Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

XP won't boot


  • Please log in to reply

#31
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
That is good as it will save a shedload of updates - It may be that it is reading restore points from the wrong drive as they are software only and not security

Have a look at this thread and let me know your thoughts
  • 0

Advertisements


#32
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Let's give it a try. But first I want to give some virus information, if you can use it.

I have copied the sick disk to an extern disk and made a virus check with symantec antivirus. It found the following:

Filename,Risk,Action,Risk Type,Original Location,Computer,User,Status,Current Location,Primary Action,Secondary Action,Logged By,Action Description,Date and Time
Cookie:[email protected]/,Tracking Cookies,Deleted,Trackware,Cookie:[email protected]/,KFH-SERVER,Administrator,Deleted,Deleted,Quarantine,Leave alone (log only),Manual scan,The file was deleted successfully.,12/15/2010 8:58:14 PM
A0010953.exe,Trojan.FakeAV!gen29,Cleaned by deletion,Heuristics,j:\Harddisk 1 Operativsystem C drev\System Volume Information\_restore{C6E98577-297D-49A9-BFE2-137C49573166}\RP122\,KFH-SERVER,Administrator,Deleted,Deleted,Clean security risk,Quarantine,Manual scan,The file was deleted successfully.,12/15/2010 9:34:23 PM
sshnas21.dll,Trojan.FakeAV!gen29,Cleaned by deletion,Heuristics,j:\Harddisk 1 Operativsystem C drev\WINDOWS\system32\,KFH-SERVER,Administrator,Deleted,Deleted,Clean security risk,Quarantine,Manual scan,The file was deleted successfully.,12/15/2010 9:40:32 PM
ejjowgqaffm.exe,Trojan.FakeAV!gen39,Cleaned by deletion,File,j:\Harddisk 1 Operativsystem C drev\_OTL\MovedFiles\12142010_215407\C_Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\temp\capeghsrj\,KFH-SERVER,Administrator,Deleted,Deleted,Clean security risk,Quarantine,Manual scan,The file was deleted successfully.,12/15/2010 9:54:56 PM
  • 0

#33
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

C drev\_OTL\MovedFiles

some files we moved and tracking cookies, but none, as far as I can see that would stop the system booting
  • 0

#34
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
OK, but don't you think it might be a problem with the master boot record ?
  • 0

#35
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
We could try to fix the MBR

To start the Recovery Console directly from the Windows XP CD you would do the following:

Insert the Windows XP cd in your computer.

Restart your computer so you are booting off of the CD.

When the Welcome to Setup screen appears, press the R button on your keyboard to start the Recovery Console.

The Recovery Console will start and ask you which Windows installation you would like to log on to. If you have multiple Windows installations, it will list each one, and you would enter the number associated with the installation you would like to work on and press enter. If you have just one Windows installation, type 1 and press enter.

It will then prompt you for the Administrator's password. If there is no password, simply press enter. Otherwise type in the password and then press enter.

If you entered the correct password you will now be presented with a C:\Windows> prompt

At the prompt type fixmbr

Once done exit from the recovery console and try a reboot
  • 0

#36
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I think it helped. Before I contacted you, I gave the repair a chance, but with no luck, it stopped after restart, at the same point as normal mode did. Now the repair continued after restart, and is running. :-)
  • 0

#37
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
If you manage to get into normal mode re-run OTL and select all users - no need for the custom scan
  • 0

#38
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Then I have to run the fix scan or ?
  • 0

#39
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No just press run scan
  • 0

#40
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
The computer is running again. But I have to understand you properly. Do I have to restart from reatogo disken and re-run OTL ?
  • 0

Advertisements


#41
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I Copied the OTL iso file to my extra disk, and unpacked it. And ran ReatogoMenu, and OTLPE from there. Here is the result. Now, what do I have to do tomorrow, when I get home from work ?

OTL logfile created on: 16-12-2010 01:09:06 - Run
OTLPE by OldTimer - Version 3.1.43.0 Folder = D:\OTLPE_New_Net\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 77,00% Memory free
9,00 Gb Paging File | 9,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 149,00 Gb Total Space | 116,45 Gb Free Space | 78,15% Space Free | Partition Type: NTFS
Drive D: | 233,76 Gb Total Space | 227,76 Gb Free Space | 97,43% Space Free | Partition Type: NTFS
Drive W: | 189,92 Gb Total Space | 99,75 Gb Free Space | 52,52% Space Free | Partition Type: NTFS
Drive X: | 38,29 Gb Total Space | 35,39 Gb Free Space | 92,44% Space Free | Partition Type: NTFS
Drive Y: | 76,33 Gb Total Space | 61,29 Gb Free Space | 80,29% Space Free | Partition Type: NTFS
Drive Z: | 152,66 Gb Total Space | 88,11 Gb Free Space | 57,71% Space Free | Partition Type: NTFS

Computer Name: KLIENT | User Name: Tina Vilhelmsen
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand] -- d:\Programmer\iWin Games\iWinTrusted.exe -- (iWinTrusted)
SRV - [2010-10-16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto] -- C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010-09-01 15:51:28 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.) [On_Demand] -- C:\Programmer\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2010-08-05 18:11:44 | 001,885,488 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2010-07-01 16:17:24 | 001,832,072 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2010-07-01 15:24:02 | 000,357,704 | ---- | M] (Symantec Corporation) [Disabled] -- C:\Programmer\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2010-05-06 16:21:14 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2010-05-06 16:21:14 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto] -- C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2010-03-18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-03-18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010-02-17 09:53:18 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Programmer\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2009-07-20 12:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009-03-30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2008-11-04 00:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008-09-10 16:22:32 | 000,229,648 | ---- | M] (Uniblue) [Auto] -- C:\Programmer\Uniblue\DiskRescue\UBDiskRescueSrv.exe -- (Uniblue DiskRescue)
SRV - [2008-07-26 08:25:36 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008-07-26 08:23:42 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto] -- C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2008-02-28 17:07:48 | 000,529,704 | ---- | M] (Nero AG) [Disabled] -- C:\Programmer\Fælles filer\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2006-12-12 09:22:34 | 000,537,480 | ---- | M] ( ) [On_Demand] -- C:\WINDOWS\System32\dlcqcoms.exe -- (dlcq_device)
SRV - [2006-10-26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Programmer\Fælles filer\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [Kernel | System] -- -- (i2omgmt)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2010-12-09 10:00:00 | 001,360,248 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programmer\Fælles filer\Symantec Shared\VirusDefs\20101215.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2010-12-09 10:00:00 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programmer\Fælles filer\Symantec Shared\VirusDefs\20101215.003\NAVENG.SYS -- (NAVENG)
DRV - [2010-08-29 17:28:02 | 000,125,488 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010-05-26 09:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Programmer\Fælles filer\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010-05-26 09:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010-03-08 11:59:14 | 000,320,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2010-03-08 11:59:14 | 000,283,184 | ---- | M] (Symantec Corporation) [File_System | System] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2010-03-08 11:59:14 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2010-02-26 13:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010-02-26 13:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010-02-26 13:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010-02-26 13:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010-02-26 13:21:22 | 000,137,344 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009-12-18 14:42:12 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009-09-11 12:48:04 | 000,066,056 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2009-09-11 12:47:54 | 000,014,984 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2009-09-11 12:47:32 | 000,035,592 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009-09-11 12:47:22 | 000,022,792 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2009-09-03 16:03:48 | 000,188,080 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2009-09-03 16:03:48 | 000,026,416 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2009-07-14 12:51:12 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2009-06-17 17:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009-06-17 17:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009-02-18 14:44:00 | 006,308,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008-12-18 23:43:18 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2008-12-18 23:43:06 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008-08-26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008-08-25 03:22:00 | 000,014,208 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008-08-05 12:29:00 | 000,039,456 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2008-08-01 11:36:00 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008-08-01 11:36:00 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008-07-26 08:25:02 | 000,025,624 | ---- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008-05-07 12:21:40 | 004,739,072 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-04-13 11:45:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB-lyddriver (WDM)
DRV - [2008-04-13 11:00:04 | 000,225,664 | ---- | M] (Microsoft Corporation) [Kernel | System] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008-04-13 10:53:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008-04-13 08:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007-04-16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2006-02-27 06:46:20 | 000,081,408 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2004-12-16 16:41:30 | 000,089,808 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\slabser.sys -- (slabser)
DRV - [2004-08-12 11:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004-03-11 16:24:14 | 000,052,384 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\slabbus.sys -- (slabbus) CP2101 USB Composite Device driver (WDM)
DRV - [2003-10-16 10:44:04 | 000,082,704 | ---- | M] (MCCI) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\cyg_ser.sys -- (cyg_ser)
DRV - [2003-08-29 07:43:48 | 000,334,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\CamDrL21.sys -- (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0)
DRV - [2003-04-07 10:37:58 | 000,075,264 | ---- | M] (Sunix) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\snxppalx.sys -- (SNXPPALX)
DRV - [2003-04-02 16:06:58 | 000,020,864 | ---- | M] (Sunix) [Kernel | On_Demand] -- C:\WINDOWS\system32\drivers\snxpcard.sys -- (SNXPCARD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk, =
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk, = +
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk,# =
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk,% =
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk,& =
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL\www.google.dk,+ =
IE - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Programmer\Fiddler2\FiddlerHook [2010-11-04 21:04:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Programmer\Nokia\Nokia PC Suite 7\bkmrksync\ [2010-07-22 15:01:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Programmer\Mozilla Firefox\components [2010-11-04 19:57:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Programmer\Mozilla Firefox\plugins [2010-11-17 21:02:13 | 000,000,000 | ---D | M]

[2010-11-17 23:12:54 | 000,000,000 | ---D | M] -- C:\Programmer\Mozilla Firefox\extensions
[2010-07-14 12:07:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-05-18 21:46:59 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programmer\Mozilla Firefox\plugins\npdeployJava1.dll
[2010-10-24 18:19:34 | 000,001,525 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\amazon-co-uk.xml
[2010-10-24 18:19:34 | 000,001,178 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\wikipedia-da.xml
[2010-10-24 18:19:34 | 000,001,102 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\yahoo-dk.xml

