OTL logfile created on: 27.09.2010 17:32:02 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Espen og Tia\Skrivebord
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000414 | Country: Norge | Language: NOR | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 77,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 86,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programfiler
Drive C: | 698,63 Gb Total Space | 506,60 Gb Free Space | 72,51% Space Free | Partition Type: NTFS
Drive D: | 4,60 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SMURF
Current User Name: Espen og Tia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010.09.27 17:29:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Espen og Tia\Skrivebord\OTL.scr
PRC - [2010.09.27 17:22:58 | 000,089,600 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Temp\dwm.exe
PRC - [2010.09.27 17:22:55 | 000,168,960 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Programdata\Microsoft\Windows\shell.exe
PRC - [2010.09.27 17:19:54 | 000,077,824 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Programdata\Microsoft\svchost.exe
PRC - [2010.09.24 08:05:29 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgnsx.exe
PRC - [2010.08.13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.08.10 15:10:58 | 002,349,776 | ---- | M] (IObit) -- C:\Programfiler\IObit\Advanced SystemCare 3\AWC.exe
PRC - [2010.07.18 18:39:32 | 002,065,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgtray.exe
PRC - [2010.07.18 18:39:30 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgrsx.exe
PRC - [2010.07.18 18:39:28 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgwdsvc.exe
PRC - [2010.07.18 18:39:25 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgchsvx.exe
PRC - [2010.07.18 18:39:25 | 000,723,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programfiler\AVG\AVG9\avgcsrvx.exe
PRC - [2010.05.14 11:44:46 | 000,248,552 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programfiler\Fellesfiler\Java\Java Update\jusched.exe
PRC - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Programfiler\Canon\CAL\CALMAIN.exe
PRC - [2009.07.20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.) -- C:\Programfiler\Logitech\SetPoint\SetPoint.exe
PRC - [2009.07.10 12:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.) -- C:\Programfiler\Fellesfiler\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2009.05.19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Programfiler\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009.02.06 18:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- C:\Programfiler\Windows Live\Contacts\wlcomm.exe
PRC - [2008.12.03 14:37:00 | 000,189,168 | ---- | M] (Telenor) -- C:\Programfiler\Telenor\Telenorhjelpen\Telenor.exe
PRC - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) -- c:\Programfiler\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008.10.05 18:22:22 | 007,434,240 | ---- | M] (OpenOffice.org) -- C:\Programfiler\OpenOffice.org 3\program\soffice.exe
PRC - [2008.10.05 18:22:22 | 007,430,144 | ---- | M] (OpenOffice.org) -- C:\Programfiler\OpenOffice.org 3\program\soffice.bin
PRC - [2008.08.14 21:29:11 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008.01.16 12:21:44 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Programfiler\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007.08.22 14:33:26 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.06.01 11:21:30 | 001,209,904 | ---- | M] (Nero AG) -- C:\Programfiler\Fellesfiler\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.01 11:21:30 | 000,271,920 | ---- | M] (Nero AG) -- C:\Programfiler\Fellesfiler\Ahead\Lib\NMIndexingService.exe
PRC - [2007.06.01 11:21:08 | 000,153,136 | ---- | M] (Nero AG) -- C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.03.26 13:06:24 | 000,292,864 | ---- | M] (Nokia.) -- C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe
PRC - [2007.03.23 13:20:52 | 000,227,328 | ---- | M] (Nokia) -- C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe
PRC - [2006.12.18 15:34:36 | 000,868,352 | ---- | M] (Analog Devices, Inc.) -- C:\Programfiler\Analog Devices\Core\smax4pnp.exe
PRC - [2006.08.17 11:32:10 | 000,018,944 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTXFIHLP.EXE
PRC - [2006.08.17 11:32:04 | 000,017,920 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\CTHELPER.EXE
PRC - [2006.08.17 11:28:14 | 000,729,600 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTXFISPI.EXE
PRC - [2006.01.19 16:21:42 | 000,684,032 | ---- | M] (JensenScandinavia) -- C:\Programfiler\JensenScandinavia\Jensen AirLink 7554 Wlan Utility\Installer\WINXP\AWU.exe
========== Modules (SafeList) ========== MOD - [2010.09.27 17:29:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Espen og Tia\Skrivebord\OTL.scr
MOD - [2009.07.20 12:29:06 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Programfiler\Logitech\SetPoint\lgscroll.dll
MOD - [2009.07.12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2007.08.22 14:35:30 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2006.08.17 11:32:04 | 000,007,168 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTAGENT.DLL
MOD - [2004.08.04 14:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - [2010.08.13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.08.13 09:12:02 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programfiler\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2010.07.18 18:39:28 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Programfiler\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Programfiler\Fellesfiler\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Programfiler\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009.08.07 12:43:04 | 000,045,816 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Programfiler\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2009.08.05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programfiler\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009.07.20 12:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programfiler\Fellesfiler\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009.05.19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programfiler\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programfiler\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008.11.04 02:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programfiler\Fellesfiler\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008.08.14 21:29:11 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Programfiler\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2008.01.16 12:21:44 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programfiler\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007.06.01 11:21:30 | 000,271,920 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Programfiler\Fellesfiler\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2007.03.26 13:06:24 | 000,292,864 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Programfiler\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2007.02.10 15:29:54 | 029,178,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Programfiler\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2007.02.10 15:29:47 | 000,242,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Programfiler\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programfiler\Fellesfiler\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005.10.14 12:50:19 | 000,045,272 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Programfiler\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
