Avatar billede Posten50 Praktikant
19. september 2011 - 19:39 Der er 56 kommentarer og
1 løsning

Min PC "arbejder" højlydt selvom jeg ikke laver noget. Blæser kører fo at afkøle

Mit antivirus program Norton, fortæller at der er en fil svchost.exe som bruger meget af PCens ydeevne, hvilket jeg også tydeligt mærker/hører ved at blæser kører ofte selvom jeg ikke arbejder ved PCen (bærbar HP/Compaq). Hvad kan jeg evt gøre??
Avatar billede 220661 Ekspert
19. september 2011 - 19:56 #1
Det er jo en af de tjenester der er lidt svært at finde ud af hvad styrer. Du burde i joblisten kunne se hvilken af dem det er.
Du kan dog se om det har med system eller netværkstjeneste at gøre.
Avatar billede Posten50 Praktikant
19. september 2011 - 20:23 #2
Værtsproces for Windows Tjenester
Fuld sti: C:\Windows\system32\svchost.exe
____________________________
____________________________
Signatur:
Microsoft Corporation
Identificeret:
09-09-2011 i 21:07:31
Sidst brugt:
19-09-2011 i 20:21:50
Startelement:
Ja
Versionsnummer:
6.0.6001.18000
____________________________
____________________________
Mange brugere
Millioner af brugere i Norton Community har brugt denne fil.
____________________________
Moden
Denne fil blev frigivet for mere end 31 dage 3 år 1 måned siden.
____________________________
I orden
Norton har klassificeret filen som en, der er tillid til.
____________________________
Kilde

Kildefil:
svchost.exe
____________________________
Ydeevne
Gns. Ressourceforbrug:
Moderat
ProcessorprocesGennemsnitligt processorforbrug: Lav    Gennemsnitligt processorforbrug: Moderat

____________________________
Advarsel ang. ydeevne
Klokkeslæt:
19-09-2011 18:44:57

Proces-id 0
Processor Normal
Hukommelse Normal
Antal handles Normal
Disklæsningsaktivitet Normal
Diskskrivningsaktivitet 79 MB (i alt for denne proces).
____________________________
Filens fingeraftryk - SHA:
b26aafff9a4721a168fec6dbeff785121fdd3010be46bc89815e2c8c4c40b303
____________________________
Filens fingeraftryk - MD5:
cda9f1373805af88f6fa4f2064bba24d
____________________________
Avatar billede 220661 Ekspert
19. september 2011 - 20:31 #3
Må indrømme jeg desværre ikke får meget ud af din fine udskrift af processen.
Plejer du at lukke pc helt ned eller kører du den i dvale?
Avatar billede Posten50 Praktikant
19. september 2011 - 20:42 #4
Kører ofte i dvale!
Avatar billede 220661 Ekspert
19. september 2011 - 20:46 #5
Falder processen til ro hvis du genstarter pc?
Avatar billede 220661 Ekspert
19. september 2011 - 20:51 #6
Er det Vista du har i den?
Avatar billede Posten50 Praktikant
19. september 2011 - 20:58 #7
Processen falder kortvarigt til ro efter genstart og efter opstart fra dvale!
Ja jeg kører Vista.
Har faktisk win7 til at ligge, men har ikke taget mig sammen til at have det bøvl med opgradering.
Avatar billede 220661 Ekspert
19. september 2011 - 21:03 #8
Hmm Du kunne prøve at rydde op på pc.
Kender du CCleaner?
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
http://vistaguide.dk/?Artikler/CCleaner-GuideTilOptimeringAfVista/763
Lad programmet foretage en oprydning...
Og bagefter kunne du køre en tur med denne:
Hent Malwarebytes Anti-Malware herfra:
http://www.malwarebytes.org/

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen. Kopier loggen herind.
Mht.: Vista/Win7 - HøjreMusseTast - "Kør som Administrator..."

Og så ser vi hvordan det så går.
Avatar billede Flemming63 Juniormester
19. september 2011 - 21:24 #9
Proces-id 0
Mærkeligt sted.
Avatar billede Posten50 Praktikant
19. september 2011 - 21:31 #10
Hvad med mine programmer/indstillinger osv.
Hvad med office, kører alt videre når jeg har opgraderet??
Avatar billede pstidsen Novice
19. september 2011 - 21:57 #12
Avatar billede Posten50 Praktikant
20. september 2011 - 05:23 #13
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7750

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

20-09-2011 05:22:26
mbam-log-2011-09-20 (05-22-26).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|E:\|)
Objekter skannet: 608077
Tid gået: 6 time(e), 42 minut(ter), 44 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 9
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 4

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\J8RPLTROBQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\LEO0WTUNO7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
c:\SWSetup\temp\open_cd.exe (PUP.Joke.RJLSoftware) -> Not selected for removal.
c:\Users\Ole\AppData\LocalLow\mywebsearch\bar\setups\mwsautSp.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Users\Ole\AppData\Roaming\thinstall\picture collage maker pro\4000003e500002i\picturecollagemakerpro.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Ole\downloads\mywebface.exe (Adware.FunWeb) -> Quarantined and deleted successfully.
Avatar billede f-arn Guru
20. september 2011 - 05:46 #14
Hent og kør DDS

Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af begge  herind.