O1 HOSTS File: ([2010-12-15 03:54:19 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Hjælp til tilmelding til Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (CutePDF Form Filler Helper) - {D41289F2-69C6-417B-897E-C653D677CBAF} - C:\Programmer\Acro Software\CutePDF Pro\CPFillerCo.dll (Acro Software Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ccApp] C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DLCQCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL ()
O4 - HKLM..\Run: [dlcqmon.exe] C:\Programmer\Dell Photo AIO Printer 966\dlcqmon.exe ()
O4 - HKLM..\Run: [FaxCenterServer] C:\Programmer\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [Google Quick Search Box] C:\Programmer\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe File not found
O4 - HKLM..\Run: [ISUSScheduler] C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Programmer\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [MemoryCardManager] C:\Programmer\Dell Photo AIO Printer 966\memcard.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Programmer\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Programmer\Fælles filer\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PlexUtilities] C:\Programmer\Plextor\PlexUTILITIES\PlexRadar.exe File not found
O4 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003..\Run: [DriverFinder] C:\Programmer\DriverFinder\DriverFinder.exe File not found
O4 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003..\Run: [PC Suite Tray] C:\Programmer\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003..\Run: [Uniblue SpyEraser] C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe (Uniblue Software)
O4 - HKU\.DEFAULT..\RunOnce: [_nltide_2] File not found
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\System32\tscupgrd.exe File not found
O4 - Startup: Error locating startup folders.
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki ... - C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Programmer\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Programmer\Fiddler2\Fiddler.exe (Eric Lawrence)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} https://www.sparnord...e-prod-1.30.cab (ActiveX sikkerhedssoftware Control)
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} http://www.kps.dk/Codebase/FormCtl.cab (Adobe Form Control)
O16 - DPF: {1469FF24-47F6-11D2-8805-006008C537E3} http://www.kps.dk/codebase/ffmail.cab (Adobe Mail Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4F2A3649-7A9F-4950-9C31-409FAC6FC7C8} https://danid.dk/csp...nticode/csp.exe (IssueUtilCtrl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1236725578966 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.h...ctDetection.cab (Reg Error: Key error.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} http://aolsvc.aol.co...web.1.0.0.9.cab (CPlayFirstdreamControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {92EB6641-286A-11D2-A68E-00A0C996A6DD} http://www.kps.dk/co...jfsignature.cab (Adobe Signature Object)
O16 - DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} https://danid.dk/csp...nticode/csp.exe (Util Class)
O16 - DPF: {AD90E8D1-3B47-11D2-A696-00A0C996A6DD} http://www.kps.dk/co...se/jfcrypto.cab (jfCryptoSignature Class)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} http://www.kps.dk/co...criptobject.cab (Adobe Script Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {EF2FB80F-0975-408E-A871-B00CC863478A} http://www.kps.dk/co...ntinstaller.cab (Adobe Soft Font Installer)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll - C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop BackupWallPaper: C:\WINDOWS\Prærievind.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programmer\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-03-10 16:15:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004-04-11 21:48:30 | 000,000,000 | ---- | M] () - Y:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - Z:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010-12-16 00:01:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010-12-15 23:59:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winzm.ime
[2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsp.ime
[2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winpy.ime
[2010-12-15 23:54:56 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wingb.ime
[2010-12-15 23:54:56 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winime.ime
[2010-12-15 23:54:55 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winar30.ime
[2010-12-15 23:54:55 | 000,041,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.dll
[2010-12-15 23:54:55 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.sys
[2010-12-15 23:54:54 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamreg51.dll
[2010-12-15 23:54:53 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svc.dll
[2010-12-15 23:54:53 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wam51.dll
[2010-12-15 23:54:53 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ext.dll
[2010-12-15 23:54:53 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamps51.dll
[2010-12-15 23:54:53 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svapi.dll
[2010-12-15 23:54:53 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ctrs51.dll
[2010-12-15 23:54:52 | 000,426,041 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicepad.dll
[2010-12-15 23:54:52 | 000,086,073 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\voicesub.dll
[2010-12-15 23:54:52 | 000,048,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w32.dll
[2010-12-15 23:54:48 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uihelper.dll
[2010-12-15 23:54:48 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniime.dll
[2010-12-15 23:54:48 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unicdime.ime
[2010-12-15 23:54:47 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsprof.exe
[2010-12-15 23:54:46 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tools.dll
[2010-12-15 23:54:46 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tmigrate.dll
[2010-12-15 23:54:45 | 000,571,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlgnt.ime
[2010-12-15 23:54:45 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintsetp.exe
[2010-12-15 23:54:45 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2010-12-15 23:54:45 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tintlphr.exe
[2010-12-15 23:54:44 | 000,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdipx.sys
[2010-12-15 23:54:44 | 000,019,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdspx.sys
[2010-12-15 23:54:44 | 000,013,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdasync.sys
[2010-12-15 23:54:41 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\svcext51.dll
[2010-12-15 23:54:41 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\status.dll
[2010-12-15 23:54:40 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sspifilt.dll
[2010-12-15 23:54:40 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ssinc51.dll
[2010-12-15 23:54:39 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusbusd.dll
[2010-12-15 23:54:37 | 000,143,422 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\softkey.dll
[2010-12-15 23:54:36 | 000,358,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpincl.dll
[2010-12-15 23:54:36 | 000,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpsmir.dll
[2010-12-15 23:54:36 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpthrd.dll
[2010-12-15 23:54:36 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpstup.dll
[2010-12-15 23:54:36 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmptrap.exe
[2010-12-15 23:54:36 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2010-12-15 23:54:36 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpmib.dll
[2010-12-15 23:54:35 | 000,460,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsvc.dll
[2010-12-15 23:54:35 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpcl.dll
[2010-12-15 23:54:35 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmp.exe
[2010-12-15 23:54:34 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smi2smir.exe
[2010-12-15 23:54:34 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm9aw.dll
[2010-12-15 23:54:34 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb6w.dll
[2010-12-15 23:54:34 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma3w.dll
[2010-12-15 23:54:34 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm93w.dll
[2010-12-15 23:54:34 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsm.dll
[2010-12-15 23:54:34 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2010-12-15 23:54:34 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpapi.dll
[2010-12-15 23:54:34 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smimsgif.dll
[2010-12-15 23:54:34 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsy.dll
[2010-12-15 23:54:33 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm87w.dll
[2010-12-15 23:54:33 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm81w.dll
[2010-12-15 23:54:33 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8cw.dll
[2010-12-15 23:54:33 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm92w.dll
[2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm90w.dll
[2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8dw.dll
[2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8aw.dll
[2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm89w.dll
[2010-12-15 23:54:33 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm59w.dll
[2010-12-15 23:54:32 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\simptcp.dll
[2010-12-15 23:54:30 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seo.dll
[2010-12-15 23:54:29 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2010-12-15 23:54:28 | 000,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2010-12-15 23:54:28 | 000,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2010-12-15 23:54:28 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwnh.dll
[2010-12-15 23:54:27 | 000,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2010-12-15 23:54:27 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rw001ext.dll
[2010-12-15 23:54:26 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\romanime.ime
[2010-12-15 23:54:26 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcref.dll
[2010-12-15 23:54:25 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2010-12-15 23:54:25 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\register.exe
[2010-12-15 23:54:22 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quick.ime
[2010-12-15 23:54:22 | 000,020,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ramdisk.sys
[2010-12-15 23:54:22 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quser.exe
[2010-12-15 23:54:22 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.exe
[2010-12-15 23:54:21 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pwsdata.dll
[2010-12-15 23:54:19 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2010-12-15 23:54:19 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2010-12-15 23:54:19 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxgl.dll
[2010-12-15 23:54:18 | 000,482,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlgnt.ime
[2010-12-15 23:54:18 | 000,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlphr.exe
[2010-12-15 23:54:18 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmigrate.dll
[2010-12-15 23:54:18 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pintlcsd.dll
[2010-12-15 23:54:17 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\phon.ime
[2010-12-15 23:54:17 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\permchk.dll
[2010-12-15 23:54:16 | 000,036,927 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs411.dll
[2010-12-15 23:54:16 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pagecnt.dll
[2010-12-15 23:54:16 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs804.dll
[2010-12-15 23:54:16 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs412.dll
[2010-12-15 23:54:15 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\padrs404.dll
[2010-12-15 23:54:11 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsepm.dll
[2010-12-15 23:54:11 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2010-12-15 23:54:09 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nextlink.dll
[2010-12-15 23:54:06 | 000,229,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\multibox.dll
[2010-12-15 23:54:06 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtstocom.exe
[2010-12-15 23:54:02 | 001,875,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.lex
[2010-12-15 23:54:02 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.dll
[2010-12-15 23:53:55 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\migregdb.exe
[2010-12-15 23:53:54 | 000,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.sys
[2010-12-15 23:53:54 | 000,092,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.dll
[2010-12-15 23:53:54 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\metada51.dll
[2010-12-15 23:53:54 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mdsync.dll
[2010-12-15 23:53:53 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\md5filt.dll
[2010-12-15 23:53:52 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2010-12-15 23:53:51 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lpdsvc.dll
[2010-12-15 23:53:51 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logscrpt.dll
[2010-12-15 23:53:51 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lprmon.dll
[2010-12-15 23:53:51 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lonsint.dll
[2010-12-15 23:53:50 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lmmib2.dll
[2010-12-15 23:53:49 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2010-12-15 23:53:48 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdvntc.dll
[2010-12-15 23:53:48 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdusa.dll
[2010-12-15 23:53:47 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth3.dll
[2010-12-15 23:53:47 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth2.dll
[2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdurdu.dll
[2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth1.dll
[2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdth0.dll
[2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr2.dll
[2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsyr1.dll
[2010-12-15 23:53:46 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecat.dll
[2010-12-15 23:53:46 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnecnt.dll
[2010-12-15 23:53:46 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdnec95.dll
[2010-12-15 23:53:46 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlk41a.dll
[2010-12-15 23:53:46 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlk41j.dll
[2010-12-15 23:53:45 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdibm02.dll
[2010-12-15 23:53:45 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinpun.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintel.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdintam.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinmar.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinkan.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinhin.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdinguj.dll
[2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdindev.dll
[2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdheb.dll
[2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdfa.dll
[2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv2.dll
[2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbddiv1.dll
[2010-12-15 23:53:44 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgeo.dll
[2010-12-15 23:53:43 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jupiw.dll
[2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdax2.dll
[2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd106n.dll
[2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101a.dll
[2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101.dll
[2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda3.dll
[2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda2.dll
[2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbda1.dll
[2010-12-15 23:53:43 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarmw.dll
[2010-12-15 23:53:43 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdarme.dll
[2010-12-15 23:53:42 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iscomlog.dll
[2010-12-15 23:53:42 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iwrps.dll
[2010-12-15 23:53:42 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isapips.dll
[2010-12-15 23:53:41 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iprip.dll
[2010-12-15 23:53:40 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infocomm.dll
[2010-12-15 23:53:40 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoctrs.dll
[2010-12-15 23:53:39 | 000,471,102 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskdic.dll
[2010-12-15 23:53:39 | 000,315,455 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imskf.dll
[2010-12-15 23:53:39 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetin51.exe
[2010-12-15 23:53:38 | 000,274,489 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputyc.dll
[2010-12-15 23:53:38 | 000,262,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjputy.exe
[2010-12-15 23:53:38 | 000,233,527 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjprw.exe
[2010-12-15 23:53:38 | 000,102,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imlang.dll
[2010-12-15 23:53:38 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imkrinst.exe
[2010-12-15 23:53:38 | 000,045,109 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpuex.exe
[2010-12-15 23:53:37 | 000,716,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcus.dll
[2010-12-15 23:53:37 | 000,368,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpcic.dll
[2010-12-15 23:53:37 | 000,307,257 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.exe
[2010-12-15 23:53:37 | 000,208,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpmig.exe
[2010-12-15 23:53:37 | 000,155,705 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdsvr.exe
[2010-12-15 23:53:37 | 000,081,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdct.dll
[2010-12-15 23:53:37 | 000,057,398 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjpdadm.exe
[2010-12-15 23:53:36 | 000,811,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81k.dll
[2010-12-15 23:53:36 | 000,340,023 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imjp81.ime
[2010-12-15 23:53:36 | 000,311,359 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsv.exe
[2010-12-15 23:53:36 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrcic.dll
[2010-12-15 23:53:36 | 000,102,463 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsm.dll
[2010-12-15 23:53:36 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekr61.ime
[2010-12-15 23:53:36 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmbx.dll
[2010-12-15 23:53:36 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imekrmig.exe
[2010-12-15 23:53:35 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iische51.dll
[2010-12-15 23:53:35 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iislog51.dll
[2010-12-15 23:53:35 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisclex4.dll
[2010-12-15 23:53:35 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iiscrmap.dll
[2010-12-15 23:53:35 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisfecnv.dll
[2010-12-15 23:53:35 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iissync.exe
[2010-12-15 23:53:35 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismui.dll
[2010-12-15 23:53:34 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisadmin.dll
[2010-12-15 23:53:30 | 010,129,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxkor.dll
[2010-12-15 23:53:24 | 010,096,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hwxcht.dll
[2010-12-15 23:53:23 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpext.dll
[2010-12-15 23:53:23 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpod51.dll
[2010-12-15 23:53:23 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpmb51.dll
[2010-12-15 23:53:22 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hostmib.dll
[2010-12-15 23:53:22 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hanjadic.dll
[2010-12-15 23:53:21 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gzip.dll
[2010-12-15 23:53:20 | 000,400,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsxp32.dll
[2010-12-15 23:53:20 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxswzrd.dll
[2010-12-15 23:53:20 | 000,154,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsui.dll
[2010-12-15 23:53:19 | 000,562,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsst.dll
[2010-12-15 23:53:19 | 000,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxstiff.dll
[2010-12-15 23:53:19 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssvc.exe
[2010-12-15 23:53:19 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxst30.dll
[2010-12-15 23:53:19 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsroute.dll
[2010-12-15 23:53:19 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsmon.dll
[2010-12-15 23:53:19 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsext32.dll
[2010-12-15 23:53:19 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssend.exe
[2010-12-15 23:53:19 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsperf.dll
[2010-12-15 23:53:19 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsres.dll
[2010-12-15 23:53:18 | 000,451,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsapi.dll
[2010-12-15 23:53:18 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscomex.dll
[2010-12-15 23:53:18 | 000,232,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscover.exe
[2010-12-15 23:53:18 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclnt.exe
[2010-12-15 23:53:18 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclntr.dll
[2010-12-15 23:53:18 | 000,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscfgwz.dll
[2010-12-15 23:53:18 | 000,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscom.dll
[2010-12-15 23:53:18 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsevent.dll
[2010-12-15 23:53:18 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsdrv.dll
[2010-12-15 23:53:17 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsv251.dll
[2010-12-15 23:53:17 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpctrs2.dll
[2010-12-15 23:53:17 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpmib.dll
[2010-12-15 23:53:17 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftlx041e.dll
[2010-12-15 23:53:16 | 000,024,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmcgi.exe
[2010-12-15 23:53:16 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmdll.dll
[2010-12-15 23:53:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2010-12-15 23:53:15 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\flattemp.exe
[2010-12-15 23:53:14 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntagnt.dll
[2010-12-15 23:53:14 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntwin.exe
[2010-12-15 23:53:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntcmd.exe
[2010-12-15 23:53:14 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\exstrace.dll
[2010-12-15 23:53:14 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\f3ahvoas.dll
[2010-12-15 23:53:13 | 000,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2010-12-15 23:53:13 | 000,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2010-12-15 23:53:13 | 000,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2010-12-15 23:53:13 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\et4000.sys
[2010-12-15 23:53:04 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dayi.ime
[2010-12-15 23:53:04 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\davcdata.exe
[2010-12-15 23:53:02 | 000,057,399 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cplexe.exe
[2010-12-15 23:53:02 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cprofile.exe
[2010-12-15 23:53:01 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\convlog.exe
[2010-12-15 23:53:01 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\controt.dll
[2010-12-15 23:53:01 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\counters.dll
[2010-12-15 23:53:00 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\compfilt.dll
[2010-12-15 23:52:59 | 000,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintsetp.exe
[2010-12-15 23:52:58 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintime.dll
[2010-12-15 23:52:58 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtmbx.dll
[2010-12-15 23:52:58 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtskdic.dll
[2010-12-15 23:52:58 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cintlgnt.ime
[2010-12-15 23:52:57 | 001,677,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2010-12-15 23:52:57 | 000,838,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2010-12-15 23:52:57 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgusr.exe
[2010-12-15 23:52:56 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chajei.ime
[2010-12-15 23:52:56 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgport.exe
[2010-12-15 23:52:56 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chglogon.exe
[2010-12-15 23:52:56 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\change.exe
[2010-12-15 23:52:55 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2010-12-15 23:52:55 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_iscii.dll
[2010-12-15 23:52:55 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_is2022.dll
[2010-12-15 23:52:54 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\c_g18030.dll
[2010-12-15 23:52:47 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browscap.dll
[2010-12-15 23:52:47 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bootok.exe
[2010-12-15 23:52:45 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\authfilt.dll
[2010-12-15 23:52:44 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asp51.dll
[2010-12-15 23:52:44 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asptxn.dll
[2010-12-15 23:52:44 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aspperf.dll
[2010-12-15 23:52:43 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\appconf.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0804.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0412.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0411.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt040d.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0404.dll
[2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0401.dll
[2010-12-15 23:52:41 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2010-12-15 23:52:40 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adrot.dll
[2010-12-15 23:52:40 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admexs.dll
[2010-12-15 23:52:40 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admxprox.dll
[2010-12-15 23:52:36 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamregps.dll
[2010-12-15 23:52:35 | 002,134,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2010-12-15 23:52:35 | 000,032,827 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptest.exe
[2010-12-15 23:52:35 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptsat.dll
[2010-12-15 23:52:35 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\staxmem.dll
[2010-12-15 23:52:34 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpadm.dll
[2010-12-15 23:52:34 | 000,020,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.dll
[2010-12-15 23:52:34 | 000,016,437 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.exe
[2010-12-15 23:52:30 | 000,833,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.dll
[2010-12-15 23:52:30 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logui.ocx
[2010-12-15 23:52:30 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isatq.dll
[2010-12-15 23:52:30 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetsloc.dll
[2010-12-15 23:52:30 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoadmn.dll
[2010-12-15 23:52:30 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.exe
[2010-12-15 23:52:29 | 000,171,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisui.dll
[2010-12-15 23:52:29 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrtl.dll
[2010-12-15 23:52:29 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisext51.dll
[2010-12-15 23:52:29 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismap.dll
[2010-12-15 23:52:29 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstas.exe
[2010-12-15 23:52:29 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisreset.exe
[2010-12-15 23:52:29 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstap.dll
[2010-12-15 23:52:28 | 000,598,071 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmc.dll
[2010-12-15 23:52:28 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2010-12-15 23:52:28 | 000,188,494 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpcount.exe
[2010-12-15 23:52:28 | 000,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpexedll.dll
[2010-12-15 23:52:28 | 000,020,538 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpremadm.exe
[2010-12-15 23:52:28 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2010-12-15 23:52:27 | 000,876,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awel.dll
[2010-12-15 23:52:27 | 000,147,513 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4apws.dll
[2010-12-15 23:52:27 | 000,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2010-12-15 23:52:27 | 000,102,509 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2010-12-15 23:52:27 | 000,082,035 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2010-12-15 23:52:27 | 000,049,212 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2010-12-15 23:52:27 | 000,049,210 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4areg.dll
[2010-12-15 23:52:27 | 000,041,020 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2010-12-15 23:52:27 | 000,032,826 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avss.dll
[2010-12-15 23:52:27 | 000,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2010-12-15 23:52:26 | 000,184,435 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2010-12-15 23:52:26 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\coadmin.dll
[2010-12-15 23:52:25 | 000,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certwiz.ocx
[2010-12-15 23:52:25 | 000,188,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2010-12-15 23:52:25 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certmap.ocx
[2010-12-15 23:52:25 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2010-12-15 23:52:25 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.dll
[2010-12-15 23:52:25 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.exe
[2010-12-15 23:52:24 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adsiis51.dll
[2010-12-15 23:52:24 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admwprox.dll
[2010-12-15 23:52:24 | 000,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.exe
[2010-12-15 23:52:23 | 000,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.dll
[2010-12-15 23:49:39 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isignup.exe
[2010-12-15 23:47:26 | 000,000,000 | ---D | C] -- C:\Programmer\ComPlus Applications
[2010-12-15 23:47:06 | 000,000,000 | ---D | C] -- C:\Programmer\Messenger
[2010-12-15 23:33:18 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2010-12-15 23:33:18 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll
[2010-12-15 23:33:17 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll
[2010-12-15 23:33:17 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxcoins.dll
[2010-12-15 03:54:07 | 000,000,000 | ---D | C] -- C:\_OTL
[2010-12-13 19:59:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Driver_Detective_v6.4.1.5_Full_Cracked_Version_Of_2010_Multilang_incl_Bonus_Tools.part2
[2010-12-13 19:47:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Usenet.nl
[2010-12-13 19:47:17 | 000,000,000 | ---D | C] -- C:\Programmer\Usenet.nl
[2010-12-13 19:12:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\PlexUTILITIES
[2010-12-13 19:12:30 | 000,000,000 | ---D | C] -- C:\Programmer\Plextor
[2010-12-13 18:48:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\DriverFinder
[2010-12-08 22:14:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010-11-18 21:51:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\.oces2
[2010-11-18 21:02:54 | 000,000,000 | ---D | C] -- C:\Programmer\Fælles filer\Adobe
[2010-11-18 21:02:54 | 000,000,000 | ---D | C] -- C:\Programmer\Adobe
[2010-11-18 17:45:25 | 000,000,000 | ---D | C] -- C:\Programmer\Windows Installer Clean Up
[2010-11-17 21:02:12 | 000,000,000 | ---D | C] -- C:\Programmer\NOS
[2010-11-17 19:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF_Filler
[2010-11-17 19:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CustomStamp
[2010-11-17 19:28:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF_Pro
[2010-11-17 19:28:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF
[2010-11-17 19:28:51 | 000,000,000 | ---D | C] -- C:\Programmer\GPLGS
[2010-11-17 18:47:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF Writer
[2010-11-16 15:53:07 | 000,000,000 | ---D | C] -- C:\iPod Photo Cache
[2010-11-16 15:53:05 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2010-11-16 15:53:04 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2009-03-18 21:48:06 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\DLCQhcp.dll
[2006-10-11 23:41:42 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqinpa.dll
[2006-10-11 23:01:40 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqpmui.dll
[2006-10-11 22:59:56 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqserv.dll
[2006-10-11 22:54:10 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqcomm.dll
[2006-10-11 22:52:34 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqlmpm.dll
[2006-10-11 22:51:16 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqiesc.dll
[2006-10-11 22:48:58 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqpplc.dll
[2006-10-11 22:48:14 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqcomc.dll
[2006-10-11 22:47:42 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqprox.dll
[2006-10-11 22:41:04 | 000,991,232 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqusb1.dll
[2006-10-11 22:37:14 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcqhbn3.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-12-16 00:58:06 | 000,544,506 | ---- | M] () -- C:\WINDOWS\System32\perfh006.dat
[2010-12-16 00:58:06 | 000,505,436 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-12-16 00:58:06 | 000,110,916 | ---- | M] () -- C:\WINDOWS\System32\perfc006.dat
[2010-12-16 00:58:06 | 000,089,004 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-12-16 00:54:46 | 000,206,324 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-12-16 00:54:10 | 000,000,910 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010-12-16 00:54:10 | 000,000,198 | ---- | M] () -- C:\PSLOG
[2010-12-16 00:53:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-12-16 00:50:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010-12-16 00:35:51 | 000,001,064 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003UA.job
[2010-12-16 00:35:39 | 000,002,439 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Google Chrome.lnk
[2010-12-16 00:35:39 | 000,002,417 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010-12-16 00:07:22 | 000,026,192 | ---- | M] () -- C:\WINDOWS\System32\LexFiles.ulf
[2010-12-16 00:06:31 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job
[2010-12-16 00:03:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-12-15 23:58:49 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-12-15 23:56:19 | 000,000,287 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2010-12-15 23:52:01 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010-12-15 23:52:00 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010-12-15 23:52:00 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010-12-15 23:51:47 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2010-12-15 23:47:37 | 000,023,404 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-12-15 23:44:58 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010-12-15 00:33:56 | 000,003,069 | ---- | M] () -- C:\rst.sh
[2010-12-13 19:47:18 | 000,001,552 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Usenet.nl.lnk
[2010-12-12 22:12:40 | 000,000,111 | ---- | M] () -- C:\WINDOWS\GMouse.ini
[2010-12-12 21:35:00 | 000,001,012 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003Core.job
[2010-12-11 08:11:00 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010-12-06 19:42:14 | 000,000,760 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\setup_ldm.iss
[2010-11-30 19:43:53 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\temp.dat
[2010-11-17 22:27:23 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk
[2010-11-16 15:55:17 | 000,053,216 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-12-15 23:54:18 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010-12-15 23:53:49 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010-12-15 23:53:38 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010-12-15 23:53:37 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010-12-15 23:53:35 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010-12-15 23:53:26 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010-12-15 23:53:21 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010-12-15 23:53:16 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010-12-15 23:52:58 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010-12-15 23:33:01 | 001,246,013 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2010-12-15 23:33:01 | 000,809,684 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010-12-15 23:33:01 | 000,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010-12-15 23:33:01 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2010-12-15 23:33:01 | 000,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2010-12-15 23:33:01 | 000,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010-12-15 23:33:01 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2010-12-15 23:33:01 | 000,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2010-12-15 23:33:01 | 000,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2010-12-15 23:33:01 | 000,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010-12-15 23:33:01 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010-12-15 23:33:01 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010-12-15 23:33:01 | 000,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010-12-15 23:33:01 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010-12-15 23:33:00 | 002,033,299 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2010-12-15 23:33:00 | 000,633,432 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2010-12-15 23:06:58 | 000,003,069 | ---- | C] () -- C:\rst.sh
[2010-12-13 19:47:18 | 000,001,552 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Usenet.nl.lnk
[2010-12-06 19:42:14 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\setup_ldm.iss
[2010-11-18 21:51:26 | 001,085,191 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\danid.log.1
[2010-11-18 21:51:26 | 000,804,502 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\danid.log
[2010-11-17 22:27:23 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk
[2010-11-17 19:27:42 | 000,087,544 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010-11-16 15:55:17 | 000,053,216 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010-11-09 00:35:32 | 000,000,111 | ---- | C] () -- C:\WINDOWS\GMouse.ini
[2010-10-20 06:48:18 | 000,272,254 | ---- | C] () -- C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-2052111302-412668190-1801674531-1003-0.dat
[2010-10-20 06:48:16 | 000,160,712 | ---- | C] () -- C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat
[2010-10-20 06:48:14 | 000,272,254 | ---- | C] () -- C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-System.dat
[2010-08-12 22:29:37 | 000,010,361 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\golfbolde.xlsx
[2010-06-19 11:35:47 | 000,000,001 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\oashdihasidhasuidhiasdhiashdiuasdhasd
[2010-05-16 20:21:14 | 000,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010-05-16 20:21:14 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\BCEDB1EE70.sys
[2010-01-27 19:14:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EkspresLøn.INI
[2009-10-03 16:10:54 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009-10-03 15:29:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\WgaLogon.dll
[2009-04-02 19:18:51 | 000,007,610 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\slot1.mm1
[2009-03-25 12:54:00 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\temp.dat
[2009-03-18 21:48:06 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\DLCQinst.dll
[2009-03-18 21:42:28 | 000,344,064 | R--- | C] () -- C:\WINDOWS\System32\dlcqcoin.dll
[2009-03-18 21:42:27 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\DLCQcfg.dll
[2009-03-18 20:30:53 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\Bot.dll
[2009-03-18 20:30:53 | 000,000,101 | ---- | C] () -- C:\WINDOWS\Psxlpr.ini
[2009-03-18 16:53:28 | 000,054,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\snxpserx.sys
[2009-03-18 16:53:28 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\snxprops.dll
[2009-03-14 22:30:10 | 000,000,216 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-03-14 03:43:31 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\default.pls
[2009-03-12 22:41:36 | 000,001,199 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\CommandDispatchers.xml
[2009-03-12 22:41:35 | 000,001,162 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\cleaner-config.xml
[2009-03-11 22:48:33 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-03-11 22:47:55 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-03-11 20:09:06 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\WBCustomizer.dll
[2009-03-11 17:07:39 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\.rnd
[2009-03-11 03:35:14 | 000,014,938 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009-03-11 03:21:59 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\DLPRMON.DLL
[2009-03-11 03:21:59 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\DLPMONUI.DLL
[2009-03-11 02:54:51 | 000,000,602 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2009-03-11 02:50:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\HPMProp.INI
[2009-03-11 00:58:39 | 000,035,000 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2009-03-11 00:19:00 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\fusioncache.dat
[2009-03-10 22:53:23 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009-03-10 22:53:10 | 000,036,054 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009-03-10 22:53:08 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009-03-10 16:57:18 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008-10-07 09:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008-10-07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008-07-26 08:25:02 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008-05-26 22:23:18 | 000,016,130 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008-05-26 22:23:16 | 000,021,898 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008-05-26 22:23:14 | 000,016,012 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008-01-03 15:26:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-01-03 15:26:00 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-01-03 15:26:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-01-03 15:26:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-01-03 15:26:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-10-21 01:17:44 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcqinsb.dll
[2006-10-21 01:17:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcqcub.dll
[2006-10-21 01:15:28 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcqcu.dll
[2006-10-21 01:14:54 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcqins.dll
[2006-10-21 01:09:16 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\dlcqutil.dll
[2006-10-20 08:35:38 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlcqinsr.dll
[2006-10-20 08:35:32 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcqcur.dll
[2006-10-20 08:34:30 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\dlcqjswr.dll
[2006-10-20 06:35:40 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\dlcqgrd.dll
[2006-08-14 17:32:18 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcqcaps.dll
[2006-08-08 15:58:04 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\dlcqdrs.dll
[2006-05-09 10:10:04 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlcqcnv4.dll
[2006-04-25 08:11:18 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlcqvs.dll
[2004-07-10 18:55:38 | 000,252,416 | ---- | C] () -- C:\WINDOWS\System32\wsiShared.dll
[2004-03-15 14:29:12 | 000,000,061 | ---- | C] () -- C:\WINDOWS\System32\uninstall.ini
[1999-01-27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997-06-13 07:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2009-03-13 10:06:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Cryptomathic
[2010-12-13 19:28:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\DriverFinder
[2010-04-26 20:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\GARMIN
[2010-11-09 22:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\GetRightToGo
[2009-03-11 12:15:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Leadertech
[2010-11-09 23:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mouse Recorder Pro
[2010-06-13 14:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Nokia
[2010-06-13 14:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\PC Suite
[2010-05-26 21:01:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Uniblue
[2010-12-13 20:12:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Usenet.nl
[2009-03-11 00:16:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Windows Desktop Search
[2009-03-11 13:53:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tina Vilhelmsen\Application Data\Windows Search
[2009-04-05 12:36:38 | 000,000,386 | ---- | M] () -- C:\WINDOWS\Tasks\Uniblue DiskRescue 2009.job
[2010-07-14 13:06:38 | 000,000,346 | ---- | M] () -- C:\WINDOWS\Tasks\Uniblue SpyEraser.job
[2010-12-16 00:06:31 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job

========== Purity Check ==========


< End of report >
  • 0

#42
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I'd like to do a deep check now to see if I can find out why one of your programmes tried to kill the MBR

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#43
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
When I run Combofix I get an error message

"Windows - No disk

Exception Processing Message c0000013 Parameters 75b4bf7c"

The error message pops up several times during combofix autoscan.

How do I fix xp, so this message don't show ?

Re.: Microsoft recovery consol

Combofix can not find download page

How can I install microsoft recovery consol ?

Here is the combofix.log:

ComboFix 10-12-15.07 - Tina Vilhelmsen 16-12-2010 19:34:32.6.3 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.3582.2941 [GMT 1:00]
Kører fra: c:\documents and settings\Tina Vilhelmsen\Skrivebord\ComboFix.exe
AV: Symantec Endpoint Protection *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Tina Vilhelmsen\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((( Filer skabt fra 2010-11-16 til 2010-12-16 )))))))))))))))))))))))))))))))))))
.

2010-12-15 22:53 . 2008-04-14 07:05 7680 -c--a-w- c:\windows\system32\dllcache\migregdb.exe
2010-12-15 22:52 . 2008-04-13 07:43 480256 -c--a-w- c:\windows\system32\dllcache\cintsetp.exe
2010-12-15 22:49 . 2001-10-09 11:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-12-15 22:49 . 2001-10-09 11:00 16384 ----a-w- c:\programmer\Internet Explorer\Connection Wizard\isignup.exe
2010-12-15 22:33 . 2001-10-09 11:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-12-15 22:33 . 2001-10-09 11:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-12-15 22:33 . 2001-10-09 11:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-12-15 22:33 . 2001-10-09 11:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-12-15 22:32 . 2008-04-14 08:00 16825 ----a-r- c:\windows\SET155.tmp
2010-12-15 22:32 . 2008-04-14 08:01 1088840 ----a-r- c:\windows\SET149.tmp
2010-12-15 22:32 . 2008-04-14 08:07 1246013 ----a-r- c:\windows\SET146.tmp
2010-12-15 02:54 . 2010-12-15 02:54 -------- d-----w- C:\_OTL
2010-12-13 18:47 . 2010-12-13 19:12 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\Application Data\Usenet.nl
2010-12-13 18:47 . 2010-12-13 18:47 -------- d-----w- c:\programmer\Usenet.nl
2010-12-13 18:33 . 2010-12-13 18:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-12-13 18:12 . 2010-12-13 18:12 -------- d-----w- c:\windows\PlexUTILITIES
2010-12-13 18:12 . 2010-12-13 18:12 -------- d-----w- c:\programmer\Plextor
2010-12-13 17:48 . 2010-12-13 18:28 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\Application Data\DriverFinder
2010-12-08 21:14 . 2010-12-08 21:14 -------- d-----w- c:\documents and settings\LocalService\Application Data\Apple Computer
2010-11-18 20:51 . 2010-11-18 20:51 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\.oces2
2010-11-18 20:02 . 2010-11-18 20:02 -------- d-----w- c:\programmer\Fælles filer\Adobe
2010-11-18 19:22 . 2010-11-18 19:22 -------- d-----w- c:\documents and settings\Administrator
2010-11-18 16:45 . 2010-11-18 16:45 3584 ----a-r- c:\documents and settings\Tina Vilhelmsen\Application Data\Microsoft\Installer\{121634B0-2F4A-11D3-ADA3-00C04F52DD53}\Icon386ED4E3.exe
2010-11-18 16:45 . 2010-11-18 16:45 -------- d-----w- c:\programmer\Windows Installer Clean Up
2010-11-18 16:44 . 2010-11-18 16:44 189920 ----a-w- c:\temp\msicuu2.exe
2010-11-17 20:02 . 2010-11-17 20:02 -------- d-----w- c:\windows\system32\wbem\Repository
2010-11-17 20:02 . 2010-11-17 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-11-17 20:02 . 2010-11-17 20:02 -------- d-----w- c:\programmer\NOS
2010-11-17 19:16 . 2010-09-01 14:51 35136 ----a-w- c:\programmer\Mozilla Firefox\plugins\np_gp.dll
2010-11-17 18:29 . 2010-11-17 18:34 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CustomStamp
2010-11-17 18:28 . 2010-11-17 18:31 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF
2010-11-17 18:28 . 2010-11-17 18:28 -------- d-----w- c:\programmer\GPLGS
2010-11-17 18:27 . 2010-03-11 13:22 87544 ----a-w- c:\windows\system32\cpwmon2k.dll
2010-11-17 17:47 . 2010-12-08 16:16 -------- d-----w- c:\documents and settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF Writer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-07 11:23 . 2010-10-07 11:23 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-10-07 11:23 . 2010-10-07 11:23 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-10-07 11:23 . 2010-10-07 11:23 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-10-07 11:23 . 2010-10-07 11:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-09-28 14:44 . 2010-11-03 17:29 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2010-11-03 17:29 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
.

