O4 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bruger\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:
64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:
64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9:
64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - Reg Error: Key error. File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programmer\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programmer\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3995930073-3555480574-2151513988-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16:
64bit: - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8B7ADDC6-52E6-47B8-AC4E-86D090AC1BF0}: DhcpNameServer = 208.67.222.222 208.67.220.220
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programmer\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013-02-03 20:00:26 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013-02-03 14:37:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013-02-03 14:37:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013-02-03 14:37:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013-02-03 12:33:27 | 000,000,000 | ---D | C] -- C:\Users\Bruger\Documents\ProcAlyzer Dumps
[2013-02-03 12:27:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013-02-03 12:25:33 | 005,029,686 | R--- | C] (Swearware) -- C:\Users\Bruger\Desktop\ComboFix.exe
[2013-02-03 12:00:15 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013-02-03 11:59:12 | 000,000,000 | ---D | C] -- C:\JRT
[2013-02-03 11:59:07 | 000,547,275 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Bruger\Desktop\JRT.exe
[2013-02-03 11:50:49 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{94E4EFB3-A776-4521-A41D-2A5861723B9C}
[2013-02-02 22:39:36 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{02155C00-241D-4FF8-B2E1-14100759040E}
[2013-02-02 12:14:12 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{E4657B68-3E84-4AF3-B787-EA1BDE309D1A}
[2013-02-01 13:48:24 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{C0DB8895-72E6-4886-A1E1-07CEC6E5267A}
[2013-01-31 13:42:35 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{C39DD8AB-5E30-41F3-9D04-DE1133ED8752}
[2013-01-30 12:49:19 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{90AE50FD-9303-485D-937E-50F229AC7A54}
[2013-01-29 21:20:13 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Roaming\Malwarebytes
[2013-01-29 21:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013-01-29 21:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013-01-29 21:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013-01-29 15:57:46 | 000,000,000 | ---D | C] -- C:\_OTL
[2013-01-29 15:44:07 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{FD25824F-E47D-4522-B2DD-3173B26B4885}
[2013-01-28 16:15:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bruger\Desktop\OTL.exe
[2013-01-28 15:16:44 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{2591BA1E-11E1-4963-AF84-D1AC5A065C1F}
[2013-01-27 13:47:19 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{80A4E37A-80C7-4E1A-808C-4BBF52CD4A63}
[2013-01-27 11:44:14 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013-01-27 11:44:14 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013-01-27 11:44:14 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013-01-26 19:07:05 | 000,000,000 | ---D | C] -- C:\Users\Bruger\Desktop\Tripcode_Explorer
[2013-01-26 13:46:12 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{06ACEED0-7B74-4A95-958F-9FBCB1F4E237}
[2013-01-25 13:45:19 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{AA35EEC0-44DB-47B2-BF64-08FA2011CBE6}
[2013-01-24 15:45:22 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{7C4DF284-AEF0-4E4D-88D5-561E60381DC8}
[2013-01-23 19:16:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
[2013-01-23 13:48:50 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{45505061-2BE5-40B7-8A58-462E53843719}
[2013-01-22 20:27:01 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2013-01-22 20:26:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2013-01-22 20:26:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2013-01-22 15:55:21 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{0C0A1DB9-B608-4D53-A710-2777A970D2FF}
[2013-01-21 19:40:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2013-01-21 19:40:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013-01-21 19:40:16 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2013-01-21 19:40:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013-01-21 19:39:48 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\Programs
[2013-01-21 16:48:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013-01-21 16:47:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013-01-21 16:47:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2013-01-21 16:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013-01-20 13:48:43 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{FAB92882-37BC-4912-A450-E36FAEA73A2F}
[2013-01-19 13:47:37 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{9BBCFB09-E8F7-44CC-ADF3-A98D7E45C7C5}
[2013-01-19 01:46:57 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{7E574572-E413-458C-A8B9-0226847DAC40}
[2013-01-18 23:03:19 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\NTServer
[2013-01-18 13:46:25 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{F4DDDC70-C22D-4BFC-AE2C-EF4E6E297811}
[2013-01-17 11:49:37 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{667BE21D-13E4-4AF4-87A6-07B5A7B8E929}
[2013-01-16 15:48:58 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{1E8AF24E-87A1-4258-92D1-70B1D3BA48BF}
[2013-01-15 15:48:34 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{DB4E1AE5-94DE-4C99-8BFB-34ABEE2BE75B}
[2013-01-14 13:49:28 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{077AC819-7F9D-4268-A83E-489C10E7CD18}
[2013-01-13 13:21:41 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{42950187-9F23-44D9-9F6F-9D406D865F5C}
[2013-01-12 13:20:52 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{BD0EA2A4-A61F-4F32-905A-3A4B2EF2869E}
[2013-01-11 11:44:17 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{3C5581A0-6740-475A-83C5-48A6CFE224AB}
[2013-01-10 15:26:36 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{5CBBC934-179C-4066-8F26-090E0F9576B9}
[2013-01-09 22:36:49 | 000,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2013-01-09 22:36:48 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2013-01-09 22:36:11 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013-01-09 22:36:09 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll
[2013-01-09 22:35:56 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs
[2013-01-09 22:35:56 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs
[2013-01-09 22:35:56 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs
[2013-01-09 22:35:56 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs
[2013-01-09 22:35:56 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs
[2013-01-09 22:35:56 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs
[2013-01-09 22:35:56 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs
[2013-01-09 22:35:56 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs
[2013-01-09 22:35:56 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs
[2013-01-09 22:35:56 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs
[2013-01-09 22:35:55 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs
[2013-01-09 22:35:55 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs
[2013-01-09 22:35:55 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs
[2013-01-09 22:35:54 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs
[2013-01-09 22:35:54 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs
[2013-01-09 22:35:54 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs
[2013-01-09 22:35:54 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs
[2013-01-09 22:35:53 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs
[2013-01-09 22:35:53 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs
[2013-01-09 22:35:53 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs
[2013-01-09 22:35:52 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll
[2013-01-09 22:35:52 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll
[2013-01-09 22:35:52 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll
[2013-01-09 22:35:51 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll
[2013-01-09 22:35:36 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs
[2013-01-09 22:35:36 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs
[2013-01-09 22:35:35 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs
[2013-01-09 22:35:33 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs
[2013-01-09 22:35:33 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs
[2013-01-09 22:35:32 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs
[2013-01-09 22:35:27 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs
[2013-01-09 22:35:27 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs
[2013-01-09 22:34:09 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2013-01-09 22:34:07 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2013-01-09 22:34:03 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2013-01-09 22:34:03 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013-01-09 22:34:02 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2013-01-09 22:34:02 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2013-01-09 22:34:02 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2013-01-09 22:34:02 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013-01-09 22:34:02 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2013-01-09 22:34:02 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013-01-09 22:34:00 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013-01-09 22:33:53 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013-01-09 22:33:53 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013-01-09 22:33:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013-01-09 22:33:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013-01-09 22:33:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013-01-09 22:33:52 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013-01-09 22:33:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013-01-09 22:33:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013-01-09 22:33:50 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013-01-09 22:33:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013-01-09 22:33:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013-01-09 22:33:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013-01-09 22:33:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013-01-09 22:33:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013-01-09 22:33:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013-01-09 22:33:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013-01-09 22:33:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013-01-09 22:33:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013-01-09 22:33:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013-01-09 22:33:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013-01-09 22:33:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013-01-09 22:33:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013-01-09 22:33:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013-01-09 22:33:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013-01-09 22:33:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013-01-09 22:33:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013-01-09 22:33:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013-01-09 22:33:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013-01-09 22:33:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013-01-09 22:33:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013-01-09 22:33:47 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013-01-09 22:33:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013-01-09 22:33:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013-01-09 22:33:45 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013-01-09 22:33:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013-01-09 22:33:44 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013-01-09 22:33:44 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013-01-09 22:33:44 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013-01-09 22:33:44 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013-01-09 22:33:43 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013-01-09 22:33:40 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013-01-09 22:33:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013-01-09 22:33:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013-01-09 22:33:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013-01-09 22:33:39 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013-01-09 22:33:33 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013-01-09 22:32:24 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe
[2013-01-09 15:44:22 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{C53FB7B9-BDFE-402D-AF6B-AD6EA5A040AA}
[2013-01-08 15:46:58 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{D609CD34-3B93-496D-952B-43A393614954}
[2013-01-07 13:43:20 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{BAB20A47-6E48-46DA-A644-0904F6F21FEE}
[2013-01-06 14:08:43 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{EF1C9AFA-7510-47DB-AA90-15062C205288}
[2013-01-06 01:26:03 | 000,000,000 | ---D | C] -- C:\Users\Bruger\Documents\Essentials
[2013-01-06 01:19:41 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{D93E9ABD-EFD9-4612-A009-F5BE9BD746C8}
[2013-01-05 13:19:14 | 000,000,000 | ---D | C] -- C:\Users\Bruger\AppData\Local\{1F1978E7-3F16-475D-9AF4-D61890DD6D03}
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013-02-03 20:10:00 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3995930073-3555480574-2151513988-1000UA.job
[2013-02-03 19:58:28 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013-02-03 19:47:48 | 005,029,686 | R--- | M] (Swearware) -- C:\Users\Bruger\Desktop\ComboFix.exe
[2013-02-03 19:36:04 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-02-03 19:32:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-02-03 12:00:00 | 000,015,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-02-03 12:00:00 | 000,015,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-02-03 11:59:00 | 000,547,275 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Bruger\Desktop\JRT.exe
[2013-02-03 11:50:03 | 000,002,413 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2013-02-03 11:49:22 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-02-03 11:48:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-02-03 11:48:18 | 3214,188,544 | -HS- | M] () -- C:\hiberfil.sys
[2013-02-02 22:36:12 | 000,001,958 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013-02-02 22:36:10 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013-01-29 15:46:01 | 000,001,051 | ---- | M] () -- C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013-01-28 16:15:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruger\Desktop\OTL.exe
[2013-01-28 15:15:30 | 000,013,806 | ---- | M] () -- C:\Windows\SysNative\Pen_Tablet.dat
[2013-01-27 03:28:26 | 000,000,173 | ---- | M] () -- C:\Users\Bruger\AppData\Local\msmathematics.qat.Bruger
[2013-01-27 01:56:40 | 000,000,132 | ---- | M] () -- C:\Users\Bruger\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2013-01-25 06:23:38 | 000,042,880 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll
[2013-01-25 06:23:36 | 000,028,544 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll
[2013-01-23 19:16:02 | 000,000,985 | ---- | M] () -- C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013-01-22 21:43:35 | 000,000,512 | ---- | M] () -- C:\Users\Bruger\Desktop\MBR.dat
[2013-01-22 20:26:37 | 000,001,108 | ---- | M] () -- C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2013-01-22 20:26:33 | 000,000,909 | ---- | M] () -- C:\Users\Bruger\Desktop\ERUNT.lnk
[2013-01-19 15:17:06 | 000,001,456 | ---- | M] () -- C:\Users\Bruger\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013-01-18 23:04:08 | 000,000,427 | ---- | M] () -- C:\Windows\SysWow64\ntserverbind.ini
[2013-01-18 23:03:29 | 000,002,216 | ---- | M] () -- C:\Users\Bruger\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013-01-18 23:03:29 | 000,001,533 | ---- | M] () -- C:\Users\Bruger\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013-01-18 23:03:21 | 000,002,207 | ---- | M] () -- C:\Users\Bruger\Application Data\Microsoft\Internet Explorer\Quick Launch\portalsepeti.lnk
[2013-01-12 03:30:18 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013-01-12 03:26:16 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013-01-12 03:24:49 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013-01-11 14:56:40 | 000,234,496 | ---- | M] () -- C:\Users\Bruger\Documents\gamepad.exe
[2013-01-10 15:21:31 | 004,934,616 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-01-09 23:06:20 | 001,380,626 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013-01-09 23:06:20 | 000,661,514 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-01-09 23:06:20 | 000,516,486 | ---- | M] () -- C:\Windows\SysNative\perfh006.dat
[2013-01-09 23:06:20 | 000,125,600 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-01-09 23:06:20 | 000,102,986 | ---- | M] () -- C:\Windows\SysNative\perfc006.dat
[2013-01-09 23:06:10 | 001,380,626 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-01-09 17:32:26 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013-01-09 17:32:25 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013-02-03 14:37:44 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013-02-03 14:37:44 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013-02-03 14:37:44 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013-02-03 14:37:44 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013-02-03 14:37:44 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013-02-02 22:36:12 | 000,001,958 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013-01-25 06:23:38 | 000,042,880 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2013-01-25 06:23:36 | 000,028,544 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll
[2013-01-23 19:16:02 | 000,000,985 | ---- | C] () -- C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2013-01-22 21:43:35 | 000,000,512 | ---- | C] () -- C:\Users\Bruger\Desktop\MBR.dat
[2013-01-22 20:26:37 | 000,001,108 | ---- | C] () -- C:\Users\Bruger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2013-01-22 20:26:33 | 000,000,909 | ---- | C] () -- C:\Users\Bruger\Desktop\ERUNT.lnk
[2013-01-21 19:40:24 | 000,002,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013-01-18 23:03:21 | 000,002,207 | ---- | C] () -- C:\Users\Bruger\Application Data\Microsoft\Internet Explorer\Quick Launch\portalsepeti.lnk
[2013-01-18 23:03:19 | 000,000,427 | ---- | C] () -- C:\Windows\SysWow64\ntserverbind.ini
[2013-01-11 14:56:39 | 000,234,496 | ---- | C] () -- C:\Users\Bruger\Documents\gamepad.exe
[2012-12-23 00:38:13 | 000,001,456 | ---- | C] () -- C:\Users\Bruger\AppData\Local\Adobe Save for Web 13.0 Prefs
[2012-12-23 00:28:51 | 000,000,132 | ---- | C] () -- C:\Users\Bruger\AppData\Roaming\Adobe GIF Format CS6 Prefs
[2012-11-08 18:12:40 | 000,000,132 | ---- | C] () -- C:\Users\Bruger\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012-09-09 18:51:29 | 000,266,021 | ---- | C] () -- C:\Windows\QLPrism Uninstaller.exe
[2012-08-29 15:33:55 | 000,000,173 | ---- | C] () -- C:\Users\Bruger\AppData\Local\msmathematics.qat.Bruger
[2012-07-02 23:49:02 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2012-05-02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012-02-15 03:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-02-15 03:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011-12-14 04:55:24 | 000,081,920 | ---- | C] () -- C:\Windows\qlprism-uninstall.exe
[2011-12-04 18:37:08 | 000,109,056 | ---- | C] () -- C:\Windows\SysWow64\un-gamma.exe
[2011-10-25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011-09-28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011-08-06 23:40:13 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2011-08-06 23:40:13 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2011-07-29 19:51:30 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011-06-27 00:19:51 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011-02-12 03:24:58 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
========== ZeroAccess Check ==========
[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012-12-26 12:10:34 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\.minecraft
[2012-09-20 21:18:58 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\.spotflux
[2010-10-17 12:36:33 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Ableton
[2010-06-26 20:31:20 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Anabel
[2011-08-10 16:18:57 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\AtomZombieData
[2012-05-25 12:46:01 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Audacity
[2012-11-07 18:54:00 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Awesomium
[2012-01-20 14:33:39 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\BigHugeEngine
[2010-05-02 21:24:21 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Bioshock2
[2010-05-31 17:11:22 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\bizarre creations
[2010-05-08 15:26:31 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Blender Foundation
[2012-09-08 15:59:59 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Braid
[2011-07-29 19:51:33 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Broken Rules
[2011-07-27 16:01:42 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Crayon Physics Deluxe
[2010-05-31 12:54:45 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\DAEMON Tools Lite
[2012-06-27 16:16:45 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\digipen
[2013-02-03 19:58:32 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\DMCache
[2011-02-05 22:55:28 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Downloaded Installations
[2013-02-03 11:50:20 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Dropbox
[2010-06-28 14:39:35 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Facebook
[2012-06-02 11:57:22 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\fltk.org
[2010-11-19 16:22:46 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\GameRanger
[2011-07-10 10:15:46 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\go
[2011-01-28 21:08:37 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Gyazo
[2010-10-18 14:09:05 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Hardcore
[2013-02-02 22:28:42 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\IDM
[2011-07-29 19:56:54 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Lazy 8 Studios
[2010-03-20 20:49:46 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Leadertech
[2011-03-11 23:18:27 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\LolClient
[2012-06-08 17:27:20 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\LoneSurvivor
[2011-05-14 16:20:50 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Mount&Blade Warband
[2012-09-23 21:02:35 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Mumble
[2012-07-27 17:13:33 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Need for Speed World
[2011-12-20 17:49:33 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Nicalis
[2010-12-25 18:43:51 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\NPLUTO Corporation
[2011-10-07 16:45:57 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\OpenOffice.org
[2011-07-27 15:17:37 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Origin
[2012-01-15 02:17:46 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\RenPy
[2012-07-03 16:17:47 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\RotMG.Production
[2012-07-01 15:25:13 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Screaming Bee
[2012-11-08 14:39:28 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012-12-03 16:08:01 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\StepMania 5
[2011-01-26 22:16:44 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Subversion
[2012-08-16 18:36:08 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Thinstall
[2011-08-20 14:02:18 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\TinyAndBig
[2011-07-10 21:12:25 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\TS3Client
[2011-07-10 16:18:30 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\ts3overlay
[2013-02-02 22:29:44 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\uTorrent
[2012-03-17 23:56:16 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\wargaming.net
[2011-09-16 19:19:54 | 000,000,000 | ---D | M] -- C:\Users\Bruger\AppData\Roaming\Windows Live Writer
[2012-09-25 18:17:07 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Thinstall
[2012-09-25 18:17:07 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Thinstall
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP

1B5B4F1
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C9FD258B
< End of report >