SRV - [2005.02.09 13:59:00 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ESPENO~1\LOKALE~1\Temp\o1394bul.sys -- (o1394bul)
DRV - [2010.07.18 18:39:31 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010.07.18 18:39:25 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010.06.03 09:51:53 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010.04.04 00:55:31 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010.02.26 14:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010.02.26 14:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010.02.26 14:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010.02.26 14:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010.01.25 14:56:26 | 000,115,712 | ---- | M] (HID Global Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cxbu0wdm.sys -- (cxbu0wdm)
DRV - [2009.08.05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009.06.17 18:56:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009.06.17 18:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009.06.17 18:55:18 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008.05.28 10:33:38 | 000,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Programfiler\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2008.05.28 10:33:36 | 000,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programfiler\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2008.05.28 10:33:36 | 000,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programfiler\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2007.08.22 14:37:00 | 000,051,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
DRV - [2007.08.22 14:36:58 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2007.08.22 14:36:58 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2007.08.15 10:22:00 | 000,265,856 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2007.07.12 17:49:16 | 000,096,384 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2007.01.16 03:09:06 | 000,293,888 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2007.01.04 11:07:00 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2006.10.30 11:31:58 | 000,043,648 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID)
DRV - [2006.08.17 11:23:00 | 000,340,176 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2006.08.17 11:17:12 | 000,007,168 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2006.08.17 11:17:10 | 000,500,480 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2006.08.17 11:16:32 | 001,110,528 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2006.08.17 11:15:00 | 000,116,224 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2006.08.17 11:14:42 | 000,143,872 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2006.08.17 11:14:38 | 000,078,336 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2006.08.17 11:14:24 | 000,502,272 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2006.06.16 09:30:16 | 000,176,128 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187.sys -- (RTLWUSB)
DRV - [2006.03.17 11:18:58 | 000,392,960 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2006.02.07 19:52:58 | 000,006,912 | ---- | M] (JMicron ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\JGOGO.sys -- (JGOGO)
DRV - [2006.01.12 19:46:28 | 000,252,928 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2005.08.17 15:43:20 | 000,330,240 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS)) ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005.08.17 09:39:00 | 000,163,840 | R--- | M] (SiS Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sis163u.sys -- (SIS163u)
DRV - [2005.06.08 19:44:20 | 000,020,608 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BRGSp50.sys -- (BRGSp50)
DRV - [2005.01.07 18:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.10.25 14:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2004.08.13 10:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.live.com/?mkt=nb-no [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://no.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.live.com/?mkt=nb-no [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.startsiden.no/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50370
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.co...-8&oe=UTF-8&q="FF - prefs.js..browser.startup.homepage: "
http://www.google.no/ig"FF - prefs.js..extensions.enabledItems:
[email protected]:1.9.6.7
FF - prefs.js..extensions.enabledItems:
[email protected]:2.1.0.19
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.73
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.855
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port:
FF - user.js..network.proxy.no_proxies_on: ""
FF - user.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Programfiler\AVG\AVG9\Firefox [2010.09.24 08:06:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Programfiler\Mozilla Firefox\components [2010.09.27 00:01:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Programfiler\Mozilla Firefox\plugins [2010.09.21 16:24:22 | 000,000,000 | ---D | M]
[2008.06.20 15:51:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Extensions
[2010.09.27 00:13:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions
[2010.03.27 15:28:03 | 000,000,000 | ---D | M] (Screengrab) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010.04.27 23:28:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.09.02 19:52:02 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.09.27 00:11:26 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2010.08.27 18:26:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009.09.24 07:38:34 | 000,000,000 | ---D | M] (MushroomKingdom) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2010.09.27 00:11:26 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.03.14 16:32:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\
[email protected][2010.02.01 19:09:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\
[email protected][2010.09.10 18:05:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Mozilla\Firefox\Profiles\glr0r90n.default\extensions\