------- Sigcheck -------

[-] 2009-02-02 . 8ADD18C6AB9CF788DF7EBF08FDDC1EA7 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-10 39408]
"Uniblue SpyEraser"="c:\programmer\Uniblue\SpyEraser\SpyEraser.exe" [2010-01-11 1431816]
"PC Suite Tray"="c:\programmer\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"nwiz"="nwiz.exe" [2009-02-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"LogitechCommunicationsManager"="c:\programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\programmer\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"NeroFilterCheck"="c:\programmer\Fælles filer\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\programmer\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"FaxCenterServer"="c:\programmer\Dell PC Fax\fm3032.exe" [2007-06-29 312560]
"DLCQCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]
"Google Quick Search Box"="c:\programmer\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-08 68592]
"ccApp"="c:\programmer\Fælles filer\Symantec Shared\ccApp.exe" [2010-05-06 115560]
"MemoryCardManager"="c:\programmer\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 304368]
"dlcqmon.exe"="c:\programmer\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 292080]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [BU]

c:\documents and settings\Tina Vilhelmsen\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - c:\programmer\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Logitech SetPoint.lnk - c:\programmer\Logitech\SetPoint\SetPoint.exe [2009-3-11 813584]
Windows Search.lnk - c:\programmer\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmer\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\programmer\Fælles filer\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dlcqcoms.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmer\\ASUS\\ASUSUpdate\\Update.exe"=
"c:\\Programmer\\PrintServer Network driver\\Remote.exe"=
"c:\\Programmer\\PrintServer Utilities\\WinUtil\\wincfg.exe"=
"c:\\Programmer\\SkyGolf\\SkyCaddie Desktop\\SkyCaddieDesktop.exe"=
"c:\\Programmer\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Programmer\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Programmer\\Fælles filer\\Symantec Shared\\ccApp.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Fjernadministration

R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [11-03-2009 03:04 10384]
R2 Uniblue DiskRescue;Uniblue DiskRescue;c:\programmer\Uniblue\DiskRescue\UBDiskRescueSrv.exe [10-09-2008 16:22 229648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26-05-2010 09:00 102448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18-03-2010 12:16 130384]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [29-01-2010 08:25 135664]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [14-07-2009 12:51 23888]
S3 cyg_ser;CP2101 USB to UART Bridge Controller Drivers;c:\windows\system32\drivers\cyg_ser.sys [19-07-2010 15:54 82704]
S3 iWinTrusted;iWinTrusted;d:\programmer\iWin Games\iWinTrusted.exe --> d:\programmer\iWin Games\iWinTrusted.exe [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [13-06-2010 14:08 137344]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [14-04-2008 08:06 14336]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [11-03-2009 01:09 39456]
S3 SNXPCARD;Sunix PCI Multi I/O Card Driver;c:\windows\system32\drivers\snxpcard.sys [11-03-2009 02:34 20864]
S3 SNXPPALX;Golden Parallel Port Driver;c:\windows\system32\drivers\snxppalx.sys [11-03-2009 02:35 75264]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [03-11-2010 18:29 41984]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14-04-2008 08:06 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18-03-2010 12:16 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WINRM REG_MULTI_SZ WINRM
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Indhold af mappen 'Planlagte Opgaver'

2010-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]

2010-12-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-29 07:24]

2010-12-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-29 07:24]

2010-12-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003Core.job
- c:\documents and settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2010-10-27 19:45]

2010-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003UA.job
- c:\documents and settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2010-10-27 19:45]

2009-04-05 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\programmer\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]

2010-07-14 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\programmer\Uniblue\SpyEraser\SpyEraser.exe [2009-03-12 02:41]

2010-12-15 c:\windows\Tasks\User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job
- c:\windows\system32\msfeedssync.exe [2009-02-02 19:37]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: body-work.dk\www
Trusted Zone: danid.dk
Trusted Zone: sikker-adgang.dk\login
Trusted Zone: skat.dk\www.tastselv
Trusted Zone: sparnord.dk\www
Trusted Zone: virk.dk\www
Trusted Zone: danid.dk
TCP: {56F5A06E-C853-40A9-ACD4-A8A973433889} = 194.239.134.83,193.162.153.164
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.sparnord.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab
DPF: {1469FF24-47F6-11D2-8805-006008C537E3} - hxxp://www.kps.dk/codebase/ffmail.cab
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://aolsvc.aol.com/onlinegames/free-trial-dream-chronicles/dreamweb.1.0.0.9.cab
DPF: {92EB6641-286A-11D2-A68E-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfsignature.cab
DPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {AD90E8D1-3B47-11D2-A696-00A0C996A6DD} - hxxp://www.kps.dk/codebase/jfcrypto.cab
FF - ProfilePath - c:\documents and settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmer\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
FF - Ext: FireFTP: {a7c6cf7f-112c-4500-a7ea-39801a327e5f} - %profile%\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
FF - Ext: Java Quick Starter: [email protected] - c:\programmer\Java\jre6\lib\deploy\jqs\ff
FF - Ext: FiddlerHook: [email protected] - c:\programmer\Fiddler2\FiddlerHook
FF - Ext: PC Sync 2 Synchronisation Extension: [email protected] - c:\programmer\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - TOMME GENVEJE FJERNET - - - -

HKCU-Run-DriverFinder - c:\programmer\DriverFinder\DriverFinder.exe
HKLM-Run-ISUSPM Startup - c:\programmer\Fælles filer\InstallShield\UpdateService\isuspm.exe
HKLM-Run-PlexUtilities - c:\programmer\Plextor\PlexUTILITIES\PlexRadar.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-SYSTEMCARE_025B3ECB-F8A1-45ff-BABC-140E08C7D8C5_is1 - c:\programmer\Uniblue\unins000.exe
AddRemove-{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1 - c:\programmer\Uniblue\RegistryBooster\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-16 19:41
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ...

scanner skjulte autostarter ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,[email protected]???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanner skjulte filer ...

scanning gennemført med succes
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(896)
c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll
c:\programmer\fælles filer\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(10192)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\programmer\Logitech\SetPoint\GameHook.dll
c:\programmer\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\programmer\Google\Quick Search Box\bin\1.2.1151.245\qsb.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmer\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmer\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmer\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_dan.nlr
c:\programmer\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Symantec\Symantec Endpoint Protection\Smc.exe
c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
c:\programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
c:\programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe
c:\programmer\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
c:\programmer\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\windows\system32\dlcqcoms.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\programmer\Symantec\Symantec Endpoint Protection\SavUI.exe
c:\windows\system32\SearchIndexer.exe
c:\programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Gennemført tid: 2010-12-16 19:46:36 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-12-16 18:46
ComboFix2.txt 2010-04-18 14:34
ComboFix3.txt 2010-04-17 20:27
ComboFix4.txt 2009-12-22 11:47
ComboFix5.txt 2010-12-16 18:32

Pre-Kørsel: 125.045.153.792 byte ledig
Post-Kørsel: 125.078.192.128 byte ledig

- - End Of File - - 877BC5B58D7F1FAA7A1347778CB629B4
  • 0

#44
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Lets use a different analysis programme to see what is what

Download OTS to your Desktop and double-click on it to run it
  • Make sure you close all other programs and don't use the PC while the scan runs.
  • Select All Users
  • Under additional scans select the following
    Reg - NetSvcs
    Reg - Shell Spawning
    Evnt - EventViewer Logs (Last 10 Errors)
    File - Lop Check
    File - Purity Scan

  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Please attach the log in your next post.

  • 0

#45
Ruske

Ruske

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
After OTS scan complete the error with "Windows - no disk .........." show before the log file opens.

OTS logfile created on: 16-12-2010 20:52:56 - Run 1
OTS by OldTimer - Version 3.1.40.1 Folder = C:\Documents and Settings\Tina Vilhelmsen\Skrivebord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 79,00% Memory free
9,00 Gb Paging File | 9,00 Gb Available in Paging File | 95,00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 149,00 Gb Total Space | 116,51 Gb Free Space | 78,20% Space Free | Partition Type: NTFS
Drive D: | 233,76 Gb Total Space | 227,76 Gb Free Space | 97,43% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 465,65 Gb Total Space | 417,45 Gb Free Space | 89,65% Space Free | Partition Type: FAT32
Drive W: | 189,92 Gb Total Space | 99,75 Gb Free Space | 52,52% Space Free | Partition Type: NTFS
Drive X: | 38,29 Gb Total Space | 35,39 Gb Free Space | 92,44% Space Free | Partition Type: NTFS
Drive Y: | 76,33 Gb Total Space | 61,29 Gb Free Space | 80,29% Space Free | Partition Type: NTFS
Drive Z: | 152,66 Gb Total Space | 88,10 Gb Free Space | 57,71% Space Free | Partition Type: NTFS

Computer Name: KLIENT
Current User Name: Tina Vilhelmsen
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days

[Processes - Safe List]
ots.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\OTS.exe -> [2010-12-16 20:48:04 | 000,642,048 | ---- | M] (OldTimer Tools)
applemobiledeviceservice.exe -> C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe -> [2010-10-16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.)
smc.exe -> C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe -> [2010-08-05 18:11:44 | 001,885,488 | ---- | M] (Symantec Corporation)
smcgui.exe -> C:\Programmer\Symantec\Symantec Endpoint Protection\SmcGui.exe -> [2010-08-05 18:05:52 | 001,459,568 | ---- | M] (Symantec Corporation)
rtvscan.exe -> C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> [2010-07-01 16:17:24 | 001,832,072 | ---- | M] (Symantec Corporation)
pcsuite.exe -> C:\Programmer\Nokia\Nokia PC Suite 7\PCSuite.exe -> [2010-05-14 09:32:30 | 001,479,680 | ---- | M] (Nokia)
ccapp.exe -> C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe -> [2010-05-06 16:21:54 | 000,115,560 | ---- | M] (Symantec Corporation)
ccsvchst.exe -> C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe -> [2010-05-06 16:21:14 | 000,108,392 | ---- | M] (Symantec Corporation)
spyeraser.exe -> C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe -> [2010-01-11 03:41:24 | 001,431,816 | ---- | M] (Uniblue Software)
setpoint.exe -> C:\Programmer\Logitech\SetPoint\SetPoint.exe -> [2009-07-20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.)
khalmnpr.exe -> C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.exe -> [2009-07-10 12:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.)
googlequicksearchbox.exe -> C:\Programmer\Google\Quick Search Box\GoogleQuickSearchBox.exe -> [2009-04-08 21:32:00 | 000,068,592 | ---- | M] (Google Inc.)
wlidsvc.exe -> C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009-03-30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation)
wlidsvcm.exe -> C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVCM.EXE -> [2009-03-30 16:28:36 | 000,183,152 | ---- | M] (Microsoft Corporation)
googletoolbarnotifier.exe -> C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009-03-11 00:43:39 | 000,039,408 | ---- | M] (Google Inc.)
ubdiskrescuesrv.exe -> C:\Programmer\Uniblue\DiskRescue\UBDiskRescueSrv.exe -> [2008-09-10 16:22:32 | 000,229,648 | ---- | M] (Uniblue)
communications_helper.exe -> C:\Programmer\Fælles filer\Logishrd\LComMgr\Communications_Helper.exe -> [2008-08-14 17:11:48 | 000,565,008 | ---- | M] ()
lvprcsrv.exe -> C:\Programmer\Fælles filer\Logishrd\LVMVFM\LVPrcSrv.exe -> [2008-07-26 08:25:36 | 000,150,040 | ---- | M] (Logitech Inc.)
lvcomser.exe -> C:\Programmer\Fælles filer\Logishrd\LVCOMSER\LVComSer.exe -> [2008-07-26 08:23:42 | 000,186,904 | ---- | M] (Logitech Inc.)
explorer.exe -> C:\WINDOWS\explorer.exe -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
memcard.exe -> C:\Programmer\Dell Photo AIO Printer 966\memcard.exe -> [2007-06-29 16:48:06 | 000,304,368 | ---- | M] ()
dlcqmon.exe -> C:\Programmer\Dell Photo AIO Printer 966\dlcqmon.exe -> [2007-06-29 16:47:48 | 000,292,080 | ---- | M] ()
dlcqcoms.exe -> C:\WINDOWS\system32\dlcqcoms.exe -> [2006-12-12 09:22:34 | 000,537,480 | ---- | M] ( )
mdm.exe -> C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe -> [2006-10-26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation)

[Modules - Safe List]
ots.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\OTS.exe -> [2010-12-16 20:48:04 | 000,642,048 | ---- | M] (OldTimer Tools)
comctl32.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll -> [2010-08-23 17:12:31 | 001,054,208 | ---- | M] (Microsoft Corporation)
lgscroll.dll -> C:\Programmer\Logitech\SetPoint\lgscroll.dll -> [2009-07-20 12:29:06 | 000,045,584 | ---- | M] (Logitech, Inc.)
gamehook.dll -> C:\Programmer\Logitech\SetPoint\GameHook.dll -> [2009-07-20 12:25:22 | 000,064,016 | ---- | M] (Logitech, Inc.)
msvcr80.dll -> C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll -> [2009-07-12 00:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation)
lvprcinj01.dll -> C:\WINDOWS\temp\logishrd\LVPrcInj01.dll -> [2008-07-26 08:25:24 | 000,109,080 | ---- | M] (Logitech Inc.)

[Win32 Services - Safe List]
(iWinTrusted) iWinTrusted [On_Demand | Stopped] -> d:\Programmer\iWin Games\iWinTrusted.exe -> File not found
(Apple Mobile Device) Apple Mobile Device [Auto | Running] -> C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe -> [2010-10-16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.)
(nosGetPlusHelper) getPlus® Helper 3004 [On_Demand | Stopped] -> C:\Programmer\NOS\bin\getPlus_Helper_3004.dll -> [2010-09-01 15:51:28 | 000,066,112 | ---- | M] (NOS Microsystems Ltd.)
(SmcService) Symantec Management Client [Auto | Running] -> C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe -> [2010-08-05 18:11:44 | 001,885,488 | ---- | M] (Symantec Corporation)
(Symantec AntiVirus) Symantec Endpoint Protection [Auto | Running] -> C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> [2010-07-01 16:17:24 | 001,832,072 | ---- | M] (Symantec Corporation)
(SNAC) Symantec Network Access Control [Disabled | Stopped] -> C:\Programmer\Symantec\Symantec Endpoint Protection\SNAC.EXE -> [2010-07-01 15:24:02 | 000,357,704 | ---- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Auto | Running] -> C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe -> [2010-05-06 16:21:14 | 000,108,392 | ---- | M] (Symantec Corporation)
(ccEvtMgr) Symantec Event Manager [Auto | Running] -> C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe -> [2010-05-06 16:21:14 | 000,108,392 | ---- | M] (Symantec Corporation)
(WPFFontCache_v0400) Windows Presentation Foundation Font Cache 4.0.0.0 [On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -> [2010-03-18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation)
(clr_optimization_v4.0.30319_32) Microsoft .NET Framework NGEN v4.0.30319_X86 [Auto | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -> [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Disabled | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -> [2010-03-18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation)
(LiveUpdate) LiveUpdate [On_Demand | Stopped] -> C:\Programmer\Symantec\LiveUpdate\LuComServer_3_3.EXE -> [2010-02-17 09:53:18 | 003,093,880 | ---- | M] (Symantec Corporation)
(LBTServ) Logitech Bluetooth Service [On_Demand | Stopped] -> C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTServ.exe -> [2009-07-20 12:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.)
(wlidsvc) Windows Live ID Sign-in Assistant [Auto | Running] -> C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009-03-30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation)
(odserv) Microsoft Office Diagnostics Service [On_Demand | Stopped] -> C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2008-11-04 00:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation)
(Uniblue DiskRescue) Uniblue DiskRescue [Auto | Running] -> C:\Programmer\Uniblue\DiskRescue\UBDiskRescueSrv.exe -> [2008-09-10 16:22:32 | 000,229,648 | ---- | M] (Uniblue)
(LVPrcSrv) Process Monitor [Auto | Running] -> C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe -> [2008-07-26 08:25:36 | 000,150,040 | ---- | M] (Logitech Inc.)
(LVCOMSer) LVCOMSer [Auto | Running] -> C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe -> [2008-07-26 08:23:42 | 000,186,904 | ---- | M] (Logitech Inc.)
(NMIndexingService) NMIndexingService [Disabled | Stopped] -> C:\Programmer\Fælles filer\Nero\Lib\NMIndexingService.exe -> [2008-02-28 17:07:48 | 000,529,704 | ---- | M] (Nero AG)
(dlcq_device) dlcq_device [On_Demand | Running] -> C:\WINDOWS\System32\dlcqcoms.exe -> [2006-12-12 09:22:34 | 000,537,480 | ---- | M] ( )
(MDM) Machine Debug Manager [Auto | Running] -> C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe -> [2006-10-26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [On_Demand | Stopped] -> C:\Programmer\Fælles filer\Microsoft Shared\Source Engine\OSE.EXE -> [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation)

[Driver Services - Safe List]
(catchme) catchme [Kernel | On_Demand | Stopped] -> C:\DOCUME~1\TINAVI~1\LOKALE~1\Temp\catchme.sys -> File not found
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Programmer\Fælles filer\Symantec Shared\VirusDefs\20101215.003\NAVEX15.SYS -> [2010-12-09 10:00:00 | 001,360,248 | ---- | M] (Symantec Corporation)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Programmer\Fælles filer\Symantec Shared\VirusDefs\20101215.003\NAVENG.SYS -> [2010-12-09 10:00:00 | 000,086,136 | ---- | M] (Symantec Corporation)
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\SYMEVENT.SYS -> [2010-08-29 17:28:02 | 000,125,488 | ---- | M] (Symantec Corporation)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Programmer\Fælles filer\Symantec Shared\EENGINE\eeCtrl.sys -> [2010-05-26 09:00:00 | 000,371,248 | ---- | M] (Symantec Corporation)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2010-05-26 09:00:00 | 000,102,448 | ---- | M] (Symantec Corporation)
(SRTSPL) SRTSPL [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\srtspl.sys -> [2010-03-08 11:59:14 | 000,320,944 | ---- | M] (Symantec Corporation)
(SRTSP) SRTSP [File_System | System | Running] -> C:\WINDOWS\system32\drivers\srtsp.sys -> [2010-03-08 11:59:14 | 000,283,184 | ---- | M] (Symantec Corporation)
(SRTSPX) SRTSPX [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\srtspx.sys -> [2010-03-08 11:59:14 | 000,043,696 | ---- | M] (Symantec Corporation)
(UsbserFilt) UsbserFilt [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -> [2010-02-26 13:32:58 | 000,008,192 | ---- | M] (Nokia)
(upperdev) upperdev [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -> [2010-02-26 13:32:46 | 000,008,192 | ---- | M] (Nokia)
(nmwcdc) Nokia USB Generic [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ccdcmbo.sys -> [2010-02-26 13:32:44 | 000,022,528 | ---- | M] (Nokia)
(nmwcd) Nokia USB Phone Parent [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ccdcmb.sys -> [2010-02-26 13:32:44 | 000,018,176 | ---- | M] (Nokia)
(nmwcdnsu) Nokia USB Flashing Phone Parent [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\nmwcdnsu.sys -> [2010-02-26 13:21:22 | 000,137,344 | ---- | M] (Nokia)
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2009-12-18 14:42:12 | 000,421,424 | ---- | M] (Symantec Corporation)
(WmXlCore) Logitech Translation Layer Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\WmXlCore.sys -> [2009-09-11 12:48:04 | 000,066,056 | ---- | M] (Logitech Inc.)
(WmVirHid) Logitech Virtual Hid Device Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\WmVirHid.sys -> [2009-09-11 12:47:54 | 000,014,984 | ---- | M] (Logitech Inc.)
(WmFilter) Logitech Gaming HID Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\WmFilter.sys -> [2009-09-11 12:47:32 | 000,035,592 | ---- | M] (Logitech Inc.)
(WmBEnum) Logitech Virtual Bus Enumerator Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\WmBEnum.sys -> [2009-09-11 12:47:22 | 000,022,792 | ---- | M] (Logitech Inc.)
(SYMTDI) SYMTDI [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\SYMTDI.SYS -> [2009-09-03 16:03:48 | 000,188,080 | ---- | M] (Symantec Corporation)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -> [2009-09-03 16:03:48 | 000,026,416 | ---- | M] (Symantec Corporation)
(COH_Mon) COH_Mon [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\COH_Mon.sys -> [2009-07-14 12:51:12 | 000,023,888 | ---- | M] (Symantec Corporation)
(LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\LMouFilt.Sys -> [2009-06-17 17:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.)
(LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\LHidFilt.Sys -> [2009-06-17 17:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.)
(nv) nv [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\nv4_mini.sys -> [2009-02-18 14:44:00 | 006,308,224 | ---- | M] (NVIDIA Corporation)
(LBeepKE) LBeepKE [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\LBeepKE.sys -> [2008-12-18 23:43:18 | 000,010,384 | ---- | M] (Logitech, Inc.)
(L8042Kbd) Logitech SetPoint Keyboard Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\L8042Kbd.sys -> [2008-12-18 23:43:06 | 000,020,240 | ---- | M] (Logitech, Inc.)
(pccsmcfd) PCCS Mode Change Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\pccsmcfd.sys -> [2008-08-26 09:26:12 | 000,018,816 | ---- | M] (Nokia)
(nvsmu) nvsmu [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\nvsmu.sys -> [2008-08-25 03:22:00 | 000,014,208 | ---- | M] (NVIDIA Corporation)
(NVHDA) Service for NVIDIA High Definition Audio Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\nvhda32.sys -> [2008-08-05 12:29:00 | 000,039,456 | ---- | M] (NVIDIA Corporation)
(NVENETFD) NVIDIA nForce 10/100/1000 Mbps Ethernet [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\NVENETFD.sys -> [2008-08-01 11:36:00 | 000,054,784 | ---- | M] (NVIDIA Corporation)
(nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\nvnetbus.sys -> [2008-08-01 11:36:00 | 000,022,016 | ---- | M] (NVIDIA Corporation)
(LVPr2Mon) Logitech LVPr2Mon Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\LVPr2Mon.sys -> [2008-07-26 08:25:02 | 000,025,624 | ---- | M] ()
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\RtkHDAud.sys -> [2008-05-07 12:21:40 | 004,739,072 | R--- | M] (Realtek Semiconductor Corp.)
(usbaudio) USB-lyddriver (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\USBAUDIO.sys -> [2008-04-13 11:45:14 | 000,060,032 | ---- | M] (Microsoft Corporation)
(Tcpip6) Microsoft IPv6-protokoldriver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\tcpip6.sys -> [2008-04-13 11:00:04 | 000,225,664 | ---- | M] (Microsoft Corporation)
(nm) Driver til Netværksovervågning [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\nmnt.sys -> [2008-04-13 10:53:10 | 000,040,320 | ---- | M] (Microsoft Corporation)
(HDAudBus) Microsoft UAA-busdriver til High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\hdaudbus.sys -> [2008-04-13 08:36:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider)
(AmdPPM) Driver til AMD HwPState processor [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\AmdPPM.sys -> [2007-04-16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices)
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\Rtnicxp.sys -> [2006-02-27 06:46:20 | 000,081,408 | R--- | M] (Realtek Semiconductor Corporation )
(slabser) CP210x USB to UART Bridge Controller Drivers [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\slabser.sys -> [2004-12-16 16:41:30 | 000,089,808 | ---- | M] (MCCI)
(MTsensor) ATK0110 ACPI UTILITY [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ASACPI.sys -> [2004-08-12 11:56:20 | 000,005,810 | R--- | M] ()
(slabbus) CP2101 USB Composite Device driver (WDM) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\slabbus.sys -> [2004-03-11 16:24:14 | 000,052,384 | ---- | M] (MCCI)
(cyg_ser) CP2101 USB to UART Bridge Controller Drivers [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\cyg_ser.sys -> [2003-10-16 10:44:04 | 000,082,704 | ---- | M] (MCCI)
(PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\CamDrL21.sys -> [2003-08-29 07:43:48 | 000,334,096 | ---- | M] (Logitech Inc.)
(SNXPPALX) Golden Parallel Port Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\snxppalx.sys -> [2003-04-07 10:37:58 | 000,075,264 | ---- | M] (Sunix)
(SNXPCARD) Sunix PCI Multi I/O Card Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\snxpcard.sys -> [2003-04-02 16:06:58 | 000,020,864 | ---- | M] (Sunix)

[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: Main\\"Start Page" -> http://www.google.dk/ ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\"" -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\" " -> + ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\"#" -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\"%" -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\"&" -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: SearchURL\www.google.dk\\"+" -> ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\FireFox\Profiles\vyfs9ia5.default\prefs.js ->
browser.startup.homepage -> "http://www.google.dk" ->
extensions.enabledItems -> {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 ->
extensions.enabledItems -> [email protected]:1.0 ->
extensions.enabledItems -> {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0625 ->
extensions.enabledItems -> [email protected]:2.2.9.8 ->
extensions.enabledItems -> [email protected]:1.0.0.732 ->
extensions.enabledItems -> {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\[email protected] -> C:\Programmer\Fiddler2\FiddlerHook [C:\PROGRAMMER\FIDDLER2\FIDDLERHOOK] -> [2010-11-04 21:04:55 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\[email protected] -> C:\PROGRAMMER\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\ [C:\PROGRAMMER\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\] -> [2010-07-22 15:01:39 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components -> C:\Programmer\Mozilla Firefox\components [C:\PROGRAMMER\MOZILLA FIREFOX\COMPONENTS] -> [2010-11-04 19:57:00 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins -> C:\Programmer\Mozilla Firefox\plugins [C:\PROGRAMMER\MOZILLA FIREFOX\PLUGINS] -> [2010-11-17 21:02:13 | 000,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Extensions -> [2010-01-04 17:23:12 | 000,000,000 | ---D | M]
-> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\extensions -> [2010-11-17 23:12:54 | 000,000,000 | ---D | M]
Zynga Toolbar -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} -> [2010-07-27 11:51:35 | 000,000,000 | ---D | M]
FireFTP -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} -> [2010-11-04 20:01:48 | 000,000,000 | ---D | M]
No name found -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} -> [2010-06-30 15:06:08 | 000,000,000 | ---D | M]
Adobe DLM (powered by getPlus®) -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mozilla\Firefox\Profiles\vyfs9ia5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}(2) -> [2010-04-16 22:34:57 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Programmer\Mozilla Firefox\extensions -> [2010-11-17 23:12:54 | 000,000,000 | ---D | M]
Java Console -> C:\Programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} -> [2010-07-14 12:07:53 | 000,000,000 | ---D | M]
< HOSTS File > ([2010-12-16 19:41:10 | 000,000,027 | ---- | M] - 1 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2010-09-22 18:04:14 | 000,075,200 | ---- | M] (Adobe Systems Incorporated)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Hjælp til tilmelding til Windows Live ID] -> [2009-03-30 16:31:54 | 000,403,824 | ---- | M] (Microsoft Corporation)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Programmer\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [Google Toolbar Notifier BHO] -> [2010-10-27 12:10:49 | 000,843,832 | ---- | M] (Google Inc.)
{D41289F2-69C6-417B-897E-C653D677CBAF} [HKLM] -> C:\Programmer\Acro Software\CutePDF Pro\CPFillerCo.dll [CutePDF Form Filler Helper] -> [2010-03-11 13:32:06 | 000,583,216 | ---- | M] (Acro Software Inc.)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar Helper] -> [2010-12-06 13:44:49 | 000,297,648 | ---- | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010-12-06 13:44:49 | 000,297,648 | ---- | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Programmer\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010-12-06 13:44:49 | 000,297,648 | ---- | M] (Google Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe ARM" -> C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe ["C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe"] -> [2010-09-20 23:07:44 | 000,932,288 | R--- | M] (Adobe Systems Incorporated)
"ccApp" -> C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe ["C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"] -> [2010-05-06 16:21:54 | 000,115,560 | ---- | M] (Symantec Corporation)
"DLCQCATS" -> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL [rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,[email protected]] -> [2006-10-16 06:31:56 | 000,106,496 | ---- | M] ()
"dlcqmon.exe" -> C:\Programmer\Dell Photo AIO Printer 966\dlcqmon.exe [C:\Programmer\Dell Photo AIO Printer 966\dlcqmon.exe] -> [2007-06-29 16:47:48 | 000,292,080 | ---- | M] ()
"FaxCenterServer" -> C:\Programmer\Dell PC Fax\fm3032.exe ["C:\Programmer\Dell PC Fax\fm3032.exe" /s] -> [2007-06-29 16:49:04 | 000,312,560 | ---- | M] ()
"Google Quick Search Box" -> C:\Programmer\Google\Quick Search Box\GoogleQuickSearchBox.exe ["C:\Programmer\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun] -> [2009-04-08 21:32:00 | 000,068,592 | ---- | M] (Google Inc.)
"ISUSScheduler" -> C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe ["C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" -start] -> [2005-06-10 10:44:02 | 000,081,920 | ---- | M] (InstallShield Software Corporation)
"Kernel and Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2009-06-17 17:55:10 | 000,055,824 | ---- | M] (Logitech, Inc.)
"LogitechCommunicationsManager" -> C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe ["C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"] -> [2008-08-14 17:11:48 | 000,565,008 | ---- | M] ()
"LogitechQuickCamRibbon" -> C:\Programmer\Logitech\QuickCam\Quickcam.exe ["C:\Programmer\Logitech\QuickCam\Quickcam.exe" /hide] -> [2008-08-14 17:15:46 | 002,407,184 | ---- | M] ()
"MemoryCardManager" -> C:\Programmer\Dell Photo AIO Printer 966\memcard.exe [C:\Programmer\Dell Photo AIO Printer 966\memcard.exe] -> [2007-06-29 16:48:06 | 000,304,368 | ---- | M] ()
"NBKeyScan" -> C:\Programmer\Nero\Nero8\Nero BackItUp\NBKeyScan.exe ["C:\Programmer\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"] -> [2008-02-18 16:29:02 | 002,221,352 | ---- | M] (Nero AG)
"NeroFilterCheck" -> C:\Programmer\Fælles filer\Nero\Lib\NeroCheck.exe [C:\Programmer\Fælles filer\Nero\Lib\NeroCheck.exe] -> [2008-02-28 09:59:20 | 000,570,664 | ---- | M] (Nero AG)
"NvCplDaemon" -> C:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2009-02-18 14:44:00 | 013,680,640 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2009-02-18 14:44:00 | 000,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" -> C:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2009-02-18 14:44:00 | 001,657,376 | ---- | M] ()
< RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"_nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found
"tscuninstall" -> C:\WINDOWS\System32\tscupgrd.exe [%systemroot%\system32\tscupgrd.exe] -> File not found
< RunOnce [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"_nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found
"tscuninstall" -> C:\WINDOWS\System32\tscupgrd.exe [%systemroot%\system32\tscupgrd.exe] -> File not found
< Run [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"PC Suite Tray" -> C:\Programmer\Nokia\Nokia PC Suite 7\PCSuite.exe ["C:\Programmer\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray] -> [2010-05-14 09:32:30 | 001,479,680 | ---- | M] (Nokia)
"swg" -> C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ["C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"] -> [2009-03-11 00:43:39 | 000,039,408 | ---- | M] (Google Inc.)
"Uniblue SpyEraser" -> C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe ["C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe" -m] -> [2010-01-11 03:41:24 | 001,431,816 | ---- | M] (Uniblue Software)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Menuen Start\Programmer\Start ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Menuen Start\Programmer\Start ->
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Logitech SetPoint.lnk -> C:\Programmer\Logitech\SetPoint\SetPoint.exe -> [2009-07-20 12:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Menuen Start\Programmer\Start ->
< Tina Vilhelmsen Startup Folder > -> C:\Documents and Settings\Tina Vilhelmsen\Menuen Start\Programmer\Start ->
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< Software Policy Settings [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\Software\Microsoft\Internet Explorer\MenuExt\ ->
Google Sidewiki ... -> C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll [res://C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html] -> [2010-12-06 13:45:07 | 001,866,416 | ---- | M] (Google Inc.)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}:Exec [HKLM] -> C:\Programmer\Fiddler2\Fiddler.exe [Button: Fiddler2] -> [2010-10-14 19:33:30 | 000,652,200 | ---- | M] (Eric Lawrence)
{CF819DA3-9882-4944-ADF5-6EF17ECF3C6E}:Exec [HKLM] -> C:\Programmer\Fiddler2\Fiddler.exe [Menu: Fiddler2] -> [2010-10-14 19:33:30 | 000,652,200 | ---- | M] (Eric Lawrence)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
danid.dk .[http] -> Trusted sites ->
danid.dk .[https] -> Trusted sites ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6 domain(s) found. ->
www_body-work.dk [https] -> Websteder, du har tillid til ->
danid.dk .[http] -> Websteder, du har tillid til ->
danid.dk .[https] -> Websteder, du har tillid til ->
login_sikker-adgang.dk [https] -> Websteder, du har tillid til ->
www.tastselv_skat.dk [https] -> Websteder, du har tillid til ->
www_sparnord.dk [https] -> Websteder, du har tillid til ->
www_virk.dk [https] -> Websteder, du har tillid til ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\] > -> HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-2052111302-412668190-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BCC737-B171-4746-94C9-0D8A0B2C0089} [HKLM] -> http://office.micros...n/ieawsdc32.cab [Microsoft Office Template and Media Control] ->
{07D09E9E-C667-45DD-B035-217BC2A61A3B} [HKLM] -> https://www.sparnord...e-prod-1.30.cab [ActiveX sikkerhedssoftware Control] ->
{11818680-FCF6-11D0-9808-0800092A4865} [HKLM] -> http://www.kps.dk/Codebase/FormCtl.cab [Adobe Form Control] ->
{1469FF24-47F6-11D2-8805-006008C537E3} [HKLM] -> http://www.kps.dk/codebase/ffmail.cab [Adobe Mail Control] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macr...director/sw.cab [Shockwave ActiveX Control] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://download.micr...heckControl.cab [Windows Genuine Advantage Validation Tool] ->
{1E54D648-B804-468d-BC78-4AFFED8E262E} [HKLM] -> http://www.nvidia.co.../sysreqlab3.cab [System Requirements Lab Class] ->
{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} [HKLM] -> http://security.syma...bin/AvSniff.cab [Reg Error: Key error.] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.aka...vex-2.2.5.0.cab [DLM Control] ->
{4F2A3649-7A9F-4950-9C31-409FAC6FC7C8} [HKLM] -> https://danid.dk/csp...nticode/csp.exe [IssueUtilCtrl Class] ->
{644E432F-49D3-41A1-8DD5-E099162EEEC5} [HKLM] -> http://security.syma...n/bin/cabsa.cab [Symantec RuFSI Utility Class] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.micros...b?1236725578966 [MUWebControl Class] ->
{73ECB3AA-4717-450C-A2AB-D00DAD9EE203} [HKLM] -> http://h20270.www2.h...ctDetection.cab [Reg Error: Key error.] ->
{74DBCB52-F298-4110-951D-AD2FF67BC8AB} [HKLM] -> http://www.nvidia.co...iaSmartScan.cab [NVIDIA Smart Scan] ->
{775879E2-7309-4619-BB02-AADE41F4B690} [HKLM] -> http://aolsvc.aol.co...web.1.0.0.9.cab [CPlayFirstdreamControl Object] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_20] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.ma...r/ultrashim.cab [Reg Error: Key error.] ->
{92EB6641-286A-11D2-A68E-00A0C996A6DD} [HKLM] -> http://www.kps.dk/co...jfsignature.cab [Adobe Signature Object] ->
{9DF01F00-08E7-4DBE-9070-94841463B3FE} [HKLM] -> https://danid.dk/csp...nticode/csp.exe [Util Class] ->
{AD90E8D1-3B47-11D2-A696-00A0C996A6DD} [HKLM] -> http://www.kps.dk/co...se/jfcrypto.cab [jfCryptoSignature Class] ->
{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Reg Error: Key error.] ->
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_18] ->
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_20] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/...indows-i586.cab [Java Plug-in 1.6.0_19] ->
{CDDCFBB3-4D93-11D2-B1A9-00A0C9B742BE} [HKLM] -> http://www.kps.dk/co...criptobject.cab [Adobe Script Object] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.m...ash/swflash.cab [Shockwave Flash Object] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.ad...Plus/1.6/gp.cab [get_atlcom Class] ->
{EF2FB80F-0975-408E-A871-B00CC863478A} [HKLM] -> http://www.kps.dk/co...ntinstaller.cab [Adobe Soft Font Installer] ->
Garmin Communicator Plug-In [HKLM] -> https://static.garmi...inAxControl.CAB [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{56F5A06E-C853-40A9-ACD4-A8A973433889}\\DhcpNameServer -> 192.168.1.1 (NVIDIA nForce 10/100/1000 Mbps Ethernet ) ->
{56F5A06E-C853-40A9-ACD4-A8A973433889}\\NameServer -> 194.239.134.83,193.162.153.164 (NVIDIA nForce 10/100/1000 Mbps Ethernet ) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
LBTWlgn -> c:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTWLgn.dll -> [2009-07-20 12:28:42 | 000,072,208 | ---- | M] (Logitech, Inc.)
WgaLogon -> C:\WINDOWS\System32\WgaLogon.dll -> [2009-10-03 15:29:24 | 000,000,000 | ---- | M] ()
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> C:\Programmer\Windows Desktop Search\MsnlNamespaceMgr.dll [] -> [2009-05-24 21:41:34 | 000,304,128 | ---- | M] (Microsoft Corporation)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" [HKLM] -> Reg Error: Key error. [] -> File not found
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Programmer\ASUS\ASUSUpdate\Update.exe" -> C:\Programmer\ASUS\ASUSUpdate\Update.exe [C:\Programmer\ASUS\ASUSUpdate\Update.exe:*:Enabled:ASUS Windows Platform Flash Program] -> [2008-10-14 17:31:26 | 001,421,312 | ---- | M] (ASUSTek Computer Inc.)
"C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" -> C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe [C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email] -> [2010-05-06 16:21:54 | 000,115,560 | ---- | M] (Symantec Corporation)
"C:\Programmer\PrintServer Network driver\Remote.exe" -> C:\Programmer\PrintServer Network driver\Remote.exe [C:\Programmer\PrintServer Network driver\Remote.exe:*:Enabled:Remote ports] -> [2002-11-11 17:07:20 | 000,163,840 | ---- | M] ()
"C:\Programmer\PrintServer Utilities\WinUtil\wincfg.exe" -> C:\Programmer\PrintServer Utilities\WinUtil\wincfg.exe [C:\Programmer\PrintServer Utilities\WinUtil\wincfg.exe:*:Enabled:PrintServer Configuration] -> [2002-11-11 17:08:08 | 000,110,592 | ---- | M] (PrintServer)
"C:\Programmer\SkyGolf\SkyCaddie Desktop\SkyCaddieDesktop.exe" -> C:\Programmer\SkyGolf\SkyCaddie Desktop\SkyCaddieDesktop.exe [C:\Programmer\SkyGolf\SkyCaddie Desktop\SkyCaddieDesktop.exe:*:Enabled:SkyCaddie Desktop] -> [2010-07-15 15:12:54 | 000,226,744 | ---- | M] (Skyhawke Technologies)
"C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe" -> C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe [C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service] -> [2010-08-05 18:11:44 | 001,885,488 | ---- | M] (Symantec Corporation)
"C:\Programmer\Symantec\Symantec Endpoint Protection\SNAC.EXE" -> C:\Programmer\Symantec\Symantec Endpoint Protection\SNAC.EXE [C:\Programmer\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service] -> [2010-07-01 15:24:02 | 000,357,704 | ---- | M] (Symantec Corporation)
"C:\WINDOWS\system32\dlcqcoms.exe" -> C:\WINDOWS\System32\dlcqcoms.exe [C:\WINDOWS\system32\dlcqcoms.exe:*:Enabled:Dell 966 Server] -> [2006-12-12 09:22:34 | 000,537,480 | ---- | M] ( )
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> Cd-rom-driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2009-03-10 16:15:13 | 000,000,000 | ---- | M] ()
Y:\AUTOEXEC.BAT [] -> Y:\AUTOEXEC.BAT [ NTFS ] -> [2004-04-11 21:48:30 | 000,000,000 | ---- | M] ()
Z:\autoexec.bat [REM Dummy file for NTVDM | ] -> Z:\autoexec.bat [ NTFS ] -> [2006-09-18 22:43:36 | 000,000,024 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->

[Registry - Additional Scans - Safe List]
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
Ias -> -> File not found
Iprip -> -> File not found
Irmon -> -> File not found
NWCWorkstation -> -> File not found
Nwsapagent -> -> File not found
WmdmPmSp -> -> File not found
*MultiFile Done* -> ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
batfile [open] -> "%1" %* ->
cmdfile [open] -> "%1" %* ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
piffile [open] -> "%1" %* ->
scrfile [config] -> "%1" ->
scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008-04-14 08:06:08 | 000,136,192 | ---- | M] (Microsoft Corporation)
scrfile [open] -> "%1" /S ->
Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 ->
Directory [find] -> %SystemRoot%\Explorer.exe -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
Folder [open] -> %SystemRoot%\Explorer.exe /idlist,%I,%L -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
Folder [explore] -> %SystemRoot%\Explorer.exe /e,/idlist,%I,%L -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
Drive [find] -> %SystemRoot%\Explorer.exe -> [2008-04-14 08:05:50 | 001,034,752 | ---- | M] (Microsoft Corporation)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 16-12-2010 15:08:03 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.HistoryHandler kan ikke indlæses. Fejlbeskrivelse: Den angivne fil blev ikke fundet. .
Application [ Error ] 16-12-2010 15:08:03 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.RSSHandler kan ikke indlæses. Fejlbeskrivelse: MAPI: Logon mislykkedes. .
Application [ Error ] 16-12-2010 15:14:24 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.HistoryHandler kan ikke indlæses. Fejlbeskrivelse: Den angivne fil blev ikke fundet. .
Application [ Error ] 16-12-2010 15:14:24 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.RSSHandler kan ikke indlæses. Fejlbeskrivelse: MAPI: Logon mislykkedes. .
Application [ Error ] 16-12-2010 15:22:56 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.HistoryHandler kan ikke indlæses. Fejlbeskrivelse: Den angivne fil blev ikke fundet. .
Application [ Error ] 16-12-2010 15:22:56 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.RSSHandler kan ikke indlæses. Fejlbeskrivelse: MAPI: Logon mislykkedes. .
Application [ Error ] 16-12-2010 15:28:08 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.HistoryHandler kan ikke indlæses. Fejlbeskrivelse: Den angivne fil blev ikke fundet. .
Application [ Error ] 16-12-2010 15:28:08 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.RSSHandler kan ikke indlæses. Fejlbeskrivelse: MAPI: Logon mislykkedes. .
Application [ Error ] 16-12-2010 15:51:05 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.HistoryHandler kan ikke indlæses. Fejlbeskrivelse: Den angivne fil blev ikke fundet. .
Application [ Error ] 16-12-2010 15:51:05 Computer Name = KLIENT | Source = Windows Search Service | ID = 3083 -> Description = Protokolbehandleren IEPH.RSSHandler kan ikke indlæses. Fejlbeskrivelse: MAPI: Logon mislykkedes. .
OSession [ Error ] 17-04-2009 11:47:32 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 17670 seconds with 1080 seconds of active time. This session ended with a crash.
OSession [ Error ] 30-04-2009 10:44:15 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 21240 seconds with 1320 seconds of active time. This session ended with a crash.
OSession [ Error ] 07-05-2009 13:44:10 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 17927 seconds with 1560 seconds of active time. This session ended with a crash.
OSession [ Error ] 10-06-2009 15:10:00 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 16925 seconds with 2220 seconds of active time. This session ended with a crash.
OSession [ Error ] 28-08-2009 12:05:07 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10233 seconds with 1740 seconds of active time. This session ended with a crash.
OSession [ Error ] 22-12-2009 11:55:22 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 45 seconds with 0 seconds of active time. This session ended with a crash.
OSession [ Error ] 05-01-2010 12:06:01 Computer Name = KLIENT | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4193 seconds with 1740 seconds of active time. This session ended with a crash.
System [ Error ] 15-12-2010 18:52:05 Computer Name = KLIENT | Source = SideBySide | ID = 16842811 -> Description = Resolve Partial Assembly mislykkedes for Microsoft.VC80.CRT. Referencefejlmeddelelse: Den refererede samling er ikke installeret på systemet. .
System [ Error ] 15-12-2010 18:57:20 Computer Name = KLIENT | Source = Setup | ID = 60055 -> Description = Der opstod fejl, der ikke er alvorlige, under installationen af Windows. Hvis du vil have flere oplysninger, kan du finde dem i logfilen setuperr.log, der er placeret i mappen Window
System [ Error ] 15-12-2010 19:00:37 Computer Name = KLIENT | Source = DCOM | ID = 10005 -> Description = Fejlen "%1055" opstod på DCOM under forsøg på at starte tjenesten BITS med argumenterne "" for at køre serveren: {4991D34B-80A1-4291-83B6-3328366B9097}
System [ Error ] 15-12-2010 19:00:42 Computer Name = KLIENT | Source = Service Control Manager | ID = 7024 -> Description = Tjenesten Java Quick Starter blev afbrudt med den tjenestespecifikke fejl 1 (0x1).
System [ Error ] 15-12-2010 19:54:18 Computer Name = KLIENT | Source = Service Control Manager | ID = 7024 -> Description = Tjenesten Java Quick Starter blev afbrudt med den tjenestespecifikke fejl 1 (0x1).
System [ Error ] 15-12-2010 20:00:38 Computer Name = KLIENT | Source = Cdrom | ID = 262151 -> Description = Enheden \Device\CdRom1 havde en fejlbehæftet blok.
System [ Error ] 16-12-2010 14:23:01 Computer Name = KLIENT | Source = Service Control Manager | ID = 7024 -> Description = Tjenesten Java Quick Starter blev afbrudt med den tjenestespecifikke fejl 1 (0x1).
System [ Error ] 16-12-2010 14:30:53 Computer Name = KLIENT | Source = Service Control Manager | ID = 7034 -> Description = Tjenesten Process Monitor afsluttede uventet. Dette er sket 1 gang(e).
System [ Error ] 16-12-2010 14:41:07 Computer Name = KLIENT | Source = Service Control Manager | ID = 7024 -> Description = Tjenesten Java Quick Starter blev afbrudt med den tjenestespecifikke fejl 1 (0x1).
System [ Error ] 16-12-2010 14:53:24 Computer Name = KLIENT | Source = Service Control Manager | ID = 7024 -> Description = Tjenesten Java Quick Starter blev afbrudt med den tjenestespecifikke fejl 1 (0x1).

[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\OTS.exe -> [2010-12-16 20:48:00 | 000,642,048 | ---- | C] (OldTimer Tools)
RECYCLER -> C:\RECYCLER -> [2010-12-16 20:24:34 | 000,000,000 | -HSD | C]
usbdeview -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\usbdeview -> [2010-12-16 20:08:06 | 000,000,000 | ---D | C]
Prefetch -> C:\WINDOWS\Prefetch -> [2010-12-15 23:59:50 | 000,000,000 | ---D | C]
winzm.ime -> C:\WINDOWS\System32\dllcache\winzm.ime -> [2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation)
winsp.ime -> C:\WINDOWS\System32\dllcache\winsp.ime -> [2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation)
winpy.ime -> C:\WINDOWS\System32\dllcache\winpy.ime -> [2010-12-15 23:54:57 | 000,156,672 | ---- | C] (Microsoft Corporation)
wingb.ime -> C:\WINDOWS\System32\dllcache\wingb.ime -> [2010-12-15 23:54:56 | 000,072,704 | ---- | C] (Microsoft Corporation)
winime.ime -> C:\WINDOWS\System32\dllcache\winime.ime -> [2010-12-15 23:54:56 | 000,065,536 | ---- | C] (Microsoft Corporation)
winar30.ime -> C:\WINDOWS\System32\dllcache\winar30.ime -> [2010-12-15 23:54:55 | 000,079,360 | ---- | C] (Microsoft Corporation)
weitekp9.dll -> C:\WINDOWS\System32\dllcache\weitekp9.dll -> [2010-12-15 23:54:55 | 000,041,600 | ---- | C] (Microsoft Corporation)
weitekp9.sys -> C:\WINDOWS\System32\dllcache\weitekp9.sys -> [2010-12-15 23:54:55 | 000,031,232 | ---- | C] (Microsoft Corporation)
wamreg51.dll -> C:\WINDOWS\System32\dllcache\wamreg51.dll -> [2010-12-15 23:54:54 | 000,053,248 | ---- | C] (Microsoft Corporation)
w3svc.dll -> C:\WINDOWS\System32\dllcache\w3svc.dll -> [2010-12-15 23:54:53 | 000,364,544 | ---- | C] (Microsoft Corporation)
wam51.dll -> C:\WINDOWS\System32\dllcache\wam51.dll -> [2010-12-15 23:54:53 | 000,076,800 | ---- | C] (Microsoft Corporation)
w3ext.dll -> C:\WINDOWS\System32\dllcache\w3ext.dll -> [2010-12-15 23:54:53 | 000,073,728 | ---- | C] (Microsoft Corporation)
wamps51.dll -> C:\WINDOWS\System32\dllcache\wamps51.dll -> [2010-12-15 23:54:53 | 000,009,216 | ---- | C] (Microsoft Corporation)
w3svapi.dll -> C:\WINDOWS\System32\dllcache\w3svapi.dll -> [2010-12-15 23:54:53 | 000,005,632 | ---- | C] (Microsoft Corporation)
w3ctrs51.dll -> C:\WINDOWS\System32\dllcache\w3ctrs51.dll -> [2010-12-15 23:54:53 | 000,004,608 | ---- | C] (Microsoft Corporation)
voicepad.dll -> C:\WINDOWS\System32\dllcache\voicepad.dll -> [2010-12-15 23:54:52 | 000,426,041 | ---- | C] (Microsoft Corporation)
voicesub.dll -> C:\WINDOWS\System32\dllcache\voicesub.dll -> [2010-12-15 23:54:52 | 000,086,073 | ---- | C] (Microsoft Corporation)
w32.dll -> C:\WINDOWS\System32\dllcache\w32.dll -> [2010-12-15 23:54:52 | 000,048,256 | ---- | C] (Microsoft Corporation)
uihelper.dll -> C:\WINDOWS\System32\dllcache\uihelper.dll -> [2010-12-15 23:54:48 | 000,103,936 | ---- | C] (Microsoft Corporation)
uniime.dll -> C:\WINDOWS\System32\dllcache\uniime.dll -> [2010-12-15 23:54:48 | 000,076,288 | ---- | C] (Microsoft Corporation)
unicdime.ime -> C:\WINDOWS\System32\dllcache\unicdime.ime -> [2010-12-15 23:54:48 | 000,065,024 | ---- | C] (Microsoft Corporation)
tsprof.exe -> C:\WINDOWS\System32\dllcache\tsprof.exe -> [2010-12-15 23:54:47 | 000,014,336 | ---- | C] (Microsoft Corporation)
tools.dll -> C:\WINDOWS\System32\dllcache\tools.dll -> [2010-12-15 23:54:46 | 000,033,792 | ---- | C] (Microsoft Corporation)
tmigrate.dll -> C:\WINDOWS\System32\dllcache\tmigrate.dll -> [2010-12-15 23:54:46 | 000,010,240 | ---- | C] (Microsoft Corporation)
tintlgnt.ime -> C:\WINDOWS\System32\dllcache\tintlgnt.ime -> [2010-12-15 23:54:45 | 000,571,392 | ---- | C] (Microsoft Corporation)
tintsetp.exe -> C:\WINDOWS\System32\dllcache\tintsetp.exe -> [2010-12-15 23:54:45 | 000,455,168 | ---- | C] (Microsoft Corporation)
thawbrkr.dll -> C:\WINDOWS\System32\dllcache\thawbrkr.dll -> [2010-12-15 23:54:45 | 000,185,344 | ---- | C] (Microsoft Corporation)
tintlphr.exe -> C:\WINDOWS\System32\dllcache\tintlphr.exe -> [2010-12-15 23:54:45 | 000,044,032 | ---- | C] (Microsoft Corporation)
tdipx.sys -> C:\WINDOWS\System32\dllcache\tdipx.sys -> [2010-12-15 23:54:44 | 000,021,896 | ---- | C] (Microsoft Corporation)
tdspx.sys -> C:\WINDOWS\System32\dllcache\tdspx.sys -> [2010-12-15 23:54:44 | 000,019,464 | ---- | C] (Microsoft Corporation)
tdasync.sys -> C:\WINDOWS\System32\dllcache\tdasync.sys -> [2010-12-15 23:54:44 | 000,013,192 | ---- | C] (Microsoft Corporation)
svcext51.dll -> C:\WINDOWS\System32\dllcache\svcext51.dll -> [2010-12-15 23:54:41 | 000,046,592 | ---- | C] (Microsoft Corporation)
status.dll -> C:\WINDOWS\System32\dllcache\status.dll -> [2010-12-15 23:54:41 | 000,016,896 | ---- | C] (Microsoft Corporation)
sspifilt.dll -> C:\WINDOWS\System32\dllcache\sspifilt.dll -> [2010-12-15 23:54:40 | 000,046,592 | ---- | C] (Microsoft Corporation)
ssinc51.dll -> C:\WINDOWS\System32\dllcache\ssinc51.dll -> [2010-12-15 23:54:40 | 000,045,056 | ---- | C] (Microsoft Corporation)
srusbusd.dll -> C:\WINDOWS\System32\dllcache\srusbusd.dll -> [2010-12-15 23:54:39 | 000,101,376 | ---- | C] (Microsoft Corporation)
softkey.dll -> C:\WINDOWS\System32\dllcache\softkey.dll -> [2010-12-15 23:54:37 | 000,143,422 | ---- | C] (Microsoft Corporation)
snmpincl.dll -> C:\WINDOWS\System32\dllcache\snmpincl.dll -> [2010-12-15 23:54:36 | 000,358,400 | ---- | C] (Microsoft Corporation)
snmpsmir.dll -> C:\WINDOWS\System32\dllcache\snmpsmir.dll -> [2010-12-15 23:54:36 | 000,188,416 | ---- | C] (Microsoft Corporation)
snmpthrd.dll -> C:\WINDOWS\System32\dllcache\snmpthrd.dll -> [2010-12-15 23:54:36 | 000,039,936 | ---- | C] (Microsoft Corporation)
snmpstup.dll -> C:\WINDOWS\System32\dllcache\snmpstup.dll -> [2010-12-15 23:54:36 | 000,010,240 | ---- | C] (Microsoft Corporation)
snmptrap.exe -> C:\WINDOWS\System32\dllcache\snmptrap.exe -> [2010-12-15 23:54:36 | 000,008,704 | ---- | C] (Microsoft Corporation)
EXCH_snprfdll.dll -> C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll -> [2010-12-15 23:54:36 | 000,007,168 | ---- | C] (Microsoft Corporation)
snmpmib.dll -> C:\WINDOWS\System32\dllcache\snmpmib.dll -> [2010-12-15 23:54:36 | 000,006,144 | ---- | C] (Microsoft Corporation)
smtpsvc.dll -> C:\WINDOWS\System32\dllcache\smtpsvc.dll -> [2010-12-15 23:54:35 | 000,460,288 | ---- | C] (Microsoft Corporation)
snmpcl.dll -> C:\WINDOWS\System32\dllcache\snmpcl.dll -> [2010-12-15 23:54:35 | 000,259,072 | ---- | C] (Microsoft Corporation)
snmp.exe -> C:\WINDOWS\System32\dllcache\snmp.exe -> [2010-12-15 23:54:35 | 000,033,280 | ---- | C] (Microsoft Corporation)
smi2smir.exe -> C:\WINDOWS\System32\dllcache\smi2smir.exe -> [2010-12-15 23:54:34 | 000,236,544 | ---- | C] (Microsoft Corporation)
sm9aw.dll -> C:\WINDOWS\System32\dllcache\sm9aw.dll -> [2010-12-15 23:54:34 | 000,038,912 | ---- | C] (Microsoft Corporation)
smb6w.dll -> C:\WINDOWS\System32\dllcache\smb6w.dll -> [2010-12-15 23:54:34 | 000,031,744 | ---- | C] (Microsoft Corporation)
sma3w.dll -> C:\WINDOWS\System32\dllcache\sma3w.dll -> [2010-12-15 23:54:34 | 000,031,744 | ---- | C] (Microsoft Corporation)
sm93w.dll -> C:\WINDOWS\System32\dllcache\sm93w.dll -> [2010-12-15 23:54:34 | 000,026,624 | ---- | C] (Microsoft Corporation)
smierrsm.dll -> C:\WINDOWS\System32\dllcache\smierrsm.dll -> [2010-12-15 23:54:34 | 000,015,872 | ---- | C] (Microsoft Corporation)
EXCH_smtpctrs.dll -> C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll -> [2010-12-15 23:54:34 | 000,012,288 | ---- | C] (Microsoft Corporation)
smtpapi.dll -> C:\WINDOWS\System32\dllcache\smtpapi.dll -> [2010-12-15 23:54:34 | 000,010,752 | ---- | C] (Microsoft Corporation)
smimsgif.dll -> C:\WINDOWS\System32\dllcache\smimsgif.dll -> [2010-12-15 23:54:34 | 000,005,632 | ---- | C] (Microsoft Corporation)
smierrsy.dll -> C:\WINDOWS\System32\dllcache\smierrsy.dll -> [2010-12-15 23:54:34 | 000,005,632 | ---- | C] (Microsoft Corporation)
sm87w.dll -> C:\WINDOWS\System32\dllcache\sm87w.dll -> [2010-12-15 23:54:33 | 000,030,208 | ---- | C] (Microsoft Corporation)
sm81w.dll -> C:\WINDOWS\System32\dllcache\sm81w.dll -> [2010-12-15 23:54:33 | 000,030,208 | ---- | C] (Microsoft Corporation)
sm8cw.dll -> C:\WINDOWS\System32\dllcache\sm8cw.dll -> [2010-12-15 23:54:33 | 000,029,184 | ---- | C] (Microsoft Corporation)
sm92w.dll -> C:\WINDOWS\System32\dllcache\sm92w.dll -> [2010-12-15 23:54:33 | 000,026,624 | ---- | C] (Microsoft Corporation)
sm90w.dll -> C:\WINDOWS\System32\dllcache\sm90w.dll -> [2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation)
sm8dw.dll -> C:\WINDOWS\System32\dllcache\sm8dw.dll -> [2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation)
sm8aw.dll -> C:\WINDOWS\System32\dllcache\sm8aw.dll -> [2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation)
sm89w.dll -> C:\WINDOWS\System32\dllcache\sm89w.dll -> [2010-12-15 23:54:33 | 000,026,112 | ---- | C] (Microsoft Corporation)
sm59w.dll -> C:\WINDOWS\System32\dllcache\sm59w.dll -> [2010-12-15 23:54:33 | 000,025,088 | ---- | C] (Microsoft Corporation)
simptcp.dll -> C:\WINDOWS\System32\dllcache\simptcp.dll -> [2010-12-15 23:54:32 | 000,018,944 | ---- | C] (Microsoft Corporation)
seo.dll -> C:\WINDOWS\System32\dllcache\seo.dll -> [2010-12-15 23:54:30 | 000,221,696 | ---- | C] (Microsoft Corporation)
EXCH_scripto.dll -> C:\WINDOWS\System32\dllcache\EXCH_scripto.dll -> [2010-12-15 23:54:29 | 000,057,856 | ---- | C] (Microsoft Corporation)
rwia330.dll -> C:\WINDOWS\System32\dllcache\rwia330.dll -> [2010-12-15 23:54:28 | 000,080,896 | ---- | C] (Ricoh Co., Ltd.)
rwia001.dll -> C:\WINDOWS\System32\dllcache\rwia001.dll -> [2010-12-15 23:54:28 | 000,080,896 | ---- | C] (Ricoh Co., Ltd.)
rwnh.dll -> C:\WINDOWS\System32\dllcache\rwnh.dll -> [2010-12-15 23:54:28 | 000,009,728 | ---- | C] (Microsoft Corporation)
rw330ext.dll -> C:\WINDOWS\System32\dllcache\rw330ext.dll -> [2010-12-15 23:54:27 | 000,029,184 | ---- | C] (Ricoh Co., Ltd.)
rw001ext.dll -> C:\WINDOWS\System32\dllcache\rw001ext.dll -> [2010-12-15 23:54:27 | 000,027,648 | ---- | C] (Microsoft Corporation)
romanime.ime -> C:\WINDOWS\System32\dllcache\romanime.ime -> [2010-12-15 23:54:26 | 000,026,112 | ---- | C] (Microsoft Corporation)
rpcref.dll -> C:\WINDOWS\System32\dllcache\rpcref.dll -> [2010-12-15 23:54:26 | 000,004,096 | ---- | C] (Microsoft Corporation)
EXCH_regtrace.exe -> C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe -> [2010-12-15 23:54:25 | 000,023,040 | ---- | C] (Microsoft Corporation)
register.exe -> C:\WINDOWS\System32\dllcache\register.exe -> [2010-12-15 23:54:25 | 000,014,848 | ---- | C] (Microsoft Corporation)
quick.ime -> C:\WINDOWS\System32\dllcache\quick.ime -> [2010-12-15 23:54:22 | 000,077,824 | ---- | C] (Microsoft Corporation)
ramdisk.sys -> C:\WINDOWS\System32\dllcache\ramdisk.sys -> [2010-12-15 23:54:22 | 000,020,736 | ---- | C] (Microsoft Corporation)
quser.exe -> C:\WINDOWS\System32\dllcache\quser.exe -> [2010-12-15 23:54:22 | 000,016,896 | ---- | C] (Microsoft Corporation)
query.exe -> C:\WINDOWS\System32\dllcache\query.exe -> [2010-12-15 23:54:22 | 000,009,728 | ---- | C] (Microsoft Corporation)
pwsdata.dll -> C:\WINDOWS\System32\dllcache\pwsdata.dll -> [2010-12-15 23:54:21 | 000,007,680 | ---- | C] (Microsoft Corporation)
pmxviceo.dll -> C:\WINDOWS\System32\dllcache\pmxviceo.dll -> [2010-12-15 23:54:19 | 000,131,584 | ---- | C] (Microsoft Corporation)
pmxmcro.dll -> C:\WINDOWS\System32\dllcache\pmxmcro.dll -> [2010-12-15 23:54:19 | 000,011,264 | ---- | C] (Microsoft Corporation)
pmxgl.dll -> C:\WINDOWS\System32\dllcache\pmxgl.dll -> [2010-12-15 23:54:19 | 000,006,144 | ---- | C] (Microsoft Corporation)
pintlgnt.ime -> C:\WINDOWS\System32\dllcache\pintlgnt.ime -> [2010-12-15 23:54:18 | 000,482,304 | ---- | C] (Microsoft Corporation)
pintlphr.exe -> C:\WINDOWS\System32\dllcache\pintlphr.exe -> [2010-12-15 23:54:18 | 000,070,144 | ---- | C] (Microsoft Corporation)
pmigrate.dll -> C:\WINDOWS\System32\dllcache\pmigrate.dll -> [2010-12-15 23:54:18 | 000,067,584 | ---- | C] (Microsoft Corporation)
pintlcsd.dll -> C:\WINDOWS\System32\dllcache\pintlcsd.dll -> [2010-12-15 23:54:18 | 000,053,760 | ---- | C] (Microsoft Corporation)
phon.ime -> C:\WINDOWS\System32\dllcache\phon.ime -> [2010-12-15 23:54:17 | 000,079,360 | ---- | C] (Microsoft Corporation)
permchk.dll -> C:\WINDOWS\System32\dllcache\permchk.dll -> [2010-12-15 23:54:17 | 000,020,992 | ---- | C] (Microsoft Corporation)
padrs411.dll -> C:\WINDOWS\System32\dllcache\padrs411.dll -> [2010-12-15 23:54:16 | 000,036,927 | ---- | C] (Microsoft Corporation)
pagecnt.dll -> C:\WINDOWS\System32\dllcache\pagecnt.dll -> [2010-12-15 23:54:16 | 000,031,744 | ---- | C] (Microsoft Corporation)
padrs804.dll -> C:\WINDOWS\System32\dllcache\padrs804.dll -> [2010-12-15 23:54:16 | 000,015,360 | ---- | C] (Microsoft Corporation)
padrs412.dll -> C:\WINDOWS\System32\dllcache\padrs412.dll -> [2010-12-15 23:54:16 | 000,014,336 | ---- | C] (Microsoft Corporation)
padrs404.dll -> C:\WINDOWS\System32\dllcache\padrs404.dll -> [2010-12-15 23:54:15 | 000,015,872 | ---- | C] (Microsoft Corporation)
nsepm.dll -> C:\WINDOWS\System32\dllcache\nsepm.dll -> [2010-12-15 23:54:11 | 000,044,544 | ---- | C] (Microsoft Corporation)
EXCH_ntfsdrv.dll -> C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll -> [2010-12-15 23:54:11 | 000,038,912 | ---- | C] (Microsoft Corporation)
nextlink.dll -> C:\WINDOWS\System32\dllcache\nextlink.dll -> [2010-12-15 23:54:09 | 000,053,248 | ---- | C] (Microsoft Corporation)
multibox.dll -> C:\WINDOWS\System32\dllcache\multibox.dll -> [2010-12-15 23:54:06 | 000,229,439 | ---- | C] (Microsoft Corporation)
mtstocom.exe -> C:\WINDOWS\System32\dllcache\mtstocom.exe -> [2010-12-15 23:54:06 | 000,119,808 | ---- | C] (Microsoft Corporation)
msir3jp.lex -> C:\WINDOWS\System32\dllcache\msir3jp.lex -> [2010-12-15 23:54:02 | 001,875,968 | ---- | C] (Microsoft Corporation)
msir3jp.dll -> C:\WINDOWS\System32\dllcache\msir3jp.dll -> [2010-12-15 23:54:02 | 000,098,304 | ---- | C] (Microsoft Corporation)
migregdb.exe -> C:\WINDOWS\System32\dllcache\migregdb.exe -> [2010-12-15 23:53:55 | 000,007,680 | ---- | C] (Microsoft Corporation)
mga.sys -> C:\WINDOWS\System32\dllcache\mga.sys -> [2010-12-15 23:53:54 | 000,092,416 | ---- | C] (Microsoft Corporation)
mga.dll -> C:\WINDOWS\System32\dllcache\mga.dll -> [2010-12-15 23:53:54 | 000,092,032 | ---- | C] (Microsoft Corporation)
metada51.dll -> C:\WINDOWS\System32\dllcache\metada51.dll -> [2010-12-15 23:53:54 | 000,085,504 | ---- | C] (Microsoft Corporation)
mdsync.dll -> C:\WINDOWS\System32\dllcache\mdsync.dll -> [2010-12-15 23:53:54 | 000,026,624 | ---- | C] (Microsoft Corporation)
md5filt.dll -> C:\WINDOWS\System32\dllcache\md5filt.dll -> [2010-12-15 23:53:53 | 000,037,888 | ---- | C] (Microsoft Corporation)
EXCH_mailmsg.dll -> C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll -> [2010-12-15 23:53:52 | 000,065,536 | ---- | C] (Microsoft Corporation)
lpdsvc.dll -> C:\WINDOWS\System32\dllcache\lpdsvc.dll -> [2010-12-15 23:53:51 | 000,023,040 | ---- | C] (Microsoft Corporation)
logscrpt.dll -> C:\WINDOWS\System32\dllcache\logscrpt.dll -> [2010-12-15 23:53:51 | 000,022,016 | ---- | C] (Microsoft Corporation)
lprmon.dll -> C:\WINDOWS\System32\dllcache\lprmon.dll -> [2010-12-15 23:53:51 | 000,019,456 | ---- | C] (Microsoft Corporation)
lonsint.dll -> C:\WINDOWS\System32\dllcache\lonsint.dll -> [2010-12-15 23:53:51 | 000,013,312 | ---- | C] (Microsoft Corporation)
lmmib2.dll -> C:\WINDOWS\System32\dllcache\lmmib2.dll -> [2010-12-15 23:53:50 | 000,033,792 | ---- | C] (Microsoft Corporation)
korwbrkr.dll -> C:\WINDOWS\System32\dllcache\korwbrkr.dll -> [2010-12-15 23:53:49 | 000,070,656 | ---- | C] (Microsoft Corporation)
kbdvntc.dll -> C:\WINDOWS\System32\dllcache\kbdvntc.dll -> [2010-12-15 23:53:48 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdusa.dll -> C:\WINDOWS\System32\dllcache\kbdusa.dll -> [2010-12-15 23:53:48 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdth3.dll -> C:\WINDOWS\System32\dllcache\kbdth3.dll -> [2010-12-15 23:53:47 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbdth2.dll -> C:\WINDOWS\System32\dllcache\kbdth2.dll -> [2010-12-15 23:53:47 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbdurdu.dll -> C:\WINDOWS\System32\dllcache\kbdurdu.dll -> [2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdth1.dll -> C:\WINDOWS\System32\dllcache\kbdth1.dll -> [2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdth0.dll -> C:\WINDOWS\System32\dllcache\kbdth0.dll -> [2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdsyr2.dll -> C:\WINDOWS\System32\dllcache\kbdsyr2.dll -> [2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdsyr1.dll -> C:\WINDOWS\System32\dllcache\kbdsyr1.dll -> [2010-12-15 23:53:47 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdnecat.dll -> C:\WINDOWS\System32\dllcache\kbdnecat.dll -> [2010-12-15 23:53:46 | 000,009,216 | ---- | C] (Microsoft Corporation)
kbdnecnt.dll -> C:\WINDOWS\System32\dllcache\kbdnecnt.dll -> [2010-12-15 23:53:46 | 000,007,680 | ---- | C] (Microsoft Corporation)
kbdnec95.dll -> C:\WINDOWS\System32\dllcache\kbdnec95.dll -> [2010-12-15 23:53:46 | 000,007,168 | ---- | C] (Microsoft Corporation)
kbdlk41a.dll -> C:\WINDOWS\System32\dllcache\kbdlk41a.dll -> [2010-12-15 23:53:46 | 000,006,656 | ---- | C] (Microsoft Corporation)
kbdlk41j.dll -> C:\WINDOWS\System32\dllcache\kbdlk41j.dll -> [2010-12-15 23:53:46 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbdibm02.dll -> C:\WINDOWS\System32\dllcache\kbdibm02.dll -> [2010-12-15 23:53:45 | 000,007,168 | ---- | C] (Microsoft Corporation)
kbdinpun.dll -> C:\WINDOWS\System32\dllcache\kbdinpun.dll -> [2010-12-15 23:53:45 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbdintel.dll -> C:\WINDOWS\System32\dllcache\kbdintel.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdintam.dll -> C:\WINDOWS\System32\dllcache\kbdintam.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdinmar.dll -> C:\WINDOWS\System32\dllcache\kbdinmar.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdinkan.dll -> C:\WINDOWS\System32\dllcache\kbdinkan.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdinhin.dll -> C:\WINDOWS\System32\dllcache\kbdinhin.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdinguj.dll -> C:\WINDOWS\System32\dllcache\kbdinguj.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdindev.dll -> C:\WINDOWS\System32\dllcache\kbdindev.dll -> [2010-12-15 23:53:45 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdheb.dll -> C:\WINDOWS\System32\dllcache\kbdheb.dll -> [2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdfa.dll -> C:\WINDOWS\System32\dllcache\kbdfa.dll -> [2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbddiv2.dll -> C:\WINDOWS\System32\dllcache\kbddiv2.dll -> [2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbddiv1.dll -> C:\WINDOWS\System32\dllcache\kbddiv1.dll -> [2010-12-15 23:53:44 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdgeo.dll -> C:\WINDOWS\System32\dllcache\kbdgeo.dll -> [2010-12-15 23:53:44 | 000,005,120 | ---- | C] (Microsoft Corporation)
jupiw.dll -> C:\WINDOWS\System32\dllcache\jupiw.dll -> [2010-12-15 23:53:43 | 000,018,432 | ---- | C] (Microsoft Corporation)
kbdax2.dll -> C:\WINDOWS\System32\dllcache\kbdax2.dll -> [2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbd106n.dll -> C:\WINDOWS\System32\dllcache\kbd106n.dll -> [2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbd101a.dll -> C:\WINDOWS\System32\dllcache\kbd101a.dll -> [2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbd101.dll -> C:\WINDOWS\System32\dllcache\kbd101.dll -> [2010-12-15 23:53:43 | 000,006,144 | ---- | C] (Microsoft Corporation)
kbda3.dll -> C:\WINDOWS\System32\dllcache\kbda3.dll -> [2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbda2.dll -> C:\WINDOWS\System32\dllcache\kbda2.dll -> [2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbda1.dll -> C:\WINDOWS\System32\dllcache\kbda1.dll -> [2010-12-15 23:53:43 | 000,005,632 | ---- | C] (Microsoft Corporation)
kbdarmw.dll -> C:\WINDOWS\System32\dllcache\kbdarmw.dll -> [2010-12-15 23:53:43 | 000,005,120 | ---- | C] (Microsoft Corporation)
kbdarme.dll -> C:\WINDOWS\System32\dllcache\kbdarme.dll -> [2010-12-15 23:53:43 | 000,005,120 | ---- | C] (Microsoft Corporation)
iscomlog.dll -> C:\WINDOWS\System32\dllcache\iscomlog.dll -> [2010-12-15 23:53:42 | 000,027,136 | ---- | C] (Microsoft Corporation)
iwrps.dll -> C:\WINDOWS\System32\dllcache\iwrps.dll -> [2010-12-15 23:53:42 | 000,009,216 | ---- | C] (Microsoft Corporation)
isapips.dll -> C:\WINDOWS\System32\dllcache\isapips.dll -> [2010-12-15 23:53:42 | 000,007,168 | ---- | C] (Microsoft Corporation)
iprip.dll -> C:\WINDOWS\System32\dllcache\iprip.dll -> [2010-12-15 23:53:41 | 000,035,840 | ---- | C] (Microsoft Corporation)
infocomm.dll -> C:\WINDOWS\System32\dllcache\infocomm.dll -> [2010-12-15 23:53:40 | 000,257,024 | ---- | C] (Microsoft Corporation)
infoctrs.dll -> C:\WINDOWS\System32\dllcache\infoctrs.dll -> [2010-12-15 23:53:40 | 000,009,216 | ---- | C] (Microsoft Corporation)
imskdic.dll -> C:\WINDOWS\System32\dllcache\imskdic.dll -> [2010-12-15 23:53:39 | 000,471,102 | ---- | C] (Microsoft Corporation)
imskf.dll -> C:\WINDOWS\System32\dllcache\imskf.dll -> [2010-12-15 23:53:39 | 000,315,455 | ---- | C] (Microsoft Corporation)
inetin51.exe -> C:\WINDOWS\System32\dllcache\inetin51.exe -> [2010-12-15 23:53:39 | 000,015,360 | ---- | C] (Microsoft Corporation)
imjputyc.dll -> C:\WINDOWS\System32\dllcache\imjputyc.dll -> [2010-12-15 23:53:38 | 000,274,489 | ---- | C] (Microsoft Corporation)
imjputy.exe -> C:\WINDOWS\System32\dllcache\imjputy.exe -> [2010-12-15 23:53:38 | 000,262,200 | ---- | C] (Microsoft Corporation)
imjprw.exe -> C:\WINDOWS\System32\dllcache\imjprw.exe -> [2010-12-15 23:53:38 | 000,233,527 | ---- | C] (Microsoft Corporation)
imlang.dll -> C:\WINDOWS\System32\dllcache\imlang.dll -> [2010-12-15 23:53:38 | 000,102,456 | ---- | C] (Microsoft Corporation)
imkrinst.exe -> C:\WINDOWS\System32\dllcache\imkrinst.exe -> [2010-12-15 23:53:38 | 000,059,904 | ---- | C] (Microsoft Corporation)
imjpuex.exe -> C:\WINDOWS\System32\dllcache\imjpuex.exe -> [2010-12-15 23:53:38 | 000,045,109 | ---- | C] (Microsoft Corporation)
imjpcus.dll -> C:\WINDOWS\System32\dllcache\imjpcus.dll -> [2010-12-15 23:53:37 | 000,716,856 | ---- | C] (Microsoft Corporation)
imjpcic.dll -> C:\WINDOWS\System32\dllcache\imjpcic.dll -> [2010-12-15 23:53:37 | 000,368,696 | ---- | C] (Microsoft Corporation)
imjpdct.exe -> C:\WINDOWS\System32\dllcache\imjpdct.exe -> [2010-12-15 23:53:37 | 000,307,257 | ---- | C] (Microsoft Corporation)
imjpmig.exe -> C:\WINDOWS\System32\dllcache\imjpmig.exe -> [2010-12-15 23:53:37 | 000,208,952 | ---- | C] (Microsoft Corporation)
imjpdsvr.exe -> C:\WINDOWS\System32\dllcache\imjpdsvr.exe -> [2010-12-15 23:53:37 | 000,155,705 | ---- | C] (Microsoft Corporation)
imjpdct.dll -> C:\WINDOWS\System32\dllcache\imjpdct.dll -> [2010-12-15 23:53:37 | 000,081,976 | ---- | C] (Microsoft Corporation)
imjpdadm.exe -> C:\WINDOWS\System32\dllcache\imjpdadm.exe -> [2010-12-15 23:53:37 | 000,057,398 | ---- | C] (Microsoft Corporation)
imjp81k.dll -> C:\WINDOWS\System32\dllcache\imjp81k.dll -> [2010-12-15 23:53:36 | 000,811,064 | ---- | C] (Microsoft Corporation)
imjp81.ime -> C:\WINDOWS\System32\dllcache\imjp81.ime -> [2010-12-15 23:53:36 | 000,340,023 | ---- | C] (Microsoft Corporation)
imepadsv.exe -> C:\WINDOWS\System32\dllcache\imepadsv.exe -> [2010-12-15 23:53:36 | 000,311,359 | ---- | C] (Microsoft Corporation)
imekrcic.dll -> C:\WINDOWS\System32\dllcache\imekrcic.dll -> [2010-12-15 23:53:36 | 000,106,496 | ---- | C] (Microsoft Corporation)
imepadsm.dll -> C:\WINDOWS\System32\dllcache\imepadsm.dll -> [2010-12-15 23:53:36 | 000,102,463 | ---- | C] (Microsoft Corporation)
imekr61.ime -> C:\WINDOWS\System32\dllcache\imekr61.ime -> [2010-12-15 23:53:36 | 000,094,720 | ---- | C] (Microsoft Corporation)
imekrmbx.dll -> C:\WINDOWS\System32\dllcache\imekrmbx.dll -> [2010-12-15 23:53:36 | 000,086,016 | ---- | C] (Microsoft Corporation)
imekrmig.exe -> C:\WINDOWS\System32\dllcache\imekrmig.exe -> [2010-12-15 23:53:36 | 000,044,032 | ---- | C] (Microsoft Corporation)
iische51.dll -> C:\WINDOWS\System32\dllcache\iische51.dll -> [2010-12-15 23:53:35 | 000,145,408 | ---- | C] (Microsoft Corporation)
iislog51.dll -> C:\WINDOWS\System32\dllcache\iislog51.dll -> [2010-12-15 23:53:35 | 000,079,872 | ---- | C] (Microsoft Corporation)
iisclex4.dll -> C:\WINDOWS\System32\dllcache\iisclex4.dll -> [2010-12-15 23:53:35 | 000,060,928 | ---- | C] (Microsoft Corporation)
iiscrmap.dll -> C:\WINDOWS\System32\dllcache\iiscrmap.dll -> [2010-12-15 23:53:35 | 000,019,456 | ---- | C] (Microsoft Corporation)
iisfecnv.dll -> C:\WINDOWS\System32\dllcache\iisfecnv.dll -> [2010-12-15 23:53:35 | 000,007,168 | ---- | C] (Microsoft Corporation)
iissync.exe -> C:\WINDOWS\System32\dllcache\iissync.exe -> [2010-12-15 23:53:35 | 000,006,656 | ---- | C] (Microsoft Corporation)
iismui.dll -> C:\WINDOWS\System32\dllcache\iismui.dll -> [2010-12-15 23:53:35 | 000,003,584 | ---- | C] (Microsoft Corporation)
iisadmin.dll -> C:\WINDOWS\System32\dllcache\iisadmin.dll -> [2010-12-15 23:53:34 | 000,025,088 | ---- | C] (Microsoft Corporation)
hwxkor.dll -> C:\WINDOWS\System32\dllcache\hwxkor.dll -> [2010-12-15 23:53:30 | 010,129,408 | ---- | C] (Microsoft Corporation)
hwxcht.dll -> C:\WINDOWS\System32\dllcache\hwxcht.dll -> [2010-12-15 23:53:24 | 010,096,640 | ---- | C] (Microsoft Corporation)
httpext.dll -> C:\WINDOWS\System32\dllcache\httpext.dll -> [2010-12-15 23:53:23 | 000,268,288 | ---- | C] (Microsoft Corporation)
httpod51.dll -> C:\WINDOWS\System32\dllcache\httpod51.dll -> [2010-12-15 23:53:23 | 000,061,440 | ---- | C] (Microsoft Corporation)
httpmb51.dll -> C:\WINDOWS\System32\dllcache\httpmb51.dll -> [2010-12-15 23:53:23 | 000,008,192 | ---- | C] (Microsoft Corporation)
hostmib.dll -> C:\WINDOWS\System32\dllcache\hostmib.dll -> [2010-12-15 23:53:22 | 000,039,936 | ---- | C] (Microsoft Corporation)
hanjadic.dll -> C:\WINDOWS\System32\dllcache\hanjadic.dll -> [2010-12-15 23:53:22 | 000,036,864 | ---- | C] (Microsoft Corporation)
gzip.dll -> C:\WINDOWS\System32\dllcache\gzip.dll -> [2010-12-15 23:53:21 | 000,032,256 | ---- | C] (Microsoft Corporation)
fxsxp32.dll -> C:\WINDOWS\System32\dllcache\fxsxp32.dll -> [2010-12-15 23:53:20 | 000,400,384 | ---- | C] (Microsoft Corporation)
fxswzrd.dll -> C:\WINDOWS\System32\dllcache\fxswzrd.dll -> [2010-12-15 23:53:20 | 000,193,536 | ---- | C] (Microsoft Corporation)
fxsui.dll -> C:\WINDOWS\System32\dllcache\fxsui.dll -> [2010-12-15 23:53:20 | 000,154,624 | ---- | C] (Microsoft Corporation)
fxsst.dll -> C:\WINDOWS\System32\dllcache\fxsst.dll -> [2010-12-15 23:53:19 | 000,562,176 | ---- | C] (Microsoft Corporation)
fxstiff.dll -> C:\WINDOWS\System32\dllcache\fxstiff.dll -> [2010-12-15 23:53:19 | 000,397,312 | ---- | C] (Microsoft Corporation)
fxssvc.exe -> C:\WINDOWS\System32\dllcache\fxssvc.exe -> [2010-12-15 23:53:19 | 000,268,288 | ---- | C] (Microsoft Corporation)
fxst30.dll -> C:\WINDOWS\System32\dllcache\fxst30.dll -> [2010-12-15 23:53:19 | 000,246,272 | ---- | C] (Microsoft Corporation)
fxsroute.dll -> C:\WINDOWS\System32\dllcache\fxsroute.dll -> [2010-12-15 23:53:19 | 000,031,744 | ---- | C] (Microsoft Corporation)
fxsmon.dll -> C:\WINDOWS\System32\dllcache\fxsmon.dll -> [2010-12-15 23:53:19 | 000,023,552 | ---- | C] (Microsoft Corporation)
fxsext32.dll -> C:\WINDOWS\System32\dllcache\fxsext32.dll -> [2010-12-15 23:53:19 | 000,023,552 | ---- | C] (Microsoft Corporation)
fxssend.exe -> C:\WINDOWS\System32\dllcache\fxssend.exe -> [2010-12-15 23:53:19 | 000,011,264 | ---- | C] (Microsoft Corporation)
fxsperf.dll -> C:\WINDOWS\System32\dllcache\fxsperf.dll -> [2010-12-15 23:53:19 | 000,008,704 | ---- | C] (Microsoft Corporation)
fxsres.dll -> C:\WINDOWS\System32\dllcache\fxsres.dll -> [2010-12-15 23:53:19 | 000,006,656 | ---- | C] (Microsoft Corporation)
fxsapi.dll -> C:\WINDOWS\System32\dllcache\fxsapi.dll -> [2010-12-15 23:53:18 | 000,451,584 | ---- | C] (Microsoft Corporation)
fxscomex.dll -> C:\WINDOWS\System32\dllcache\fxscomex.dll -> [2010-12-15 23:53:18 | 000,285,184 | ---- | C] (Microsoft Corporation)
fxscover.exe -> C:\WINDOWS\System32\dllcache\fxscover.exe -> [2010-12-15 23:53:18 | 000,232,448 | ---- | C] (Microsoft Corporation)
fxsclnt.exe -> C:\WINDOWS\System32\dllcache\fxsclnt.exe -> [2010-12-15 23:53:18 | 000,142,848 | ---- | C] (Microsoft Corporation)
fxsclntr.dll -> C:\WINDOWS\System32\dllcache\fxsclntr.dll -> [2010-12-15 23:53:18 | 000,135,680 | ---- | C] (Microsoft Corporation)
fxscfgwz.dll -> C:\WINDOWS\System32\dllcache\fxscfgwz.dll -> [2010-12-15 23:53:18 | 000,111,104 | ---- | C] (Microsoft Corporation)
fxscom.dll -> C:\WINDOWS\System32\dllcache\fxscom.dll -> [2010-12-15 23:53:18 | 000,072,192 | ---- | C] (Microsoft Corporation)
fxsevent.dll -> C:\WINDOWS\System32\dllcache\fxsevent.dll -> [2010-12-15 23:53:18 | 000,057,344 | ---- | C] (Microsoft Corporation)
fxsdrv.dll -> C:\WINDOWS\System32\dllcache\fxsdrv.dll -> [2010-12-15 23:53:18 | 000,026,624 | ---- | C] (Microsoft Corporation)
ftpsv251.dll -> C:\WINDOWS\System32\dllcache\ftpsv251.dll -> [2010-12-15 23:53:17 | 000,125,952 | ---- | C] (Microsoft Corporation)
ftpctrs2.dll -> C:\WINDOWS\System32\dllcache\ftpctrs2.dll -> [2010-12-15 23:53:17 | 000,007,680 | ---- | C] (Microsoft Corporation)
ftpmib.dll -> C:\WINDOWS\System32\dllcache\ftpmib.dll -> [2010-12-15 23:53:17 | 000,006,144 | ---- | C] (Microsoft Corporation)
ftlx041e.dll -> C:\WINDOWS\System32\dllcache\ftlx041e.dll -> [2010-12-15 23:53:17 | 000,006,144 | ---- | C] (Microsoft Corporation)
fpadmcgi.exe -> C:\WINDOWS\System32\dllcache\fpadmcgi.exe -> [2010-12-15 23:53:16 | 000,024,632 | ---- | C] (Microsoft Corporation)
fpadmdll.dll -> C:\WINDOWS\System32\dllcache\fpadmdll.dll -> [2010-12-15 23:53:16 | 000,020,541 | ---- | C] (Microsoft Corporation)
EXCH_fcachdll.dll -> C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll -> [2010-12-15 23:53:15 | 000,043,520 | ---- | C] (Microsoft Corporation)
flattemp.exe -> C:\WINDOWS\System32\dllcache\flattemp.exe -> [2010-12-15 23:53:15 | 000,014,848 | ---- | C] (Microsoft Corporation)
evntagnt.dll -> C:\WINDOWS\System32\dllcache\evntagnt.dll -> [2010-12-15 23:53:14 | 000,108,544 | ---- | C] (Microsoft Corporation)
evntwin.exe -> C:\WINDOWS\System32\dllcache\evntwin.exe -> [2010-12-15 23:53:14 | 000,092,672 | ---- | C] (Microsoft Corporation)
evntcmd.exe -> C:\WINDOWS\System32\dllcache\evntcmd.exe -> [2010-12-15 23:53:14 | 000,025,600 | ---- | C] (Microsoft Corporation)
exstrace.dll -> C:\WINDOWS\System32\dllcache\exstrace.dll -> [2010-12-15 23:53:14 | 000,014,336 | ---- | C] (Microsoft Corporation)
f3ahvoas.dll -> C:\WINDOWS\System32\dllcache\f3ahvoas.dll -> [2010-12-15 23:53:14 | 000,007,168 | ---- | C] (Microsoft Corporation)
esuimgd.dll -> C:\WINDOWS\System32\dllcache\esuimgd.dll -> [2010-12-15 23:53:13 | 000,057,856 | ---- | C] (SEIKO EPSON CORP.)
esunid.dll -> C:\WINDOWS\System32\dllcache\esunid.dll -> [2010-12-15 23:53:13 | 000,045,056 | ---- | C] (SEIKO EPSON CORP.)
esucmd.dll -> C:\WINDOWS\System32\dllcache\esucmd.dll -> [2010-12-15 23:53:13 | 000,031,744 | ---- | C] (SEIKO EPSON CORP.)
et4000.sys -> C:\WINDOWS\System32\dllcache\et4000.sys -> [2010-12-15 23:53:13 | 000,025,856 | ---- | C] (Microsoft Corporation)
dayi.ime -> C:\WINDOWS\System32\dllcache\dayi.ime -> [2010-12-15 23:53:04 | 000,078,848 | ---- | C] (Microsoft Corporation)
davcdata.exe -> C:\WINDOWS\System32\dllcache\davcdata.exe -> [2010-12-15 23:53:04 | 000,042,496 | ---- | C] (Microsoft Corporation)
cplexe.exe -> C:\WINDOWS\System32\dllcache\cplexe.exe -> [2010-12-15 23:53:02 | 000,057,399 | ---- | C] (Microsoft Corporation)
cprofile.exe -> C:\WINDOWS\System32\dllcache\cprofile.exe -> [2010-12-15 23:53:02 | 000,019,456 | ---- | C] (Microsoft Corporation)
convlog.exe -> C:\WINDOWS\System32\dllcache\convlog.exe -> [2010-12-15 23:53:01 | 000,056,320 | ---- | C] (Microsoft Corporation)
controt.dll -> C:\WINDOWS\System32\dllcache\controt.dll -> [2010-12-15 23:53:01 | 000,033,792 | ---- | C] (Microsoft Corporation)
counters.dll -> C:\WINDOWS\System32\dllcache\counters.dll -> [2010-12-15 23:53:01 | 000,020,480 | ---- | C] (Microsoft Corporation)
compfilt.dll -> C:\WINDOWS\System32\dllcache\compfilt.dll -> [2010-12-15 23:53:00 | 000,024,064 | ---- | C] (Microsoft Corporation)
cintsetp.exe -> C:\WINDOWS\System32\dllcache\cintsetp.exe -> [2010-12-15 23:52:59 | 000,480,256 | ---- | C] (Microsoft Corporation)
cintime.dll -> C:\WINDOWS\System32\dllcache\cintime.dll -> [2010-12-15 23:52:58 | 000,198,656 | ---- | C] (Microsoft Corporation)
chtmbx.dll -> C:\WINDOWS\System32\dllcache\chtmbx.dll -> [2010-12-15 23:52:58 | 000,097,792 | ---- | C] (Microsoft Corporation)
chtskdic.dll -> C:\WINDOWS\System32\dllcache\chtskdic.dll -> [2010-12-15 23:52:58 | 000,056,320 | ---- | C] (Microsoft Corporation)
cintlgnt.ime -> C:\WINDOWS\System32\dllcache\cintlgnt.ime -> [2010-12-15 23:52:58 | 000,021,504 | ---- | C] (Microsoft Corporation)
chsbrkr.dll -> C:\WINDOWS\System32\dllcache\chsbrkr.dll -> [2010-12-15 23:52:57 | 001,677,824 | ---- | C] (Microsoft Corporation)
chtbrkr.dll -> C:\WINDOWS\System32\dllcache\chtbrkr.dll -> [2010-12-15 23:52:57 | 000,838,144 | ---- | C] (Microsoft Corporation)
chgusr.exe -> C:\WINDOWS\System32\dllcache\chgusr.exe -> [2010-12-15 23:52:57 | 000,014,848 | ---- | C] (Microsoft Corporation)
chajei.ime -> C:\WINDOWS\System32\dllcache\chajei.ime -> [2010-12-15 23:52:56 | 000,078,336 | ---- | C] (Microsoft Corporation)
chgport.exe -> C:\WINDOWS\System32\dllcache\chgport.exe -> [2010-12-15 23:52:56 | 000,016,384 | ---- | C] (Microsoft Corporation)
chglogon.exe -> C:\WINDOWS\System32\dllcache\chglogon.exe -> [2010-12-15 23:52:56 | 000,013,824 | ---- | C] (Microsoft Corporation)
change.exe -> C:\WINDOWS\System32\dllcache\change.exe -> [2010-12-15 23:52:56 | 000,010,240 | ---- | C] (Microsoft Corporation)
cap7146.sys -> C:\WINDOWS\System32\dllcache\cap7146.sys -> [2010-12-15 23:52:55 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH)
c_iscii.dll -> C:\WINDOWS\System32\dllcache\c_iscii.dll -> [2010-12-15 23:52:55 | 000,010,752 | ---- | C] (Microsoft Corporation)
c_is2022.dll -> C:\WINDOWS\System32\dllcache\c_is2022.dll -> [2010-12-15 23:52:55 | 000,006,656 | ---- | C] (Microsoft Corporation)
c_g18030.dll -> C:\WINDOWS\System32\dllcache\c_g18030.dll -> [2010-12-15 23:52:54 | 000,218,112 | ---- | C] (Microsoft Corporation)
browscap.dll -> C:\WINDOWS\System32\dllcache\browscap.dll -> [2010-12-15 23:52:47 | 000,045,568 | ---- | C] (Microsoft Corporation)
bootok.exe -> C:\WINDOWS\System32\dllcache\bootok.exe -> [2010-12-15 23:52:47 | 000,004,608 | ---- | C] (Microsoft Corporation)
authfilt.dll -> C:\WINDOWS\System32\dllcache\authfilt.dll -> [2010-12-15 23:52:45 | 000,009,216 | ---- | C] (Microsoft Corporation)
asp51.dll -> C:\WINDOWS\System32\dllcache\asp51.dll -> [2010-12-15 23:52:44 | 000,372,736 | ---- | C] (Microsoft Corporation)
asptxn.dll -> C:\WINDOWS\System32\dllcache\asptxn.dll -> [2010-12-15 23:52:44 | 000,029,184 | ---- | C] (Microsoft Corporation)
aspperf.dll -> C:\WINDOWS\System32\dllcache\aspperf.dll -> [2010-12-15 23:52:44 | 000,010,240 | ---- | C] (Microsoft Corporation)
appconf.dll -> C:\WINDOWS\System32\dllcache\appconf.dll -> [2010-12-15 23:52:43 | 000,109,056 | ---- | C] (Microsoft Corporation)
agt0804.dll -> C:\WINDOWS\System32\dllcache\agt0804.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
agt0412.dll -> C:\WINDOWS\System32\dllcache\agt0412.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
agt0411.dll -> C:\WINDOWS\System32\dllcache\agt0411.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
agt040d.dll -> C:\WINDOWS\System32\dllcache\agt040d.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
agt0404.dll -> C:\WINDOWS\System32\dllcache\agt0404.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
agt0401.dll -> C:\WINDOWS\System32\dllcache\agt0401.dll -> [2010-12-15 23:52:42 | 000,019,456 | ---- | C] (Microsoft Corporation)
EXCH_adsiisex.dll -> C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll -> [2010-12-15 23:52:41 | 000,005,632 | ---- | C] (Microsoft Corporation)
adrot.dll -> C:\WINDOWS\System32\dllcache\adrot.dll -> [2010-12-15 23:52:40 | 000,049,664 | ---- | C] (Microsoft Corporation)
admexs.dll -> C:\WINDOWS\System32\dllcache\admexs.dll -> [2010-12-15 23:52:40 | 000,029,696 | ---- | C] (Microsoft Corporation)
admxprox.dll -> C:\WINDOWS\System32\dllcache\admxprox.dll -> [2010-12-15 23:52:40 | 000,006,144 | ---- | C] (Microsoft Corporation)
wamregps.dll -> C:\WINDOWS\System32\dllcache\wamregps.dll -> [2010-12-15 23:52:36 | 000,007,168 | ---- | C] (Microsoft Corporation)
smtpsnap.dll -> C:\WINDOWS\System32\dllcache\smtpsnap.dll -> [2010-12-15 23:52:35 | 002,134,528 | ---- | C] (Microsoft Corporation)
tcptest.exe -> C:\WINDOWS\System32\dllcache\tcptest.exe -> [2010-12-15 23:52:35 | 000,032,827 | ---- | C] (Microsoft Corporation)
tcptsat.dll -> C:\WINDOWS\System32\dllcache\tcptsat.dll -> [2010-12-15 23:52:35 | 000,016,384 | ---- | C] (Microsoft Corporation)
staxmem.dll -> C:\WINDOWS\System32\dllcache\staxmem.dll -> [2010-12-15 23:52:35 | 000,008,192 | ---- | C] (Microsoft Corporation)
smtpadm.dll -> C:\WINDOWS\System32\dllcache\smtpadm.dll -> [2010-12-15 23:52:34 | 000,189,440 | ---- | C] (Microsoft Corporation)
shtml.dll -> C:\WINDOWS\System32\dllcache\shtml.dll -> [2010-12-15 23:52:34 | 000,020,536 | ---- | C] (Microsoft Corporation)
shtml.exe -> C:\WINDOWS\System32\dllcache\shtml.exe -> [2010-12-15 23:52:34 | 000,016,437 | ---- | C] (Microsoft Corporation)
inetmgr.dll -> C:\WINDOWS\System32\dllcache\inetmgr.dll -> [2010-12-15 23:52:30 | 000,833,024 | ---- | C] (Microsoft Corporation)
logui.ocx -> C:\WINDOWS\System32\dllcache\logui.ocx -> [2010-12-15 23:52:30 | 000,077,312 | ---- | C] (Microsoft Corporation)
isatq.dll -> C:\WINDOWS\System32\dllcache\isatq.dll -> [2010-12-15 23:52:30 | 000,068,608 | ---- | C] (Microsoft Corporation)
inetsloc.dll -> C:\WINDOWS\System32\dllcache\inetsloc.dll -> [2010-12-15 23:52:30 | 000,019,968 | ---- | C] (Microsoft Corporation)
infoadmn.dll -> C:\WINDOWS\System32\dllcache\infoadmn.dll -> [2010-12-15 23:52:30 | 000,013,312 | ---- | C] (Microsoft Corporation)
inetmgr.exe -> C:\WINDOWS\System32\dllcache\inetmgr.exe -> [2010-12-15 23:52:30 | 000,007,680 | ---- | C] (Microsoft Corporation)
iisui.dll -> C:\WINDOWS\System32\dllcache\iisui.dll -> [2010-12-15 23:52:29 | 000,171,008 | ---- | C] (Microsoft Corporation)
iisrtl.dll -> C:\WINDOWS\System32\dllcache\iisrtl.dll -> [2010-12-15 23:52:29 | 000,133,632 | ---- | C] (Microsoft Corporation)
iisext51.dll -> C:\WINDOWS\System32\dllcache\iisext51.dll -> [2010-12-15 23:52:29 | 000,068,608 | ---- | C] (Microsoft Corporation)
iismap.dll -> C:\WINDOWS\System32\dllcache\iismap.dll -> [2010-12-15 23:52:29 | 000,064,512 | ---- | C] (Microsoft Corporation)
iisrstas.exe -> C:\WINDOWS\System32\dllcache\iisrstas.exe -> [2010-12-15 23:52:29 | 000,030,720 | ---- | C] (Microsoft Corporation)
iisreset.exe -> C:\WINDOWS\System32\dllcache\iisreset.exe -> [2010-12-15 23:52:29 | 000,014,848 | ---- | C] (Microsoft Corporation)
iisrstap.dll -> C:\WINDOWS\System32\dllcache\iisrstap.dll -> [2010-12-15 23:52:29 | 000,005,632 | ---- | C] (Microsoft Corporation)
fpmmc.dll -> C:\WINDOWS\System32\dllcache\fpmmc.dll -> [2010-12-15 23:52:28 | 000,598,071 | ---- | C] (Microsoft Corporation)
fpmmcsat.dll -> C:\WINDOWS\System32\dllcache\fpmmcsat.dll -> [2010-12-15 23:52:28 | 000,208,896 | ---- | C] (Microsoft Corporation)
fpcount.exe -> C:\WINDOWS\System32\dllcache\fpcount.exe -> [2010-12-15 23:52:28 | 000,188,494 | ---- | C] (Microsoft Corporation)
fpexedll.dll -> C:\WINDOWS\System32\dllcache\fpexedll.dll -> [2010-12-15 23:52:28 | 000,020,541 | ---- | C] (Microsoft Corporation)
fpremadm.exe -> C:\WINDOWS\System32\dllcache\fpremadm.exe -> [2010-12-15 23:52:28 | 000,020,538 | ---- | C] (Microsoft Corporation)
ftpsapi2.dll -> C:\WINDOWS\System32\dllcache\ftpsapi2.dll -> [2010-12-15 23:52:28 | 000,006,144 | ---- | C] (Microsoft Corporation)
fp4awel.dll -> C:\WINDOWS\System32\dllcache\fp4awel.dll -> [2010-12-15 23:52:27 | 000,876,653 | ---- | C] (Microsoft Corporation)
fp4apws.dll -> C:\WINDOWS\System32\dllcache\fp4apws.dll -> [2010-12-15 23:52:27 | 000,147,513 | ---- | C] (Microsoft Corporation)
fp98swin.exe -> C:\WINDOWS\System32\dllcache\fp98swin.exe -> [2010-12-15 23:52:27 | 000,109,328 | ---- | C] (Microsoft Corporation)
fp4atxt.dll -> C:\WINDOWS\System32\dllcache\fp4atxt.dll -> [2010-12-15 23:52:27 | 000,102,509 | ---- | C] (Microsoft Corporation)
fp4anscp.dll -> C:\WINDOWS\System32\dllcache\fp4anscp.dll -> [2010-12-15 23:52:27 | 000,082,035 | ---- | C] (Microsoft Corporation)
fp4awebs.dll -> C:\WINDOWS\System32\dllcache\fp4awebs.dll -> [2010-12-15 23:52:27 | 000,049,212 | ---- | C] (Microsoft Corporation)
fp4areg.dll -> C:\WINDOWS\System32\dllcache\fp4areg.dll -> [2010-12-15 23:52:27 | 000,049,210 | ---- | C] (Microsoft Corporation)
fp4avnb.dll -> C:\WINDOWS\System32\dllcache\fp4avnb.dll -> [2010-12-15 23:52:27 | 000,041,020 | ---- | C] (Microsoft Corporation)
fp4avss.dll -> C:\WINDOWS\System32\dllcache\fp4avss.dll -> [2010-12-15 23:52:27 | 000,032,826 | ---- | C] (Microsoft Corporation)
fp98sadm.exe -> C:\WINDOWS\System32\dllcache\fp98sadm.exe -> [2010-12-15 23:52:27 | 000,014,608 | ---- | C] (Microsoft Corporation)
fp4amsft.dll -> C:\WINDOWS\System32\dllcache\fp4amsft.dll -> [2010-12-15 23:52:26 | 000,184,435 | ---- | C] (Microsoft Corporation)
coadmin.dll -> C:\WINDOWS\System32\dllcache\coadmin.dll -> [2010-12-15 23:52:26 | 000,046,592 | ---- | C] (Microsoft Corporation)
certwiz.ocx -> C:\WINDOWS\System32\dllcache\certwiz.ocx -> [2010-12-15 23:52:25 | 000,276,992 | ---- | C] (Microsoft Corporation)
cfgwiz.exe -> C:\WINDOWS\System32\dllcache\cfgwiz.exe -> [2010-12-15 23:52:25 | 000,188,480 | ---- | C] (Microsoft Corporation)
certmap.ocx -> C:\WINDOWS\System32\dllcache\certmap.ocx -> [2010-12-15 23:52:25 | 000,094,720 | ---- | C] (Microsoft Corporation)
cnfgprts.ocx -> C:\WINDOWS\System32\dllcache\cnfgprts.ocx -> [2010-12-15 23:52:25 | 000,076,800 | ---- | C] (Microsoft Corporation)
author.dll -> C:\WINDOWS\System32\dllcache\author.dll -> [2010-12-15 23:52:25 | 000,020,540 | ---- | C] (Microsoft Corporation)
author.exe -> C:\WINDOWS\System32\dllcache\author.exe -> [2010-12-15 23:52:25 | 000,016,439 | ---- | C] (Microsoft Corporation)
adsiis51.dll -> C:\WINDOWS\System32\dllcache\adsiis51.dll -> [2010-12-15 23:52:24 | 000,290,816 | ---- | C] (Microsoft Corporation)
admwprox.dll -> C:\WINDOWS\System32\dllcache\admwprox.dll -> [2010-12-15 23:52:24 | 000,043,520 | ---- | C] (Microsoft Corporation)
admin.exe -> C:\WINDOWS\System32\dllcache\admin.exe -> [2010-12-15 23:52:24 | 000,016,439 | ---- | C] (Microsoft Corporation)
admin.dll -> C:\WINDOWS\System32\dllcache\admin.dll -> [2010-12-15 23:52:23 | 000,020,540 | ---- | C] (Microsoft Corporation)
isignup.exe -> C:\WINDOWS\System32\dllcache\isignup.exe -> [2010-12-15 23:49:39 | 000,016,384 | ---- | C] (Microsoft Corporation)
ComPlus Applications -> C:\Programmer\ComPlus Applications -> [2010-12-15 23:47:26 | 000,000,000 | ---D | C]
Messenger -> C:\Programmer\Messenger -> [2010-12-15 23:47:06 | 000,000,000 | ---D | C]
irclass.dll -> C:\WINDOWS\System32\irclass.dll -> [2010-12-15 23:33:18 | 000,013,312 | ---- | C] (Microsoft Corporation)
irclass.dll -> C:\WINDOWS\System32\dllcache\irclass.dll -> [2010-12-15 23:33:18 | 000,013,312 | ---- | C] (Microsoft Corporation)
spxcoins.dll -> C:\WINDOWS\System32\spxcoins.dll -> [2010-12-15 23:33:17 | 000,024,661 | ---- | C] (Perle Systems Ltd.)
spxcoins.dll -> C:\WINDOWS\System32\dllcache\spxcoins.dll -> [2010-12-15 23:33:17 | 000,024,661 | ---- | C] (Perle Systems Ltd.)
_OTL -> C:\_OTL -> [2010-12-15 03:54:07 | 000,000,000 | ---D | C]
Driver_Detective_v6.4.1.5_Full_Cracked_Version_Of_2010_Multilang_incl_Bonus_Tools.part2 -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Driver_Detective_v6.4.1.5_Full_Cracked_Version_Of_2010_Multilang_incl_Bonus_Tools.part2 -> [2010-12-13 19:59:23 | 000,000,000 | ---D | C]
Usenet.nl -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Usenet.nl -> [2010-12-13 19:47:22 | 000,000,000 | ---D | C]
Usenet.nl -> C:\Programmer\Usenet.nl -> [2010-12-13 19:47:17 | 000,000,000 | ---D | C]
Driver Whiz -> C:\Documents and Settings\All Users\Application Data\Driver Whiz -> [2010-12-13 19:33:51 | 000,000,000 | ---D | C]
PlexUTILITIES -> C:\WINDOWS\PlexUTILITIES -> [2010-12-13 19:12:30 | 000,000,000 | ---D | C]
Plextor -> C:\Programmer\Plextor -> [2010-12-13 19:12:30 | 000,000,000 | ---D | C]
DriverFinder -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\DriverFinder -> [2010-12-13 18:48:12 | 000,000,000 | ---D | C]
Apple Computer -> C:\Documents and Settings\LocalService\Application Data\Apple Computer -> [2010-12-08 22:14:54 | 000,000,000 | ---D | C]
.oces2 -> C:\Documents and Settings\Tina Vilhelmsen\.oces2 -> [2010-11-18 21:51:22 | 000,000,000 | ---D | C]
Adobe -> C:\Programmer\Fælles filer\Adobe -> [2010-11-18 21:02:54 | 000,000,000 | ---D | C]
Adobe -> C:\Programmer\Adobe -> [2010-11-18 21:02:54 | 000,000,000 | ---D | C]
Windows Installer Clean Up -> C:\Programmer\Windows Installer Clean Up -> [2010-11-18 17:45:25 | 000,000,000 | ---D | C]
NOS -> C:\Programmer\NOS -> [2010-11-17 21:02:12 | 000,000,000 | ---D | C]
NOS -> C:\Documents and Settings\All Users\Application Data\NOS -> [2010-11-17 21:02:12 | 000,000,000 | ---D | C]
CutePDF_Filler -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF_Filler -> [2010-11-17 19:31:19 | 000,000,000 | ---D | C]
CustomStamp -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CustomStamp -> [2010-11-17 19:29:48 | 000,000,000 | ---D | C]
CutePDF_Pro -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF_Pro -> [2010-11-17 19:28:56 | 000,000,000 | ---D | C]
CutePDF -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF -> [2010-11-17 19:28:56 | 000,000,000 | ---D | C]
GPLGS -> C:\Programmer\GPLGS -> [2010-11-17 19:28:51 | 000,000,000 | ---D | C]
CutePDF Writer -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\CutePDF Writer -> [2010-11-17 18:47:54 | 000,000,000 | ---D | C]
DLCQhcp.dll -> C:\WINDOWS\System32\DLCQhcp.dll -> [2009-03-18 21:48:06 | 000,323,584 | ---- | C] ( )
dlcqinpa.dll -> C:\WINDOWS\System32\dlcqinpa.dll -> [2006-10-11 23:41:42 | 000,413,696 | ---- | C] ( )
dlcqpmui.dll -> C:\WINDOWS\System32\dlcqpmui.dll -> [2006-10-11 23:01:40 | 000,643,072 | ---- | C] ( )
dlcqserv.dll -> C:\WINDOWS\System32\dlcqserv.dll -> [2006-10-11 22:59:56 | 001,224,704 | ---- | C] ( )
dlcqcomm.dll -> C:\WINDOWS\System32\dlcqcomm.dll -> [2006-10-11 22:54:10 | 000,421,888 | ---- | C] ( )
dlcqlmpm.dll -> C:\WINDOWS\System32\dlcqlmpm.dll -> [2006-10-11 22:52:34 | 000,585,728 | ---- | C] ( )
dlcqiesc.dll -> C:\WINDOWS\System32\dlcqiesc.dll -> [2006-10-11 22:51:16 | 000,397,312 | ---- | C] ( )
dlcqpplc.dll -> C:\WINDOWS\System32\dlcqpplc.dll -> [2006-10-11 22:48:58 | 000,094,208 | ---- | C] ( )
dlcqcomc.dll -> C:\WINDOWS\System32\dlcqcomc.dll -> [2006-10-11 22:48:14 | 000,684,032 | ---- | C] ( )
dlcqprox.dll -> C:\WINDOWS\System32\dlcqprox.dll -> [2006-10-11 22:47:42 | 000,163,840 | ---- | C] ( )
dlcqusb1.dll -> C:\WINDOWS\System32\dlcqusb1.dll -> [2006-10-11 22:41:04 | 000,991,232 | ---- | C] ( )
dlcqhbn3.dll -> C:\WINDOWS\System32\dlcqhbn3.dll -> [2006-10-11 22:37:14 | 000,696,320 | ---- | C] ( )
3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->

[Files/Folders - Modified Within 30 Days]
GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2010-12-16 20:50:00 | 000,000,914 | ---- | M] ()
OTS.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\OTS.exe -> [2010-12-16 20:48:04 | 000,642,048 | ---- | M] (OldTimer Tools)
GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003UA.job -> [2010-12-16 20:35:00 | 000,001,064 | ---- | M] ()
Genvej til Download.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Genvej til Download.lnk -> [2010-12-16 20:29:25 | 000,000,862 | ---- | M] ()
perfh006.dat -> C:\WINDOWS\System32\perfh006.dat -> [2010-12-16 19:57:04 | 000,544,506 | ---- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2010-12-16 19:57:04 | 000,505,436 | ---- | M] ()
perfc006.dat -> C:\WINDOWS\System32\perfc006.dat -> [2010-12-16 19:57:04 | 000,110,916 | ---- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2010-12-16 19:57:04 | 000,089,004 | ---- | M] ()
nvapps.xml -> C:\WINDOWS\System32\nvapps.xml -> [2010-12-16 19:53:28 | 000,206,324 | ---- | M] ()
PSLOG -> C:\PSLOG -> [2010-12-16 19:53:26 | 000,000,198 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2010-12-16 19:53:08 | 000,000,910 | ---- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2010-12-16 19:52:41 | 000,002,048 | --S- | M] ()
hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2010-12-16 19:41:10 | 000,000,027 | ---- | M] ()
ComboFix.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\ComboFix.exe -> [2010-12-16 19:32:00 | 003,992,805 | R--- | M] ()
Google Chrome.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Google Chrome.lnk -> [2010-12-16 00:35:39 | 000,002,439 | ---- | M] ()
Google Chrome.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> [2010-12-16 00:35:39 | 000,002,417 | ---- | M] ()
LexFiles.ulf -> C:\WINDOWS\System32\LexFiles.ulf -> [2010-12-16 00:07:22 | 000,026,192 | ---- | M] ()
User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job -> C:\WINDOWS\tasks\User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job -> [2010-12-16 00:06:31 | 000,000,434 | -H-- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2010-12-16 00:03:32 | 000,002,206 | ---- | M] ()
FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2010-12-15 23:58:49 | 000,273,376 | ---- | M] ()
$winnt$.inf -> C:\WINDOWS\System32\$winnt$.inf -> [2010-12-15 23:56:19 | 000,000,287 | ---- | M] ()
WMSysPr9.prx -> C:\WINDOWS\WMSysPr9.prx -> [2010-12-15 23:52:01 | 000,316,640 | ---- | M] ()
nscompat.tlb -> C:\WINDOWS\System32\nscompat.tlb -> [2010-12-15 23:52:00 | 000,023,392 | ---- | M] ()
amcompat.tlb -> C:\WINDOWS\System32\amcompat.tlb -> [2010-12-15 23:52:00 | 000,016,832 | ---- | M] ()
ODBCINST.INI -> C:\WINDOWS\ODBCINST.INI -> [2010-12-15 23:51:47 | 000,004,161 | ---- | M] ()
emptyregdb.dat -> C:\WINDOWS\System32\emptyregdb.dat -> [2010-12-15 23:47:37 | 000,023,404 | ---- | M] ()
boot.ini -> C:\boot.ini -> [2010-12-15 23:44:58 | 000,000,211 | -HS- | M] ()
rst.sh -> C:\rst.sh -> [2010-12-15 00:33:56 | 000,003,069 | ---- | M] ()
Usenet.nl.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Usenet.nl.lnk -> [2010-12-13 19:47:18 | 000,001,552 | ---- | M] ()
GMouse.ini -> C:\WINDOWS\GMouse.ini -> [2010-12-12 22:12:40 | 000,000,111 | ---- | M] ()
GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-412668190-1801674531-1003Core.job -> [2010-12-12 21:35:00 | 000,001,012 | ---- | M] ()
AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2010-12-11 08:11:00 | 000,000,278 | ---- | M] ()
setup_ldm.iss -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\setup_ldm.iss -> [2010-12-06 19:42:14 | 000,000,760 | ---- | M] ()
temp.dat -> C:\Documents and Settings\Tina Vilhelmsen\temp.dat -> [2010-11-30 19:43:53 | 000,000,000 | ---- | M] ()
SpeedUpMyPC.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk -> [2010-11-17 22:27:23 | 000,000,759 | ---- | M] ()
3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->