OBS - DDS skal gemmes på computeren og ikke køres fra nettet.
Avatar billede 220661 Ekspert
20. september 2011 - 15:46 #15
Udfør #14 som farn anbefaler.
Har rensning med CCleaner og Malwarebytes ændret på hvordan pc kører?
Avatar billede Posten50 Praktikant
20. september 2011 - 16:06 #16
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_26
Run by Ole at 16:02:36 on 2011-09-20
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.4093.1091 [GMT 2:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vfsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe
C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\SMINST\BLService.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Windows\system32\conime.exe
C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\System32\alg.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\sdclt.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\PROGRA~2\MICROS~1\Office12\OUTLOOK.EXE
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10v_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.dk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cnnb
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - C:\Program Files (x86)\Search Settings\kb128\SearchSettings.dll
mURLSearchHooks: TranslatorBar 5.2 Toolbar: {23256f20-0d9b-4323-b005-6e5de569c4b7} - C:\Program Files (x86)\TranslatorBar_5.2\tbTran.dll
mWinlogon: Userinit=C:\Windows\system32\ezShellStart.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TranslatorBar 5.2 Toolbar: {23256f20-0d9b-4323-b005-6e5de569c4b7} - C:\Program Files (x86)\TranslatorBar_5.2\tbTran.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
BHO: DigitalPersona Personal Extension: {395610ae-c624-4f58-b89e-23733ea00f9a} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - C:\Program Files (x86)\Search Settings\kb128\SearchSettings.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: TranslatorBar 5.2 Toolbar: {23256f20-0d9b-4323-b005-6e5de569c4b7} - C:\Program Files (x86)\TranslatorBar_5.2\tbTran.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
TB: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
mRun: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [<NO NAME>]
mRun: [IJNetworkScanUtility] "C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
mRun: [Iomega Home Storage Manager] C:\Program Files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe
mRun: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe"
mRun: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
mRun: [SearchSettings] "C:\Program Files (x86)\Search Settings\SearchSettings.exe"
mRun: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
StartupFolder: C:\Users\Ole\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SKRMKL~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki ... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
Trusted Zone: danskebank.dk\www-2
Trusted Zone: danid.dk
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
DPF: {DB7ACFA2-9634-4C98-BC9D-FB9416153022} - hxxp://89.184.152.179:117/nvEPLMedia.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.0.0.1 212.242.40.3 212.242.40.51
TCP: Interfaces\{BB3F20A5-2980-428B-BAD0-CED288037F31} : DhcpNameServer = 10.0.0.1 212.242.40.3 212.242.40.51
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
LSA: Notification Packages = scecli DPPWDFLT
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{23256f20-0d9b-4323-b005-6e5de569c4b7}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{395610AE-C624-4f58-B89E-23733EA00F9A}
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
{6D53EC84-6AAE-4787-AEEE-F4628F01010C}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9FDDE16B-836F-4806-AB1F-1455CBEFF289}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{AE7CD045-E861-484f-8273-0445EE161910}
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
{B4F3A835-0E21-4959-BA22-42B3008E02FF}
{D4027C7F-154A-4066-A1AD-4243D8127440}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
{23256f20-0d9b-4323-b005-6e5de569c4b7}
{30F9B915-B755-4826-820B-08FBA6BD249D}
{D4027C7F-154A-4066-A1AD-4243D8127440}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
EB-X64: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - No File
mRun-x64: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun-x64: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun-x64: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
mRun-x64: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
mRun-x64: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [(Standard)]
mRun-x64: [IJNetworkScanUtility] "C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
mRun-x64: [Iomega Home Storage Manager] C:\Program Files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe
mRun-x64: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe"
mRun-x64: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
mRun-x64: [SearchSettings] "C:\Program Files (x86)\Search Settings\SearchSettings.exe"
mRun-x64: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
SEH-X64: {E54729E8-BB3D-4270-9D49-7389EA579090}: EasyBits Security Shield Hook - prevents launching insecure programs by kids
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ole\AppData\Roaming\Mozilla\Firefox\Profiles\2zv48li9.default\
FF - component: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_1_3\components\coFFPlgn.dll
FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Ole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\Ole\AppData\Roaming\Mozilla\plugins\npicaN.dll
FF - plugin: C:\Windows\system32\C2MP\npdivx32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Nero Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_1_3
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110909.001\BHDrvx64.sys [2011-9-9 1152632]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110917.033\IDSviA64.sys [2011-9-20 488568]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [?]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/11 04:02:27];C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-11-29 146928]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-2-24 222512]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2008-1-21 21504]
R2 FontCache;Tjenesten Windows-skrifttypecache;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-19 366152]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-9-9 130008]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
R2 OMSI download service;Sony Ericsson OMSI download service;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2010-1-10 90112]
R2 Recovery Service for Windows;Recovery Service for Windows;C:\Program Files (x86)\SMINST\BLService.exe [2009-2-24 365952]
R2 Sentinel64;Sentinel64;C:\Windows\system32\Drivers\Sentinel64.sys --> C:\Windows\system32\Drivers\Sentinel64.sys [?]
R2 TVCapSvc;TV Background Capture Service (TVBCS);C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-2-9 296320]
R2 TVSched;TV Task Scheduler (TVTS);C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-2-9 116096]
R2 vfsFPService;Validity Fingerprint Service;C:\Windows\System32\vfsFPService.exe [2008-11-18 599344]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --> C:\Windows\system32\DRIVERS\enecir.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-7-28 136824]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 seehcri;Sony Ericsson seehcri Device Driver;C:\Windows\system32\DRIVERS\seehcri.sys --> C:\Windows\system32\DRIVERS\seehcri.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Tjenesten Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
S3 fssfltr;FssFltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys --> C:\Windows\system32\DRIVERS\ggflt.sys [?]
S3 gupdatem;Google Update Tjeneste (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 NETw3v64;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETw3v64.sys --> C:\Windows\system32\DRIVERS\NETw3v64.sys [?]
S3 OlyUsbCam;OLYMPUS USB Camera;C:\Windows\system32\DRIVERS\OlyUsbCam.sys --> C:\Windows\system32\DRIVERS\OlyUsbCam.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PerfHost;Vært for DLL-ydelsestæller;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 rcp_service;ReaConverter scheduler service;C:\Program Files (x86)\ReaConverter 5.5 Pro\rcp_scheduler.exe [2007-11-30 558592]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);C:\Windows\system32\DRIVERS\s0017bus.sys --> C:\Windows\system32\DRIVERS\s0017bus.sys [?]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s0017mdfl.sys --> C:\Windows\system32\DRIVERS\s0017mdfl.sys [?]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s0017mdm.sys --> C:\Windows\system32\DRIVERS\s0017mdm.sys [?]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s0017mgmt.sys --> C:\Windows\system32\DRIVERS\s0017mgmt.sys [?]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);C:\Windows\system32\DRIVERS\s0017nd5.sys --> C:\Windows\system32\DRIVERS\s0017nd5.sys [?]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s0017obex.sys --> C:\Windows\system32\DRIVERS\s0017obex.sys [?]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);C:\Windows\system32\DRIVERS\s0017unic.sys --> C:\Windows\system32\DRIVERS\s0017unic.sys [?]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-9-10 155344]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 WSDPrintDevice;Support til WSD-udskrivning via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x64.sys --> C:\Windows\system32\DRIVERS\yk60x64.sys [?]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-24 89920]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-09-19 19:17:28    --------    d-----w-    C:\Users\Ole\AppData\Roaming\Malwarebytes
2011-09-19 19:17:17    --------    d-----w-    C:\ProgramData\Malwarebytes
2011-09-19 19:17:13    25416    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2011-09-19 19:17:13    --------    d-----w-    C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-16 12:36:25    2409784    ----a-w-    C:\Program Files\Windows Mail\OESpamFilter.dat
2011-09-16 12:36:25    2409784    ----a-w-    C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2011-09-10 15:01:03    75264    ----a-w-    C:\Windows\System32\WUDFSvc.dll
2011-09-10 15:01:03    681472    ----a-w-    C:\Windows\System32\WUDFx.dll
2011-09-10 15:01:03    44544    ----a-w-    C:\Windows\System32\WUDFCoinstaller.dll
2011-09-10 15:01:03    226816    ----a-w-    C:\Windows\System32\WUDFHost.exe
2011-09-10 15:01:03    182784    ----a-w-    C:\Windows\System32\WUDFPlatform.dll
2011-09-10 15:01:03    172544    ----a-w-    C:\Windows\System32\drivers\WUDFRd.sys
2011-09-10 15:01:03    112128    ----a-w-    C:\Windows\System32\drivers\WUDFPf.sys