[email protected][2010.09.27 00:13:16 | 000,000,000 | ---D | M] -- C:\Programfiler\Mozilla Firefox\extensions
[2007.11.08 16:02:09 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Programfiler\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.05.07 17:13:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Programfiler\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.07 14:08:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Programfiler\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2007.12.05 07:13:55 | 000,000,000 | ---D | M] -- C:\Programfiler\Mozilla Firefox\extensions\
[email protected][2010.07.17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programfiler\Mozilla Firefox\plugins\npdeployJava1.dll
[2008.01.18 00:00:17 | 000,390,512 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\plugins\npoctoshape.dll
[2010.06.25 21:01:47 | 000,001,525 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010.06.25 21:01:47 | 000,000,955 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\bok-NO.xml
[2010.06.25 21:01:47 | 000,000,968 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\qxl-NO.xml
[2010.06.25 21:01:47 | 000,001,203 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\telefonkatalogen-NO.xml
[2010.06.25 21:01:47 | 000,001,176 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\wikipedia-NO.xml
[2010.06.25 21:01:47 | 000,001,192 | ---- | M] () -- C:\Programfiler\Mozilla Firefox\searchplugins\yahoo-NO.xml
O1 HOSTS File: ([2010.04.30 14:56:09 | 000,001,798 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programfiler\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Påloggingshjelp for Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Telenor Telenorhjelpen Plugin) - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Programfiler\Telenor\Telenorhjelpen\IEFixItNowPlugin.dll (Telenor)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Programfiler\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programfiler\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Programfiler\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Programfiler\Fellesfiler\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Programfiler\Fellesfiler\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Programfiler\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programfiler\Fellesfiler\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Programfiler\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
O4 - HKLM..\Run: [rundll32] C:\WINDOWS\System32\ntdevice.exe File not found
O4 - HKLM..\Run: [SoundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programfiler\Fellesfiler\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [svchost] C:\Documents and Settings\Espen og Tia\Programdata\Microsoft\svchost.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Programfiler\Fellesfiler\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Telenorhjelpen] C:\Programfiler\Telenor\Telenorhjelpen\Telenor.exe (Telenor)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Programfiler\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [rundll32] C:\Documents and Settings\Espen og Tia\userinit.exe File not found
O4 - HKCU..\Run: [Steam] C:\Programfiler\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Jensen AirLink 7554 Wlan Utility.lnk = C:\Programfiler\JensenScandinavia\Jensen AirLink 7554 Wlan Utility\Installer\WINXP\AWU.exe (JensenScandinavia)
O4 - Startup: C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\Logitech SetPoint.lnk = C:\Programfiler\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Espen og Tia\Start-meny\Programmer\Oppstart\OpenOffice.org 3.0.lnk = C:\Programfiler\OpenOffice.org 3\program\quickstart.exe ()
F3 - HKCU WinNT: Load - (C:\DOCUME~1\ESPENO~1\LOKALE~1\Temp\dwm.exe) - C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Temp\dwm.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: E&ksporter til Microsoft Excel - C:\Programfiler\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Åpne i ny bakgrunnsflik - C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui (Microsoft Corporation)
O8 - Extra context menu item: Åpne i ny forgrunnsflik - C:\Programfiler\Windows Live Toolbar\Components\nb-no\msntabres.dll.mui (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programfiler\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programfiler\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Programfiler\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programfiler\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe (Microgaming)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programfiler\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A}
http://tky09.celarte...ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.micr...78f/wvc1dmo.cab (Reg Error: Value error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 130.67.15.198 193.213.112.4
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programfiler\Fellesfiler\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programfiler\Fellesfiler\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programfiler\Fellesfiler\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programfiler\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programfiler\Fellesfiler\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\WINDOWS\system32\ntdevice.exe) - C:\WINDOWS\System32\ntdevice.exe File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Espen og Tia\Programdata\Microsoft\Windows\shell.exe) - C:\Documents and Settings\Espen og Tia\Programdata\Microsoft\Windows\shell.exe ()
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\__c001B609: DllName - C:\WINDOWS\system32\__c001B609.dat - C:\WINDOWS\System32\__c001B609.dat File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\programfiler\fellesfiler\logitech\bluetooth\LBTWlgn.dll - c:\Programfiler\Fellesfiler\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Min gjeldende hjemmeside) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.21 19:50:00 | 000,000,093 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.20 22:37:17 | 000,054,544 | R--- | M] (Electronic Arts) - D:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2010.03.27 06:03:00 | 000,000,049 | R--- | M] () - D:\Autorun.inf -- [ UDF ]
O33 - MountPoints2\{68ce571f-3f9e-11dd-8b08-001bfcce5369}\Shell - "" = AutoRun
O33 - MountPoints2\{68ce571f-3f9e-11dd-8b08-001bfcce5369}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027075282206720)
========== Files/Folders - Created Within 90 Days ========== [2010.09.27 17:29:32 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Espen og Tia\Skrivebord\OTL.scr
[2010.09.26 23:59:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Espen og Tia\Siste
[2010.09.26 23:43:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Programdata\IObit
[2010.09.21 16:23:55 | 000,000,000 | ---D | C] -- C:\Programfiler\QuickTime