[Files - No Company Name]
sed.exe -> C:\WINDOWS\sed.exe -> [2010-12-16 19:32:44 | 000,098,816 | ---- | C] ()
ComboFix.exe -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\ComboFix.exe -> [2010-12-16 19:18:58 | 003,992,805 | R--- | C] ()
pintlcsa.dll -> C:\WINDOWS\System32\dllcache\pintlcsa.dll -> [2010-12-15 23:54:18 | 000,175,104 | ---- | C] ()
korwbrkr.lex -> C:\WINDOWS\System32\dllcache\korwbrkr.lex -> [2010-12-15 23:53:49 | 001,158,818 | ---- | C] ()
imscinst.exe -> C:\WINDOWS\System32\dllcache\imscinst.exe -> [2010-12-15 23:53:38 | 000,059,392 | ---- | C] ()
imjpinst.exe -> C:\WINDOWS\System32\dllcache\imjpinst.exe -> [2010-12-15 23:53:37 | 000,196,665 | ---- | C] ()
imekr.lex -> C:\WINDOWS\System32\dllcache\imekr.lex -> [2010-12-15 23:53:35 | 000,134,339 | ---- | C] ()
hwxjpn.dll -> C:\WINDOWS\System32\dllcache\hwxjpn.dll -> [2010-12-15 23:53:26 | 013,463,552 | ---- | C] ()
hanja.lex -> C:\WINDOWS\System32\dllcache\hanja.lex -> [2010-12-15 23:53:21 | 000,108,827 | ---- | C] ()
fpencode.dll -> C:\WINDOWS\System32\dllcache\fpencode.dll -> [2010-12-15 23:53:16 | 000,094,208 | ---- | C] ()
chtskf.dll -> C:\WINDOWS\System32\dllcache\chtskf.dll -> [2010-12-15 23:52:58 | 000,173,568 | ---- | C] ()
SP3.CAT -> C:\WINDOWS\System32\dllcache\SP3.CAT -> [2010-12-15 23:33:01 | 001,246,013 | ---- | C] ()
NT5IIS.CAT -> C:\WINDOWS\System32\dllcache\NT5IIS.CAT -> [2010-12-15 23:33:01 | 000,809,684 | ---- | C] ()
MAPIMIG.CAT -> C:\WINDOWS\System32\dllcache\MAPIMIG.CAT -> [2010-12-15 23:33:01 | 000,399,670 | ---- | C] ()
netfx.cat -> C:\WINDOWS\System32\dllcache\netfx.cat -> [2010-12-15 23:33:01 | 000,144,484 | ---- | C] ()
tabletpc.cat -> C:\WINDOWS\System32\dllcache\tabletpc.cat -> [2010-12-15 23:33:01 | 000,105,628 | ---- | C] ()
MW770.CAT -> C:\WINDOWS\System32\dllcache\MW770.CAT -> [2010-12-15 23:33:01 | 000,037,509 | ---- | C] ()
mediactr.cat -> C:\WINDOWS\System32\dllcache\mediactr.cat -> [2010-12-15 23:33:01 | 000,034,747 | ---- | C] ()
FP4.CAT -> C:\WINDOWS\System32\dllcache\FP4.CAT -> [2010-12-15 23:33:01 | 000,033,765 | ---- | C] ()
IMS.CAT -> C:\WINDOWS\System32\dllcache\IMS.CAT -> [2010-12-15 23:33:01 | 000,016,825 | ---- | C] ()
HPCRDP.CAT -> C:\WINDOWS\System32\dllcache\HPCRDP.CAT -> [2010-12-15 23:33:01 | 000,013,497 | ---- | C] ()
MSMSGS.CAT -> C:\WINDOWS\System32\dllcache\MSMSGS.CAT -> [2010-12-15 23:33:01 | 000,012,363 | ---- | C] ()
MSTSWEB.CAT -> C:\WINDOWS\System32\dllcache\MSTSWEB.CAT -> [2010-12-15 23:33:01 | 000,010,027 | ---- | C] ()
IASNT4.CAT -> C:\WINDOWS\System32\dllcache\IASNT4.CAT -> [2010-12-15 23:33:01 | 000,008,599 | ---- | C] ()
OEMBIOS.CAT -> C:\WINDOWS\System32\dllcache\OEMBIOS.CAT -> [2010-12-15 23:33:01 | 000,007,382 | ---- | C] ()
NT5.CAT -> C:\WINDOWS\System32\dllcache\NT5.CAT -> [2010-12-15 23:33:00 | 002,033,299 | ---- | C] ()
NT5INF.CAT -> C:\WINDOWS\System32\dllcache\NT5INF.CAT -> [2010-12-15 23:33:00 | 000,633,432 | ---- | C] ()
rst.sh -> C:\rst.sh -> [2010-12-15 23:06:58 | 000,003,069 | ---- | C] ()
Usenet.nl.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Skrivebord\Usenet.nl.lnk -> [2010-12-13 19:47:18 | 000,001,552 | ---- | C] ()
setup_ldm.iss -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\setup_ldm.iss -> [2010-12-06 19:42:14 | 000,000,760 | ---- | C] ()
danid.log.1 -> C:\Documents and Settings\Tina Vilhelmsen\danid.log.1 -> [2010-11-18 21:51:26 | 001,085,191 | ---- | C] ()
danid.log -> C:\Documents and Settings\Tina Vilhelmsen\danid.log -> [2010-11-18 21:51:26 | 000,804,502 | ---- | C] ()
SpeedUpMyPC.lnk -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Microsoft\Internet Explorer\Quick Launch\SpeedUpMyPC.lnk -> [2010-11-17 22:27:23 | 000,000,759 | ---- | C] ()
cpwmon2k.dll -> C:\WINDOWS\System32\cpwmon2k.dll -> [2010-11-17 19:27:42 | 000,087,544 | ---- | C] ()
GMouse.ini -> C:\WINDOWS\GMouse.ini -> [2010-11-09 00:35:32 | 000,000,111 | ---- | C] ()
WPFFontCache_v0400-S-1-5-21-2052111302-412668190-1801674531-1003-0.dat -> C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-2052111302-412668190-1801674531-1003-0.dat -> [2010-10-20 06:48:18 | 000,272,254 | ---- | C] ()
FontCache3.0.0.0.dat -> C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat -> [2010-10-20 06:48:16 | 000,160,712 | ---- | C] ()
WPFFontCache_v0400-System.dat -> C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-System.dat -> [2010-10-20 06:48:14 | 000,272,254 | ---- | C] ()
KGyGaAvL.sys -> C:\WINDOWS\System32\KGyGaAvL.sys -> [2010-05-16 20:21:14 | 000,003,766 | -HS- | C] ()
BCEDB1EE70.sys -> C:\WINDOWS\System32\BCEDB1EE70.sys -> [2010-05-16 20:21:14 | 000,000,056 | RHS- | C] ()
LUUnInstall.LiveUpdate -> C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate -> [2010-03-26 19:43:06 | 000,002,598 | ---- | C] ()
EkspresLøn.INI -> C:\WINDOWS\EkspresLøn.INI -> [2010-01-27 19:14:02 | 000,000,000 | ---- | C] ()
OGACheckControl.dll -> C:\WINDOWS\System32\OGACheckControl.dll -> [2009-10-03 16:10:54 | 000,676,224 | ---- | C] ()
WgaLogon.dll -> C:\WINDOWS\System32\WgaLogon.dll -> [2009-10-03 15:29:24 | 000,000,000 | ---- | C] ()
slot1.mm1 -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\slot1.mm1 -> [2009-04-02 19:18:51 | 000,007,610 | ---- | C] ()
DLCQinst.dll -> C:\WINDOWS\System32\DLCQinst.dll -> [2009-03-18 21:48:06 | 000,274,432 | ---- | C] ()
dlcqcoin.dll -> C:\WINDOWS\System32\dlcqcoin.dll -> [2009-03-18 21:42:28 | 000,344,064 | R--- | C] ()
DLCQcfg.dll -> C:\WINDOWS\System32\DLCQcfg.dll -> [2009-03-18 21:42:27 | 000,077,824 | ---- | C] ()
Bot.dll -> C:\WINDOWS\System32\Bot.dll -> [2009-03-18 20:30:53 | 000,200,704 | ---- | C] ()
Psxlpr.ini -> C:\WINDOWS\Psxlpr.ini -> [2009-03-18 20:30:53 | 000,000,101 | ---- | C] ()
snxpserx.sys -> C:\WINDOWS\System32\drivers\snxpserx.sys -> [2009-03-18 16:53:28 | 000,054,912 | ---- | C] ()
snxprops.dll -> C:\WINDOWS\System32\snxprops.dll -> [2009-03-18 16:53:28 | 000,027,136 | ---- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2009-03-14 22:30:10 | 000,000,216 | ---- | C] ()
NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2009-03-11 22:48:33 | 000,000,069 | ---- | C] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009-03-11 22:47:55 | 000,008,192 | ---- | C] ()
WBCustomizer.dll -> C:\WINDOWS\System32\WBCustomizer.dll -> [2009-03-11 20:09:06 | 000,021,504 | ---- | C] ()
lvcoinst.ini -> C:\WINDOWS\System32\lvcoinst.ini -> [2009-03-11 03:35:14 | 000,014,938 | ---- | C] ()
DLPRMON.DLL -> C:\WINDOWS\System32\DLPRMON.DLL -> [2009-03-11 03:21:59 | 000,045,056 | ---- | C] ()
DLPMONUI.DLL -> C:\WINDOWS\System32\DLPMONUI.DLL -> [2009-03-11 03:21:59 | 000,032,768 | ---- | C] ()
hpbafd.ini -> C:\WINDOWS\hpbafd.ini -> [2009-03-11 02:54:51 | 000,000,602 | ---- | C] ()
HPMProp.INI -> C:\WINDOWS\HPMProp.INI -> [2009-03-11 02:50:37 | 000,000,000 | ---- | C] ()
Ascd_log.ini -> C:\WINDOWS\Ascd_log.ini -> [2009-03-11 00:58:39 | 000,035,000 | ---- | C] ()
fusioncache.dat -> C:\Documents and Settings\Tina Vilhelmsen\Lokale indstillinger\Application Data\fusioncache.dat -> [2009-03-11 00:19:00 | 000,000,144 | ---- | C] ()
ASACPI.sys -> C:\WINDOWS\System32\drivers\ASACPI.sys -> [2009-03-10 22:53:23 | 000,005,810 | R--- | C] ()
Ascd_tmp.ini -> C:\WINDOWS\Ascd_tmp.ini -> [2009-03-10 22:53:10 | 000,036,054 | ---- | C] ()
ASUSHWIO.SYS -> C:\WINDOWS\System32\drivers\ASUSHWIO.SYS -> [2009-03-10 22:53:08 | 000,010,296 | ---- | C] ()
ODBCINST.INI -> C:\WINDOWS\ODBCINST.INI -> [2009-03-10 16:57:18 | 000,004,161 | ---- | C] ()
physxcudart_20.dll -> C:\WINDOWS\System32\physxcudart_20.dll -> [2008-10-07 09:13:30 | 000,197,912 | ---- | C] ()
AgCPanelTraditionalChinese.dll -> C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll -> [2008-10-07 09:13:22 | 000,058,648 | ---- | C] ()
AgCPanelSwedish.dll -> C:\WINDOWS\System32\AgCPanelSwedish.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelSpanish.dll -> C:\WINDOWS\System32\AgCPanelSpanish.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelSimplifiedChinese.dll -> C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelPortugese.dll -> C:\WINDOWS\System32\AgCPanelPortugese.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelKorean.dll -> C:\WINDOWS\System32\AgCPanelKorean.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelJapanese.dll -> C:\WINDOWS\System32\AgCPanelJapanese.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelGerman.dll -> C:\WINDOWS\System32\AgCPanelGerman.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
AgCPanelFrench.dll -> C:\WINDOWS\System32\AgCPanelFrench.dll -> [2008-10-07 09:13:20 | 000,058,648 | ---- | C] ()
LVPr2Mon.sys -> C:\WINDOWS\System32\drivers\LVPr2Mon.sys -> [2008-07-26 08:25:02 | 000,025,624 | ---- | C] ()
gthrctr.ini -> C:\WINDOWS\System32\gthrctr.ini -> [2008-05-26 22:23:18 | 000,016,130 | ---- | C] ()
idxcntrs.ini -> C:\WINDOWS\System32\idxcntrs.ini -> [2008-05-26 22:23:16 | 000,021,898 | ---- | C] ()
gsrvctr.ini -> C:\WINDOWS\System32\gsrvctr.ini -> [2008-05-26 22:23:14 | 000,016,012 | ---- | C] ()
nvwdmcpl.dll -> C:\WINDOWS\System32\nvwdmcpl.dll -> [2008-01-03 15:26:00 | 001,724,416 | ---- | C] ()
nview.dll -> C:\WINDOWS\System32\nview.dll -> [2008-01-03 15:26:00 | 001,507,328 | ---- | C] ()
nvwimg.dll -> C:\WINDOWS\System32\nvwimg.dll -> [2008-01-03 15:26:00 | 001,101,824 | ---- | C] ()
nvshell.dll -> C:\WINDOWS\System32\nvshell.dll -> [2008-01-03 15:26:00 | 000,466,944 | ---- | C] ()
nvnt4cpl.dll -> C:\WINDOWS\System32\nvnt4cpl.dll -> [2008-01-03 15:26:00 | 000,286,720 | ---- | C] ()
dlcqinsb.dll -> C:\WINDOWS\System32\dlcqinsb.dll -> [2006-10-21 01:17:44 | 000,176,128 | ---- | C] ()
dlcqcub.dll -> C:\WINDOWS\System32\dlcqcub.dll -> [2006-10-21 01:17:00 | 000,086,016 | ---- | C] ()
dlcqcu.dll -> C:\WINDOWS\System32\dlcqcu.dll -> [2006-10-21 01:15:28 | 000,073,728 | ---- | C] ()
dlcqins.dll -> C:\WINDOWS\System32\dlcqins.dll -> [2006-10-21 01:14:54 | 000,176,128 | ---- | C] ()
dlcqutil.dll -> C:\WINDOWS\System32\dlcqutil.dll -> [2006-10-21 01:09:16 | 000,454,656 | ---- | C] ()
dlcqinsr.dll -> C:\WINDOWS\System32\dlcqinsr.dll -> [2006-10-20 08:35:38 | 000,106,496 | ---- | C] ()
dlcqcur.dll -> C:\WINDOWS\System32\dlcqcur.dll -> [2006-10-20 08:35:32 | 000,036,864 | ---- | C] ()
dlcqjswr.dll -> C:\WINDOWS\System32\dlcqjswr.dll -> [2006-10-20 08:34:30 | 000,139,264 | ---- | C] ()
dlcqgrd.dll -> C:\WINDOWS\System32\dlcqgrd.dll -> [2006-10-20 06:35:40 | 000,188,416 | ---- | C] ()
dlcqcaps.dll -> C:\WINDOWS\System32\dlcqcaps.dll -> [2006-08-14 17:32:18 | 000,065,536 | ---- | C] ()
dlcqdrs.dll -> C:\WINDOWS\System32\dlcqdrs.dll -> [2006-08-08 15:58:04 | 000,692,224 | ---- | C] ()
dlcqcnv4.dll -> C:\WINDOWS\System32\dlcqcnv4.dll -> [2006-05-09 10:10:04 | 000,061,440 | ---- | C] ()
dlcqvs.dll -> C:\WINDOWS\System32\dlcqvs.dll -> [2006-04-25 08:11:18 | 000,040,960 | ---- | C] ()
wsiShared.dll -> C:\WINDOWS\System32\wsiShared.dll -> [2004-07-10 18:55:38 | 000,252,416 | ---- | C] ()
uninstall.ini -> C:\WINDOWS\System32\uninstall.ini -> [2004-03-15 14:29:12 | 000,000,061 | ---- | C] ()
indounin.dll -> C:\WINDOWS\System32\indounin.dll -> [1999-01-27 13:39:06 | 000,065,024 | ---- | C] ()
Iyvu9_32.dll -> C:\WINDOWS\System32\Iyvu9_32.dll -> [1997-06-13 07:56:08 | 000,056,832 | ---- | C] ()

[File - Lop Check]
Avery -> C:\Documents and Settings\All Users\Application Data\Avery -> [2009-03-11 20:23:08 | 000,000,000 | ---D | M]
BVRP Software -> C:\Documents and Settings\All Users\Application Data\BVRP Software -> [2009-03-11 03:22:53 | 000,000,000 | ---D | M]
Driver Whiz -> C:\Documents and Settings\All Users\Application Data\Driver Whiz -> [2010-12-13 19:33:51 | 000,000,000 | ---D | M]
DriverScanner -> C:\Documents and Settings\All Users\Application Data\DriverScanner -> [2010-05-26 21:05:11 | 000,000,000 | ---D | M]
GARMIN -> C:\Documents and Settings\All Users\Application Data\GARMIN -> [2009-07-16 22:34:52 | 000,000,000 | ---D | M]
Installations -> C:\Documents and Settings\All Users\Application Data\Installations -> [2010-07-22 14:59:17 | 000,000,000 | ---D | M]
Nokia -> C:\Documents and Settings\All Users\Application Data\Nokia -> [2010-06-13 14:41:05 | 000,000,000 | ---D | M]
OLDSymantec -> C:\Documents and Settings\All Users\Application Data\OLDSymantec -> [2009-12-22 16:13:34 | 000,000,000 | ---D | M]
PC Drivers HeadQuarters -> C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters -> [2009-03-18 15:27:31 | 000,000,000 | ---D | M]
PC Suite -> C:\Documents and Settings\All Users\Application Data\PC Suite -> [2010-06-13 14:12:08 | 000,000,000 | ---D | M]
SecTaskMan -> C:\Documents and Settings\All Users\Application Data\SecTaskMan -> [2010-04-22 20:26:01 | 000,000,000 | ---D | M]
SkyGolf -> C:\Documents and Settings\All Users\Application Data\SkyGolf -> [2009-06-22 12:43:17 | 000,000,000 | ---D | M]
TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2010-11-18 01:04:01 | 000,000,000 | ---D | M]
UClick -> C:\Documents and Settings\All Users\Application Data\UClick -> [2009-04-27 21:34:40 | 000,000,000 | ---D | M]
Uniblue -> C:\Documents and Settings\All Users\Application Data\Uniblue -> [2009-03-12 21:11:45 | 000,000,000 | ---D | M]
WinZip -> C:\Documents and Settings\All Users\Application Data\WinZip -> [2009-03-11 21:13:42 | 000,000,000 | ---D | M]
{429CAD59-35B1-4DBC-BB6D-1DB246563521} -> C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} -> [2010-11-03 18:33:00 | 000,000,000 | ---D | M]
{8A09CD83-59E1-4DB1-AAFC-E25174FC6706} -> C:\Documents and Settings\All Users\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706} -> [2009-03-12 21:01:51 | 000,000,000 | -H-D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009-06-10 14:24:39 | 000,000,000 | ---D | M]
{92E7A367-8E12-4830-AA70-29C32E331A81} -> C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} -> [2010-05-26 19:51:45 | 000,000,000 | -H-D | M]
{A613CA96-150A-4A1D-90CE-67F81379DF8C} -> C:\Documents and Settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C} -> [2010-05-26 21:00:56 | 000,000,000 | -H-D | M]
{BE1D7187-C39B-4B11-9EBD-9D19FAE66E65} -> C:\Documents and Settings\All Users\Application Data\{BE1D7187-C39B-4B11-9EBD-9D19FAE66E65} -> [2009-09-04 19:42:22 | 000,000,000 | -H-D | M]
Cryptomathic -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Cryptomathic -> [2009-03-13 10:06:57 | 000,000,000 | ---D | M]
DriverFinder -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\DriverFinder -> [2010-12-13 19:28:52 | 000,000,000 | ---D | M]
GARMIN -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\GARMIN -> [2010-04-26 20:36:17 | 000,000,000 | ---D | M]
GetRightToGo -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\GetRightToGo -> [2010-11-09 22:52:34 | 000,000,000 | ---D | M]
Leadertech -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Leadertech -> [2009-03-11 12:15:25 | 000,000,000 | ---D | M]
Mouse Recorder Pro -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Mouse Recorder Pro -> [2010-11-09 23:05:26 | 000,000,000 | ---D | M]
Nokia -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Nokia -> [2010-06-13 14:12:09 | 000,000,000 | ---D | M]
PC Suite -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\PC Suite -> [2010-06-13 14:12:12 | 000,000,000 | ---D | M]
Uniblue -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Uniblue -> [2010-05-26 21:01:21 | 000,000,000 | ---D | M]
Usenet.nl -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Usenet.nl -> [2010-12-13 20:12:53 | 000,000,000 | ---D | M]
Windows Desktop Search -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Windows Desktop Search -> [2009-03-11 00:16:01 | 000,000,000 | ---D | M]
Windows Search -> C:\Documents and Settings\Tina Vilhelmsen\Application Data\Windows Search -> [2009-03-11 13:53:58 | 000,000,000 | ---D | M]
Uniblue DiskRescue 2009.job -> C:\WINDOWS\Tasks\Uniblue DiskRescue 2009.job -> [2009-04-05 12:36:38 | 000,000,386 | ---- | M] ()
Uniblue SpyEraser.job -> C:\WINDOWS\Tasks\Uniblue SpyEraser.job -> [2010-07-14 13:06:38 | 000,000,346 | ---- | M] ()
User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job -> C:\WINDOWS\Tasks\User_Feed_Synchronization-{2F54F2CE-7C2F-445C-8DA0-C6802269CED6}.job -> [2010-12-16 00:06:31 | 000,000,434 | -H-- | M] ()

[File - Purity Scan]


[Alternate Data Streams]
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E9B629B
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB97DB91
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2F141B68
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48081133
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:538A9F02
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C07A6A6B
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B285B76
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A745DB5D
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E3CEEC4C
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:551BED5F
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E32966C0
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FC2E567F
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:69AF9D20
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D0668210
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC0A74A1
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EAFDF1CF
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F3EFA8A8
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A8BB29B
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:569CEE83
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6710EF08
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55E1514E
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1CC2D5E
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E2CB42C9
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E962FBDB
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:84CFEE62
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98DFF516
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:177313FB
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:28476D43
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:47FE7AB7
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A60D0FA6
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33EA030E
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45F3AD49
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:57176330
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E06C78F
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EC855C73
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ED3D5F5B
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F1DEA771
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48500F8
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F9283DA1
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3FD496E1
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A31B5E9B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C3C72D5F
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:225CD7D5
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D17C178
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:996104FC
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CC4C59B4
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:102394C6
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:50636E35
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7AA6FC81
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:12D9D48F
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2EA99C48
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B812EE0
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D36932D
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53DF59D1
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:58C9BCAC
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71004506
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEB25EAE
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B7E2022
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2F6462DF
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7A032A04
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B52659E
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E29063FF
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB40BC91
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:26FBC1F9
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48977386
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B1195DD
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:640EA6E8
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DB77E2C4
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1181620C
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:13EF4AF6
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5080697C
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B9B0020
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:895A78C5
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98982C88
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E80802C7
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E9FAC3AB
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:206470A5
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5025C6E4
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55F44B88
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6F0B6A5A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89CF6F9C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0E684AC9
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D186293
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A448DB2
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71612023
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD04902E
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5BC73C48
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:880F0FEF
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C7973317
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D4BB0AD6
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D351BC6
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7FCB9D0D
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C6D0ABC3
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF5B3572
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:054F0F17
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0FA1EAA7
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5FFC2819
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:88A44CC1
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:596E2371
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2CE15176
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEF60648
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E895790F
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA10407C
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F84B8DB5
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:737160C1
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E732B44B
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:341C1FBD
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6926830F
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C48A983C
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FED25C29
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:870649A4
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:890AEB7A
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91FFEC32
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E14FA16F
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:370E4EFB
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8B4B9596
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:35FAD15D
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91DEEE71
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C72A744C
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F9EDCFB0
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9F38BF31
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E7B4296D
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F8F070C2
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0EC7A545
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:700B9342
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80F63EC3
@Alternate Data Stream - 154 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E0BB7B35
@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB0B938
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEFF768F
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31106FCB
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF2B29
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1316EAD4
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A1628E5
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A2907225
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BA05E0C4
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BB71BBA2
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C22674B6
< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP