Well I have 3 small problems:
Chkdsk want to scan the harddrive after restart, but it only scans 17% and stops...
The program starts everytime I start the computer..
The boot.ini file has some strange entries:
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
The harddrive blinks all the time (about a blink each seconds..)
Except these small things, the computer is now working fine and fast. I have installed Windows security essentials, and Im thinking about installing Online Armor as firewall, both applications are lightweight and work fine together...
And here is the OTL log:
OTL logfile created on: 13-04-2011 20:17:06 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Matthias\Skrivebord
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 66,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 232,88 Gb Total Space | 99,87 Gb Free Space | 42,89% Space Free | Partition Type: NTFS
Computer Name: MATTHIAS-QYE257 | User Name: Matthias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-04-10 01:24:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\OTL.exe
PRC - [2011-03-17 00:24:21 | 002,423,752 | ---- | M] (SUPERAntiSpyware.com) -- C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2010-11-30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Microsoft Security Client\msseces.exe
PRC - [2010-11-11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Programmer\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010-08-13 13:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010-06-10 15:54:26 | 000,493,336 | ---- | M] () -- C:\Programmer\Activ Software\ActivDriver\ActivMgr.exe
PRC - [2010-06-10 15:54:22 | 001,092,896 | ---- | M] (Promethean Technologies Group Ltd) -- C:\Programmer\Activ Software\ActivDriver\ActivControl2.exe
PRC - [2008-10-26 21:25:52 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008-04-14 18:05:49 | 001,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011-04-13 17:07:32 | 000,063,488 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Activ Software\ActivApplications\ActivFocusHook.dll
MOD - [2011-04-10 01:24:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\OTL.exe
MOD - [2010-08-23 18:12:31 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2010-11-11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programmer\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010-08-13 13:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008-11-04 02:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008-10-26 21:25:52 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2006-10-26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Fælles filer\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - [2011-04-13 17:08:12 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B74C8870-2944-4700-BA42-2B4F70FB3648}\MpKsl24e739b6.sys -- (MpKsl24e739b6)
DRV - [2010-05-26 16:21:00 | 000,006,144 | ---- | M] (Promethean Technologies Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\activmouse.sys -- (prmvmouse)
DRV - [2010-05-26 16:20:44 | 000,074,752 | ---- | M] (Promethean Technologies Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\activhidsermini.sys -- (ActivHidSerMini)
DRV - [2010-05-10 20:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programmer\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010-02-17 20:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programmer\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009-08-05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2008-04-13 20:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2006-08-23 03:53:14 | 001,723,904 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006-08-02 03:53:00 | 000,168,832 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\atinavt2.sys -- (ATIAVAIW)
DRV - [2006-04-06 08:20:44 | 004,258,816 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006-03-22 07:24:02 | 000,018,944 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006-03-22 07:24:00 | 000,052,736 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006-03-16 12:51:32 | 000,099,840 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005-03-09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/
IE - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = da
IE - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 87 F5 EF ED 99 CA 01 [binary data]
IE - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.dk/"
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - HKLM\software\mozilla\Firefox\extensions\\{EBDC7EC1-549E-48ee-96F7-C2252F5BBBED}: C:\Programmer\Comodo\HopSurfToolbar\hopsurfext_ff3
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Programmer\Mozilla Firefox\components [2010-12-12 14:52:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Programmer\Mozilla Firefox\plugins [2010-12-12 14:52:09 | 000,000,000 | ---D | M]
[2008-10-31 19:16:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthias\Application Data\Mozilla\Extensions
[2011-02-27 18:03:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Matthias\Application Data\Mozilla\Firefox\Profiles\po835jhi.default\extensions
[2010-07-25 11:41:51 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Matthias\Application Data\Mozilla\Firefox\Profiles\po835jhi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009-05-07 21:52:16 | 000,001,632 | ---- | M] () -- C:\Documents and Settings\Matthias\Application Data\Mozilla\Firefox\Profiles\po835jhi.default\searchplugins\live-search.xml
[2010-07-25 10:55:20 | 000,000,000 | ---D | M] (No name found) -- C:\Programmer\Mozilla Firefox\extensions