[2010.09.15 21:13:39 | 000,000,000 | ---D | C] -- C:\f5edf9d26d3beecfb9495daf5b7e
[2010.09.03 23:41:25 | 000,000,000 | ---D | C] -- C:\Programfiler\iPod
[2010.08.28 14:10:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Skrivebord\Installeringsprogram for Adobe 9 Reader
[2010.08.26 14:23:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Espen og Tia\Mine dokumenter\TIL OPPGRADER AT GMAIL DOT COM
[2010.08.24 22:37:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Espen og Tia\Logitech
[2010.08.24 22:36:56 | 000,000,000 | ---D | C] -- C:\Programfiler\Fellesfiler\Remote Control Software Common
[2010.08.24 22:36:46 | 000,000,000 | ---D | C] -- C:\Programfiler\Fellesfiler\Remote Control USB Driver
[2010.08.14 18:55:31 | 000,000,000 | ---D | C] -- C:\Programfiler\PC Connectivity Solution
[2010.08.14 18:52:46 | 000,008,192 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerfltj.sys
[2010.08.14 18:52:45 | 000,022,528 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys
[2010.08.14 18:52:45 | 000,008,192 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys
[2010.08.14 18:52:44 | 000,662,016 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcocls.dll
[2010.08.14 18:52:44 | 000,018,176 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys
[2010.08.14 16:20:06 | 000,000,000 | ---D | C] -- C:\Programfiler\Bonjour
[2010.08.14 06:34:10 | 000,000,000 | ---D | C] -- C:\Programfiler\Table Tennis Pro V2 Lite
[2010.08.13 04:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Espen og Tia\Skrivebord\Render
[2010.08.13 03:48:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Espen og Tia\Mine dokumenter\IMx3SEVer6
[2010.08.12 20:17:01 | 000,000,000 | ---D | C] -- C:\Programfiler\PIXELA
[2010.08.12 20:14:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Programdata\ZoomBrowser
[2010.08.12 20:13:07 | 000,000,000 | ---D | C] -- C:\Programfiler\Fellesfiler\Canon
[2010.07.31 13:18:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Espen og Tia\Skrivebord\Dubaifilm
[2010.07.18 18:39:30 | 000,012,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2007.11.07 20:52:04 | 000,033,792 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2004.12.13 08:57:36 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\RCCOLLAB.DLL
========== Files - Modified Within 90 Days ========== [2010.09.27 17:29:56 | 007,340,032 | -H-- | M] () -- C:\Documents and Settings\Espen og Tia\NTUSER.DAT
[2010.09.27 17:29:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Espen og Tia\Skrivebord\OTL.scr
[2010.09.27 17:22:42 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010.09.27 17:21:53 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.27 17:21:26 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.27 17:21:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.27 17:21:21 | 3488,731,136 | -HS- | M] () -- C:\hiberfil.sys
[2010.09.27 17:20:23 | 000,064,900 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000005-00311102}.rfx
[2010.09.27 17:20:23 | 000,054,164 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000005-00311102}.rfx
[2010.09.27 17:20:23 | 000,054,164 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000005-00311102}.rfx
[2010.09.27 17:20:23 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010.09.27 17:20:23 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010.09.27 17:20:06 | 021,990,614 | -H-- | M] () -- C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\IconCache.db
[2010.09.27 15:46:04 | 065,362,881 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010.09.27 02:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-SMURF-Espen og Tia.job
[2010.09.26 22:54:47 | 000,000,184 | -HS- | M] () -- C:\Documents and Settings\Espen og Tia\ntuser.ini
[2010.09.26 16:23:50 | 000,013,348 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\BETALING FOR INNESESONG.ods
[2010.09.26 13:56:14 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.09.26 13:56:13 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.26 12:10:20 | 000,000,349 | ---- | M] () -- C:\Documents and Settings\All Users\Dokumenter\PCLECHAL.INI
[2010.09.23 01:58:48 | 000,010,993 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\kontakter
[2010.09.21 15:43:00 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.09.20 22:02:01 | 102,661,352 | ---- | M] () -- C:\backup.dpb
[2010.09.19 16:27:32 | 000,493,554 | ---- | M] () -- C:\WINDOWS\System32\perfh014.dat
[2010.09.19 16:27:32 | 000,490,746 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.09.19 16:27:32 | 000,098,708 | ---- | M] () -- C:\WINDOWS\System32\perfc014.dat
[2010.09.19 16:27:31 | 000,089,818 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.09.19 16:27:28 | 001,188,418 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.09.11 10:06:33 | 000,029,167 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper2.pdf
[2010.09.11 10:06:26 | 000,009,998 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper.odt
[2010.09.10 19:05:36 | 000,096,064 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\skattekart.jpg
[2010.09.10 18:17:21 | 002,571,478 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\arendal2.bmp
[2010.09.10 18:14:13 | 001,499,050 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\arendal.bmp
[2010.09.09 18:28:52 | 000,015,360 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\Operasjon Jungeldyr.doc
[2010.09.08 21:58:24 | 000,028,394 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper.pdf
[2010.09.08 21:57:27 | 000,028,394 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Mine dokumenter\lapper.pdf
[2010.09.07 19:53:47 | 000,001,898 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\EA Download Manager.lnk
[2010.09.01 21:12:47 | 101,836,377 | ---- | M] () -- C:\backup.dpb.bak
[2010.08.24 22:37:28 | 000,001,989 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\Logitech Harmony Remote Software 7.lnk
[2010.08.15 19:03:02 | 008,595,174 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Programdata\NMM-MetaData.db
[2010.08.14 18:56:47 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.08.14 18:56:46 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.08.13 04:59:53 | 000,000,017 | ---- | M] () -- C:\WINDOWS\MovingPicture.ini
[2010.08.12 20:21:23 | 000,002,094 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Ver.6 Programvareguide.lnk
[2010.08.12 20:20:54 | 000,000,809 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Player Ver.6.lnk
[2010.08.12 20:17:24 | 000,000,243 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\PIXELA produktregistrering.url
[2010.08.12 20:17:24 | 000,000,243 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\Hjemmesiden til ImageMixer 3 SE.url
[2010.08.12 20:17:01 | 000,000,727 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Ver.6.lnk
[2010.08.12 20:15:15 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\CANON iMAGE GATEWAY Registration Guide.lnk
[2010.08.12 20:14:12 | 000,000,916 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\ZoomBrowser EX.lnk
[2010.08.08 14:52:26 | 003,629,569 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\Norway_Final_Guerilla.wmv
[2010.08.04 23:51:25 | 000,010,413 | ---- | M] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\images.jpg
[2010.07.18 18:39:31 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010.07.18 18:39:30 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010.07.18 18:39:25 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
========== Files Created - No Company Name ========== [2010.09.23 01:58:48 | 000,010,993 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\kontakter
[2010.09.11 10:06:33 | 000,029,167 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper2.pdf
[2010.09.10 19:05:29 | 000,096,064 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\skattekart.jpg
[2010.09.10 18:17:21 | 002,571,478 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\arendal2.bmp
[2010.09.10 18:14:13 | 001,499,050 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\arendal.bmp
[2010.09.09 18:28:50 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\Operasjon Jungeldyr.doc
[2010.09.08 22:01:39 | 000,009,998 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper.odt
[2010.09.08 21:58:24 | 000,028,394 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\lapper.pdf
[2010.09.08 21:57:27 | 000,028,394 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Mine dokumenter\lapper.pdf
[2010.09.07 19:53:47 | 000,001,898 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\EA Download Manager.lnk
[2010.08.24 22:37:28 | 000,001,989 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\Logitech Harmony Remote Software 7.lnk
[2010.08.14 18:56:47 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010.08.14 18:56:46 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010.08.12 20:20:54 | 000,000,809 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Player Ver.6.lnk
[2010.08.12 20:17:29 | 000,002,094 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Ver.6 Programvareguide.lnk
[2010.08.12 20:17:24 | 000,000,243 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\PIXELA produktregistrering.url
[2010.08.12 20:17:24 | 000,000,243 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\Hjemmesiden til ImageMixer 3 SE.url
[2010.08.12 20:17:01 | 000,000,727 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\ImageMixer 3 SE Ver.6.lnk
[2010.08.12 20:15:15 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\CANON iMAGE GATEWAY Registration Guide.lnk
[2010.08.12 20:14:12 | 000,000,916 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\ZoomBrowser EX.lnk
[2010.08.08 14:52:26 | 003,629,569 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\Norway_Final_Guerilla.wmv
[2010.08.04 23:51:23 | 000,010,413 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Skrivebord\images.jpg
[2009.11.09 19:11:35 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\Install7x.dll
[2009.11.09 00:46:52 | 000,007,060 | R--- | C] () -- C:\WINDOWS\System32\setparam.ini
[2009.11.09 00:46:52 | 000,007,060 | R--- | C] () -- C:\WINDOWS\setparam.ini
[2009.11.09 00:46:52 | 000,000,033 | ---- | C] () -- C:\WINDOWS\System32\wunilog.ini
[2009.09.08 19:51:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2009.08.21 19:26:00 | 000,139,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009.08.21 19:26:00 | 000,139,152 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Programdata\PnkBstrK.sys
[2009.08.03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009.06.24 17:53:49 | 000,000,179 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Programdata\setup.log
[2009.06.24 17:53:36 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Programdata\setup_ldm.iss
[2009.04.16 17:17:00 | 008,595,174 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Programdata\NMM-MetaData.db
[2008.11.13 08:32:45 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008.01.24 16:49:33 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2008.01.24 16:49:33 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2008.01.22 14:08:09 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\DVResampleru.dll
[2008.01.22 13:53:42 | 000,000,024 | ---- | C] () -- C:\Documents and Settings\All Users\Programdata\__FileUploader.log
[2008.01.21 20:34:24 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
[2008.01.21 19:52:34 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\fusioncache.dat
[2008.01.21 19:50:00 | 000,196,096 | ---- | C] () -- C:\WINDOWS\System32\macd32.dll
[2008.01.21 19:50:00 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2008.01.21 19:50:00 | 000,136,192 | ---- | C] () -- C:\WINDOWS\System32\mamc32.dll
[2008.01.21 19:50:00 | 000,057,856 | ---- | C] () -- C:\WINDOWS\System32\masd32.dll
[2008.01.21 19:50:00 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2007.12.05 07:13:53 | 000,888,832 | ---- | C] () -- C:\WINDOWS\System32\securenet.dll
[2007.11.20 00:31:15 | 000,126,464 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2007.11.19 21:54:45 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.11.19 17:15:29 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\Espen og Tia\Lokale innstillinger\Programdata\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.11.13 21:57:21 | 000,001,365 | ---- | C] () -- C:\Documents and Settings\All Users\Programdata\QTSBandwidthCache
[2007.11.07 20:52:12 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2007.11.07 20:52:11 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007.11.07 20:52:04 | 000,070,656 | ---- | C] () -- C:\WINDOWS\System32\CTMMACTL.DLL
[2007.11.07 20:52:04 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\CTBURST.DLL
[2007.11.07 20:52:03 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2007.11.07 20:52:02 | 000,087,403 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2007.11.07 20:52:02 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2007.11.07 11:39:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005.12.07 12:31:00 | 000,202,752 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
========== LOP Check ========== [2010.09.27 17:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\avg9
[2010.02.08 17:48:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Electronic Arts
[2009.11.08 20:42:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Emotum
[2010.08.14 18:43:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Installations
[2010.09.26 23:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\IObit
[2008.11.02 00:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\MumboJumbo
[2007.11.18 00:09:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\OLYMPUS
[2009.09.21 00:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\PC Suite
[2008.01.21 19:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Pinnacle
[2008.01.21 19:48:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Pinnacle Studio
[2010.06.26 17:38:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\regid.1986-12.com.adobe
[2009.10.14 21:52:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Sports Interactive
[2009.11.08 20:42:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\Telenor
[2008.09.29 19:42:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\TEMP
[2010.01.04 20:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\VIZ_MPS
[2007.11.07 12:18:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2010.05.16 19:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.11.27 19:22:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.05.12 15:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009.09.08 20:08:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Canon
[2007.11.19 22:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\DeepBurner
[2010.06.11 22:59:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Facebook
[2008.01.04 21:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\gtk-2.0
[2009.12.26 19:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\IObit
[2010.08.30 21:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Microgaming
[2009.11.23 17:59:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\My Games
[2009.04.16 17:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Nokia
[2008.11.07 17:45:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\OpenOffice.org
[2007.11.09 19:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Opera
[2009.04.05 19:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\PC Suite
[2008.01.21 20:01:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\proDAD
[2008.08.18 19:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\SPORE Creature Creator
[2009.10.31 02:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Sports Interactive
[2010.09.26 16:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\Spotify
[2010.09.26 21:31:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Espen og Tia\Programdata\uTorrent
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%*.* >[2004.08.04 14:00:00 | 000,260,272 | ---- | M] () -- C:\$LDR$
[2008.01.21 20:28:27 | 000,898,831 | ---- | M] () -- C:\adorage-protocol.txt
[2008.01.21 19:50:00 | 000,000,093 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010.09.20 22:02:01 | 102,661,352 | ---- | M] () -- C:\backup.dpb
[2010.09.01 21:12:47 | 101,836,377 | ---- | M] () -- C:\backup.dpb.bak
[2007.11.08 15:41:44 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2004.08.04 14:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2007.11.07 12:05:20 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010.09.27 17:21:21 | 3488,731,136 | -HS- | M] () -- C:\hiberfil.sys
[2007.11.07 12:05:20 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007.11.07 12:05:20 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004.08.04 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004.08.04 14:00:00 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2007.01.11 19:17:36 | 000,065,536 | ---- | M] (Getronics Belux) -- C:\OemPnPDriversPathCreator.exe
[2010.09.27 17:21:20 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2007.11.07 11:37:32 | 000,012,922 | ---- | M] () -- C:\Report.txt
[2007.11.07 12:12:11 | 000,000,580 | ---- | M] () -- C:\RHDSetup.log
[2007.08.22 14:37:05 | 000,473,509 | ---- | M] () -- C:\txtsetup.sif
[2008.08.11 20:36:12 | 000,000,156 | ---- | M] () -- C:\xcrashdump.dat
< %systemroot%system32*.wt > < %systemroot%system32*.ruy > < %systemroot%Fonts*.com > < %systemroot%Fonts*.dll > < %systemroot%Fonts*.ini > < %systemroot%Fonts*.ini2 > < %systemroot%Fonts*.exe > < %systemroot%system32spoolprtprocsw32x86*.* > < %systemroot%REPAIR*.bak1 > < %systemroot%REPAIR*.ini > < %systemroot%system32*.jpg > < %systemroot%*.jpg > < %systemroot%*.png > < %systemroot%*.scr >[2009.07.10 12:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
< %systemroot%*._sy > < %APPDATA%AdobeUpdate*.* > < %ALLUSERSPROFILE%Favorites*.* > < %APPDATA%Microsoft*.* > < %PROGRAMFILES%*.* > < %APPDATA%Update*.* > < %systemroot%*. /mp /s > < %systemroot%System32config*.sav > < %PROGRAMFILES%|bak;true;false;false /fp >[2007.11.07 12:03:49 | 000,000,000 | ---D | M] -- C:\Programfiler\Fellesfiler\Microsoft Shared\Meldingsbakgrunn
[2008.01.21 19:52:49 | 000,000,000 | ---D | M] -- C:\Programfiler\Pinnacle\Studio 11\Sound Effects\Bakgrunn
< %systemroot%system32|bak;true;false;false /fp >[2008.09.06 08:20:06 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot_bak
< %ALLUSERSPROFILE%Start Menu*.lnk /x >[2007.11.08 15:41:45 | 000,262,144 | ---- | M] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2007.11.19 21:47:50 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
< %systemroot%system32configsystemprofile*.dat /x >[2010.09.27 17:21:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\0.log
[2005.05.03 18:43:28 | 000,069,632 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\Alcmtr.exe
[2006.05.04 16:26:36 | 002,808,832 | ---- | M] (RealTek Semicoductor Corp.) -- C:\WINDOWS\alcwzrd.exe
[2004.08.04 14:00:00 | 000,001,272 | ---- | M] () -- C:\WINDOWS\Blå tapet 16.bmp
[2004.08.04 14:00:00 | 000,065,978 | ---- | M] () -- C:\WINDOWS\Bobler.bmp
[2010.09.27 17:21:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2004.08.04 14:00:00 | 000,082,944 | ---- | M] () -- C:\WINDOWS\clock.avi
[2007.11.07 12:05:20 | 000,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
[2006.08.17 11:31:42 | 000,010,240 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\CTDCRES.DLL
[2004.06.25 10:47:10 | 003,377,466 | ---- | M] () -- C:\WINDOWS\CTDV10K1.CDF
[2001.11.15 15:25:52 | 003,735,544 | ---- | M] () -- C:\WINDOWS\CTDV10K2.CDF
[2005.01.03 12:18:12 | 004,958,588 | ---- | M] () -- C:\WINDOWS\CTDVAUDY.CDF
[2006.08.17 11:32:04 | 000,017,920 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\CTHELPER.EXE
[2004.08.04 14:00:00 | 000,000,002 | ---- | M] () -- C:\WINDOWS\desktop.ini
[2007.08.22 14:33:26 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2004.08.04 14:00:00 | 000,000,080 | ---- | M] () -- C:\WINDOWS\explorer.scf
[2005.12.02 12:46:40 | 000,000,084 | ---- | M] () -- C:\WINDOWS\filespec7x
[2004.08.04 14:00:00 | 000,016,730 | ---- | M] () -- C:\WINDOWS\Fjær.bmp
[2004.08.04 14:00:00 | 000,017,336 | ---- | M] () -- C:\WINDOWS\Fluefisker.bmp
[2007.08.22 14:33:28 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\hh.exe
[2007.11.07 12:11:34 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\HideWin.exe
[2006.08.17 11:33:40 | 000,011,776 | ---- | M] (Creative Technology Limited) -- C:\WINDOWS\INRES.DLL
[1998.10.29 17:45:06 | 000,306,688 | ---- | M] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2004.08.04 14:00:00 | 000,026,582 | ---- | M] () -- C:\WINDOWS\Jade.bmp
[2004.08.04 14:00:00 | 000,017,062 | ---- | M] () -- C:\WINDOWS\Kaffekopp.bmp
[2007.06.28 16:44:14 | 002,165,760 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\MicCal.exe
[2006.08.17 11:10:32 | 000,025,600 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\MIDIDEF.EXE
[2010.08.13 04:59:53 | 000,000,017 | ---- | M] () -- C:\WINDOWS\MovingPicture.ini
[2008.01.20 12:38:20 | 000,001,283 | ---- | M] () -- C:\WINDOWS\mozver.dat
[2004.08.04 14:00:00 | 000,001,405 | ---- | M] () -- C:\WINDOWS\msdfmap.ini
[2010.09.26 13:56:14 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2004.08.04 14:00:00 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\NOTEPAD.EXE
[2007.11.08 16:02:10 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2007.11.07 12:04:43 | 000,004,249 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2009.09.08 19:51:27 | 000,000,000 | ---- | M] () -- C:\WINDOWS\OpPrintServer.INI
[2004.08.04 14:00:00 | 000,026,680 | ---- | M] () -- C:\WINDOWS\Pastell.bmp
[2009.08.11 17:44:02 | 000,000,059 | ---- | M] () -- C:\WINDOWS\pp.enc
[2006.08.17 11:32:08 | 000,034,304 | ---- | M] () -- C:\WINDOWS\PSCONV.EXE
[2008.04.24 19:33:33 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2008.07.12 12:02:10 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2006.08.17 11:32:16 | 000,035,840 | ---- | M] (Creative Technology Limited) -- C:\WINDOWS\READREG.EXE
[2004.08.04 14:00:00 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\regedit.exe
[2007.11.08 15:31:21 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2004.08.04 14:00:00 | 000,017,362 | ---- | M] () -- C:\WINDOWS\Rododendron.bmp
[2004.02.24 14:04:48 | 000,041,219 | ---- | M] (Pinnacle Systems) -- C:\WINDOWS\RSETPATH.exe
[2007.09.19 18:14:58 | 016,844,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
[2007.03.23 19:19:10 | 009,715,200 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTLCPL.exe
[2007.07.26 17:09:20 | 000,520,192 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlExUpd.dll
[2007.07.26 18:06:22 | 001,191,936 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlUpd.exe
[2004.08.04 14:00:00 | 000,065,832 | ---- | M] () -- C:\WINDOWS\Santa Fe.bmp
[2010.09.27 17:20:18 | 000,032,506 | ---- | M] () -- C:\WINDOWS\SchedLgU.Txt
[2005.08.17 09:39:00 | 000,007,060 | R--- | M] () -- C:\WINDOWS\setparam.ini
[2010.09.27 17:20:14 | 000,001,339 | ---- | M] () -- C:\WINDOWS\setupapi.log
[2009.10.18 17:37:58 | 001,025,183 | ---- | M] () -- C:\WINDOWS\setupapi.log.0.old
[2009.10.18 18:20:39 | 001,025,111 | ---- | M] () -- C:\WINDOWS\setupapi.log.1.old
[2009.10.19 22:53:58 | 001,024,101 | ---- | M] () -- C:\WINDOWS\setupapi.log.10.old
[2009.10.19 23:34:06 | 001,024,858 | ---- | M] () -- C:\WINDOWS\setupapi.log.11.old
[2009.10.20 17:18:55 | 001,025,402 | ---- | M] () -- C:\WINDOWS\setupapi.log.12.old
[2009.10.20 17:58:21 | 001,024,739 | ---- | M] () -- C:\WINDOWS\setupapi.log.13.old
[2009.10.20 18:37:05 | 001,025,111 | ---- | M] () -- C:\WINDOWS\setupapi.log.14.old
[2009.10.20 19:15:33 | 001,025,310 | ---- | M] () -- C:\WINDOWS\setupapi.log.15.old
[2009.10.20 19:53:33 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.16.old
[2009.10.21 18:52:44 | 001,024,009 | ---- | M] () -- C:\WINDOWS\setupapi.log.17.old
[2009.10.21 19:34:13 | 001,024,840 | ---- | M] () -- C:\WINDOWS\setupapi.log.18.old
[2009.10.21 20:16:31 | 001,024,858 | ---- | M] () -- C:\WINDOWS\setupapi.log.19.old
[2009.10.18 19:00:06 | 001,024,807 | ---- | M] () -- C:\WINDOWS\setupapi.log.2.old
[2009.10.21 20:58:23 | 001,025,411 | ---- | M] () -- C:\WINDOWS\setupapi.log.20.old
[2009.10.21 21:38:02 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.21.old
[2009.10.21 22:17:53 | 001,024,316 | ---- | M] () -- C:\WINDOWS\setupapi.log.22.old
[2009.10.22 18:01:39 | 001,025,261 | ---- | M] () -- C:\WINDOWS\setupapi.log.23.old
[2009.10.22 22:56:07 | 001,025,181 | ---- | M] () -- C:\WINDOWS\setupapi.log.24.old
[2009.10.22 23:34:47 | 001,025,111 | ---- | M] () -- C:\WINDOWS\setupapi.log.25.old
[2009.10.23 00:12:43 | 001,024,973 | ---- | M] () -- C:\WINDOWS\setupapi.log.26.old
[2009.10.23 00:50:58 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.27.old
[2009.10.23 01:28:29 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.28.old
[2009.10.23 02:06:32 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.29.old
[2009.10.18 19:41:12 | 001,024,202 | ---- | M] () -- C:\WINDOWS\setupapi.log.3.old
[2009.10.23 02:45:13 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.30.old
[2009.10.23 03:23:52 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.31.old
[2009.10.23 04:03:15 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.32.old
[2009.10.23 04:42:07 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.33.old
[2009.10.23 05:21:28 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.34.old
[2009.10.23 06:00:16 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.35.old
[2009.10.23 06:37:33 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.36.old
[2009.10.23 07:15:37 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.37.old
[2009.10.23 07:53:44 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.38.old
[2009.10.23 08:32:33 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.39.old
[2009.10.18 20:22:03 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.4.old
[2009.10.23 09:12:05 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.40.old
[2009.10.23 09:50:42 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.41.old
[2009.10.23 10:28:02 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.42.old
[2009.10.23 11:05:07 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.43.old
[2009.10.23 11:43:34 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.44.old
[2009.10.23 12:23:07 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.45.old
[2009.10.23 13:03:00 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.46.old
[2009.10.23 13:43:46 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.47.old
[2009.10.23 14:23:41 | 001,024,336 | ---- | M] () -- C:\WINDOWS\setupapi.log.48.old
[2009.10.23 15:01:49 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.49.old
[2009.10.18 21:06:07 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.5.old
[2009.10.23 15:41:11 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.50.old
[2009.10.23 16:20:14 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.51.old
[2009.10.23 16:59:31 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.52.old
[2009.10.23 17:40:49 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.53.old
[2009.10.23 18:20:41 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.54.old
[2009.10.23 19:02:53 | 001,024,753 | ---- | M] () -- C:\WINDOWS\setupapi.log.55.old
[2009.10.26 21:23:39 | 001,025,080 | ---- | M] () -- C:\WINDOWS\setupapi.log.56.old
[2009.10.26 22:03:48 | 001,024,772 | ---- | M] () -- C:\WINDOWS\setupapi.log.57.old
[2009.10.26 22:43:03 | 001,024,858 | ---- | M] () -- C:\WINDOWS\setupapi.log.58.old
[2009.10.26 23:22:53 | 001,025,343 | ---- | M] () -- C:\WINDOWS\setupapi.log.59.old
[2009.10.18 21:52:03 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.6.old
[2009.10.27 00:04:06 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.60.old
[2009.10.27 00:45:25 | 001,024,316 | ---- | M] () -- C:\WINDOWS\setupapi.log.61.old
[2009.10.18 22:36:32 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.7.old
[2009.10.18 23:17:15 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.8.old
[2009.10.18 23:55:50 | 001,024,063 | ---- | M] () -- C:\WINDOWS\setupapi.log.9.old
[2007.08.03 13:22:02 | 001,826,816 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SkyTel.exe
[2007.11.07 11:39:22 | 000,000,061 | ---- | M] () -- C:\WINDOWS\smscfg.ini
[2006.07.21 16:14:36 | 000,086,016 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SoundMan.exe
[2008.01.08 20:30:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Sti_Trace.log
[2004.08.04 14:00:00 | 000,065,954 | ---- | M] () -- C:\WINDOWS\Storm i vannglass.bmp
[2007.11.07 12:57:12 | 000,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
[2004.08.04 14:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2004.08.04 14:00:00 | 000,094,800 | ---- | M] (Twain-arbeidsgruppe) -- C:\WINDOWS\twain.dll
[2004.08.04 14:00:00 | 000,050,688 | ---- | M] (Twain-arbeidsgruppe) -- C:\WINDOWS\twain_32.dll
[2004.08.04 14:00:00 | 000,049,680 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_16.exe
[2004.08.04 14:00:00 | 000,025,600 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_32.exe
[2004.08.04 14:00:00 | 000,009,522 | ---- | M] () -- C:\WINDOWS\Ullteppe.bmp
[1999.03.23 10:12:34 | 000,299,520 | ---- | M] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe
[2005.08.30 22:33:38 | 000,000,050 | ---- | M] () -- C:\WINDOWS\UNNeroBackItUp.cfg
[2007.03.20 22:22:04 | 000,972,336 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroBackItUp.exe
[2005.09.15 15:35:46 | 000,000,050 | ---- | M] () -- C:\WINDOWS\UNNeroMediaHome.cfg
[2007.06.01 11:23:46 | 000,972,336 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroMediaHome.exe
[2005.08.30 22:37:04 | 000,000,050 | ---- | M] () -- C:\WINDOWS\UNNeroShowTime.cfg
[2007.02.28 17:41:02 | 000,972,336 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroShowTime.exe
[2005.08.30 22:37:52 | 000,000,050 | ---- | M] () -- C:\WINDOWS\UNNeroVision.cfg
[2007.05.15 10:45:14 | 000,972,336 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroVision.exe
[2005.08.30 22:36:38 | 000,000,050 | ---- | M] () -- C:\WINDOWS\UNRecode.cfg
[2007.04.23 17:42:50 | 000,972,336 | ---- | M] (Nero AG) -- C:\WINDOWS\UNRecode.exe
[2007.11.07 12:03:22 | 000,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
[2007.11.07 12:03:22 | 000,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2004.08.04 14:00:00 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vmmreg32.dll
[2008.04.07 20:25:35 | 000,054,435 | ---- | M] () -- C:\WINDOWS\War3Unin.dat
[2008.04.07 20:25:31 | 000,139,264 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\War3Unin.exe
[2008.04.07 20:25:31 | 000,002,829 | ---- | M] () -- C:\WINDOWS\War3Unin.pif
[2010.09.27 17:21:33 | 000,000,159 | ---- | M] () -- C:\WINDOWS\wiadebug.log
[2010.09.27 17:21:28 | 000,000,050 | ---- | M] () -- C:\WINDOWS\wiaservc.log
[2010.01.06 01:23:42 | 000,000,674 | ---- | M] () -- C:\WINDOWS\win.ini
[2007.11.07 12:04:02 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2010.09.27 17:22:25 | 001,673,362 | ---- | M] () -- C:\WINDOWS\WindowsUpdate.log
[2004.08.04 14:00:00 | 000,256,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhelp.exe
[2004.08.04 14:00:00 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
[2004.08.04 14:00:00 | 000,048,680 | -HS- | M] () -- C:\WINDOWS\winnt.bmp
[2004.08.04 14:00:00 | 000,048,680 | -HS- | M] () -- C:\WINDOWS\winnt256.bmp
[2009.07.10 12:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
[2001.05.16 02:49:00 | 000,025,269 | ---- | M] () -- C:\WINDOWS\WMPrfAra.prx
[2001.05.16 02:48:00 | 000,000,083 | ---- | M] () -- C:\WINDOWS\WMPrfCHS.prx
[2001.05.16 02:48:00 | 000,000,077 | ---- | M] () -- C:\WINDOWS\WMPrfCHT.prx
[2001.05.16 02:48:00 | 000,018,878 | ---- | M] () -- C:\WINDOWS\wmprfcsy.prx
[2001.05.16 02:48:00 | 000,015,903 | ---- | M] () -- C:\WINDOWS\wmprfdan.prx
[2001.05.16 02:48:00 | 000,017,025 | ---- | M] () -- C:\WINDOWS\WMPrfDeu.prx
[2001.05.16 02:48:00 | 000,027,807 | ---- | M] () -- C:\WINDOWS\wmprfell.prx
[2001.05.16 02:49:00 | 000,017,953 | ---- | M] () -- C:\WINDOWS\wmprfesp.prx
[2001.05.16 02:49:00 | 000,016,265 | ---- | M] () -- C:\WINDOWS\wmprffin.prx
[2001.05.16 02:49:00 | 000,019,437 | ---- | M] () -- C:\WINDOWS\wmprffra.prx
[2001.05.16 02:49:00 | 000,020,481 | ---- | M] () -- C:\WINDOWS\wmprfheb.prx
[2001.05.16 02:49:00 | 000,019,751 | ---- | M] () -- C:\WINDOWS\wmprfhun.prx
[2001.05.16 02:49:00 | 000,017,830 | ---- | M] () -- C:\WINDOWS\wmprfita.prx
[2001.05.16 02:49:00 | 000,020,704 | ---- | M] () -- C:\WINDOWS\WMPrfJpn.prx
[2001.05.16 02:49:00 | 000,017,903 | ---- | M] () -- C:\WINDOWS\WMPrfKor.prx
[2001.05.16 02:49:00 | 000,016,398 | ---- | M] () -- C:\WINDOWS\wmprfnld.prx
[2004.08.04 14:00:00 | 000,033,844 | ---- | M] () -- C:\WINDOWS\wmprfNOR.prx
[2001.05.16 02:49:00 | 000,018,536 | ---- | M] () -- C:\WINDOWS\wmprfplk.prx
[2001.05.16 02:49:00 | 000,017,199 | ---- | M] () -- C:\WINDOWS\wmprfptb.prx
[2001.05.16 02:49:00 | 000,018,422 | ---- | M] () -- C:\WINDOWS\wmprfptg.prx
[2001.05.16 02:49:00 | 000,000,635 | ---- | M] () -- C:\WINDOWS\wmprfrus.prx
[2001.05.16 02:48:00 | 000,020,055 | ---- | M] () -- C:\WINDOWS\wmprfsky.prx
[2001.05.16 02:49:00 | 000,016,814 | ---- | M] () -- C:\WINDOWS\wmprfslv.prx
[2001.05.16 02:49:00 | 000,017,019 | ---- | M] () -- C:\WINDOWS\wmprfsve.prx
[2001.05.16 02:49:00 | 000,016,822 | ---- | M] () -- C:\WINDOWS\wmprftrk.prx
[2009.06.17 20:47:26 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2004.08.04 14:00:00 | 000,000,707 | ---- | M] () -- C:\WINDOWS\_default.pif
< %systemroot%*.config > < %systemroot%system32*.db > < HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU > < HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs > ========== Alternate Data Streams ========== @Alternate Data Stream - 55838 bytes -> C:\Documents and Settings\All Users\Skrivebord:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV
@Alternate Data Stream - 55838 bytes -> C:\Documents and Settings\All Users\Programdata\Sports Interactive:$ES_DESCRIPTOR_MVPUV1PKSVXJKX69UK1CWPP0DTVNYKM1UVXPJCEPP4DMJ3K1XYE7LRJEM53EPPJCFPLP45168LPSB5PL0EM6REGXHCTVVVVVVVVVVVVV
@Alternate Data Stream - 478 bytes -> C:\Documents and Settings\All Users\Programdata\TEMP:05EE1EEF
< End of report >