2011-09-10 14:54:32    --------    d-----w-    C:\Program Files (x86)\Common Files\PCSuite
2011-09-10 14:54:19    --------    d-----w-    C:\Program Files (x86)\Common Files\Nokia
2011-09-10 14:53:40    25600    ----a-w-    C:\Windows\System32\drivers\pccsmcfdx64.sys
2011-09-10 14:50:30    --------    d-----w-    C:\Program Files (x86)\PC Connectivity Solution
2011-09-10 14:46:02    57856    ----a-w-    C:\Windows\System32\nmwcdclsX64.dll
2011-09-10 14:46:00    --------    d-----w-    C:\Program Files (x86)\Nokia
2011-09-09 15:51:31    --------    d-----w-    C:\Users\Ole\AppData\Local\{CB8710DA-8EB0-4749-8F48-3DDB19B006D2}
2011-09-09 15:16:55    34152    ----a-w-    C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-09-09 15:13:15    912504    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\SymEFA64.sys
2011-09-09 15:13:15    744568    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\srtsp64.sys
2011-09-09 15:13:15    450680    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\SymDS64.sys
2011-09-09 15:13:15    432760    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\symtdiv.sys
2011-09-09 15:13:15    40568    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\srtspx64.sys
2011-09-09 15:13:15    382584    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\symnets.sys
2011-09-09 15:13:15    171128    ----a-r-    C:\Windows\System32\drivers\N360x64\0501000.01D\Ironx64.sys
2011-09-09 15:13:00    --------    d-----w-    C:\Windows\System32\drivers\N360x64\0501000.01D
2011-09-09 13:37:16    8862544    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BECE6C-EA15-487E-8844-5AD24E820810}\mpengine.dll
2011-09-05 17:04:56    183696    ----a-w-    C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-09-05 17:04:56    183696    ----a-w-    C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2011-08-24 19:53:18    290816    ----a-w-    C:\Windows\System32\CNMXLM9B.DLL
2011-08-24 19:33:01    --------    d-----w-    C:\ProgramData\CanonIJ
2011-08-24 13:08:22    2048    ----a-w-    C:\Windows\System32\tzres.dll
2011-08-24 13:08:21    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
.
==================== Find3M  ====================
.
2011-09-18 13:54:36    404640    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-09 15:15:03    174200    ----a-w-    C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2011-08-22 04:59:56    222208    ----a-w-    C:\Windows\System32\msls31.dll
2011-08-05 10:52:21    472808    ----a-w-    C:\Windows\SysWow64\deployJava1.dll
2011-07-06 15:49:23    275456    ----a-w-    C:\Windows\System32\drivers\mrxsmb10.sys
2011-07-05 16:37:00    94208    ----a-w-    C:\Windows\SysWow64\QuickTimeVR.qtx
2011-07-05 16:37:00    69632    ----a-w-    C:\Windows\SysWow64\QuickTime.qts
.
============= FINISH: 16:04:36,59 ===============
Avatar billede Posten50 Praktikant
20. september 2011 - 16:07 #17
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 11-07-2009 12:11:36
System Uptime: 20-09-2011 13:38:48 (3 hours ago)
.
Motherboard: Quanta |  | 3064
Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-75 | Socket M2/S1G1 | 1100/2000mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 151,697 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 365,986 GiB free.
E: is FIXED (NTFS) - 13 GiB total, 1,44 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1565: 08-09-2011 05:46:20 - Fjernelse af sprogpakke
RP1566: 08-09-2011 14:09:35 - Fjernelse af sprogpakke
RP1567: 09-09-2011 15:35:36 - Windows Update
RP1568: 10-09-2011 07:10:31 - Fjernelse af sprogpakke
RP1569: 10-09-2011 07:59:37 - Sony Ericsson PC Companion
RP1570: 10-09-2011 16:46:06 - Installation af enhedsdriverpakke: Nokia
RP1571: 10-09-2011 16:48:53 - Installation af enhedsdriverpakke: Nokia Netværkskort
RP1572: 10-09-2011 16:51:16 - Installation af enhedsdriverpakke: Nokia Bærbare enheder
RP1573: 10-09-2011 16:52:12 - Installation af enhedsdriverpakke: Nokia Modemer
RP1574: 10-09-2011 16:55:47 - Installation af enhedsdriverpakke: Nokia Modemer
RP1575: 10-09-2011 16:56:44 - Installation af enhedsdriverpakke: Nokia Modemer
RP1576: 11-09-2011 06:15:15 - Fjernelse af sprogpakke
RP1577: 12-09-2011 14:25:09 - Fjernelse af sprogpakke
RP1578: 13-09-2011 14:20:58 - Fjernelse af sprogpakke
RP1579: 17-09-2011 03:02:40 - Windows Update
RP1580: 17-09-2011 08:04:03 - Fjernelse af sprogpakke
RP1581: 17-09-2011 21:26:56 - Windows Update
RP1582: 18-09-2011 16:00:13 - Fjernelse af sprogpakke
RP1583: 19-09-2011 10:36:18 - Fjernelse af sprogpakke
RP1584: 19-09-2011 20:13:54 - Norton 360 Registreringsdataba
RP1585: 20-09-2011 13:56:35 - Fjernelse af sprogpakke
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Able Photo Slide Show 2.4.11.20
Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
adgangforalle.dk 2.1
Adobe Acrobat 8 Professional - English, Français, Deutsch
Adobe Acrobat 8.1.3 Professional
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Reader X (10.1.1) - Dansk
Adobe Shockwave Player 11.5
AlgoLab R2V Converter 2.97.2M
AMD USB Audio Driver Filter
Apple-programunderstøttelse
Apple Software Update
Ask Toolbar
Atheros Driver Installation Program
Avanquest update
Avid EDL Manager
Avid FilmScribe
Avid Log Exchange
Avid Media Composer
Avid MediaLog
AVS Update Manager 1.0
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
Canon IJ Network Scan Utility
Canon MP Navigator EX 2.0
Canon MP980 series Brugerregistrering
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Easy-PhotoPrint Pro
Canon Utilities My Printer
Canon Utilities Solution Menu
CanoScan Toolbox Ver4.6
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CD-LabelPrint
Citrix XenApp Web Plugin
Conduit Engine
CyberLink DVD Suite
D3DX10
Debut Video Capture Software
Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Digital Signatur
Double File Finder
DriverFinder
Duplicate File Detective 3
DVD Identifier
Elgiganten fotoservice
ESU for Microsoft Vista
Express Burn Disc Burning Software
ffdshow [rev 3029] [2009-07-10]
FirmTools Duplicate Photo Finder 1
Garmin USB Drivers
Garmin WebUpdater
Google Earth
Google SketchUp 8
Google SketchUp Viewer
Google Toolbar for Internet Explorer
Google Update Helper
Hotel Dash 2: Lost Luxuries
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Common Access Service Library
HP Customer Experience Enhancements
HP Games
HP Help and Support
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart TV
HP MediaSmart Webcam
HP Quick Launch Buttons 6.40 L1
HP Total Care Setup
HP Update
HP User Guides 0134
HP Wireless Assistant
HPAsset component for HP Active Support Library
Huawei modem
Haali Media Splitter
IDT Audio
ImageConverter Plus 8.0
ImageMixer 3 SE Ver.6 Transfer Utility
ImageMixer 3 SE Ver.6 Video Tools
Inkjet Printer/Scanner Extended Survey Program
Iomega Home Storage Manager
IZArc 4.1
Java Auto Updater
Java(TM) 6 Update 20
Java(TM) 6 Update 26
JMicron Flash Media Controller Driver
Junk Mail filter update
K-Lite Codec Pack 6.9.0 (Basic)
Kompatibilitetspakke til Office 2007-systemet
LabelPrint
LightScribe System Software
Magic Desktop
Malwarebytes' Anti-Malware version 1.51.2.1300
Media Player Codec Pack 3.8.0
Memeo AutoBackup
Memeo AutoSync
Menu Template Package 1 Ver 1.10
Mesh Runtime
Messenger Companion
MetaSync
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access 2003 Runtime
Microsoft Office Access MUI (Danish) 2010
Microsoft Office Excel MUI (Danish) 2007
Microsoft Office Excel MUI (Danish) 2010
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2010
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (Danish) 2007
Microsoft Office OneNote MUI (Danish) 2010
Microsoft Office Outlook 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (Danish) 2007
Microsoft Office Outlook MUI (Danish) 2010
Microsoft Office PowerPoint MUI (Danish) 2007
Microsoft Office PowerPoint MUI (Danish) 2010
Microsoft Office PowerPoint Viewer 2007 (Danish)
Microsoft Office Proof (Danish) 2007
Microsoft Office Proof (Danish) 2010
Microsoft Office Proof (English) 2007
Microsoft Office Proof (English) 2010
Microsoft Office Proof (German) 2007
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Swedish) 2010
Microsoft Office Proofing (Danish) 2007
Microsoft Office Proofing (Danish) 2010
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (Danish) 2010
Microsoft Office Shared MUI (Danish) 2007
Microsoft Office Shared MUI (Danish) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (Danish) 2007
Microsoft Office Word MUI (Danish) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Miraplacid Publisher SDK 6.5
MMD DupFinder
Mozilla Firefox (3.6.16)
MSVC90_x86
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MyHeritage Family Tree Builder
Nero BurnLite 10
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero Update
neroxml
Nokia Connectivity Cable Driver
Nokia PC Suite
Norton 360
OLYMPUS Studio 2
Opdatering til Microsoft Office Excel 2007 Help (KB963678)
Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669)
Opdatering til Microsoft Office Word 2007 Help (KB963665)
OpenOffice.org 3.2
oZone3D.Net FurMark v1.8.2
PC Connectivity Solution
PhotoStudio
Picasa 3
Pixeline - I Det Vilde Westen
Pixillion Image Converter
Pixum EasyBook
PowerDirector
PrimoPDF -- brought to you by Nitro PDF Software
Prism Video File Converter
QuickTime
ReaConverter 5.5 Pro
Realtek 8169 8168 8101E 8102E Ethernet Driver
Search Settings 1.2.2
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile DAN sprogpakke (KB2478663)
Security Update for Microsoft Excel 2010 (KB2553070)
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2584066)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Segoe UI
Sentinel Protection Installer 7.4.0
Serif DrawPlus SE
Shape Collage
Skins
Skype Toolbars
Skype™ 4.2
SnadBoy's Revelation v2
Sony Ericsson PC Companion 2.01.217
Sony Ericsson PC Suite 6.012.00
SopCast 3.0.3
TranslatorBar 5.2 Toolbar
Unity Web Player
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Outlook Social Connector (KB2583935)
Update for Outlook 2007 Junk Email Filter (KB2553110)
Update Installer for WildTangent Games App
Update Service
Vector Eye
VideoPad Video Editor
VLC media player 1.1.10
WD Diagnostics
Wedding Album Maker Gold 3.07
WildTangent Games App (HP Games)
Windows 7 Upgrade Advisor
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX-objekt til fjernforbindelser
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Wondershare Photo Collage Studio (4.2.0) Trial Version
Wondershare Photo Collage Studio (V4.2.8) Trial Version
.
==== End Of File ===========================
Avatar billede f-arn Guru
20. september 2011 - 19:37 #18
Det lader ikke til du har brugt CCleaner?

Afinstaller Ask Toolbar og Conduit Engine. De har et blakket ry.

------

Hent og gem ComboFix på dit skrivebord.

Kør så ComboFix.exe og følg anvisningerne.

Vigtigt--> Da ComboFix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Hvis du ikke deaktiverer Norton ordentligt, fryser den sandsynligvis PCen!

Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når ComboFix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: ComboFix.txt
Indholdet af denne fil må du gerne lægge herind.

Den kan findes her:  C:\ComboFix.txt
Avatar billede Posten50 Praktikant
20. september 2011 - 19:53 #19
Hvordan afinstallerer jeg Ask Toolbar, jeg kan ikke finde den??
Avatar billede pstidsen Novice
20. september 2011 - 19:59 #20
lidt afhængig af hvilken Windows udgave du har så: Kontrolpanel--->Programmer--->Tilføj eller fjern programmer

Du kan også søge på "Tilføj eller fjern programmer" i Start (win7 og vista
Avatar billede f-arn Guru
21. september 2011 - 07:52 #21
Hvordan afinstallerer jeg Ask Toolbar, jeg kan ikke finde den??

http://windows.microsoft.com/da-DK/windows-vista/Uninstall-or-change-a-program
Hvis du ikke kan finde den, springer du bare det punkt over.
Avatar billede Posten50 Praktikant
21. september 2011 - 16:29 #22
Jeg kan ikke kopiere oplysningerne herind, siden går ned når jeg trykker på opret.
Avatar billede Posten50 Praktikant
21. september 2011 - 16:38 #23
ComboFix 11-09-20.04 - Ole 20-09-2011  20:10:46.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.4093.1176 [GMT 2:00]
Kører fra: c:\users\Ole\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Search Settings
c:\program files (x86)\Search Settings\kb128\SearchSettings.dll
c:\program files (x86)\Search Settings\kb128\SearchSettingsRes409.dll
c:\program files (x86)\Search Settings\SearchSettings.exe
c:\programdata\00bfb05e.tmp
c:\programdata\016c53d1.tmp
c:\programdata\hpe7822.dll
c:\users\Ole\31052010PCrep
c:\users\Ole\31052010PCrep\$Desktop\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\09%20Karneval%20i%20Panama.jpg
c:\users\Ole\31052010PCrep\$Desktop\605625712_2_Big.jpg
c:\users\Ole\31052010PCrep\$Desktop\Briller\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\dansk_flag.jpg
c:\users\Ole\31052010PCrep\$Desktop\Flag.jpg
c:\users\Ole\31052010PCrep\$Desktop\Michelle til hest\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Ny mappe\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\P7059104.jpg
c:\users\Ole\31052010PCrep\$Desktop\P7059104r.jpg
c:\users\Ole\31052010PCrep\$Desktop\P7059104rr.jpg
c:\users\Ole\31052010PCrep\$Desktop\P7059104rrr.jpg
c:\users\Ole\31052010PCrep\$Desktop\P7059104tillykke.jpg
c:\users\Ole\31052010PCrep\$Desktop\P7059104tillykkehvid.jpg
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\5 (2)\Covers\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\5 (3)\Madagascar Escape 2 Africa[(Nintendo DS ).nds format\Ensata 1.3c\skins\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\5 (5)\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Alawar Games - Farm Frenzy 3 + Adnan_Boy 2008 + Fixed\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1956 - The Million Dollar Quartet - Johnny Cash, Elvis Presley, Jerry Lee Lewis, Carl Perkins\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1957 - With His Hot And Blue Guitar\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1958 - The Songs That Made Him Famous\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1959 - Hymns By Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1959 - Songs of Our Soil\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1959 - The Fabulous Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1960 - Now There Was A Song\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1960 - Ride This Train\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1961 - Now Here's Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1962 - All Aboard The Blue Train\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1962 - Hymns From The Heart\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1962 - The Sound of Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1963 - Blood Sweat & Tears\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1964 - Live at Newport\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1964 - Original Sun Sound\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1965 - Orange Blossom Special\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1965 - Sings The Ballads of The True West\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1966 - Everybody Loves A Nut\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1966 - Happiness is you\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1966 - Mean As Hell\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1968 - At Folsom Prison\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1968 - Carryin' On - Johnny Cash & June Carter\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1968 - Old Golden Throat\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1968 - The Heart of Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1969 - At Madison Squere Garden\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1969 - Nashville Sessions - Johnny Cash & Bob Dylan\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1969 - San Quentin\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1969 - This Is Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1970 - Hello I'm Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1970 - I Walk The Line\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1971 - Little Fauss And Big Halsy\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1972 - America\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1972 - Give My Love To Rose\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1974 - The Ragged Old Flag\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1975 - Destination Victoria Station\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1976 - One Piece At A Time\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1977 - The Rambler\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1978 - 20 Foot Tappin' Greats\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1978 - Gone Girl\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1980 - Rockabilly Blues\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1981 - Baron\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1988 - Classic Cash Hall of Fame Series\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1988 - The Best of Johnny Cash\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1989 - Boom Chicka Boom\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1989 - Live In Minneapolis\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1991 - Come Along And Ride This Train (4 Disc)\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Johnny Cash\1991 - The Mystery Of Life\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Ny mappe (4)\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Ny mappe (6)\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Olympus\.picasa.ini
c:\users\Ole\31052010PCrep\$Desktop\Traveldrive29032010\Wondershare Photo Collage Studio v4.2.8 [RES Patch][h33t][matt14]\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\2010_02_09\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\2010_02_09\IMG.jpg
c:\users\Ole\31052010PCrep\$My Documents\2010_02_09\IMG_0001.jpg
c:\users\Ole\31052010PCrep\$My Documents\593142306_Big.jpg
c:\users\Ole\31052010PCrep\$My Documents\A.jpg
c:\users\Ole\31052010PCrep\$My Documents\Adobe Acrobat 9 Pro Extended\Autoplay\Resdata\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\Bedstefar 75 mfl. 049rasmus.jpg
c:\users\Ole\31052010PCrep\$My Documents\Bedstefar 75 mfl. 095jesper.jpg
c:\users\Ole\31052010PCrep\$My Documents\Bedstefar 75 mfl. 099morten.jpg
c:\users\Ole\31052010PCrep\$My Documents\Bente\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\Bente\P5206046.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\.picasa.ini
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014014.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014015.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014016.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014017.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014018.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014019.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014020.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014021.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014022.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1014023.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024025.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024026.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024027.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024028.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024029.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024030.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024031.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024032.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024033.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024034.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024035.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024036.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024037.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024038.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024039.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024040.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024041.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1024042.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1034043.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044044.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044046.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044047.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044048.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044049.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1044050.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064051.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064052.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064053.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064055.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064056.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064057.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064058.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064059.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064060.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064061.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064062.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064063.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064064.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064065.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064066.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1064067.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094068.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094069.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094070.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094071.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094072.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094073.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094074.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094075.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094076.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094077.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094078.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094079.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094080.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094082.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094083.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094084.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094085.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094086.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094087.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094088.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094089.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094090.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094091.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094092.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094093.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094094.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094095.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094096.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094097.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094098.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094099.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094100.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094101.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094102.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094104.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094105.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094107.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094108.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094109.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094110.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094111.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094112.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094113.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094115.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P1094116.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231138.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231139.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231140.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231141.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231142.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231143.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231144.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231145.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231146.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231147.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231148.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231149.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231150.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231151.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231152.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231153.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231154.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231155.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231156.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231157.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231158.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231159.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231161.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231162.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231163.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231165.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231166.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231167.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231168.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231169.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231170.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231171.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231172.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231173.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231174.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231175.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231176.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231177.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231178.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231179.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231180.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231181.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231182.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231183.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231184.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231185.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231186.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231187.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231188.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231189.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231190.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231191.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231192.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231194.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231195.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231196.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231197.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231198.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231200.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231201.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231202.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231203.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231204.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231205.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231206.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231207.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231208.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231209.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231210.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231211.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231212.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231213.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231215.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231216.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231217.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231218.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231219.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231220.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231222.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231223.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231224.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231225.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231226.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231227.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231228.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231229.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231231.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231232.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231233.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231235.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231236.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231237.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231238.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231239.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231240.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231241.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231242.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231243.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231244.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231245.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231246.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231247.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231248.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231250.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231251.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231252.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231253.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231254.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231255.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231256.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231257.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231258.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231259.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231260.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231261.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231262.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231263.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231264.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231265.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231266.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231267.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231268.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231269.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231271.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231272.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231274.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231275.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231276.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231277.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231278.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231279.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231280.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231281.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231282.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231283.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231284.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231285.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231286.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231287.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231288.JPG
c:\users\Ole\31052010PCrep\$My Documents\Billed kopier\DCIM\101OLYMP\P5231289.JPG
Avatar billede Posten50 Praktikant
21. september 2011 - 16:39 #24
Kan åbenbart ikke klare hele teksten på en gang!
Hvordan deler jeg den bedst så det er til at finde ud af for jer??
Avatar billede Posten50 Praktikant
21. september 2011 - 16:51 #25
Har lige prøvet at kopiere det ind i et word dokument for at få et overblik over hvor meget det fylder. Der fylder det 529 sider!!
Avatar billede pstidsen Novice
21. september 2011 - 17:31 #26
gem teksten som .txt, .doc el.lign. og upload på f.eks. www.gupl.dk
Avatar billede Posten50 Praktikant
21. september 2011 - 17:35 #27
Avatar billede f-arn Guru
21. september 2011 - 19:40 #28
Det ser stadig ikke ud som om du har kørt CCleaner ?

Ved du hvad c:\users\Ole\31052010PCrep\ er for en Mappe. Jeg synes de filer virker legale.

Vil du godt kopiere ComboFix.txt fra linien Filer skabt fra 2011-08-21 til 2011-09-21 herind.
Det er nemmere at arbejde med  :-)
Avatar billede Posten50 Praktikant
21. september 2011 - 20:09 #29
(((((((((((((((((((((((((((((  Filer skabt fra 2011-08-21 til 2011-09-21  )))))))))))))))))))))))))))))))))))
.
.
2011-09-21 00:16 . 2011-09-21 00:16    --------    d-----w-    c:\users\Gæst\AppData\Local\temp
2011-09-21 00:16 . 2011-09-21 00:16    --------    d-----w-    c:\users\Default\AppData\Local\temp
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\users\Ole\AppData\Roaming\Malwarebytes
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\programdata\Malwarebytes
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2011-09-19 19:17 . 2011-08-31 15:00    25416    ----a-w-    c:\windows\system32\drivers\mbam.sys
2011-09-16 12:36 . 2011-08-10 12:14    2409784    ----a-w-    c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-09-16 12:36 . 2011-08-10 12:14    2409784    ----a-w-    c:\program files\Windows Mail\OESpamFilter.dat
2011-09-10 15:01 . 2009-07-14 18:24    681472    ----a-w-    c:\windows\system32\WUDFx.dll
2011-09-10 15:01 . 2009-07-14 18:24    75264    ----a-w-    c:\windows\system32\WUDFSvc.dll
2011-09-10 15:01 . 2009-07-14 18:24    44544    ----a-w-    c:\windows\system32\WUDFCoinstaller.dll
2011-09-10 15:01 . 2009-07-14 18:24    182784    ----a-w-    c:\windows\system32\WUDFPlatform.dll
2011-09-10 15:01 . 2009-07-14 18:18    112128    ----a-w-    c:\windows\system32\drivers\WUDFPf.sys
2011-09-10 15:01 . 2009-07-14 18:18    226816    ----a-w-    c:\windows\system32\WUDFHost.exe
2011-09-10 15:01 . 2009-07-14 18:18    172544    ----a-w-    c:\windows\system32\drivers\WUDFRd.sys
2011-09-10 14:58 . 2011-09-10 18:35    --------    d-----w-    c:\users\Ole\AppData\Roaming\Nokia
2011-09-10 14:58 . 2011-09-10 15:00    --------    d-----w-    c:\users\Ole\AppData\Roaming\PC Suite
2011-09-10 14:58 . 2011-09-10 14:59    --------    d-----w-    c:\programdata\PC Suite
2011-09-10 14:54 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Common Files\PCSuite
2011-09-10 14:54 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Common Files\Nokia
2011-09-10 14:53 . 2008-08-28 10:44    25600    ----a-w-    c:\windows\system32\drivers\pccsmcfdx64.sys
2011-09-10 14:50 . 2011-09-10 14:50    --------    d-----w-    c:\program files (x86)\PC Connectivity Solution
2011-09-10 14:46 . 2011-05-18 08:15    57856    ----a-w-    c:\windows\system32\nmwcdclsX64.dll
2011-09-10 14:46 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Nokia
2011-09-10 14:44 . 2011-09-10 14:44    --------    d-----w-    c:\programdata\Installations
2011-09-09 15:16 . 2010-08-21 03:59    34152    ----a-w-    c:\windows\system32\drivers\GEARAspiWDM.sys
2011-09-09 15:13 . 2011-09-09 15:26    --------    d-----w-    c:\windows\system32\drivers\N360x64\0501000.01D
2011-09-05 17:04 . 2011-09-05 17:04    183696    ----a-w-    c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-09-05 17:04 . 2011-09-05 17:04    183696    ----a-w-    c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2011-08-24 19:53 . 2009-12-17 03:00    290816    ----a-w-    c:\windows\system32\CNMXLM9B.DLL
2011-08-24 19:33 . 2011-08-24 19:33    --------    d-----w-    c:\programdata\CanonIJ
2011-08-24 13:08 . 2011-07-11 13:45    2048    ----a-w-    c:\windows\system32\tzres.dll
2011-08-24 13:08 . 2011-07-11 13:25    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-18 13:54 . 2011-06-05 03:56    404640    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-09 15:15 . 2009-10-24 14:05    174200    ----a-w-    c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-08-12 04:10 . 2011-09-09 13:37    8862544    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{58BECE6C-EA15-487E-8844-5AD24E820810}\mpengine.dll
2011-08-05 10:52 . 2010-05-12 15:59    472808    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2011-07-11 06:42 . 2011-07-11 06:42    0    ---ha-w-    c:\users\Ole\AppData\Local\BIT677B.tmp
2011-07-06 15:49 . 2011-08-10 12:26    275456    ----a-w-    c:\windows\system32\drivers\mrxsmb10.sys
2011-07-05 16:37 . 2011-07-05 16:37    94208    ----a-w-    c:\windows\SysWow64\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37    69632    ----a-w-    c:\windows\SysWow64\QuickTime.qts
.
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{23256f20-0d9b-4323-b005-6e5de569c4b7}]
2010-09-12 13:02    3863136    ----a-w-    c:\program files (x86)\TranslatorBar_5.2\tbTran.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 11:29    1490312    ----a-w-    c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{23256f20-0d9b-4323-b005-6e5de569c4b7}"= "c:\program files (x86)\TranslatorBar_5.2\tbTran.dll" [2010-09-12 3863136]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{23256f20-0d9b-4323-b005-6e5de569c4b7}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-30 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" [2010-01-18 124256]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"Iomega Home Storage Manager"="c:\program files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe" [2009-10-27 152936]
"Adobe Photo Downloader"="c:\program files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"TVAgent"="c:\program files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-29 1148200]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
c:\users\Ole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sk‘rmklipper og startprogram til OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 994856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
R3 ALSysIO;ALSysIO;c:\users\Ole\AppData\Local\Temp\ALSysIO64.sys [x]
R3 DIRECTIO;DIRECTIO;c:\burnintest\BurnInTest\DirectIo.sys [x]
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\users\Ole\AppData\Local\Temp\EverestDriver.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 gupdatem;Google Update Tjeneste (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 NETw3v64;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw3v64.sys [x]
R3 OlyUsbCam;OLYMPUS USB Camera;c:\windows\system32\DRIVERS\OlyUsbCam.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 rcp_service;ReaConverter scheduler service;c:\program files (x86)\ReaConverter 5.5 Pro\rcp_scheduler.exe [2007-11-30 558592]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R3 WSDPrintDevice;Support til WSD-udskrivning via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110909.001\BHDrvx64.sys [2011-09-09 1152632]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110917.033\IDSvia64.sys [2011-09-08 488568]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [x]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/11 04:02];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-11-29 01:04 146928]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 27648]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\SMINST\BLService.exe [2008-12-18 365952]
S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [x]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-02-09 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-02-09 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-11-18 721712]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-27 136824]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-10-16 11:49    451872    ----a-w-    c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-09-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 14:56]
.
2011-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 14:56]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-03 442368]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 2096424]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-19 914224]
"combofix"="c:\combofix\CF10403.3XE" [2008-01-21 363008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cnnb
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki ... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
Trusted Zone: danskebank.dk\www-2
Trusted Zone: danid.dk
TCP: DhcpNameServer = 10.0.0.1 212.242.40.3 212.242.40.51
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {DB7ACFA2-9634-4C98-BC9D-FB9416153022} - hxxp://89.184.152.179:117/nvEPLMedia.cab
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Ole\AppData\Roaming\Mozilla\Firefox\Profiles\2zv48li9.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Nero Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_1_3
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files (x86)\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - TOMME GENVEJE FJERNET - - - -
.
Wow6432Node-HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
Wow6432Node-HKLM-Run-SearchSettings - c:\program files (x86)\Search Settings\SearchSettings.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-SolutoService
WebBrowser-{23256F20-0D9B-4323-B005-6E5DE569C4B7} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-2343639470-1018389174-3513150389-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{34586732-3F29-12A5-19DC-DBB32838E508}*]
"dabdhiie"=hex:64,62,6f,61,62,6c,6c,68,6a,66,68,63,6d,62,69,6d,65,6a,64,70,67,
  69,61,69,67,6b,6d,6f,6e,61,6d,69,68,64,67,70,6c,6e,70,63,00,00
"iacbdkfbmjnindnmoi"=hex:6a,61,67,66,67,63,62,6e,6d,67,6c,62,68,62,62,69,64,67,
  6d,64,00,00
"hambbldkmdlbonbp"=hex:6a,61,67,66,67,63,62,6e,6d,67,6c,62,68,62,62,69,64,67,
  6d,64,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files (x86)\Digidesign\Drivers\MMERefresh.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files (x86)\PC Connectivity Solution\ServiceLayer.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
c:\program files (x86)\Internet Explorer\IELowutil.exe
.
**************************************************************************
.
Gennemført tid: 2011-09-21  02:42:21 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2011-09-21 00:41
.
Pre-Kørsel: 162.589.487.104 byte ledig
Post-Kørsel: 166.651.592.704 byte ledig
.
- - End Of File - - 5BD3507E985C524E719BC2618D7FBB09
Avatar billede Posten50 Praktikant
21. september 2011 - 20:09 #30
CCleaner er kørt, flere gange!!
Avatar billede Posten50 Praktikant
21. september 2011 - 20:12 #31
Jeg kan ikke finde den mappe du nævner.

c:\users\Ole\31052010PCrep\
Avatar billede f-arn Guru
21. september 2011 - 21:35 #32
CCleaner er kørt, flere gange!!

Den står ikke som installeret, og der er ikke spor af den i loggen fra ComboFix.

Jeg kan ikke finde den mappe du nævner.

c:\users\Ole\31052010PCrep\

ComboFix slettede den, men prøv at tjekke det program du bruger til dine fotos.
Avatar billede Posten50 Praktikant
22. september 2011 - 20:27 #33
"C:\Program Files (x86)\CCleaner\CCleaner64.exe"
Det er denne jeg anvender!
Hvad er næste step??
Avatar billede f-arn Guru
22. september 2011 - 21:44 #34
"C:\Program Files (x86)\CCleaner\CCleaner64.exe"
Det er denne jeg anvender!

Er den installeret under et andet brugernavn?

------

Vil du godt tjekke dine familie fotos, for det virker som om ComboFix slettede en masse af dem!!!

Hvlket program bruger du til det???
Avatar billede Posten50 Praktikant
23. september 2011 - 08:11 #35
Jeg bruger Picasa, håber fa... ikke der er slettet billeder - kigger når jeg kommer hjem.

CCleaner er "bare" installeret!
Avatar billede Posten50 Praktikant
23. september 2011 - 08:12 #36
Jeg troede i havde styr på hvilke programer der var sikre at bruge!!
Avatar billede f-arn Guru
23. september 2011 - 09:06 #37
ons. d. 21. september 2011 kl. 21:35:06

Jeg kan ikke finde den mappe du nævner.

c:\users\Ole\31052010PCrep\
ComboFix slettede den, men prøv at tjekke det program du bruger til dine fotos.

Hvorfor kikkede du ikke dengang?

Jeg troede i havde styr på hvilke programer der var sikre at bruge!!


Hvis man ved hvad man gør, er ComboFix rimelig sikker. Men hvorfor f..... tror du ikke jeg er fortsat med nye instruktioner?
Jeg vil gerne først finde ud af, hvorfor ComboFix slettede c:\users\Ole\31052010PCrep\

Foreløbig ligger de filer jeg tænker på, i en Combofix karantæne mappe.
Avatar billede Posten50 Praktikant
23. september 2011 - 09:27 #38
Mit kraftudtryk skal endelig ikke misforståes - der var mere i forhold til at jeg vil være ked af hvis billeder er væk!
Avatar billede Posten50 Praktikant
23. september 2011 - 09:36 #39
Tror forøvrigt jeg ved hvilken mappe dette drejer sig om c:\users\Ole\31052010PCrep\

Det var en midlertidig mappe jeg lavede inden jeg skulle have min have PCén sendt til reperation, denne mappe kopierede jeg så over på min eksterne harddisk, ting som jeg mente var værd at gemme.
Avatar billede Posten50 Praktikant
23. september 2011 - 14:32 #40
Pyha, ser ud til at billeder er urørte!
Avatar billede f-arn Guru
23. september 2011 - 19:16 #41
Pyha, ser ud til at billeder er urørte!

Fint!

Slet den ComboFix du har, og hent en ny.

------

Hent og gem ComboFix på dit skrivebord.

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
Filelook::
c:\users\Ole\AppData\Local\Temp\ALSysIO64.sys
c:\burnintest\BurnInTest\DirectIo.sys
Folder::
c:\program files (x86)\Ask.com\
Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
Regnull::
[HKEY_USERS\S-1-5-21-2343639470-1018389174-3513150389-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{34586732-3F29-12A5-19DC-DBB32838E508}*]


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede Posten50 Praktikant
24. september 2011 - 16:45 #42
Har problemer med at deativere Norton korrekt, kan i hjælpe.
Avatar billede Posten50 Praktikant
24. september 2011 - 16:47 #43
Deaktivere naturligvis ;-)
Avatar billede f-arn Guru
24. september 2011 - 17:08 #44
Har problemer med at deativere Norton korrekt, kan i hjælpe

Jeg forstår ikke rigtigt hvad du mener. Protesterer Norton, eller kan du ikke finde det?
Avatar billede pstidsen Novice
24. september 2011 - 22:20 #45
#42: Jeg har Norton Internet Security. Er det også det du har? Du skal bare trykke på "kontakterne" inde i interfacet. Det er der hvor der står on/til http://www.my-security-software.com/wp-content/uploads/2009/11/norton-internet-security-2010-screenshot.jpg
Avatar billede f-arn Guru
24. september 2011 - 23:39 #46
@ pstidsen
Det er vist Norton 360 vi "taler" om  :-)
Avatar billede Posten50 Praktikant
25. september 2011 - 06:01 #47
Ja, Norton 360, jeg vil jo gerne slå det "helt" fra, men det er jo opdelt vi "knapper"
Avatar billede f-arn Guru
25. september 2011 - 09:53 #48
Jeg kender ikke Norton 360, men når jeg "planter" malware på min PC, med Norton Internet Security, skal alt, bortset fra Firewallen, slåes fra.

Ellers virker ComboFix ikke ordentligt.
Avatar billede Posten50 Praktikant
25. september 2011 - 18:29 #49
Jeg har forsøgt at slå alt fra, men Combofix skriver at Norton realtidscanner stadig er aktiv, hvad gør jeg så??
Avatar billede f-arn Guru
25. september 2011 - 19:20 #50
Som sagt - jeg kender ikke Norton 360. Jeg ved ikke om denne kan hjælpe:
http://www.bleepingcomputer.com/forums/topic114351.html
Avatar billede Posten50 Praktikant
25. september 2011 - 19:42 #51
ComboFix 11-09-24.04 - Ole 25-09-2011  18:34:03.2.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.45.1030.18.4093.1152 [GMT 2:00]
Kører fra: c:\users\Ole\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Ole\Desktop\CFScript.txt
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_7b2.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
.
.
(((((((((((((((((((((((((((((  Filer skabt fra 2011-08-25 til 2011-09-25  )))))))))))))))))))))))))))))))))))
.
.
2011-09-25 17:04 . 2011-09-25 17:04    --------    d-----w-    c:\users\Gæst\AppData\Local\temp
2011-09-25 17:04 . 2011-09-25 17:04    --------    d-----w-    c:\users\Default\AppData\Local\temp
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\users\Ole\AppData\Roaming\Malwarebytes
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\programdata\Malwarebytes
2011-09-19 19:17 . 2011-09-19 19:17    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2011-09-19 19:17 . 2011-08-31 15:00    25416    ----a-w-    c:\windows\system32\drivers\mbam.sys
2011-09-16 12:36 . 2011-08-10 12:14    2409784    ----a-w-    c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-09-16 12:36 . 2011-08-10 12:14    2409784    ----a-w-    c:\program files\Windows Mail\OESpamFilter.dat
2011-09-10 15:01 . 2009-07-14 18:24    681472    ----a-w-    c:\windows\system32\WUDFx.dll
2011-09-10 15:01 . 2009-07-14 18:24    75264    ----a-w-    c:\windows\system32\WUDFSvc.dll
2011-09-10 15:01 . 2009-07-14 18:24    44544    ----a-w-    c:\windows\system32\WUDFCoinstaller.dll
2011-09-10 15:01 . 2009-07-14 18:24    182784    ----a-w-    c:\windows\system32\WUDFPlatform.dll
2011-09-10 15:01 . 2009-07-14 18:18    112128    ----a-w-    c:\windows\system32\drivers\WUDFPf.sys
2011-09-10 15:01 . 2009-07-14 18:18    226816    ----a-w-    c:\windows\system32\WUDFHost.exe
2011-09-10 15:01 . 2009-07-14 18:18    172544    ----a-w-    c:\windows\system32\drivers\WUDFRd.sys
2011-09-10 14:58 . 2011-09-10 18:35    --------    d-----w-    c:\users\Ole\AppData\Roaming\Nokia
2011-09-10 14:58 . 2011-09-10 15:00    --------    d-----w-    c:\users\Ole\AppData\Roaming\PC Suite
2011-09-10 14:58 . 2011-09-10 14:59    --------    d-----w-    c:\programdata\PC Suite
2011-09-10 14:54 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Common Files\PCSuite
2011-09-10 14:54 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Common Files\Nokia
2011-09-10 14:53 . 2008-08-28 10:44    25600    ----a-w-    c:\windows\system32\drivers\pccsmcfdx64.sys
2011-09-10 14:50 . 2011-09-10 14:50    --------    d-----w-    c:\program files (x86)\PC Connectivity Solution
2011-09-10 14:46 . 2011-05-18 08:15    57856    ----a-w-    c:\windows\system32\nmwcdclsX64.dll
2011-09-10 14:46 . 2011-09-10 14:54    --------    d-----w-    c:\program files (x86)\Nokia
2011-09-10 14:44 . 2011-09-10 14:44    --------    d-----w-    c:\programdata\Installations
2011-09-09 15:16 . 2010-08-21 03:59    34152    ----a-w-    c:\windows\system32\drivers\GEARAspiWDM.sys
2011-09-09 15:13 . 2011-09-09 15:26    --------    d-----w-    c:\windows\system32\drivers\N360x64\0501000.01D
2011-09-05 17:04 . 2011-09-05 17:04    183696    ----a-w-    c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2011-09-05 17:04 . 2011-09-05 17:04    183696    ----a-w-    c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-18 13:54 . 2011-06-05 03:56    404640    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-09 15:15 . 2009-10-24 14:05    174200    ----a-w-    c:\windows\system32\drivers\SYMEVENT64x86.SYS
2011-08-22 05:00 . 2011-08-22 05:00    161792    ----a-w-    c:\windows\SysWow64\msls31.dll
2011-08-22 05:00 . 2011-08-22 05:00    1126912    ----a-w-    c:\windows\SysWow64\wininet.dll
2011-08-22 05:00 . 2011-08-22 05:00    86528    ----a-w-    c:\windows\SysWow64\iesysprep.dll
2011-08-22 05:00 . 2011-08-22 05:00    76800    ----a-w-    c:\windows\SysWow64\SetIEInstalledDate.exe
2011-08-22 05:00 . 2011-08-22 05:00    74752    ----a-w-    c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-08-22 05:00 . 2011-08-22 05:00    48640    ----a-w-    c:\windows\SysWow64\mshtmler.dll
2011-08-22 05:00 . 2011-08-22 05:00    63488    ----a-w-    c:\windows\SysWow64\tdc.ocx
2011-08-22 05:00 . 2011-08-22 05:00    367104    ----a-w-    c:\windows\SysWow64\html.iec
2011-08-22 05:00 . 2011-08-22 05:00    74752    ----a-w-    c:\windows\SysWow64\iesetup.dll
2011-08-22 05:00 . 2011-08-22 05:00    23552    ----a-w-    c:\windows\SysWow64\licmgr10.dll
2011-08-22 05:00 . 2011-08-22 05:00    152064    ----a-w-    c:\windows\SysWow64\wextract.exe
2011-08-22 05:00 . 2011-08-22 05:00    150528    ----a-w-    c:\windows\SysWow64\iexpress.exe
2011-08-22 05:00 . 2011-08-22 05:00    1427456    ----a-w-    c:\windows\SysWow64\inetcpl.cpl
2011-08-22 05:00 . 2011-08-22 05:00    35840    ----a-w-    c:\windows\SysWow64\imgutil.dll
2011-08-22 05:00 . 2011-08-22 05:00    2382848    ----a-w-    c:\windows\SysWow64\mshtml.tlb
2011-08-22 05:00 . 2011-08-22 05:00    1797632    ----a-w-    c:\windows\SysWow64\jscript9.dll
2011-08-22 05:00 . 2011-08-22 05:00    11776    ----a-w-    c:\windows\SysWow64\mshta.exe
2011-08-22 05:00 . 2011-08-22 05:00    110592    ----a-w-    c:\windows\SysWow64\IEAdvpack.dll
2011-08-22 04:59 . 2011-08-22 04:59    222208    ----a-w-    c:\windows\system32\msls31.dll
2011-08-22 04:59 . 2011-08-22 04:59    1389056    ----a-w-    c:\windows\system32\wininet.dll
2011-08-22 04:59 . 2011-08-22 04:59    89088    ----a-w-    c:\windows\system32\RegisterIEPKEYs.exe
2011-08-22 04:59 . 2011-08-22 04:59    12288    ----a-w-    c:\windows\system32\mshta.exe
2011-08-22 04:59 . 2011-08-22 04:59    114176    ----a-w-    c:\windows\system32\admparse.dll
2011-08-22 04:59 . 2011-08-22 04:59    91648    ----a-w-    c:\windows\system32\SetIEInstalledDate.exe
2011-08-22 04:59 . 2011-08-22 04:59    49664    ----a-w-    c:\windows\system32\imgutil.dll
2011-08-22 04:59 . 2011-08-22 04:59    2303488    ----a-w-    c:\windows\system32\jscript9.dll
2011-08-22 04:59 . 2011-08-22 04:59    135168    ----a-w-    c:\windows\system32\IEAdvpack.dll
2011-08-22 04:59 . 2011-08-22 04:59    76800    ----a-w-    c:\windows\system32\tdc.ocx
2011-08-22 04:59 . 2011-08-22 04:59    48640    ----a-w-    c:\windows\system32\mshtmler.dll
2011-08-22 04:59 . 2011-08-22 04:59    111616    ----a-w-    c:\windows\system32\iesysprep.dll
2011-08-22 04:59 . 2011-08-22 04:59    448512    ----a-w-    c:\windows\system32\html.iec
2011-08-22 04:59 . 2011-08-22 04:59    85504    ----a-w-    c:\windows\system32\iesetup.dll
2011-08-22 04:59 . 2011-08-22 04:59    30720    ----a-w-    c:\windows\system32\licmgr10.dll
2011-08-22 04:59 . 2011-08-22 04:59    1492992    ----a-w-    c:\windows\system32\inetcpl.cpl
2011-08-22 04:59 . 2011-08-22 04:59    603648    ----a-w-    c:\windows\system32\vbscript.dll
2011-08-22 04:59 . 2011-08-22 04:59    165888    ----a-w-    c:\windows\system32\iexpress.exe
2011-08-22 04:59 . 2011-08-22 04:59    160256    ----a-w-    c:\windows\system32\wextract.exe
2011-08-22 04:59 . 2011-08-22 04:59    2382848    ----a-w-    c:\windows\system32\mshtml.tlb
2011-08-22 04:59 . 2011-08-22 04:59    173056    ----a-w-    c:\windows\system32\ieUnatt.exe
2011-08-12 04:10 . 2011-09-09 13:37    8862544    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{58BECE6C-EA15-487E-8844-5AD24E820810}\mpengine.dll
2011-08-05 10:52 . 2010-05-12 15:59    472808    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2011-07-11 13:45 . 2011-08-24 13:08    2048    ----a-w-    c:\windows\system32\tzres.dll
2011-07-11 13:25 . 2011-08-24 13:08    2048    ----a-w-    c:\windows\SysWow64\tzres.dll
2011-07-11 06:42 . 2011-07-11 06:42    0    ---ha-w-    c:\users\Ole\AppData\Local\BIT677B.tmp
2011-07-06 15:49 . 2011-08-10 12:26    275456    ----a-w-    c:\windows\system32\drivers\mrxsmb10.sys
2011-07-05 16:37 . 2011-07-05 16:37    94208    ----a-w-    c:\windows\SysWow64\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37    69632    ----a-w-    c:\windows\SysWow64\QuickTime.qts
.
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{23256f20-0d9b-4323-b005-6e5de569c4b7}]
2010-09-12 13:02    3863136    ----a-w-    c:\program files (x86)\TranslatorBar_5.2\tbTran.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{23256f20-0d9b-4323-b005-6e5de569c4b7}"= "c:\program files (x86)\TranslatorBar_5.2\tbTran.dll" [2010-09-12 3863136]
.
[HKEY_CLASSES_ROOT\clsid\{23256f20-0d9b-4323-b005-6e5de569c4b7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-30 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" [2010-01-18 124256]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"Iomega Home Storage Manager"="c:\program files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe" [2009-10-27 152936]
"Adobe Photo Downloader"="c:\program files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"TVAgent"="c:\program files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-29 1148200]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
c:\users\Ole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sk‘rmklipper og startprogram til OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 994856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
R3 ALSysIO;ALSysIO;c:\users\Ole\AppData\Local\Temp\ALSysIO64.sys [x]
R3 DIRECTIO;DIRECTIO;c:\burnintest\BurnInTest\DirectIo.sys [x]
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\users\Ole\AppData\Local\Temp\EverestDriver.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 gupdatem;Google Update Tjeneste (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 136176]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 NETw3v64;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw3v64.sys [x]
R3 OlyUsbCam;OLYMPUS USB Camera;c:\windows\system32\DRIVERS\OlyUsbCam.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 rcp_service;ReaConverter scheduler service;c:\program files (x86)\ReaConverter 5.5 Pro\rcp_scheduler.exe [2007-11-30 558592]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360x64\0308000.029\SYMNDISV.SYS [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R3 WSDPrintDevice;Support til WSD-udskrivning via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110909.001\BHDrvx64.sys [2011-09-09 1152632]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110923.030\IDSvia64.sys [2011-09-08 488568]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [x]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\N360x64\0501000.01D\SYMTDIV.SYS [x]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/11 04:02];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-11-29 01:04 146928]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 27648]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\SMINST\BLService.exe [2008-12-18 365952]
S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [x]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-02-09 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-02-09 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-11-18 721712]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-27 136824]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-10-16 11:49    451872    ----a-w-    c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 14:56]
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-30 14:56]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-03 442368]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 2096424]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-19 914224]
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cnnb
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki ... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: danskebank.dk\netbank
Trusted Zone: danskebank.dk\www
Trusted Zone: danskebank.dk\www-2
Trusted Zone: danid.dk
TCP: DhcpNameServer = 10.0.0.1 212.242.40.3 212.242.40.51
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {DB7ACFA2-9634-4C98-BC9D-FB9416153022} - hxxp://89.184.152.179:117/nvEPLMedia.cab
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Ole\AppData\Roaming\Mozilla\Firefox\Profiles\2zv48li9.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Nero Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_1_3
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files (x86)\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - TOMME GENVEJE FJERNET - - - -
.
WebBrowser-{23256F20-0D9B-4323-B005-6E5DE569C4B7} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files (x86)\Digidesign\Drivers\MMERefresh.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\PC Connectivity Solution\ServiceLayer.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
c:\windows\SysWOW64\DllHost.exe
c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
.
**************************************************************************
.
Gennemført tid: 2011-09-25  19:25:37 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2011-09-25 17:24
ComboFix2.txt  2011-09-21 00:42
.
Pre-Kørsel: 148.807.041.024 byte ledig
Post-Kørsel: 149.415.350.272 byte ledig
.
- - End Of File - - 935F4B070962CA34F70720835C6A87C0
Avatar billede f-arn Guru
26. september 2011 - 17:57 #52
Den lavede ikke helt det jeg ville ha' den til.

------

1. Hent dette lille værktøj:

http://jpshortstuff.247fixes.com/SystemLook_x64.exe

2. Dobbeltklik på SystemLook_x64.exe - nu dukker der et lille vindue op, hvor du skal kopiere HELE indholdet med fed skrift ind:

:reg
hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks /s
:filefind
ALSysIO64.sys
DirectIo.sys


3. Luk så alle andre vinduer og klik på knappen Look. Programmet vil nu lede på din computer.

4. Når programmet er færdig med at lede, vil der dukke et notepad-vindue op, med en log fra SystemLook. Den skal du kopiere herind i forum i dit næste svar. Log'en kan også findes på dit Skrivebord med navnet: SystemLook.txt.

Vista og Windows 7 - højreklik på filen - Kør som Administrator.
Avatar billede f-arn Guru
26. september 2011 - 18:54 #53
Du må forresten også gerne fortælle hvordan PCen kører :)
Avatar billede Posten50 Praktikant
25. november 2011 - 10:27 #54
Har lige fået opgraderet til WIN 7, jeg synes stadig der er lidt rigelig blæser/støj på!
Avatar billede f-arn Guru
25. november 2011 - 12:34 #55
Når der er gået så lang tid, du har ændret OS, duer alle de logs du har lavet før jo ikke.
Lav et nyt spørgsmål !
Avatar billede Posten50 Praktikant
25. november 2011 - 16:36 #56
Okay tak, læg et svar og jeg lukker og laver et nyt spørgsmål!
Avatar billede f-arn Guru
25. november 2011 - 18:25 #57
OK :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester



IT-JOB

Udviklings- og Forenklingsstyrelsen

Stærk IT-profil med souschef-potentiale

Businessmann A/S

DevOps Consultant

Cognizant Technology Solutions Denmark ApS

Test Manager