[2009-03-17 17:08:21 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAMMER\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010-10-26 10:32:55 | 000,001,525 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\amazon-co-uk.xml
[2010-10-26 10:32:55 | 000,001,178 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\wikipedia-da.xml
[2010-10-26 10:32:55 | 000,001,102 | ---- | M] () -- C:\Programmer\Mozilla Firefox\searchplugins\yahoo-dk.xml
O1 HOSTS File: ([2011-04-13 01:51:48 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Hjælp til tilmelding til Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Softonic English Toolbar) - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:\Programmer\Softonic_English\tbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic English Toolbar) - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:\Programmer\Softonic_English\tbSof0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\..\Toolbar\WebBrowser: (Softonic English Toolbar) - {930F1200-F5F1-4870-BAC6-E233EC8E7023} - C:\Programmer\Softonic_English\tbSof0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ActivControl] C:\Programmer\Activ Software\ActivDriver\ActivControl2.exe (Promethean Technologies Group Ltd)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Programmer\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Programmer\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1606980848-1645522239-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/DA-DK/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmer\Fælles filer\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Matthias\Dokumenter\Billeder\The big bang.png
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Matthias\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmer\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-15 20:15:35 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ==========
[2011-04-13 00:09:11 | 000,000,000 | ---D | C] -- C:\Programmer\Microsoft Security Client
[2011-04-12 23:44:26 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011-04-12 04:03:26 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011-04-12 03:59:06 | 001,090,912 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Matthias\Skrivebord\avg_remover_stf_x86_2011_1184.exe
[2011-04-12 03:07:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011-04-12 03:07:24 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011-04-12 03:07:24 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011-04-12 03:07:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011-04-11 19:31:00 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011-04-11 19:31:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menuen Start\Programmer\Malwarebytes' Anti-Malware
[2011-04-11 19:30:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011-04-11 19:30:57 | 000,000,000 | ---D | C] -- C:\Programmer\Malwarebytes' Anti-Malware
[2011-04-11 19:15:54 | 001,153,912 | ---- | C] (Emsi Software GmbH) -- C:\Documents and Settings\Matthias\Skrivebord\BlitzBlank.exe
[2011-04-11 03:36:02 | 000,000,000 | ---D | C] -- C:\found.000
[2011-04-10 08:38:31 | 000,000,000 | ---D | C] -- C:\_OTL
[2011-04-10 04:33:08 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\OTL.exe
[2011-04-08 04:07:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Matthias\Application Data\SUPERAntiSpyware.com
[2011-04-08 04:07:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011-04-08 04:07:39 | 000,000,000 | ---D | C] -- C:\Programmer\SUPERAntiSpyware
[2011-04-08 01:45:58 | 006,238,248 | ---- | C] (OPSWAT, Inc.) -- C:\Documents and Settings\Matthias\Skrivebord\AppRemover.exe
[2011-04-07 18:26:12 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\TFC.exe
[2011-04-06 14:02:56 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-04-05 20:12:26 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
========== Files - Modified Within 30 Days ==========
[2011-04-13 17:13:13 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011-04-13 17:06:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-04-13 01:51:48 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011-04-13 00:11:41 | 000,001,912 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011-04-13 00:09:01 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-04-12 23:44:30 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011-04-12 23:41:10 | 004,319,795 | R--- | M] () -- C:\Documents and Settings\Matthias\Skrivebord\ComboFix.exe
[2011-04-12 23:31:10 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011-04-11 19:31:00 | 000,000,763 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\Malwarebytes' Anti-Malware.lnk
[2011-04-11 19:27:35 | 000,449,232 | ---- | M] () -- C:\WINDOWS\System32\perfh006.dat
[2011-04-11 19:27:35 | 000,433,872 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-04-11 19:27:35 | 000,079,148 | ---- | M] () -- C:\WINDOWS\System32\perfc006.dat
[2011-04-11 19:27:35 | 000,068,444 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-04-11 15:56:42 | 000,000,631 | ---- | M] () -- C:\Documents and Settings\Matthias\Skrivebord\Genvej til notepad.lnk
[2011-04-11 15:10:26 | 001,153,912 | ---- | M] (Emsi Software GmbH) -- C:\Documents and Settings\Matthias\Skrivebord\BlitzBlank.exe
[2011-04-10 01:24:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\OTL.exe
[2011-04-08 04:07:41 | 000,001,651 | ---- | M] () -- C:\Documents and Settings\All Users\Skrivebord\SUPERAntiSpyware Free Edition.lnk
