd.sys

[2009-01-08 20:59:31 | 00,333,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys

[2009-01-08 20:59:25 | 00,666,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll

[2009-01-08 20:59:22 | 01,499,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shdocvw.dll

[2009-01-08 20:59:22 | 00,618,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll

[2009-01-08 20:59:21 | 03,088,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll

[2009-01-08 20:59:07 | 01,846,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys

[2009-01-08 20:58:11 | 00,203,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys

[2009-01-08 20:58:09 | 00,455,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys

[2009-01-08 20:58:07 | 00,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadce.dll

[2009-01-08 20:57:40 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\netapi32.dll

[2009-01-08 20:57:39 | 01,106,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll

[2009-01-08 20:55:10 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpns.dll

[2009-01-08 20:54:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch

[2009-01-08 20:52:58 | 00,000,268 | -H-- | C] () -- C:\sqmdata00.sqm

[2009-01-08 20:52:58 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt00.sqm

[2009-01-08 20:50:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\sv-se

[2009-01-08 20:50:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\sv

[2009-01-08 20:50:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas

[2009-01-08 20:50:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits

[2009-01-08 20:48:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles

[2009-01-08 20:47:21 | 00,049,152 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\E_DCINST.DLL

[2009-01-08 20:47:20 | 00,079,679 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FLMAAE.DLL

[2009-01-08 20:47:20 | 00,064,000 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FBCBAAE.DLL

[2009-01-08 20:47:20 | 00,034,304 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FBCHAAE.DLL

[2009-01-08 20:45:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic

[2009-01-08 20:44:53 | 00,000,000 | ---D | C] -- C:\Program\EPSON

[2009-01-08 20:43:07 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$

[2009-01-08 20:43:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\EHome

[2009-01-08 20:38:35 | 00,649,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm

[2009-01-08 20:38:35 | 00,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav

[2009-01-08 20:38:35 | 00,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav

[2009-01-08 20:38:35 | 00,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav

[2009-01-08 20:38:35 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav

[2009-01-08 20:38:35 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav

[2009-01-08 20:38:35 | 00,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav

[2009-01-08 20:38:35 | 00,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav

[2009-01-08 20:38:35 | 00,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav

[2009-01-08 20:38:35 | 00,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav

[2009-01-08 20:38:35 | 00,034,544 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf

[2009-01-08 20:38:35 | 00,013,540 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf

[2009-01-08 20:38:35 | 00,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif

[2009-01-08 20:38:35 | 00,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif

[2009-01-08 20:38:35 | 00,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif

[2009-01-08 20:38:35 | 00,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif

[2009-01-08 20:38:35 | 00,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif

[2009-01-08 20:38:35 | 00,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif

[2009-01-08 20:38:35 | 00,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif

[2009-01-08 20:38:35 | 00,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif

[2009-01-08 20:38:35 | 00,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif

[2009-01-08 20:38:35 | 00,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css

[2009-01-08 20:38:35 | 00,001,736 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf

[2009-01-08 20:38:34 | 00,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif

[2009-01-08 20:38:34 | 00,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif

[2009-01-08 20:38:34 | 00,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif

[2009-01-08 20:38:34 | 00,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif

[2009-01-08 20:38:34 | 00,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif

[2009-01-08 20:38:33 | 00,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif

[2009-01-08 20:38:33 | 00,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js

[2009-01-08 20:38:33 | 00,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif

[2009-01-08 20:38:33 | 00,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif

[2009-01-08 20:38:33 | 00,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif

[2009-01-08 20:38:33 | 00,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif

[2009-01-08 20:38:33 | 00,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif

[2009-01-08 20:38:33 | 00,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm

[2009-01-08 20:38:32 | 00,080,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm

[2009-01-08 20:38:32 | 00,066,136 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz

[2009-01-08 20:38:32 | 00,001,806 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf

[2009-01-08 20:38:31 | 00,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img

[2009-01-08 20:38:31 | 00,036,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf

[2009-01-08 20:38:31 | 00,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip

[2009-01-08 20:38:31 | 00,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif

[2009-01-08 20:38:31 | 00,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif

[2009-01-08 20:38:31 | 00,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip

[2009-01-08 20:38:28 | 00,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js

[2009-01-08 20:38:26 | 00,184,089 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz

[2009-01-08 20:38:26 | 00,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty

[2009-01-08 20:38:26 | 00,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css

[2009-01-08 20:38:26 | 00,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif

[2009-01-08 20:38:26 | 00,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif

[2009-01-08 20:38:26 | 00,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif

[2009-01-08 20:38:26 | 00,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif

[2009-01-08 20:38:26 | 00,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif

[2009-01-08 20:38:26 | 00,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif

[2009-01-08 20:37:36 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Adobe AIR

[2009-01-08 20:37:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Macromedia

[2009-01-08 20:37:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Adobe

[2009-01-08 20:37:32 | 00,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod

[2009-01-08 20:37:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe

[2009-01-08 20:36:57 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Adobe

[2009-01-08 20:36:57 | 00,000,000 | ---D | C] -- C:\Program\Adobe

[2009-01-08 20:35:30 | 00,000,000 | ---D | C] -- C:\Program\Java

[2009-01-08 20:35:12 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Java

[2009-01-08 20:31:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage

[2009-01-08 20:31:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall

[2009-01-08 20:24:45 | 00,000,042 | ---- | C] () -- C:\WINDOWS\System32\RegistryEasy.lie

[2009-01-08 20:24:23 | 00,000,394 | ---- | C] () -- C:\WINDOWS\tasks\Schedule Task Weekly.job

[2009-01-08 20:24:18 | 00,000,000 | ---D | C] -- C:\Program\Registry Easy

[2009-01-08 20:23:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Skype

[2009-01-08 20:23:36 | 00,000,000 | ---D | C] -- C:\Program\Skype

[2009-01-08 20:23:36 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Skype

[2009-01-08 20:23:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype

[2009-01-08 20:23:11 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2009-01-08 20:22:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Malwarebytes

[2009-01-08 20:22:29 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009-01-08 20:22:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2009-01-08 20:22:27 | 00,000,000 | ---D | C] -- C:\Program\Malwarebytes' Anti-Malware

[2009-01-08 20:21:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

[2009-01-08 20:21:34 | 00,000,000 | ---D | C] -- C:\Program\SUPERAntiSpyware

[2009-01-08 20:21:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\SUPERAntiSpyware.com

[2009-01-08 20:21:24 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Wise Installation Wizard

[2009-01-08 20:19:53 | 00,000,000 | ---D | C] -- C:\Program\Lavalys

[2009-01-08 20:17:22 | 00,000,710 | ---- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090108-201722.backup

[2009-01-08 20:15:06 | 00,000,000 | ---D | C] -- C:\Program\Apple Software Update

[2009-01-08 20:14:51 | 00,000,000 | ---D | C] -- C:\Program\Bonjour

[2009-01-08 20:14:09 | 00,000,000 | ---D | C] -- C:\Program\iPod

[2009-01-08 20:14:07 | 00,000,000 | ---D | C] -- C:\Program\iTunes

[2009-01-08 20:14:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

[2009-01-08 20:12:45 | 00,000,000 | ---D | C] -- C:\Program\QuickTime

[2009-01-08 20:11:35 | 00,000,000 | ---D | C] -- C:\Program\Spybot - Search & Destroy

[2009-01-08 20:11:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

[2009-01-08 20:11:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Personal

[2009-01-08 20:11:02 | 00,001,670 | ---- | C] () -- C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Personal.lnk

[2009-01-08 20:11:02 | 00,000,000 | ---D | C] -- C:\Program\Personal

[2009-01-08 20:10:40 | 00,000,000 | ---D | C] -- C:\Program\WinRAR

[2009-01-08 20:10:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\vlc

[2009-01-08 20:10:10 | 00,000,000 | ---D | C] -- C:\Program\VideoLAN

[2009-01-08 20:07:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Apple Computer

[2009-01-08 20:06:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer

[2009-01-08 20:06:45 | 00,000,272 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-01-08 20:06:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Apple

[2009-01-08 20:06:26 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Apple

[2009-01-08 20:06:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple

[2009-01-08 20:06:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Apple Computer

[2009-01-08 19:53:47 | 00,000,000 | -HSD | C] -- C:\Program\Delade filer\WindowsLiveInstaller

[2009-01-08 19:53:44 | 00,000,000 | ---D | C] -- C:\Program\Windows Live

[2009-01-08 19:53:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WLInstaller

[2009-01-08 19:53:07 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2009-01-08 19:53:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Mozilla

[2009-01-08 19:53:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Mozilla

[2009-01-08 19:53:02 | 00,001,546 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivbord\Mozilla Firefox.lnk

[2009-01-08 19:53:00 | 00,000,000 | ---D | C] -- C:\Program\Mozilla Firefox

[2009-01-08 19:37:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Identities

[2009-01-08 19:36:46 | 01,650,838 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\julkort 2008.jpg

[2009-01-08 19:36:46 | 00,144,207 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Richard.jpg

[2009-01-08 19:36:46 | 00,111,104 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Dok1.doc

[2009-01-08 19:36:46 | 00,034,396 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\maaalin.JPG

[2009-01-08 19:36:46 | 00,000,362 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Downloads.lnk

[2009-01-08 19:36:46 | 00,000,351 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Bilder.lnk

[2009-01-08 19:36:46 | 00,000,338 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\MP3.lnk

[2009-01-08 19:36:45 | 00,029,180 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\9c86fe66fc54ee402348cbbbec6dc0a3.jpg

[2009-01-08 19:36:45 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Spel

[2009-01-08 19:36:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Smillas kort

[2009-01-08 19:36:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Smillas bakgrunder

[2009-01-08 19:35:39 | 00,070,081 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\smssms.xps

[2009-01-08 19:35:39 | 00,024,576 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Tider Fritids.doc

[2009-01-08 19:35:38 | 00,000,956 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Smillas tider 36,37,38.rtf

[2009-01-08 19:35:37 | 00,084,416 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\SCRIPTIN.ttf

[2009-01-08 19:35:37 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\rohypnol.doc

[2009-01-08 19:35:37 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Schema Smilla.doc

[2009-01-08 19:35:37 | 00,010,272 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\SCRIPALT.ttf

[2009-01-08 19:35:36 | 00,311,673 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\P1030351.JPG

[2009-01-08 19:35:36 | 00,295,566 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\P1030347.JPG

[2009-01-08 19:35:36 | 00,024,576 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Nuvarande Nypriser på richards data delar.doc

[2009-01-08 19:35:36 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Naaaaamn.doc

[2009-01-08 19:35:36 | 00,019,456 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Långsamt Farväl.doc

[2009-01-08 19:35:36 | 00,010,752 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Ny(tt) Microsoft Word-dokument.doc

[2009-01-08 19:35:36 | 00,001,694 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Leons Tider.rtf

[2009-01-08 19:35:36 | 00,000,898 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Leons tider v.36,37,38.rtf

[2009-01-08 19:35:36 | 00,000,598 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Mina delade mappar.lnk

[2009-01-08 19:35:35 | 01,276,764 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\CuteSecurity.wmv

[2009-01-08 19:35:35 | 00,042,316 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\jenny tejp.jpg

[2009-01-08 19:35:35 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Den viktiga informationen på blåskärmen är följande.doc

[2009-01-08 19:35:35 | 00,010,651 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\fakta torsdag.rtf

[2009-01-08 19:35:35 | 00,003,586 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\F.rtf

[2009-01-08 19:35:35 | 00,000,662 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Dagistider.rtf

[2009-01-08 19:35:34 | 00,258,560 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Cream cheese frosting.doc

[2009-01-08 19:35:33 | 03,837,697 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\AutoRuns080813.arn

[2009-01-08 19:35:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Sms

[2009-01-08 19:34:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\My Games

[2009-01-08 19:34:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Mitt Djursjukhus i Australien

[2009-01-08 19:34:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Mina mottagna filer

[2009-01-08 19:29:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Richard

[2009-01-08 19:27:58 | 00,005,077 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Torsdagsmötet.rtf

[2009-01-08 19:27:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\barbapapa772014096274

[2009-01-08 19:27:54 | 00,000,000 | -HSD | C] -- C:\RECYCLER

[2009-01-08 19:27:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Proggs

[2009-01-08 19:26:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Leons bakgrunder

[2009-01-08 19:26:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Julkort

[2009-01-08 19:26:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Hanna bakgrunder

[2009-01-08 19:26:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Drivers Old

[2009-01-08 19:26:29 | 09,591,737 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Untitled-1.psd

[2009-01-08 19:26:29 | 00,037,334 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Skärmsläckare.jpg

[2009-01-08 19:26:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Bakgrunder

[2009-01-08 19:25:26 | 00,000,383 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009-01-08 19:25:19 | 00,028,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdimon.dll

[2009-01-08 19:24:38 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\DESIGNER

[2009-01-08 19:24:36 | 00,000,000 | ---D | C] -- C:\Program\Microsoft Works

[2009-01-08 19:24:30 | 00,000,000 | ---D | C] -- C:\Program\Microsoft Visual Studio

[2009-01-08 19:24:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW

[2009-01-08 19:24:24 | 00,000,000 | ---D | C] -- C:\Program\Microsoft Office

[2009-01-08 19:22:32 | 00,000,000 | RH-D | C] -- C:\MSOCache

[2009-01-08 19:21:24 | 00,026,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbstor.sys

[2009-01-08 19:17:53 | 00,199,604 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml

[2009-01-08 19:17:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview

[2009-01-08 19:16:48 | 02,146,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe

[2009-01-08 19:16:47 | 02,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe

[2009-01-08 19:16:47 | 02,066,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe

[2009-01-08 19:16:47 | 02,024,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe

[2009-01-08 19:16:41 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll

[2009-01-08 19:12:55 | 00,000,000 | ---D | C] -- C:\Program\My Company Name

[2009-01-08 19:12:39 | 00,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll

[2009-01-08 19:12:39 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll

[2009-01-08 19:12:39 | 00,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll

[2009-01-08 19:12:38 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll

[2009-01-08 19:12:38 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll

[2009-01-08 19:12:38 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll

[2009-01-08 19:12:37 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll

[2009-01-08 19:12:37 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll

[2009-01-08 19:12:37 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll

[2009-01-08 19:12:37 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll

[2009-01-08 19:12:36 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll

[2009-01-08 19:12:36 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll

[2009-01-08 19:12:36 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll

[2009-01-08 19:12:35 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll

[2009-01-08 19:12:35 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll

[2009-01-08 19:09:54 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mstee.sys

[2009-01-08 19:09:52 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax

[2009-01-08 19:09:52 | 00,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\streamip.sys

[2009-01-08 19:09:51 | 00,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\slip.sys

[2009-01-08 19:09:49 | 00,085,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nabtsfec.sys

[2009-01-08 19:09:48 | 00,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ndisip.sys

[2009-01-08 19:09:47 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ccdecode.sys

[2009-01-08 19:09:46 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wstcodec.sys

[2009-01-08 19:09:44 | 00,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mskssrv.sys

[2009-01-08 19:09:43 | 00,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mspclock.sys

[2009-01-08 19:09:42 | 00,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mspqm.sys

[2009-01-08 19:09:38 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\audstub.sys

[2009-01-08 19:09:27 | 00,351,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\OVCodek2.sys

[2009-01-08 19:09:27 | 00,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\OVCodec2.dll

[2009-01-08 19:09:27 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\OVUI2.dll

[2009-01-08 19:09:27 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\OVUI2RC.dll

[2009-01-08 19:09:27 | 00,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\OVComS.exe

[2009-01-08 19:09:27 | 00,028,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\OVCD.sys

[2009-01-08 19:09:27 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\OVComC.dll

[2009-01-08 19:09:24 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax

[2009-01-08 19:09:24 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax

[2009-01-08 19:09:24 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax

[2009-01-08 19:09:24 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll

[2009-01-08 19:09:24 | 00,048,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\OVCam2.sys

[2009-01-08 19:09:24 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax

[2009-01-08 19:09:24 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax

[2009-01-08 19:09:24 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll

[2009-01-08 19:09:11 | 00,058,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\redbook.sys

[2009-01-08 19:09:08 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbprint.sys

[2009-01-08 19:08:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Drivers

[2009-01-08 19:08:29 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll

[2009-01-08 19:08:14 | 00,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wmiacpi.sys

[2009-01-08 19:07:44 | 00,002,422 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak

[2009-01-08 19:07:33 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK

[2009-01-08 19:07:31 | 00,966,698 | ---- | C] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009-01-08 19:07:31 | 00,000,000 | -HSD | C] -- C:\WINDOWS\Installer

[2009-01-08 19:07:30 | 00,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2009-01-08 19:07:30 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\ODBC

[2009-01-08 19:07:29 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd

[2009-01-08 19:07:29 | 00,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spttseng.dll

[2009-01-08 19:07:29 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcommon.dll

[2009-01-08 19:07:29 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcplui.dll

[2009-01-08 19:07:29 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf

[2009-01-08 19:07:28 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa

[2009-01-08 19:07:28 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa

[2009-01-08 19:07:28 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapisvr.exe

[2009-01-08 19:07:28 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\SpeechEngines

[2009-01-08 19:07:28 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Microsoft Shared

[2009-01-08 19:07:27 | 00,000,000 | R--D | C] -- C:\Program

[2009-01-08 19:07:27 | 00,000,000 | ---D | C] -- C:\Program\Delade filer

[2009-01-08 19:07:22 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll

[2009-01-08 19:07:22 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll

[2009-01-08 19:07:22 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuq.dll

[2009-01-08 19:07:22 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuf.dll

[2009-01-08 19:07:22 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll

[2009-01-08 19:07:22 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdazel.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll

[2009-01-08 19:07:21 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycc.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbduzb.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdur.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtat.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru1.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdmon.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkyr.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkaz.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdbu.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdblr.dll

[2009-01-08 19:07:21 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdaze.dll

[2009-01-08 19:07:19 | 00,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll

[2009-01-08 19:07:19 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhept.dll

[2009-01-08 19:07:19 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll

[2009-01-08 19:07:19 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela3.dll

[2009-01-08 19:07:19 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll

[2009-01-08 19:07:19 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll

[2009-01-08 19:07:19 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela2.dll

[2009-01-08 19:07:19 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgkl.dll

[2009-01-08 19:07:19 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll

[2009-01-08 19:07:19 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll

[2009-01-08 19:07:19 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll

[2009-01-08 19:07:19 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe319.dll

[2009-01-08 19:07:19 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe220.dll

[2009-01-08 19:07:19 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe.dll

[2009-01-08 19:07:18 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll

[2009-01-08 19:07:18 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll

[2009-01-08 19:07:18 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll

[2009-01-08 19:07:18 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv1.dll

[2009-01-08 19:07:18 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv.dll

[2009-01-08 19:07:18 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdest.dll

[2009-01-08 19:07:18 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll

[2009-01-08 19:07:18 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll

[2009-01-08 19:07:18 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt1.dll

[2009-01-08 19:07:18 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt.dll

[2009-01-08 19:07:17 | 00,007,168 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz.dll

[2009-01-08 19:07:17 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz2.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz1.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll

[2009-01-08 19:07:17 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycl.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl1.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz2.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz1.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcr.dll

[2009-01-08 19:07:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdal.dll

[2009-01-08 19:07:17 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll

[2009-01-08 19:07:17 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll

[2009-01-08 19:07:17 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll

[2009-01-08 19:07:17 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdro.dll

[2009-01-08 19:07:17 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl1.dll

[2009-01-08 19:07:17 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu1.dll

[2009-01-08 19:07:13 | 00,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll

[2009-01-08 19:07:13 | 00,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxcoins.dll

[2009-01-08 19:07:13 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll

[2009-01-08 19:07:13 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll

[2009-01-08 19:07:12 | 00,126,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL

[2009-01-08 19:07:12 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL

[2009-01-08 19:07:12 | 00,073,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV

[2009-01-08 19:07:12 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV

[2009-01-08 19:07:12 | 00,025,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV

[2009-01-08 19:07:12 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL

[2009-01-08 19:07:12 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL

[2009-01-08 19:07:12 | 00,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV

[2009-01-08 19:07:12 | 00,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL

[2009-01-08 19:07:12 | 00,009,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL

[2009-01-08 19:07:12 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL

[2009-01-08 19:07:12 | 00,004,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV

[2009-01-08 19:07:12 | 00,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV

[2009-01-08 19:07:12 | 00,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV

[2009-01-08 19:07:12 | 00,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV

[2009-01-08 19:07:12 | 00,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV

[2009-01-08 19:07:12 | 00,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV

[2009-01-08 19:07:12 | 00,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK

[2009-01-08 19:07:11 | 00,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\winspool.drv

[2009-01-08 19:07:11 | 00,109,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL

[2009-01-08 19:07:11 | 00,070,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL

[2009-01-08 19:07:11 | 00,033,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL

[2009-01-08 19:07:11 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE

[2009-01-08 19:07:11 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\taskman.exe

[2009-01-08 19:07:11 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irenum.sys

[2009-01-08 19:07:11 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll

[2009-01-08 19:07:11 | 00,001,572 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT

[2009-01-08 19:07:10 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll

[2009-01-08 19:07:10 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe

[2009-01-08 19:07:10 | 00,069,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMSYSTEM.DLL

[2009-01-08 19:07:03 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\All Users\Start-meny\Program\Autostart\desktop.ini

[2009-01-08 19:07:03 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dokument\desktop.ini

[2009-01-08 19:07:03 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2009-01-08 19:07:01 | 01,013,559 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT

[2009-01-08 19:07:01 | 00,808,234 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT

[2009-01-08 19:07:01 | 00,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT

[2009-01-08 19:07:01 | 00,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT

[2009-01-08 19:07:01 | 00,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT

[2009-01-08 19:07:01 | 00,007,407 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT

[2009-01-08 19:07:01 | 00,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat

[2009-01-08 19:06:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2

[2009-01-08 19:06:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot

[2009-01-08 19:06:47 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft

[2009-01-08 19:06:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings

[2009-01-08 19:06:29 | 00,166,712 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009-01-08 19:06:29 | 00,000,000 | -HSD | C] -- C:\System Volume Information

[2009-01-08 19:05:44 | 00,000,223 | RHS- | C] () -- C:\boot.ini

[2009-01-08 19:05:41 | 00,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf

[2009-01-08 19:01:56 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts

[2009-01-08 19:01:56 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache

[2009-01-08 19:01:56 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web

[2009-01-08 19:01:56 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1053

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\system

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\security

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Provisioning

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\PeerNet

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\pchealth

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\NLDRV

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\java

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins

[2009-01-08 19:01:56 | 00,000,000 | ---D | C] -- C:\WINDOWS

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Här är del 2 av den stora loggen:

 

[log][2009-01-08 18:45:35 | 00,000,634 | ---- | C] () -- C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hanna Smilla Leon.job

[2009-01-08 18:45:08 | 00,039,656 | ---- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\GDIPFONTCACHEV1.DAT

[2009-01-08 18:42:09 | 00,213,493 | ---- | C] () -- C:\WINDOWS\System32\nvdspcht.chm

[2009-01-08 18:42:09 | 00,139,792 | ---- | C] () -- C:\WINDOWS\System32\nv3dcht.chm

[2009-01-08 18:42:09 | 00,059,261 | ---- | C] () -- C:\WINDOWS\System32\nvmobcht.chm

[2009-01-08 18:42:08 | 00,124,817 | ---- | C] () -- C:\WINDOWS\System32\nvcplcht.chm

[2009-01-08 18:42:08 | 00,058,607 | ---- | C] () -- C:\WINDOWS\System32\nvmobchs.chm

[2009-01-08 18:42:07 | 00,219,669 | ---- | C] () -- C:\WINDOWS\System32\nvdspchs.chm

[2009-01-08 18:42:07 | 00,134,133 | ---- | C] () -- C:\WINDOWS\System32\nv3dchs.chm

[2009-01-08 18:42:07 | 00,124,229 | ---- | C] () -- C:\WINDOWS\System32\nvcplchs.chm

[2009-01-08 18:42:06 | 00,210,720 | ---- | C] () -- C:\WINDOWS\System32\nvdsptrk.chm

[2009-01-08 18:42:06 | 00,133,761 | ---- | C] () -- C:\WINDOWS\System32\nv3dtrk.chm

[2009-01-08 18:42:06 | 00,126,892 | ---- | C] () -- C:\WINDOWS\System32\nvcpltrk.chm

[2009-01-08 18:42:06 | 00,057,450 | ---- | C] () -- C:\WINDOWS\System32\nvmobtrk.chm

[2009-01-08 18:42:05 | 00,137,045 | ---- | C] () -- C:\WINDOWS\System32\nv3dtha.chm

[2009-01-08 18:42:05 | 00,059,225 | ---- | C] () -- C:\WINDOWS\System32\nvmobtha.chm

[2009-01-08 18:42:04 | 00,220,312 | ---- | C] () -- C:\WINDOWS\System32\nvdsptha.chm

[2009-01-08 18:42:04 | 00,128,148 | ---- | C] () -- C:\WINDOWS\System32\nvcpltha.chm

[2009-01-08 18:42:03 | 00,195,910 | ---- | C] () -- C:\WINDOWS\System32\nvdspsve.chm

[2009-01-08 18:42:03 | 00,118,734 | ---- | C] () -- C:\WINDOWS\System32\nv3dsve.chm

[2009-01-08 18:42:03 | 00,055,693 | ---- | C] () -- C:\WINDOWS\System32\nvmobsve.chm

[2009-01-08 18:42:02 | 00,206,105 | ---- | C] () -- C:\WINDOWS\System32\nvdspslv.chm

[2009-01-08 18:42:02 | 00,128,913 | ---- | C] () -- C:\WINDOWS\System32\nv3dslv.chm

[2009-01-08 18:42:02 | 00,122,675 | ---- | C] () -- C:\WINDOWS\System32\nvcplsve.chm

[2009-01-08 18:42:02 | 00,057,380 | ---- | C] () -- C:\WINDOWS\System32\nvmobslv.chm

[2009-01-08 18:42:01 | 00,124,964 | ---- | C] () -- C:\WINDOWS\System32\nvcplslv.chm

[2009-01-08 18:42:00 | 00,217,076 | ---- | C] () -- C:\WINDOWS\System32\nvdspsky.chm

[2009-01-08 18:42:00 | 00,129,499 | ---- | C] () -- C:\WINDOWS\System32\nv3dsky.chm

[2009-01-08 18:42:00 | 00,126,105 | ---- | C] () -- C:\WINDOWS\System32\nvcplsky.chm

[2009-01-08 18:42:00 | 00,057,545 | ---- | C] () -- C:\WINDOWS\System32\nvmobsky.chm

[2009-01-08 18:41:59 | 00,214,210 | ---- | C] () -- C:\WINDOWS\System32\nvdsprus.chm

[2009-01-08 18:41:59 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\nv3drus.chm

[2009-01-08 18:41:59 | 00,125,181 | ---- | C] () -- C:\WINDOWS\System32\nvcplrus.chm

[2009-01-08 18:41:59 | 00,057,339 | ---- | C] () -- C:\WINDOWS\System32\nvmobrus.chm

[2009-01-08 18:41:51 | 00,189,104 | ---- | C] () -- C:\WINDOWS\System32\nvdspptb.chm

[2009-01-08 18:41:51 | 00,124,078 | ---- | C] () -- C:\WINDOWS\System32\nvcplptb.chm

[2009-01-08 18:41:51 | 00,118,410 | ---- | C] () -- C:\WINDOWS\System32\nv3dptb.chm

[2009-01-08 18:41:51 | 00,055,946 | ---- | C] () -- C:\WINDOWS\System32\nvmobptb.chm

[2009-01-08 18:41:50 | 00,129,550 | ---- | C] () -- C:\WINDOWS\System32\nv3dptg.chm

[2009-01-08 18:41:50 | 00,055,845 | ---- | C] () -- C:\WINDOWS\System32\nvmobptg.chm

[2009-01-08 18:41:49 | 00,194,380 | ---- | C] () -- C:\WINDOWS\System32\nvdspptg.chm

[2009-01-08 18:41:49 | 00,124,044 | ---- | C] () -- C:\WINDOWS\System32\nvcplptg.chm

[2009-01-08 18:41:48 | 00,205,816 | ---- | C] () -- C:\WINDOWS\System32\nvdspplk.chm

[2009-01-08 18:41:48 | 00,130,245 | ---- | C] () -- C:\WINDOWS\System32\nv3dplk.chm

[2009-01-08 18:41:48 | 00,124,019 | ---- | C] () -- C:\WINDOWS\System32\nvcplplk.chm

[2009-01-08 18:41:48 | 00,057,376 | ---- | C] () -- C:\WINDOWS\System32\nvmobplk.chm

[2009-01-08 18:41:47 | 00,055,525 | ---- | C] () -- C:\WINDOWS\System32\nvmobnor.chm

[2009-01-08 18:41:46 | 00,189,041 | ---- | C] () -- C:\WINDOWS\System32\nvdspnor.chm

[2009-01-08 18:41:46 | 00,120,026 | ---- | C] () -- C:\WINDOWS\System32\nvcplnor.chm

[2009-01-08 18:41:46 | 00,119,706 | ---- | C] () -- C:\WINDOWS\System32\nv3dnor.chm

[2009-01-08 18:41:45 | 00,189,364 | ---- | C] () -- C:\WINDOWS\System32\nvdspnld.chm

[2009-01-08 18:41:45 | 00,122,809 | ---- | C] () -- C:\WINDOWS\System32\nvcplnld.chm

[2009-01-08 18:41:45 | 00,118,401 | ---- | C] () -- C:\WINDOWS\System32\nv3dnld.chm

[2009-01-08 18:41:45 | 00,055,475 | ---- | C] () -- C:\WINDOWS\System32\nvmobnld.chm

[2009-01-08 18:41:44 | 00,132,251 | ---- | C] () -- C:\WINDOWS\System32\nv3dkor.chm

[2009-01-08 18:41:44 | 00,059,061 | ---- | C] () -- C:\WINDOWS\System32\nvmobkor.chm

[2009-01-08 18:41:43 | 00,224,281 | ---- | C] () -- C:\WINDOWS\System32\nvdspkor.chm

[2009-01-08 18:41:43 | 00,124,741 | ---- | C] () -- C:\WINDOWS\System32\nvcplkor.chm

[2009-01-08 18:41:42 | 00,251,599 | ---- | C] () -- C:\WINDOWS\System32\nvdspjpn.chm

[2009-01-08 18:41:42 | 00,144,421 | ---- | C] () -- C:\WINDOWS\System32\nv3djpn.chm

[2009-01-08 18:41:42 | 00,060,357 | ---- | C] () -- C:\WINDOWS\System32\nvmobjpn.chm

[2009-01-08 18:41:41 | 00,129,704 | ---- | C] () -- C:\WINDOWS\System32\nvcpljpn.chm

[2009-01-08 18:41:40 | 00,201,378 | ---- | C] () -- C:\WINDOWS\System32\nvdspita.chm

[2009-01-08 18:41:40 | 00,124,148 | ---- | C] () -- C:\WINDOWS\System32\nvcplita.chm

[2009-01-08 18:41:40 | 00,121,053 | ---- | C] () -- C:\WINDOWS\System32\nv3dita.chm

[2009-01-08 18:41:40 | 00,056,175 | ---- | C] () -- C:\WINDOWS\System32\nvmobita.chm

[2009-01-08 18:41:39 | 00,131,070 | ---- | C] () -- C:\WINDOWS\System32\nv3dhun.chm

[2009-01-08 18:41:39 | 00,057,512 | ---- | C] () -- C:\WINDOWS\System32\nvmobhun.chm

[2009-01-08 18:41:38 | 00,203,902 | ---- | C] () -- C:\WINDOWS\System32\nvdsphun.chm

[2009-01-08 18:41:38 | 00,125,552 | ---- | C] () -- C:\WINDOWS\System32\nvcplhun.chm

[2009-01-08 18:41:37 | 00,207,116 | ---- | C] () -- C:\WINDOWS\System32\nvdspheb.chm

[2009-01-08 18:41:37 | 00,132,088 | ---- | C] () -- C:\WINDOWS\System32\nv3dheb.chm

[2009-01-08 18:41:37 | 00,126,196 | ---- | C] () -- C:\WINDOWS\System32\nvcplheb.chm

[2009-01-08 18:41:37 | 00,058,340 | ---- | C] () -- C:\WINDOWS\System32\nvmobheb.chm

[2009-01-08 18:41:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2009-01-08 18:41:36 | 00,056,087 | ---- | C] () -- C:\WINDOWS\System32\nvmobfra.chm

[2009-01-08 18:41:35 | 00,189,184 | ---- | C] () -- C:\WINDOWS\System32\nvdspfra.chm

[2009-01-08 18:41:35 | 00,122,227 | ---- | C] () -- C:\WINDOWS\System32\nvcplfra.chm

[2009-01-08 18:41:35 | 00,119,315 | ---- | C] () -- C:\WINDOWS\System32\nv3dfra.chm

[2009-01-08 18:41:34 | 00,124,278 | ---- | C] () -- C:\WINDOWS\System32\nv3dfin.chm

[2009-01-08 18:41:34 | 00,056,934 | ---- | C] () -- C:\WINDOWS\System32\nvmobfin.chm

[2009-01-08 18:41:33 | 00,195,677 | ---- | C] () -- C:\WINDOWS\System32\nvdspfin.chm

[2009-01-08 18:41:33 | 00,124,544 | ---- | C] () -- C:\WINDOWS\System32\nvcplfin.chm

[2009-01-08 18:41:32 | 00,197,555 | ---- | C] () -- C:\WINDOWS\System32\nvdspesm.chm

[2009-01-08 18:41:32 | 00,124,138 | ---- | C] () -- C:\WINDOWS\System32\nvcplesm.chm

[2009-01-08 18:41:32 | 00,118,608 | ---- | C] () -- C:\WINDOWS\System32\nv3desm.chm

[2009-01-08 18:41:32 | 00,055,992 | ---- | C] () -- C:\WINDOWS\System32\nvmobesm.chm

[2009-01-08 18:41:31 | 00,117,909 | ---- | C] () -- C:\WINDOWS\System32\nv3desn.chm

[2009-01-08 18:41:31 | 00,055,669 | ---- | C] () -- C:\WINDOWS\System32\nvmobesn.chm

[2009-01-08 18:41:30 | 00,196,421 | ---- | C] () -- C:\WINDOWS\System32\nvdspesn.chm

[2009-01-08 18:41:30 | 00,124,084 | ---- | C] () -- C:\WINDOWS\System32\nvcplesn.chm

[2009-01-08 18:41:29 | 00,182,024 | ---- | C] () -- C:\WINDOWS\System32\nvdspeng.chm

[2009-01-08 18:41:29 | 00,121,758 | ---- | C] () -- C:\WINDOWS\System32\nvcpleng.chm

[2009-01-08 18:41:29 | 00,117,083 | ---- | C] () -- C:\WINDOWS\System32\nv3deng.chm

[2009-01-08 18:41:29 | 00,055,103 | ---- | C] () -- C:\WINDOWS\System32\nvmobeng.chm

[2009-01-08 18:41:28 | 00,131,422 | ---- | C] () -- C:\WINDOWS\System32\nv3dell.chm

[2009-01-08 18:41:28 | 00,059,100 | ---- | C] () -- C:\WINDOWS\System32\nvmobell.chm

[2009-01-08 18:41:27 | 00,220,768 | ---- | C] () -- C:\WINDOWS\System32\nvdspell.chm

[2009-01-08 18:41:27 | 00,126,670 | ---- | C] () -- C:\WINDOWS\System32\nvcplell.chm

[2009-01-08 18:41:26 | 00,197,544 | ---- | C] () -- C:\WINDOWS\System32\nvdspdeu.chm

[2009-01-08 18:41:26 | 00,123,526 | ---- | C] () -- C:\WINDOWS\System32\nv3ddeu.chm

[2009-01-08 18:41:26 | 00,056,087 | ---- | C] () -- C:\WINDOWS\System32\nvmobdeu.chm

[2009-01-08 18:41:25 | 00,124,590 | ---- | C] () -- C:\WINDOWS\System32\nvcpldeu.chm

[2009-01-08 18:41:25 | 00,118,926 | ---- | C] () -- C:\WINDOWS\System32\nv3ddan.chm

[2009-01-08 18:41:25 | 00,055,622 | ---- | C] () -- C:\WINDOWS\System32\nvmobdan.chm

[2009-01-08 18:41:24 | 00,188,707 | ---- | C] () -- C:\WINDOWS\System32\nvdspdan.chm

[2009-01-08 18:41:24 | 00,120,933 | ---- | C] () -- C:\WINDOWS\System32\nvcpldan.chm

[2009-01-08 18:41:23 | 00,219,156 | ---- | C] () -- C:\WINDOWS\System32\nvdspcsy.chm

[2009-01-08 18:41:23 | 00,128,958 | ---- | C] () -- C:\WINDOWS\System32\nv3dcsy.chm

[2009-01-08 18:41:23 | 00,124,067 | ---- | C] () -- C:\WINDOWS\System32\nvcplcsy.chm

[2009-01-08 18:41:23 | 00,057,387 | ---- | C] () -- C:\WINDOWS\System32\nvmobcsy.chm

[2009-01-08 18:41:22 | 00,200,405 | ---- | C] () -- C:\WINDOWS\System32\nvdspara.chm

[2009-01-08 18:41:22 | 00,128,544 | ---- | C] () -- C:\WINDOWS\System32\nv3dara.chm

[2009-01-08 18:41:22 | 00,125,735 | ---- | C] () -- C:\WINDOWS\System32\nvcplara.chm

[2009-01-08 18:41:22 | 00,057,328 | ---- | C] () -- C:\WINDOWS\System32\nvmobara.chm

[2009-01-08 18:41:20 | 00,116,384 | ---- | C] () -- C:\WINDOWS\System32\nv3d.chm

[2009-01-08 18:41:20 | 00,054,988 | ---- | C] () -- C:\WINDOWS\System32\nvmob.chm

[2009-01-08 18:41:19 | 00,181,895 | ---- | C] () -- C:\WINDOWS\System32\nvdsp.chm

[2009-01-08 18:41:19 | 00,121,529 | ---- | C] () -- C:\WINDOWS\System32\nvcpl.chm

[2009-01-08 18:41:14 | 00,018,335 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu

[2009-01-08 18:40:19 | 00,003,948 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin

[2009-01-08 18:40:05 | 00,002,344 | ---- | C] () -- C:\WINDOWS\System32\nvsmb.nvu

[2009-01-08 18:39:48 | 00,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav

[2009-01-08 18:39:48 | 00,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav

[2009-01-08 18:39:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang

[2009-01-08 18:38:23 | 00,000,553 | ---- | C] () -- C:\WINDOWS\USetup.iss

[2009-01-08 18:38:19 | 00,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\splitter.sys

[2009-01-08 18:38:18 | 00,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wdmaud.sys

[2009-01-08 18:38:17 | 00,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dmusic.sys

[2009-01-08 18:38:14 | 00,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\swmidi.sys

[2009-01-08 18:38:13 | 00,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aec.sys

[2009-01-08 18:38:12 | 00,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kmixer.sys

[2009-01-08 18:38:12 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmkaud.sys

[2009-01-08 18:38:11 | 00,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sysaudio.sys

[2009-01-08 18:38:06 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM

[2009-01-08 18:38:04 | 00,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys

[2009-01-08 18:38:04 | 00,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys

[2009-01-08 18:37:37 | 00,026,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe

[2009-01-08 18:37:01 | 02,808,832 | ---- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\ALCWZRD.EXE

[2009-01-08 18:36:59 | 00,000,000 | ---D | C] -- C:\Program\Realtek

[2009-01-08 18:36:45 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\InstallShield

[2009-01-08 18:34:58 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups

[2009-01-08 18:34:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE

[2009-01-08 18:34:53 | 00,000,000 | -H-D | C] -- C:\Program\InstallShield Installation Information

[2009-01-08 18:34:53 | 00,000,000 | ---D | C] -- C:\Program\AMD

[2009-01-08 18:34:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\InstallShield

[2009-01-08 18:29:54 | 04,838,642 | -H-- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\IconCache.db

[2009-01-08 18:29:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\AsusInstAll

[2009-01-08 18:27:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Symantec

[2009-01-08 18:26:35 | 00,000,000 | ---D | C] -- C:\Program\Windows Sidebar

[2009-01-08 18:26:14 | 00,000,000 | ---D | C] -- C:\Program\Norton Internet Security

[2009-01-08 18:24:05 | 00,124,464 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS

[2009-01-08 18:24:05 | 00,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL

[2009-01-08 18:24:05 | 00,010,635 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT

[2009-01-08 18:24:05 | 00,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF

[2009-01-08 18:24:01 | 00,000,000 | ---D | C] -- C:\Program\Symantec

[2009-01-08 18:24:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec

[2009-01-08 18:23:42 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Symantec Shared

[2009-01-08 18:23:21 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$

[2009-01-08 18:22:20 | 00,028,821 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini

[2009-01-08 18:21:48 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys

[2009-01-08 18:21:41 | 00,028,499 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini

[2009-01-08 18:21:41 | 00,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

[2009-01-08 18:20:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Identities

[2009-01-08 18:20:32 | 00,000,000 | -H-D | C] -- C:\Program\Uninstall Information

[2009-01-08 18:20:29 | 00,000,089 | -HS- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\desktop.ini

[2009-01-08 18:20:29 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Mina bilder

[2009-01-08 18:20:29 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Min musik

[2009-01-08 18:20:26 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Start-meny\Program\Autostart\desktop.ini

[2009-01-08 18:20:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\desktop.ini

[2009-01-08 18:20:25 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\Microsoft

[2009-01-08 18:20:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Microsoft

[2009-01-08 18:19:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\SDOLD

[2009-01-08 18:19:28 | 00,000,006 | -H-- | C] () -- C:\WINDOWS\tasks\SA.DAT

[2009-01-08 18:19:28 | 00,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft

[2009-01-08 18:19:11 | 00,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD

[2009-01-08 18:18:25 | 00,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2009-01-08 18:18:19 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winzm.ime

[2009-01-08 18:18:19 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsp.ime

[2009-01-08 18:18:19 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winpy.ime

[2009-01-08 18:18:18 | 00,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winar30.ime

[2009-01-08 18:18:18 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wingb.ime

[2009-01-08 18:18:18 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winime.ime

[2009-01-08 18:18:17 | 00,426,041 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicepad.dll

[2009-01-08 18:18:17 | 00,086,073 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicesub.dll

[2009-01-08 18:18:17 | 00,048,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w32.dll

[2009-01-08 18:18:17 | 00,041,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.dll

[2009-01-08 18:18:17 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.sys

[2009-01-08 18:18:16 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniime.dll

[2009-01-08 18:18:16 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unicdime.ime

[2009-01-08 18:18:15 | 00,571,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlgnt.ime

[2009-01-08 18:18:15 | 00,455,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintsetp.exe

[2009-01-08 18:18:15 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlphr.exe

[2009-01-08 18:18:15 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsprof.exe

[2009-01-08 18:18:15 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tmigrate.dll

[2009-01-08 18:18:14 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\thawbrkr.dll

[2009-01-08 18:18:14 | 00,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdipx.sys

[2009-01-08 18:18:14 | 00,019,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdspx.sys

[2009-01-08 18:18:14 | 00,013,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdasync.sys

[2009-01-08 18:18:13 | 00,143,422 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\softkey.dll

[2009-01-08 18:18:13 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusbusd.dll

[2009-01-08 18:18:12 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpstup.dll

[2009-01-08 18:18:12 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll

[2009-01-08 18:18:11 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb6w.dll

[2009-01-08 18:18:11 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma3w.dll

[2009-01-08 18:18:11 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsm.dll

[2009-01-08 18:18:11 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll

[2009-01-08 18:18:11 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smimsgif.dll

[2009-01-08 18:18:11 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsy.dll

[2009-01-08 18:18:10 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm9aw.dll

[2009-01-08 18:18:10 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm87w.dll

[2009-01-08 18:18:10 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm81w.dll

[2009-01-08 18:18:10 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8cw.dll

[2009-01-08 18:18:10 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm93w.dll

[2009-01-08 18:18:10 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm92w.dll

[2009-01-08 18:18:10 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm90w.dll

[2009-01-08 18:18:10 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8dw.dll

[2009-01-08 18:18:10 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8aw.dll

[2009-01-08 18:18:10 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm89w.dll

[2009-01-08 18:18:10 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm59w.dll

[2009-01-08 18:18:10 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\simptcp.dll

[2009-01-08 18:18:08 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll

[2009-01-08 18:18:08 | 00,080,384 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll

[2009-01-08 18:18:08 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_scripto.dll

[2009-01-08 18:18:08 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_seos.dll

[2009-01-08 18:18:07 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\romanime.ime

[2009-01-08 18:18:07 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe

[2009-01-08 18:18:07 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\register.exe

[2009-01-08 18:18:06 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quick.ime

[2009-01-08 18:18:06 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quser.exe

[2009-01-08 18:18:05 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxviceo.dll

[2009-01-08 18:18:05 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxmcro.dll

[2009-01-08 18:18:05 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.exe

[2009-01-08 18:18:05 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxgl.dll

[2009-01-08 18:18:04 | 00,482,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlgnt.ime

[2009-01-08 18:18:04 | 00,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll

[2009-01-08 18:18:04 | 00,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phon.ime

[2009-01-08 18:18:04 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlphr.exe

[2009-01-08 18:18:04 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmigrate.dll

[2009-01-08 18:18:04 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlcsd.dll

[2009-01-08 18:18:04 | 00,036,927 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs411.dll

[2009-01-08 18:18:04 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs804.dll

[2009-01-08 18:18:04 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs412.dll

[2009-01-08 18:18:03 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs404.dll

[2009-01-08 18:18:02 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll

[2009-01-08 18:18:01 | 00,229,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\multibox.dll

[2009-01-08 18:17:59 | 01,875,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.lex

[2009-01-08 18:17:59 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.dll

[2009-01-08 18:17:57 | 00,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.sys

[2009-01-08 18:17:57 | 00,092,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.dll

[2009-01-08 18:17:56 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll

[2009-01-08 18:17:54 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex

[2009-01-08 18:17:54 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\korwbrkr.dll

[2009-01-08 18:17:54 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth3.dll

[2009-01-08 18:17:54 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth2.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdvntc.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdusa.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdurdu.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth1.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth0.dll

[2009-01-08 18:17:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr2.dll

[2009-01-08 18:17:53 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecat.dll

[2009-01-08 18:17:53 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecnt.dll

[2009-01-08 18:17:53 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnec95.dll

[2009-01-08 18:17:53 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinpun.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr1.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintel.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintam.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinmar.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinkan.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinhin.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinguj.dll

[2009-01-08 18:17:53 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdindev.dll

[2009-01-08 18:17:52 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101a.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdheb.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdfa.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv2.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv1.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda3.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda2.dll

[2009-01-08 18:17:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda1.dll

[2009-01-08 18:17:52 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgeo.dll

[2009-01-08 18:17:52 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarmw.dll

[2009-01-08 18:17:52 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarme.dll

[2009-01-08 18:17:51 | 00,315,455 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskf.dll

[2009-01-08 18:17:51 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jupiw.dll

[2009-01-08 18:17:50 | 00,471,102 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskdic.dll

[2009-01-08 18:17:50 | 00,274,489 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputyc.dll

[2009-01-08 18:17:50 | 00,262,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputy.exe

[2009-01-08 18:17:50 | 00,233,527 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjprw.exe

[2009-01-08 18:17:50 | 00,208,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpmig.exe

[2009-01-08 18:17:50 | 00,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe

[2009-01-08 18:17:50 | 00,155,705 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdsvr.exe

[2009-01-08 18:17:50 | 00,102,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imlang.dll

[2009-01-08 18:17:50 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imkrinst.exe

[2009-01-08 18:17:50 | 00,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe

[2009-01-08 18:17:50 | 00,045,109 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpuex.exe

[2009-01-08 18:17:49 | 00,811,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81k.dll

[2009-01-08 18:17:49 | 00,716,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcus.dll

[2009-01-08 18:17:49 | 00,368,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcic.dll

[2009-01-08 18:17:49 | 00,340,023 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81.ime

[2009-01-08 18:17:49 | 00,311,359 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsv.exe

[2009-01-08 18:17:49 | 00,307,257 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.exe

[2009-01-08 18:17:49 | 00,102,463 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsm.dll

[2009-01-08 18:17:49 | 00,081,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.dll

[2009-01-08 18:17:49 | 00,057,398 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdadm.exe

[2009-01-08 18:17:49 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmig.exe

[2009-01-08 18:17:48 | 00,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex

[2009-01-08 18:17:48 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrcic.dll

[2009-01-08 18:17:48 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekr61.ime

[2009-01-08 18:17:48 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmbx.dll

[2009-01-08 18:17:45 | 10,129,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxkor.dll

[2009-01-08 18:17:42 | 13,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll

[2009-01-08 18:17:40 | 10,096,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxcht.dll

[2009-01-08 18:17:39 | 00,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex

[2009-01-08 18:17:39 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hanjadic.dll

[2009-01-08 18:17:38 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsroute.dll

[2009-01-08 18:17:38 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssend.exe

[2009-01-08 18:17:37 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclntr.dll

[2009-01-08 18:17:37 | 00,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscfgwz.dll

[2009-01-08 18:17:37 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftlx041e.dll

[2009-01-08 18:17:36 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll

[2009-01-08 18:17:36 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\flattemp.exe

[2009-01-08 18:17:35 | 00,514,587 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\edb500.dll

[2009-01-08 18:17:35 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll

[2009-01-08 18:17:35 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll

[2009-01-08 18:17:35 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll

[2009-01-08 18:17:35 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\et4000.sys

[2009-01-08 18:17:32 | 00,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dayi.ime

[2009-01-08 18:17:31 | 00,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintsetp.exe

[2009-01-08 18:17:31 | 00,057,399 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cplexe.exe

[2009-01-08 18:17:31 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cprofile.exe

[2009-01-08 18:17:30 | 01,677,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chsbrkr.dll

[2009-01-08 18:17:30 | 00,838,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtbrkr.dll

[2009-01-08 18:17:30 | 00,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintime.dll

[2009-01-08 18:17:30 | 00,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll

[2009-01-08 18:17:30 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtmbx.dll

[2009-01-08 18:17:30 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtskdic.dll

[2009-01-08 18:17:30 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintlgnt.ime

[2009-01-08 18:17:29 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chajei.ime

[2009-01-08 18:17:29 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgport.exe

[2009-01-08 18:17:29 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgusr.exe

[2009-01-08 18:17:29 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chglogon.exe

[2009-01-08 18:17:29 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\change.exe

[2009-01-08 18:17:28 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys

[2009-01-08 18:17:28 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_iscii.dll

[2009-01-08 18:17:28 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_is2022.dll

[2009-01-08 18:17:23 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll

[2009-01-08 18:17:22 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll

[2009-01-08 18:17:20 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptsat.dll

[2009-01-08 18:17:17 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll

[2009-01-08 18:17:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom

[2009-01-08 18:17:13 | 00,000,000 | ---D | C] -- C:\Program\xerox

[2009-01-08 18:17:13 | 00,000,000 | ---D | C] -- C:\Program\microsoft frontpage

[2009-01-08 18:17:08 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$

[2009-01-08 18:16:57 | 00,002,578 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT

[2009-01-08 18:16:57 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS

[2009-01-08 18:16:57 | 00,000,000 | RHS- | C] () -- C:\IO.SYS

[2009-01-08 18:16:57 | 00,000,000 | ---- | C] () -- C:\WINDOWS\control.ini

[2009-01-08 18:16:57 | 00,000,000 | ---- | C] () -- C:\CONFIG.SYS

[2009-01-08 18:16:57 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT

[2009-01-08 18:16:54 | 00,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx

[2009-01-08 18:16:54 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb

[2009-01-08 18:16:54 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb

[2009-01-08 18:16:46 | 00,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mapi32.dll

[2009-01-08 18:16:09 | 00,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files

[2009-01-08 18:16:09 | 00,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages

[2009-01-08 18:16:01 | 00,000,000 | -H-D | C] -- C:\Program\WindowsUpdate

[2009-01-08 18:15:58 | 00,000,000 | ---D | C] -- C:\Program\Onlinetjänster

[2009-01-08 18:15:52 | 04,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex

[2009-01-08 18:15:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX

[2009-01-08 18:15:33 | 00,099,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helphost.exe

[2009-01-08 18:15:33 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\notiflag.exe

[2009-01-08 18:15:33 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\brpinfo.dll

[2009-01-08 18:15:33 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\atrace.dll

[2009-01-08 18:15:33 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\atrace.dll

[2009-01-08 18:15:33 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hcappres.dll

[2009-01-08 18:15:31 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp

[2009-01-08 18:15:31 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp

[2009-01-08 18:15:31 | 00,000,002 | ---- | C] () -- C:\WINDOWS\System32\desktop.ini

[2009-01-08 18:15:31 | 00,000,002 | ---- | C] () -- C:\WINDOWS\desktop.ini

[2009-01-08 18:15:26 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msg723.acm

[2009-01-08 18:15:26 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srdiag.exe

[2009-01-08 18:15:26 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmevtmsg.dll

[2009-01-08 18:15:26 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmevtmsg.dll

[2009-01-08 18:15:26 | 00,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf

[2009-01-08 18:15:25 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\acctres.dll

[2009-01-08 18:15:25 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\acctres.dll

[2009-01-08 18:15:25 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msinfo32.exe

[2009-01-08 18:15:25 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wb32.exe

[2009-01-08 18:15:25 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cb32.exe

[2009-01-08 18:15:24 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\Services

[2009-01-08 18:15:23 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icfgnt5.dll

[2009-01-08 18:15:23 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icfgnt5.dll

[2009-01-08 18:15:23 | 00,000,065 | RH-- | C] () -- C:\WINDOWS\tasks\desktop.ini

[2009-01-08 18:15:23 | 00,000,000 | --SD | C] -- C:\WINDOWS\Tasks

[2009-01-08 18:15:22 | 00,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mssoap1.dll

[2009-01-08 18:15:22 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwtutor.exe

[2009-01-08 18:15:22 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwres.dll

[2009-01-08 18:15:22 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\trialoc.dll

[2009-01-08 18:15:22 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wisc10.dll

[2009-01-08 18:15:22 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mssoapr.dll

[2009-01-08 18:15:22 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isignup.exe

[2009-01-08 18:15:22 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\MSSoap

[2009-01-08 18:15:21 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieinfo5.ocx

[2009-01-08 18:15:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed

[2009-01-08 18:15:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\srchasst

[2009-01-08 18:15:18 | 01,670,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setup_wm.exe

[2009-01-08 18:15:18 | 00,786,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\migrate.exe

[2009-01-08 18:15:18 | 00,244,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpvis.dll

[2009-01-08 18:15:18 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmpns.dll

[2009-01-08 18:15:18 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmpband.dll

[2009-01-08 18:15:18 | 00,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmplayer.exe

[2009-01-08 18:15:18 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\custsat.dll

[2009-01-08 18:15:17 | 00,364,544 | ---- | C] (Microsoft Corporation (written by Digital Renaissance Inc.)) -- C:\WINDOWS\System32\dllcache\npdsplay.dll

[2009-01-08 18:15:17 | 00,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll

[2009-01-08 18:15:17 | 00,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wucltui.dll

[2009-01-08 18:15:17 | 00,226,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\npdrmv2.dll

[2009-01-08 18:15:17 | 00,202,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuweb.dll

[2009-01-08 18:15:17 | 00,202,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuweb.dll

[2009-01-08 18:15:17 | 00,183,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll

[2009-01-08 18:15:17 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\npwmsdrm.dll

[2009-01-08 18:15:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauserv.dll

[2009-01-08 18:15:17 | 00,004,639 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mplayer2.exe

[2009-01-08 18:15:16 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng.dll

[2009-01-08 18:15:16 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaueng.dll

[2009-01-08 18:15:16 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll

[2009-01-08 18:15:16 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuapi.dll

[2009-01-08 18:15:16 | 00,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgr.dll

[2009-01-08 18:15:16 | 00,213,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl

[2009-01-08 18:15:16 | 00,213,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaucpl.cpl

[2009-01-08 18:15:16 | 00,166,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe

[2009-01-08 18:15:16 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt.exe

[2009-01-08 18:15:16 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauclt.exe

[2009-01-08 18:15:16 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll

[2009-01-08 18:15:16 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wups.dll

[2009-01-08 18:15:16 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgrprxy.dll

[2009-01-08 18:15:16 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll

[2009-01-08 18:15:16 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll

[2009-01-08 18:15:13 | 00,000,000 | ---D | C] -- C:\Program\Movie Maker

[2009-01-08 18:15:10 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrslv.dll

[2009-01-08 18:15:10 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrcdlg.dll

[2009-01-08 18:15:10 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\racpldlg.dll

[2009-01-08 18:15:10 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrdm.dll

[2009-01-08 18:15:08 | 00,240,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srrstr.dll

[2009-01-08 18:15:08 | 00,171,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srsvc.dll

[2009-01-08 18:15:08 | 00,129,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fltmgr.sys

[2009-01-08 18:15:08 | 00,073,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sr.sys

[2009-01-08 18:15:08 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srclient.dll

[2009-01-08 18:15:08 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltmc.exe

[2009-01-08 18:15:08 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltlib.dll

[2009-01-08 18:15:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore

[2009-01-08 18:15:07 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msh261.drv

[2009-01-08 18:15:07 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ils.dll

[2009-01-08 18:15:07 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msconf.dll

[2009-01-08 18:15:07 | 00,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmdd.dll

[2009-01-08 18:15:07 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmsrvc.exe

[2009-01-08 18:15:07 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmmkcert.dll

[2009-01-08 18:15:05 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoeacct.dll

[2009-01-08 18:15:05 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoert2.dll

[2009-01-08 18:15:05 | 00,000,000 | ---D | C] -- C:\Program\NetMeeting

[2009-01-08 18:15:04 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcomm.dll

[2009-01-08 18:15:04 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetres.dll

[2009-01-08 18:15:03 | 00,277,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstask.dll

[2009-01-08 18:15:03 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\schedsvc.dll

[2009-01-08 18:15:03 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstinit.exe

[2009-01-08 18:15:03 | 00,000,000 | ---D | C] -- C:\Program\Outlook Express

[2009-01-08 18:15:02 | 00,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcfg.dll

[2009-01-08 18:15:02 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\isign32.dll

[2009-01-08 18:15:02 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwdial.dll

[2009-01-08 18:15:02 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwphbk.dll

[2009-01-08 18:14:58 | 00,000,000 | ---D | C] -- C:\Program\Internet Explorer

[2009-01-08 18:14:58 | 00,000,000 | ---D | C] -- C:\Program\Delade filer\System

[2009-01-08 18:14:57 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokument\Mina bilder

[2009-01-08 18:14:56 | 00,021,700 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2009-01-08 18:14:47 | 00,000,000 | ---D | C] -- C:\Program\ComPlus Applications

[2009-01-08 18:14:46 | 00,000,037 | ---- | C] () -- C:\WINDOWS\vbaddin.ini

[2009-01-08 18:14:46 | 00,000,036 | ---- | C] () -- C:\WINDOWS\vb.ini

[2009-01-08 18:14:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Registration

[2009-01-08 18:14:19 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokument\Min musik

[2009-01-08 18:14:19 | 00,000,000 | ---D | C] -- C:\Program\Windows Media Player

[2009-01-08 18:14:15 | 01,817,687 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckgres.dll

[2009-01-08 18:14:15 | 00,753,236 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvseres.dll

[2009-01-08 18:14:15 | 00,082,501 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckg.dll

[2009-01-08 18:14:15 | 00,048,706 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvse.dll

[2009-01-08 18:14:15 | 00,042,577 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckgzm.exe

[2009-01-08 18:14:15 | 00,042,574 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvsezm.exe

[2009-01-08 18:14:15 | 00,000,000 | ---D | C] -- C:\Program\Messenger

[2009-01-08 18:14:14 | 02,178,131 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvlres.dll

[2009-01-08 18:14:14 | 01,175,635 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtzres.dll

[2009-01-08 18:14:14 | 00,780,885 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkrres.dll

[2009-01-08 18:14:14 | 00,066,113 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvl.dll

[2009-01-08 18:14:14 | 00,057,409 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtz.dll

[2009-01-08 18:14:14 | 00,042,575 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkrzm.exe

[2009-01-08 18:14:14 | 00,042,573 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvlzm.exe

[2009-01-08 18:14:14 | 00,042,573 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtzzm.exe

[2009-01-08 18:14:14 | 00,041,029 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zcorem.dll

[2009-01-08 18:14:14 | 00,040,515 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkr.dll

[2009-01-08 18:14:14 | 00,032,339 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniansi.dll

[2009-01-08 18:14:14 | 00,013,894 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zonelibm.dll

[2009-01-08 18:14:14 | 00,004,677 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zeeverm.dll

[2009-01-08 18:14:13 | 01,040,467 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmnresm.dll

[2009-01-08 18:14:13 | 00,217,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmnclim.dll

[2009-01-08 18:14:13 | 00,113,222 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zoneclim.dll

[2009-01-08 18:14:13 | 00,036,937 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zclientm.exe

[2009-01-08 18:14:13 | 00,029,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\znetm.dll

[2009-01-08 18:14:13 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\write.exe

[2009-01-08 18:14:13 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\write.exe

[2009-01-08 18:14:13 | 00,000,000 | ---D | C] -- C:\Program\MSN Gaming Zone

[2009-01-08 18:14:07 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndvol32.exe

[2009-01-08 18:14:07 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sndvol32.exe

[2009-01-08 18:14:06 | 00,228,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avtapi.dll

[2009-01-08 18:14:06 | 00,228,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avtapi.dll

[2009-01-08 18:14:06 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avwav.dll

[2009-01-08 18:14:06 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avwav.dll

[2009-01-08 18:14:06 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winchat.exe

[2009-01-08 18:14:06 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winchat.exe

[2009-01-08 18:14:06 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avmeter.dll

[2009-01-08 18:14:06 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avmeter.dll

[2009-01-08 18:14:03 | 00,065,832 | ---- | C] () -- C:\WINDOWS\Ökensand.bmp

[2009-01-08 18:14:03 | 00,009,522 | ---- | C] () -- C:\WINDOWS\Kalejdoskop.bmp

[2009-01-08 18:14:02 | 00,065,978 | ---- | C] () -- C:\WINDOWS\Bubblor.bmp

[2009-01-08 18:14:02 | 00,065,954 | ---- | C] () -- C:\WINDOWS\Gotlandsbris.bmp

[2009-01-08 18:14:02 | 00,026,680 | ---- | C] () -- C:\WINDOWS\Solfjädrar.bmp

[2009-01-08 18:14:02 | 00,026,582 | ---- | C] () -- C:\WINDOWS\Ärgad koppar.bmp

[2009-01-08 18:14:02 | 00,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp

[2009-01-08 18:14:02 | 00,017,336 | ---- | C] () -- C:\WINDOWS\Fisketur.bmp

[2009-01-08 18:14:02 | 00,017,062 | ---- | C] () -- C:\WINDOWS\Kaffekoppar.bmp

[2009-01-08 18:14:02 | 00,016,730 | ---- | C] () -- C:\WINDOWS\Fjädrar.bmp

[2009-01-08 18:14:02 | 00,001,272 | ---- | C] () -- C:\WINDOWS\Vaxduk.bmp

[2009-01-08 18:14:01 | 00,605,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\getuname.dll

[2009-01-08 18:14:01 | 00,605,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\getuname.dll

[2009-01-08 18:14:01 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winmine.exe

[2009-01-08 18:14:01 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmine.exe

[2009-01-08 18:14:01 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\calc.exe

[2009-01-08 18:14:01 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\calc.exe

[2009-01-08 18:14:01 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\charmap.exe

[2009-01-08 18:14:01 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\charmap.exe

[2009-01-08 18:14:01 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sol.exe

[2009-01-08 18:14:01 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sol.exe

[2009-01-08 18:14:00 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshearts.exe

[2009-01-08 18:14:00 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshearts.exe

[2009-01-08 18:14:00 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\freecell.exe

[2009-01-08 18:14:00 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\freecell.exe

[2009-01-08 18:14:00 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regini.exe

[2009-01-08 18:14:00 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\regini.exe

[2009-01-08 18:14:00 | 00,025,971 | ---- | C] () -- C:\WINDOWS\System32\tslabels.ini

[2009-01-08 18:14:00 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qwinsta.exe

[2009-01-08 18:14:00 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qwinsta.exe

[2009-01-08 18:14:00 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsshutdn.exe

[2009-01-08 18:14:00 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsshutdn.exe

[2009-01-08 18:14:00 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qappsrv.exe

[2009-01-08 18:14:00 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qappsrv.exe

[2009-01-08 18:14:00 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tskill.exe

[2009-01-08 18:14:00 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwinsta.exe

[2009-01-08 18:14:00 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tskill.exe

[2009-01-08 18:14:00 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwinsta.exe

[2009-01-08 18:14:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscon.exe

[2009-01-08 18:14:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tscon.exe

[2009-01-08 18:14:00 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsdiscon.exe

[2009-01-08 18:14:00 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shadow.exe

[2009-01-08 18:14:00 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsdiscon.exe

[2009-01-08 18:14:00 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shadow.exe

[2009-01-08 18:14:00 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reset.exe

[2009-01-08 18:14:00 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\reset.exe

[2009-01-08 18:14:00 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpcfgex.dll

[2009-01-08 18:14:00 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpcfgex.dll

[2009-01-08 18:14:00 | 00,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h

[2009-01-08 18:14:00 | 00,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd

[2009-01-08 18:13:59 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxlegih.dll

[2009-01-08 18:13:59 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxdm.dll

[2009-01-08 18:13:59 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msg.exe

[2009-01-08 18:13:59 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msg.exe

[2009-01-08 18:13:59 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtsadmin.tlb

[2009-01-08 18:13:59 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdmodem.dll

[2009-01-08 18:13:59 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdmodem.dll

[2009-01-08 18:13:59 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logoff.exe

[2009-01-08 18:13:59 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logoff.exe

[2009-01-08 18:13:59 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dcomcnfg.exe

[2009-01-08 18:13:59 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxex.dll

[2009-01-08 18:13:59 | 00,003,809 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.ini

[2009-01-08 18:13:59 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h

[2009-01-08 18:13:58 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsnap.dll

[2009-01-08 18:13:58 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comrepl.dll

[2009-01-08 18:13:58 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stclient.dll

[2009-01-08 18:13:58 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmi2xml.dll

[2009-01-08 18:13:58 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comaddin.dll

[2009-01-08 18:13:56 | 00,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipicmp.dll

[2009-01-08 18:13:56 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmimsg.dll

[2009-01-08 18:13:56 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemdisp.tlb

[2009-01-08 18:13:56 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmitimep.dll

[2009-01-08 18:13:56 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemads.tlb

[2009-01-08 18:13:56 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmgmtr.dll

[2009-01-08 18:13:56 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmgmt.exe

[2009-01-08 18:13:56 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemads.dll

[2009-01-08 18:13:55 | 00,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msiprov.dll

[2009-01-08 18:13:55 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dsprov.dll

[2009-01-08 18:13:55 | 00,116,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\updprov.dll

[2009-01-08 18:13:55 | 00,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc

[2009-01-08 18:13:55 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tmplprov.dll

[2009-01-08 18:13:55 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\trnsprov.dll

[2009-01-08 18:13:55 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fwdprov.dll

[2009-01-08 18:13:55 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpcons.dll

[2009-01-08 18:13:55 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unsecapp.exe

[2009-01-08 18:13:54 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\accwiz.exe

[2009-01-08 18:13:54 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndrec32.exe

[2009-01-08 18:13:54 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mplay32.exe

[2009-01-08 18:13:54 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mplay32.exe

[2009-01-08 18:13:54 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\access.cpl

[2009-01-08 18:13:53 | 00,538,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe

[2009-01-08 18:13:53 | 00,343,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspaint.exe

[2009-01-08 18:13:53 | 00,139,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rdpwd.sys

[2009-01-08 18:13:53 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clipbrd.exe

[2009-01-08 18:13:53 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscfgwmi.dll

[2009-01-08 18:13:53 | 00,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdtcp.sys

[2009-01-08 18:13:53 | 00,012,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdpipe.sys

[2009-01-08 18:13:53 | 00,000,000 | ---D | C] -- C:\Program\Windows NT

[2009-01-08 18:13:52 | 02,061,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstscax.dll

[2009-01-08 18:13:52 | 00,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstsc.exe

[2009-01-08 18:13:52 | 00,655,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstscax.dll

[2009-01-08 18:13:52 | 00,406,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstsc.exe

[2009-01-08 18:13:52 | 00,295,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\termsrv.dll

[2009-01-08 18:13:52 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdchost.dll

[2009-01-08 18:13:52 | 00,141,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sessmgr.exe

[2009-01-08 18:13:52 | 00,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll

[2009-01-08 18:13:52 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdshost.exe

[2009-01-08 18:13:52 | 00,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpclip.exe

[2009-01-08 18:13:52 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\remotepg.dll

[2009-01-08 18:13:52 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscupgrd.exe

[2009-01-08 18:13:52 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tscupgrd.exe

[2009-01-08 18:13:52 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qprocess.exe

[2009-01-08 18:13:52 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpsnd.dll

[2009-01-08 18:13:52 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdsaddin.exe

[2009-01-08 18:13:51 | 00,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll

[2009-01-08 18:13:51 | 00,427,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll

[2009-01-08 18:13:51 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcuiu.dll

[2009-01-08 18:13:51 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxoci.dll

[2009-01-08 18:13:51 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll

[2009-01-08 18:13:51 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgbkend.dll

[2009-01-08 18:13:51 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll

[2009-01-08 18:13:51 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icaapi.dll

[2009-01-08 18:13:51 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtc.exe

[2009-01-08 18:13:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc

[2009-01-08 18:13:50 | 01,267,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsvcs.dll

[2009-01-08 18:13:50 | 00,625,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvut.dll

[2009-01-08 18:13:50 | 00,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrv.dll

[2009-01-08 18:13:50 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatex.dll

[2009-01-08 18:13:50 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvps.dll

[2009-01-08 18:13:50 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\colbact.dll

[2009-01-08 18:13:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Com

[2009-01-08 18:13:49 | 00,539,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comuid.dll

[2009-01-08 18:13:49 | 00,498,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatq.dll

[2009-01-08 18:13:46 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licwmi.dll

[2009-01-08 18:13:46 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\servdeps.dll

[2009-01-08 18:13:46 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmfutil.dll

[2009-01-08 18:13:45 | 00,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmprops.dll

[2009-01-08 18:13:43 | 00,196,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rdpdr.sys

[2009-01-08 18:13:43 | 00,040,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\termdd.sys

 

========== Files - Modified Within 30 Days ==========

 

[1 C:\WINDOWS\System32\*.tmp files]

[9 C:\WINDOWS\*.tmp files]

[2009-01-17 09:32:15 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\OTViewIt.exe

[2009-01-17 00:32:30 | 00,031,744 | -HS- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Thumbs.db

@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Thumbs.db:encryptable

[2009-01-17 00:32:00 | 00,013,824 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-01-17 00:27:19 | 00,076,489 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bf0f5.jpg

[2009-01-17 00:25:14 | 00,075,047 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bea01.jpg

[2009-01-17 00:22:34 | 00,089,290 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\PhotoFunia_2bdfd6.jpg

[2009-01-16 22:39:45 | 00,057,472 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\biiindaaa.jpg

[2009-01-16 20:22:00 | 00,000,272 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-01-16 19:41:59 | 00,966,698 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009-01-16 19:41:59 | 00,408,948 | ---- | M] () -- C:\WINDOWS\System32\perfh01D.dat

[2009-01-16 19:41:59 | 00,406,328 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009-01-16 19:41:59 | 00,075,310 | ---- | M] () -- C:\WINDOWS\System32\perfc01D.dat

[2009-01-16 19:41:59 | 00,063,528 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009-01-16 19:38:08 | 00,199,604 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2009-01-16 19:37:56 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009-01-16 19:37:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009-01-16 19:37:30 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009-01-16 19:37:24 | 00,166,712 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009-01-16 16:56:28 | 00,057,462 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\1023468.jpg

[2009-01-16 16:48:27 | 00,026,057 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\sx8ee7cf448.jpg

[2009-01-16 07:00:25 | 00,290,890 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts

[2009-01-15 12:11:39 | 00,000,394 | ---- | M] () -- C:\WINDOWS\tasks\Schedule Task Weekly.job

[2009-01-15 03:00:22 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009-01-14 19:43:42 | 00,018,406 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\huuusvagn.jpg

[2009-01-14 19:43:19 | 00,116,027 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\vagnahus.jpg

[2009-01-14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2009-01-14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009-01-14 12:03:31 | 00,039,656 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\GDIPFONTCACHEV1.DAT

[2009-01-14 12:03:14 | 00,000,362 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Downloads.lnk

[2009-01-14 12:03:14 | 00,000,338 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\MP3.lnk

[2009-01-14 12:03:12 | 00,049,938 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\n618847606_1308412_3302.jpg

[2009-01-14 08:07:58 | 00,000,041 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\.zreglib

[2009-01-13 22:22:04 | 00,000,351 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Bilder.lnk

[2009-01-13 09:35:02 | 00,737,280 | ---- | M] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe

[2009-01-13 08:21:34 | 00,003,371 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\install.rtf

[2009-01-13 08:16:17 | 00,000,769 | ---- | M] () -- C:\fix_reg.cmd

[2009-01-13 08:10:18 | 00,379,392 | ---- | M] () -- C:\WINDOWS\System32\subinacl.msi

[2009-01-13 08:10:18 | 00,379,392 | ---- | M] () -- C:\WINDOWS\System32\subinacl.exe

[2009-01-12 20:57:14 | 00,000,634 | ---- | M] () -- C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hanna Smilla Leon.job

[2009-01-12 12:37:25 | 04,838,642 | -H-- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\IconCache.db

[2009-01-12 11:23:58 | 00,290,890 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090116-070024.backup

[2009-01-12 09:34:02 | 00,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat

[2009-01-11 13:33:52 | 00,290,890 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090112-112358.backup

[2009-01-11 12:47:01 | 00,000,507 | ---- | M] () -- C:\WINDOWS\win.ini

[2009-01-11 12:47:01 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2009-01-11 12:47:01 | 00,000,223 | RHS- | M] () -- C:\boot.ini

[2009-01-11 11:58:37 | 00,068,663 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\917925.htm

[2009-01-11 11:14:29 | 00,000,335 | ---- | M] () -- C:\WINDOWS\Julens hjältar.ini

[2009-01-11 11:06:54 | 00,231,445 | ---- | M] () -- C:\WINDOWS\uninstall Star_War.exe

[2009-01-11 11:06:53 | 30,359,902 | ---- | M] () -- C:\WINDOWS\Star_War.scr

[2009-01-11 11:03:29 | 05,745,270 | ---- | M] (3Planesoft ) -- C:\WINDOWS\System32\xa63536421.exe

[2009-01-11 11:03:29 | 05,745,270 | ---- | M] (3Planesoft ) -- C:\WINDOWS\System32\xa63534890.exe

[2009-01-10 16:31:08 | 00,288,612 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090111-133352.backup

[2009-01-10 14:50:38 | 00,000,885 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090110-155229.backup

[2009-01-10 14:27:42 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\Mina delade mappar.lnk

[2009-01-10 14:09:19 | 00,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrszht.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrszhc.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrstr.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsth.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrssv.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrszht.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrszhc.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrstr.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsth.dll

[2009-01-10 14:06:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvapps.nvb

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrssl.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrssk.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsru.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsptb.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrspt.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrspl.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrssv.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrssl.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrssk.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsru.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsptb.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrspt.dll

[2009-01-10 14:06:29 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrspl.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsno.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsnl.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsko.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsja.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsit.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrshu.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrshe.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsfr.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsfi.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsno.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsnl.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsko.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsja.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsit.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrshu.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrshe.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsfr.dll

[2009-01-10 14:06:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsfi.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsesm.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrses.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrseng.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsel.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsde.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsda.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrscs.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwrsar.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwimg.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvwdmcpl.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvtuicpl.cpl

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvshell.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsesm.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrses.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrseng.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsel.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsde.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsda.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrscs.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvrsar.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvmccsrs.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nwiz.exe

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nview.dll

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvdspsch.exe

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvcolor.exe

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvappbar.exe

[2009-01-10 14:06:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\keystone.exe

[2009-01-10 13:50:50 | 00,001,746 | ---- | M] () -- C:\WINDOWS\Language_trs.ini

[2009-01-10 12:47:01 | 00,240,240 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\wpcap.dll

[2009-01-10 12:47:01 | 00,088,704 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\packet.dll

[2009-01-10 12:47:01 | 00,042,512 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\drivers\npf.sys

[2009-01-10 12:45:07 | 00,000,082 | ---- | M] () -- C:\WINDOWS\ka.ini

[2009-01-10 12:14:25 | 00,000,035 | ---- | M] () -- C:\WINDOWS\vg5aloc.ini

[2009-01-10 12:08:37 | 00,000,035 | ---- | M] () -- C:\WINDOWS\vg5bloc.ini

[2009-01-10 11:01:05 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-01-10 02:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe

[2009-01-09 16:54:57 | 00,009,349 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\the_devil.jpg

[2009-01-09 16:35:02 | 00,290,748 | RH-- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts.bak

[2009-01-09 16:26:20 | 02,117,632 | ---- | M] (Python Software Foundation) -- C:\WINDOWS\System32\python25.dll

[2009-01-09 16:26:20 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2009-01-09 16:26:20 | 00,339,968 | ---- | M] () -- C:\WINDOWS\System32\pythoncom25.dll

[2009-01-09 16:26:20 | 00,114,688 | ---- | M] () -- C:\WINDOWS\System32\pywintypes25.dll

[2009-01-09 15:42:49 | 00,013,511 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\toilet04.gif

[2009-01-09 13:34:28 | 00,000,268 | -H-- | M] () -- C:\sqmdata03.sqm

[2009-01-09 13:34:28 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm

[2009-01-09 07:06:04 | 00,290,748 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090109-163502.backup

[2009-01-08 22:02:10 | 00,000,268 | -H-- | M] () -- C:\sqmdata02.sqm

[2009-01-08 22:02:10 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm

[2009-01-08 21:49:36 | 00,000,146 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\fusioncache.dat

[2009-01-08 21:42:50 | 00,000,268 | -H-- | M] () -- C:\sqmdata01.sqm

[2009-01-08 21:42:50 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm

[2009-01-08 21:13:47 | 00,000,099 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Felsök Internet Explorer.url

[2009-01-08 21:10:32 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2009-01-08 21:10:32 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2009-01-08 21:09:17 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2009-01-08 20:55:26 | 00,000,089 | -HS- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\desktop.ini

[2009-01-08 20:55:17 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx

[2009-01-08 20:52:58 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm

[2009-01-08 20:52:58 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm

[2009-01-08 20:45:38 | 00,250,560 | RHS- | M] () -- C:\ntldr

[2009-01-08 20:24:45 | 00,000,042 | ---- | M] () -- C:\WINDOWS\System32\RegistryEasy.lie

[2009-01-08 20:17:22 | 00,290,748 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090109-070604.backup

[2009-01-08 20:11:02 | 00,001,670 | ---- | M] () -- C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Personal.lnk

[2009-01-08 19:53:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat

[2009-01-08 19:53:02 | 00,001,546 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivbord\Mozilla Firefox.lnk

[2009-01-08 19:25:26 | 00,000,383 | ---- | M] () -- C:\WINDOWS\ODBC.INI

[2009-01-08 19:07:44 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak

[2009-01-08 19:07:03 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\desktop.ini

[2009-01-08 19:07:03 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Dokument\desktop.ini

[2009-01-08 19:07:03 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2009-01-08 18:55:41 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS

[2009-01-08 18:55:41 | 00,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL

[2009-01-08 18:55:41 | 00,010,635 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT

[2009-01-08 18:55:41 | 00,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF

[2009-01-08 18:49:12 | 00,028,499 | ---- | M] () -- C:\WINDOWS\Ascd_tmp.ini

[2009-01-08 18:43:44 | 00,028,821 | ---- | M] () -- C:\WINDOWS\Ascd_log.ini

[2009-01-08 18:39:48 | 00,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav

[2009-01-08 18:39:48 | 00,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav

[2009-01-08 18:19:11 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD

[2009-01-08 18:18:25 | 00,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf

[2009-01-08 18:17:03 | 00,000,084 | -HS- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Start-meny\Program\Autostart\desktop.ini

[2009-01-08 18:17:03 | 00,000,084 | -HS- | M] () -- C:\Documents and Settings\All Users\Start-meny\Program\Autostart\desktop.ini

[2009-01-08 18:16:57 | 00,002,578 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2009-01-08 18:16:57 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2009-01-08 18:16:57 | 00,000,000 | RHS- | M] () -- C:\IO.SYS

[2009-01-08 18:16:57 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini

[2009-01-08 18:16:57 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2009-01-08 18:16:57 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2009-01-08 18:16:46 | 00,004,293 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI

[2009-01-08 18:14:56 | 00,021,700 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat

[2009-01-08 18:14:46 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini

[2009-01-08 18:14:46 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini

[2009-01-05 19:29:18 | 00,034,396 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\maaalin.JPG

[2008-12-22 19:04:06 | 01,650,838 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\julkort 2008.jpg

[2008-12-22 12:23:58 | 00,111,104 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Dok1.doc

[2008-12-21 22:10:52 | 00,037,334 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Skärmsläckare.jpg

[2008-12-21 21:51:17 | 00,144,207 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Richard.jpg

[2008-12-18 15:34:52 | 00,311,673 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\P1030351.JPG

[2008-12-18 15:34:51 | 01,276,764 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\CuteSecurity.wmv

[2008-12-18 15:34:51 | 00,295,566 | ---- | M] () -- C:\Documents and Settings\Hanna Smilla Leon\Mina dokument\P1030347.JPG

< End of report >

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Men den där sgvhost.exe verkar inte finnas fysiskt, men finns omskriven i några filer i alla fall, det är ju i loggar till OTViewIt. hijackthis och spybot.

 

Men finns även i filerna:

 

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1-Global.reg

 

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS3-Global.reg

 

C:\Documents and Settings\Hanna Smilla Leon\Application Data\Mozilla\Firefox\Profiles\6tnfu9z7.default\sessionstore.js

 

C:\WINDOWS\pchealth\helpctr\DataColl\CollectedData_164.xml

 

Bara tänkte för det verkar inte som det är en bra fil den där sgvhost.

 

Länk till kommentar
Dela på andra webbplatser

Så bra att du kom på hur du skulle göra inläggen :thumbsup:

 

Avinstallera Java™ 6 Update 7, det är en gammal version med säkerhetshål.

 

Vilken årsmodell av Norton har du?

 

Vad är det för versionsnummer på Firefox (Hjälp - Om)?

 

Surfa till http://www.virustotal.com (fungerar bäst med Internet Explorer) klistra in ett av följande filnamn i rutan, tryck på Skicka Fil och vänta tills resultatet är klart (Närvarande status blir genomförd). Klistra in resultatet från de olika antivirusprogrammen (inte Övrig information) här. Upprepa med nästa filnamn.

C:\WINDOWS\system32\drivers\npf.sys

C:\WINDOWS\System32\GkSui18.EXE

C:\WINDOWS\System32\xa63536421.exe

C:\WINDOWS\System32\xa63534890.exe

C:\WINDOWS\System32\vp6vfw.dll

 

Hur är det med Daemon Tools egentligen? Är det Pro eller Lite som ska vara installerat? Att ha båda kan kanske bli konstigt.

[2009-01-10 12:01:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Application Data\DAEMON Tools Pro

[2009-01-10 12:00:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

 

Vad gjorde du 8 januari på kvällen när det skapades så mycket nya filer?

 

Länk till kommentar
Dela på andra webbplatser

Men den där sgvhost.exe verkar inte finnas fysiskt
Det stämmer med OTViewIt-loggen, filen finns inte men det finns referens till den från registret.

 

Bara tänkte för det verkar inte som det är en bra fil den där sgvhost.
Alldeles riktigt.

 

Länk till kommentar
Dela på andra webbplatser

Ja du vilken norton det är är jag osäker på, men står 1997-2008 i programet, och Current SKU står det 12863951, och på versoin står det 15.5.0.23 men på start filerna står det 15.5.0.32

 

Firefox 3.0.5.

 

Den åttonde så byggde jag datorn o installerade xp o allt annat.

 

C:\WINDOWS\system32\drivers\npf.sys inget hittades.

C:\WINDOWS\System32\GkSui18.EXE inget hittades.

C:\WINDOWS\System32\xa63536421.exe inget hittades.

C:\WINDOWS\System32\xa63534890.exe inget hittades.

C:\WINDOWS\System32\vp6vfw.dll inget hittades.

 

Har av installerat den gamla java.

 

Alla daemon tools mappar var tomma, så nu är dom borta, förmodar de hängt med från den gamla datorn.

 

Men nu är de borttagna.

 

 

 

 

 

 

Länk till kommentar
Dela på andra webbplatser

Det är nog årsmodell 2008 av Norton och då kan du uppgradera till Norton 2009

http://www.symantec.com/sv/se/home_homeoffice/support/special/upgrade2007/vista/migration_start.jsp?site=nuc

 

I ditt första inlägg så skrev du att du hade haft virus i datorn för en vecka sedan vilket blir ca den sjätte, men nu skriver du att du installerade XP den åttonde. Fick du in virus under installationen? Vad för sorts installation eftersom den verkar ha skapat mycket som inte har med Windows att göra?

[2009-01-08 19:26:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Hanna Smilla Leon\Skrivbord\Julkort

 

Sen klagade norton på de filer som hette dotnetfx.exe, netfxupdate.exe, qttask.exe, pythonservice.exe, sgvhost.exe, asussetup.exe, autorun.exe, nvuninst.exe pythonw.exe, re.exe, nwiz.exe
Finns någon av dessa filer kvar i datorn? svghost har du ju kollat upp, men de andra. qttask och nwiz brukar vara normala filer, quicktime resp. grafikkortsdrivrutin. Om du hittar någon så ta inte bort dem utan kolla dem på virustotal-sidan.

 

Lägg hit en ny HijackThis-logg också

 

Länk till kommentar
Dela på andra webbplatser

Mmm, då kom nog virus den nionde då.

 

Tar alltid en kopia på mappen mina dokument o skrivbord och filer till outlook express o favoriter, dessa klistrar jag sedan in i igen efter ominstallation.

 

QTTask.exe: VBA32 3.12.8.10 2009.01.18 suspected of Win32 Shadow AutoStart Install

 

RE.exe: DrWeb 4.44.0.09170 2009.01.18 WIN.WORM.Virus

 

Nwiz.exe går inte ladda upp har hållt på en halvtimme, o när man kollar hur stor den är så är den 0 byte stor.

 

Resten av filerna antingen rena eller så fanns dom inte kvar.

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:34:42, on 2009-01-18

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Java\jre6\bin\jusched.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\Windows Live\Messenger\MsnMsgr.Exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program\Skype\Phone\Skype.exe

C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program\Spybot - Search & Destroy\TeaTimer.exe

C:\Program\Personal\bin\Personal.exe

C:\Program\Skype\Plugin Manager\skypePM.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\iPod\bin\iPodService.exe

C:\Program\Mozilla Firefox\firefox.exe

C:\Documents and Settings\All Users\Symantec Temporary Files\NIS09SW.exe

C:\Program\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar

R3 - Default URLSearchHook is missing

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [Video Driver] sgvhost.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [NIS] "C:\Documents and Settings\All Users\Symantec Temporary Files\NIS09SW.exe" /RELAUNCH /RUNONCE /NOPROMPT /PATH "C:\Program\Norton Internet Security\Norton Internet Security"

O4 - HKLM\..\RunServices: [Video Driver] sgvhost.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [skype] "C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre6\bin\jp2iexp.dll

O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre6\bin\jp2iexp.dll

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231442855500

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 5587 bytes

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Ta bort mappen

C:\Documents and Settings\Hanna Smilla Leon\Lokala inställningar\Application Data\Kiwee Toolbar

 

nwiz.exe: C:\WINDOWS\System32\nwiz.exe installerades samtidigt med andra filer som tillhör Nividias grafikdrivrutiner. Jag har svårt att tro att den skulle vara infekterad men för säkerhets skull så kan du ju alltid avinstallera dem och så ladda ner nya från tillverkarens webbplats. Särskilt om den nu skulle vara 0 byte.

 

qttask.exe: hittar jag inte i OTViewIt-loggen, men quicktime kan du ju avinstallera och ladda ner på nytt från Apples webbplats.

 

Resten av filerna antingen rena eller så fanns dom inte kvar.
Om du skannar igen med Norton klagar Norton då igen? Och i så fall vad skriver Norton om filerna?

 

[log]TeaTimer-funktionen i Spybot S&D är väldigt bra, men just nu så kan den störa de nödvändiga förändringarna i registret så du behöver stänga av den. Kom ihåg att sätta på den sedan men inte förrän jag säger till eller att allt är klart med datorn.

 

Starta Spybot S&D

Välj Advanced i Mode-menyn

Till vänster välj Tools - Resident

Ta bort bocken för TeaTimer

Avsluta programmet.

Starta om datorn.

 

Skanna med HijackThis och bocka för:

 

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [Video Driver] sgvhost.exe

O4 - HKLM\..\RunServices: [Video Driver] sgvhost.exe

 

Om du inte själv har valt att det inte ska gå att ändra inställningarna i Internet Explorer så även:

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

 

Avsluta alla andra program.

Tryck Fix checked.

 

Starta om datorn och kontrollera själv att ovanstående rader är borta ur en ny HijackThis-logg. [/log]

 

Länk till kommentar
Dela på andra webbplatser

Allt fixat, raderna borta från hijackthis.

 

Norton 2009 hittar inget.

 

Teetimer är avstängt.

 

Tagit bort de nwiz.exe o qttask.exe, avinstallerat o installerat igen.

 

[log]Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:18:30, on 2009-01-19

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program\Bonjour\mDNSResponder.exe

C:\Program\Java\jre6\bin\jqs.exe

C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Program\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program\Windows Live\Messenger\MsnMsgr.Exe

C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program\Skype\Phone\Skype.exe

C:\Program\Personal\bin\Personal.exe

C:\WINDOWS\System32\svchost.exe

C:\Program\Skype\Plugin Manager\skypePM.exe

C:\Program\Mozilla Firefox\firefox.exe

C:\Program\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll

O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre6\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll

O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [skype] "C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre6\bin\jp2iexp.dll

O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre6\bin\jp2iexp.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231442855500

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL

O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe

O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program\Norton Internet Security\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 5854 bytes

[/log]

 

Länk till kommentar
Dela på andra webbplatser

Ok, om jag fattade rätt så ska man låta filen finnas kvar, men ta bort den från startup, då ska allt fortfarande fungera? Gör jag det lättast via hijackthis?

 

Nepp, gick inte installera IE7 nu heller, samma felmedelande, vill du se loggen?

 

Länk till kommentar
Dela på andra webbplatser

Arkiverat

Det här ämnet är nu arkiverat och är stängt för ytterligare svar.

×
×
  • Skapa nytt...