[2011-04-08 01:36:54 | 006,238,248 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\Matthias\Skrivebord\AppRemover.exe
[2011-04-08 00:12:40 | 001,090,912 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Documents and Settings\Matthias\Skrivebord\avg_remover_stf_x86_2011_1184.exe
[2011-04-07 12:51:46 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\Matthias\Skrivebord\dds.scr
[2011-04-07 12:51:16 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\Matthias\Skrivebord\zrckln5k.exe
[2011-04-07 12:50:24 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Matthias\Skrivebord\TFC.exe
[2011-04-06 16:52:47 | 000,002,453 | ---- | M] () -- C:\Documents and Settings\Matthias\Skrivebord\Microsoft Office Excel 2007.lnk
========== Files Created - No Company Name ==========
[2011-04-13 00:14:32 | 000,000,418 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011-04-13 00:11:41 | 000,001,912 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011-04-13 00:09:17 | 000,001,659 | ---- | C] () -- C:\Documents and Settings\All Users\Menuen Start\Programmer\Microsoft Security Essentials.lnk
[2011-04-12 23:44:30 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011-04-12 23:44:27 | 000,260,800 | RHS- | C] () -- C:\cmldr
[2011-04-12 03:07:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011-04-12 03:07:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011-04-12 03:07:24 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011-04-12 03:07:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011-04-12 03:07:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-04-12 03:05:23 | 004,319,795 | R--- | C] () -- C:\Documents and Settings\Matthias\Skrivebord\ComboFix.exe
[2011-04-11 19:31:00 | 000,000,763 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\Malwarebytes' Anti-Malware.lnk
[2011-04-11 15:56:42 | 000,000,631 | ---- | C] () -- C:\Documents and Settings\Matthias\Skrivebord\Genvej til notepad.lnk
[2011-04-10 08:38:34 | 002,234,368 | R--- | C] () -- C:\OTLPE.exe
[2011-04-08 04:07:41 | 000,001,651 | ---- | C] () -- C:\Documents and Settings\All Users\Skrivebord\SUPERAntiSpyware Free Edition.lnk
[2011-04-07 19:17:38 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\Matthias\Skrivebord\dds.scr
[2011-04-07 18:40:27 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\Matthias\Skrivebord\zrckln5k.exe
[2010-11-10 17:45:01 | 000,023,920 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010-10-31 21:22:26 | 000,075,776 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2010-08-01 23:53:42 | 000,152,192 | ---- | C] () -- C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat
[2010-07-24 18:04:47 | 000,000,259 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010-06-10 15:54:42 | 000,227,624 | ---- | C] () -- C:\WINDOWS\libactivboardex.dll
[2010-06-10 15:54:24 | 000,256,280 | ---- | C] () -- C:\WINDOWS\ActivDRV.dll
[2010-05-01 01:20:21 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DToPcM40.dat
[2009-09-30 23:41:03 | 001,474,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat
[2009-09-27 14:17:36 | 001,481,728 | ---- | C] () -- C:\WINDOWS\System32\legitcheckcontrol.dll.bak
[2009-09-27 14:17:36 | 001,481,728 | ---- | C] () -- C:\WINDOWS\System32\LegitCheckControl.dll
[2009-09-27 14:17:36 | 000,323,072 | ---- | C] () -- C:\WINDOWS\System32\wgatray.exe.bak
[2009-09-27 14:17:36 | 000,190,976 | ---- | C] () -- C:\WINDOWS\System32\wgalogon.dll.bak
[2008-12-28 11:02:46 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008-12-28 10:59:48 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2008-10-31 19:17:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008-05-16 12:58:04 | 000,012,632 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2008-05-04 20:27:17 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\Matthias\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-04-18 12:32:56 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008-02-21 21:50:59 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2008-02-21 19:27:21 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008-02-16 12:02:28 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2008-02-15 20:35:49 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008-02-15 20:32:36 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2008-02-15 20:26:58 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-02-15 20:26:58 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008-02-15 20:16:27 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008-02-15 20:14:05 | 000,021,644 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-02-15 20:11:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008-02-15 20:10:41 | 000,149,200 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006-08-16 19:52:54 | 000,133,583 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2004-08-02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003-03-24 07:03:00 | 000,279,552 | ---- | C] () -- C:\WINDOWS\System32\FGWVB32.DLL
[2002-09-16 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2002-09-16 14:00:00 | 000,449,232 | ---- | C] () -- C:\WINDOWS\System32\perfh006.dat
[2002-09-16 14:00:00 | 000,433,872 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2002-09-16 14:00:00 | 000,284,912 | ---- | C] () -- C:\WINDOWS\System32\perfi006.dat
[2002-09-16 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2002-09-16 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2002-09-16 14:00:00 | 000,079,148 | ---- | C] () -- C:\WINDOWS\System32\perfc006.dat
[2002-09-16 14:00:00 | 000,068,444 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2002-09-16 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2002-09-16 14:00:00 | 000,034,026 | ---- | C] () -- C:\WINDOWS\System32\perfd006.dat
[2002-09-16 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2002-09-16 14:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2002-09-16 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001-09-04 11:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-09-04 11:10:20 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
========== LOP Check ==========
[2011-02-01 18:00:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Activ Software
[2010-07-24 15:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Backup
[2010-10-26 10:46:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010-10-26 10:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011-02-01 18:00:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Promethean
[2010-11-01 19:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-02-01 17:59:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\ACTIV Software
[2010-10-26 10:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\AVG10
[2008-03-14 23:12:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\Command & Conquer 3 Tiberium Wars
[2010-05-01 16:11:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\DNA
[2009-01-19 18:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\LimeWire
[2011-02-01 22:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matthias\Application Data\Promethean
[2011-04-13 17:13:13 | 000,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008-02-15 20:15:35 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011-04-11 19:25:35 | 000,033,780 | ---- | M] () -- C:\blitzblank.log
[2011-04-12 23:31:10 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011-04-12 23:44:30 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2002-09-16 14:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2004-08-03 23:00:04 | 000,260,800 | RHS- | M] () -- C:\cmldr
[2011-04-13 01:52:55 | 000,013,157 | ---- | M] () -- C:\ComboFix.txt
[2008-02-15 20:15:35 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008-02-15 20:15:35 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009-02-12 01:00:02 | 001,481,728 | ---- | M] () -- C:\LegitCheckControl.dll
[2008-02-15 20:15:35 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008-02-15 20:44:26 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009-09-27 13:13:16 | 000,250,576 | RHS- | M] () -- C:\ntldr
[2011-04-10 09:52:36 | 000,046,092 | ---- | M] () -- C:\OTL.Txt
[2011-03-07 00:12:59 | 002,234,368 | R--- | M] () -- C:\OTLPE.exe
[2011-04-13 17:06:47 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2001-01-10 13:23:58 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
[2009-02-12 01:00:02 | 000,190,976 | ---- | M] () -- C:\WgaLogon.dll
[2009-02-12 01:00:02 | 000,323,072 | ---- | M] () -- C:\WgaTray.exe
< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008-02-15 20:15:24 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008-07-06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006-10-26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008-07-06 12:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010-04-17 01:53:08 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008-02-15 21:10:03 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008-02-15 21:10:03 | 000,602,112 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008-02-15 21:10:03 | 000,405,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008-02-15 20:48:18 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Matthias\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008-02-15 20:17:55 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Matthias\Application Data\Microsoft\Internet Explorer\Quick Launch\Vis skrivebord.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2008-10-31 19:03:57 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Matthias\Cookies\desktop.ini
[2011-04-13 20:16:36 | 000,049,152 | -HS- | M] () -- C:\Documents and Settings\Matthias\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2007-06-27 16:34:24 | 000,317,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
[2008-04-14 18:05:19 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Messenger\custsat.dll
[2002-09-16 14:00:00 | 000,004,821 | ---- | M] () -- C:\Programmer\Messenger\logowin.gif
[2002-08-20 13:32:18 | 000,007,047 | ---- | M] () -- C:\Programmer\Messenger\lvback.gif
[2002-04-11 12:56:56 | 000,000,937 | ---- | M] () -- C:\Programmer\Messenger\mailtmpl.txt
[2008-05-02 16:05:52 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Messenger\msgsc.dll
[2008-04-13 19:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Messenger\msgslang.dll
[2008-04-14 18:05:55 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Messenger\msmsgs.exe
[2002-08-20 16:08:38 | 000,069,663 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Messenger\msmsgsin.exe
[2002-09-16 14:00:00 | 000,002,882 | ---- | M] () -- C:\Programmer\Messenger\newalert.wav
[2002-09-16 14:00:00 | 000,006,156 | ---- | M] () -- C:\Programmer\Messenger\newemail.wav
[2002-09-16 14:00:00 | 000,006,160 | ---- | M] () -- C:\Programmer\Messenger\online.wav
[2002-08-20 13:32:20 | 000,004,454 | ---- | M] () -- C:\Programmer\Messenger\type.wav
[2004-07-17 12:37:16 | 000,121,026 | ---- | M] () -- C:\Programmer\Messenger\xpmsgr.chm
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >