Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-02-2013 01
Ran by SYSTEM at 18-02-2013 21:41:15
Running from J:\
Windows 7 Ultimate (X64) OS Language: Norwegian Bokmal
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6827664 2012-12-23] (Realtek Semiconductor)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation)
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [IntelliType Pro] "C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe" [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2076272 2012-11-02] (Microsoft Corporation)
HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2012-08-20] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUS ShellProcess Execute] C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe [252544 2010-11-25] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1263512 2012-11-30] ()
HKLM-x32\...\Run: [Nero MediaHome 4] "C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN [5178664 2012-02-28] (Nero AG)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.)
HKU\Jon\...\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" [495616 2007-09-02] ()
HKU\Jon\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3673728 2012-11-06] (DT Soft Ltd)
HKU\Jon\...\Run: [SteelSeries Engine] C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [237056 2012-11-28] (SteelSeries ApS)
HKU\Jon\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18708224 2013-01-08] (Skype Technologies S.A.)
HKU\Jon\...\Run: [Spotify] "C:\Users\Jon\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [5926808 2013-02-16] (Spotify Ltd)
HKU\Jon\...\Run: [Spotify Web Helper] "C:\Users\Jon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199000 2013-02-16] (Spotify Ltd)
HKU\Jon\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.)
Tcpip\Parameters: [DhcpNameServer] 193.213.112.4 130.67.15.198 10.0.0.138
Tcpip\..\Interfaces\{E9EED517-B476-4CF0-A4A6-A141B63A5AB4}: [NameServer]8.8.8.8,8.8.4.4
==================== Services (Whitelisted) ===================
2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-12-23] ()
2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-12-23] (ASUSTeK Computer Inc.)
2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-12-23] (ASUSTeK Computer Inc.)
2 AsusFanControlService; "C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.15\AsusFanControlService.exe" [1457664 2012-12-23] (ASUSTeK Computer Inc.)
2 MBAMScheduler; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-29] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-29] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22056 2013-01-27] (Microsoft Corporation)
2 NeroMediaHomeService.4; "C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe" [517416 2012-02-28] (Nero AG)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [379360 2013-01-27] (Microsoft Corporation)
2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
==================== Drivers (Whitelisted) =====================
3 AiChargerPlus; C:\Windows\SysWow64\Drivers\AiChargerPlus.sys [14848 2012-04-19] (ASUSTek Computer Inc.)
1 AsIO; C:\Windows\SysWow64\Drivers\AsIO.sys [13440 2012-12-23] ()
1 AsUpIO; C:\Windows\SysWow64\Drivers\AsUpIO.sys [14464 2012-12-23] ()
3 ASUSFILTER; C:\Windows\SysWow64\Drivers\ASUSFILTER.sys [46152 2012-12-23] (MCCI Corporation)
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [25928 2012-09-29] (Malwarebytes Corporation)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [38016 2012-10-15] (SteelSeries Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-12-23] (Duplex Secure Ltd.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-02-18 21:40 - 2013-02-18 21:40 - 00000000 ____D C:\FRST
2013-02-18 20:53 - 2013-02-18 20:53 - 00000781 ____A C:\Windows\setupact.log
2013-02-18 20:53 - 2013-02-18 20:53 - 00000000 ____A C:\Windows\setuperr.log
2013-02-18 20:15 - 2013-02-18 20:15 - 00001568 ____A C:\Users\Jon\Desktop\RKreport[5]_SC_02182013_02d2015.txt
2013-02-18 20:13 - 2013-02-18 20:13 - 00002666 ____A C:\Users\Jon\Desktop\RKreport[4]_D_02182013_02d2013.txt
2013-02-18 20:10 - 2013-02-18 20:10 - 00002625 ____A C:\Users\Jon\Desktop\RKreport[3]_S_02182013_02d2010.txt
2013-02-18 20:07 - 2013-02-18 20:07 - 00798208 ____A C:\Users\Jon\Desktop\RogueKiller (1).exe
2013-02-18 19:59 - 2013-02-18 19:59 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Jon\Desktop\tdsskiller (1).exe
2013-02-18 11:18 - 2013-02-18 11:18 - 00002792 ____A C:\Users\Jon\Desktop\RKreport[2]_D_02182013_02d1118.txt
2013-02-18 11:15 - 2013-02-18 11:15 - 00002737 ____A C:\Users\Jon\Desktop\RKreport[1]_S_02182013_02d1115.txt
2013-02-18 11:14 - 2013-02-18 20:12 - 00000000 ____D C:\Users\Jon\Desktop\RK_Quarantine
2013-02-18 11:13 - 2013-02-18 11:13 - 00798208 ____A C:\Users\Jon\Downloads\RogueKiller.exe
2013-02-18 07:25 - 2013-02-18 09:17 - 00000000 ____D C:\Program Files (x86)\Trojan SVCHOSTRemoval Tool
2013-02-18 07:25 - 2013-02-18 07:25 - 00001365 ____A C:\Users\Jon\Desktop\Trojan SVCHOSTRemoval Tool.lnk
2013-02-18 07:25 - 2012-12-10 10:04 - 00356352 ____A (eSellerate Inc.) C:\Windows\eSellerateEngine.dll
2013-02-18 07:25 - 2012-12-10 10:04 - 00081920 ____A (eSellerate Inc.) C:\Windows\eSellerateControl350.dll
2013-02-18 07:25 - 2009-07-23 17:32 - 01122304 ____A (The OpenSSL Project,
http://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
2013-02-18 07:25 - 2009-07-23 17:32 - 00274432 ____A (The OpenSSL Project,
http://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll
2013-02-18 07:23 - 2013-02-18 07:23 - 02729904 ____A (Security Stronghold ) C:\Users\Jon\Downloads\TrojanSVCHOSTRemovalTool.exe
2013-02-18 07:20 - 2013-02-18 07:20 - 00000000 ____D C:\Program Files\CCleaner
2013-02-18 07:19 - 2013-02-18 07:19 - 04189792 ____A (Piriform Ltd) C:\Users\Jon\Downloads\ccsetup327.exe
2013-02-18 07:13 - 2013-02-18 07:13 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Jon\Downloads\tdsskiller.exe
2013-02-18 07:03 - 2013-02-18 07:04 - 19139088 ____A (Microsoft Corporation) C:\Users\Jon\Downloads\Windows-KB890830-x64-V4.17.exe
2013-02-18 06:58 - 2013-02-18 07:26 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-02-18 06:58 - 2013-02-18 06:58 - 00002173 ____A C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-02-18 06:58 - 2013-02-18 06:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-02-18 06:58 - 2009-01-25 12:14 - 00017272 ____A (Safer Networking Limited) C:\Windows\System32\sdnclean64.exe
2013-02-18 06:57 - 2013-02-18 06:57 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Jon\Downloads\SpybotSD2.exe
2013-02-18 06:01 - 2013-01-09 07:02 - 08390656 ____A C:\Users\Jon\Desktop\Rampage-IV-Extreme-ASUS-3404.CAP
2013-02-18 05:59 - 2013-02-18 05:59 - 04331547 ____A C:\Users\Jon\Downloads\Rampage-IV-Extreme-ASUS-3404.zip
2013-02-17 10:26 - 2013-02-17 10:27 - 49227190 ____A C:\Users\Jon\Downloads\DCPlusPlus-0.810.exe
2013-02-16 06:49 - 2013-02-16 06:49 - 00001757 ____A C:\Users\Jon\Desktop\Spotify.lnk
2013-02-16 06:49 - 2013-02-16 06:49 - 00000000 ____D C:\Users\Jon\AppData\Local\Spotify
2013-02-16 06:48 - 2013-02-18 06:45 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Spotify
2013-02-16 06:48 - 2013-02-16 06:48 - 00090624 ____A (Spotify Ltd) C:\Users\Jon\Downloads\SpotifySetup.exe
2013-02-14 19:33 - 2013-02-14 19:33 - 04873520 ____A C:\Users\Jon\Downloads\YTDSetup.exe
2013-02-13 19:12 - 2013-02-13 19:12 - 00000000 ____D C:\Users\Jon\AppData\Local\DDMSettings
2013-02-13 16:52 - 2013-01-09 02:48 - 17812992 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-02-13 16:52 - 2013-01-09 02:22 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-02-13 16:52 - 2013-01-09 02:19 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-02-13 16:52 - 2013-01-09 02:12 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-02-13 16:52 - 2013-01-09 02:12 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-02-13 16:52 - 2013-01-09 02:11 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-02-13 16:52 - 2013-01-09 02:10 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-02-13 16:52 - 2013-01-09 02:09 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-02-13 16:52 - 2013-01-09 02:07 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-02-13 16:52 - 2013-01-09 02:07 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-02-13 16:52 - 2013-01-09 02:07 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-02-13 16:52 - 2013-01-09 02:06 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-02-13 16:52 - 2013-01-09 02:05 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-02-13 16:52 - 2013-01-09 02:04 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-02-13 16:52 - 2013-01-09 02:04 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-02-13 16:52 - 2013-01-09 02:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-02-13 16:52 - 2013-01-08 23:23 - 12321280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-02-13 16:52 - 2013-01-08 23:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-02-13 16:52 - 2013-01-08 23:09 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-02-13 16:52 - 2013-01-08 23:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-02-13 16:52 - 2013-01-08 23:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-02-13 16:52 - 2013-01-08 23:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-02-13 16:52 - 2013-01-08 23:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-02-13 16:52 - 2013-01-08 23:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-02-13 16:52 - 2013-01-08 22:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-02-13 16:52 - 2013-01-08 22:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-02-13 16:52 - 2013-01-08 22:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-02-13 16:52 - 2013-01-08 22:57 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-02-13 16:52 - 2013-01-08 22:56 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-02-13 16:52 - 2013-01-08 22:56 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-02-13 16:52 - 2013-01-08 22:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-02-13 16:52 - 2013-01-08 22:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-02-13 11:13 - 2013-02-13 11:13 - 00001912 ____A C:\Windows\epplauncher.mif
2013-02-13 11:08 - 2013-01-05 06:53 - 05553512 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-02-13 11:08 - 2013-01-05 06:00 - 03967848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-02-13 11:08 - 2013-01-05 06:00 - 03913064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-02-13 11:07 - 2013-01-04 06:46 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-02-13 11:07 - 2013-01-04 05:51 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-02-13 11:07 - 2013-01-04 04:26 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-02-13 11:07 - 2013-01-04 03:47 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-02-13 11:07 - 2013-01-04 03:47 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-02-13 11:07 - 2013-01-04 03:47 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-02-13 11:07 - 2013-01-04 03:47 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-02-13 11:06 - 2013-01-03 07:00 - 01913192 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-02-13 11:06 - 2013-01-03 07:00 - 00288088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2013-02-13 10:57 - 2013-02-13 10:57 - 00000000 ____D C:\Users\Jon\AppData\Local\FLT
2013-02-13 10:47 - 2013-02-14 09:05 - 00009216 __ASH C:\Users\Jon\Desktop\Thumbs.db
2013-02-13 10:38 - 2013-02-13 16:57 - 01333634 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-02-13 08:28 - 2013-02-13 08:28 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-13 08:28 - 2013-02-13 08:28 - 00000000 ____D C:\Program Files (x86)\Java
2013-02-11 16:42 - 2013-02-11 16:42 - 00000000 ____D C:\Users\Jon\AppData\Roaming\HackSlashLoot
2013-02-10 22:45 - 2013-02-10 23:01 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Might & Magic Heroes VI
2013-02-10 22:45 - 2013-02-10 23:01 - 00000000 ____D C:\Users\Jon\AppData\Local\Ubisoft Game Launcher
2013-02-10 22:45 - 2013-02-10 22:51 - 00000000 ____D C:\Users\Jon\Documents\Might & Magic Heroes VI
2013-02-10 22:36 - 2013-02-10 22:36 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-02-10 17:36 - 2013-02-10 17:36 - 00000000 ____D C:\Users\Jon\Desktop\Ny mappe
2013-02-10 08:12 - 2013-02-10 08:12 - 00001545 ____A C:\Users\Jon\Desktop\dont rain on my parade.txt
2013-02-09 07:13 - 2013-02-09 07:13 - 00001098 ____A C:\Users\Jon\Desktop\Heroes3 - Snarvei.lnk
2013-02-09 04:09 - 2013-02-09 04:39 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Omerta
2013-02-07 11:00 - 2013-02-07 11:00 - 00000000 ____D C:\Users\Jon\AppData\Local\Funcom
2013-02-05 10:46 - 2013-02-05 10:46 - 00000000 ____D C:\Users\Jon\AppData\Local\PunkBuster
2013-02-05 10:46 - 2013-02-05 10:46 - 00000000 ____D C:\ProgramData\Orbit
2013-02-05 10:21 - 2013-02-14 09:08 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-02-04 15:13 - 2013-02-04 15:13 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Windows Live Writer
2013-02-04 15:13 - 2013-02-04 15:13 - 00000000 ____D C:\Users\Jon\AppData\Local\Windows Live Writer
2013-02-04 02:21 - 2013-02-04 02:21 - 00000000 ____D C:\ProgramData\TERA
2013-02-03 04:53 - 2013-02-03 04:53 - 00000000 ____D C:\Users\Jon\AppData\Local\SCE
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\ProgramData\ATI
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-02-03 01:41 - 2013-02-03 01:43 - 153548912 ____A (Advanced Micro Devices, Inc.) C:\Users\Jon\Downloads\13-1_vista_win7_win8_64_dd_ccc_whql.exe
2013-01-30 04:42 - 2013-01-30 04:42 - 00000000 ____D C:\ProgramData\Steam
2013-01-29 03:25 - 2013-01-29 03:26 - 00000000 ____D C:\xenomorph
2013-01-28 18:16 - 2013-02-18 08:19 - 00000000 ____D C:\Users\Jon\AppData\Roaming\DC++
2013-01-28 18:16 - 2013-02-18 08:19 - 00000000 ____D C:\Users\Jon\AppData\Local\DC++
2013-01-28 18:15 - 2013-01-28 18:16 - 00000000 ____D C:\Program Files (x86)\DC++
2013-01-28 15:41 - 2013-01-28 15:41 - 00000000 ____D C:\Users\NeroMediaHomeUser.4\AppData\Roaming\Nero
2013-01-28 15:31 - 2013-01-30 06:15 - 00000000 ____D C:\users\NeroMediaHomeUser.4
2013-01-28 15:31 - 2013-01-28 15:31 - 00000020 ___SH C:\Users\NeroMediaHomeUser.4\ntuser.ini
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Start-meny
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Skrivere
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Mine dokumenter
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Maler
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Lokale innstillinger
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Mine bilder
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Min musikk
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Intern video
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\AppData\Local\Logg
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\AndrMask
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\NeroMediaHomeUser.4\AppData\Local\Nero
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Nero
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\Jon\AppData\Local\Nero
2013-01-28 15:29 - 2013-01-28 15:31 - 00000000 ____D C:\ProgramData\Nero
2013-01-28 15:29 - 2013-01-28 15:30 - 00000000 ____D C:\Program Files (x86)\Nero
2013-01-28 15:29 - 2013-01-28 15:29 - 00002383 ____A C:\Users\Public\Desktop\Nero MediaHome 4.lnk
2013-01-28 15:21 - 2013-01-28 15:22 - 85139100 ____A C:\Users\Jon\Downloads\NMH-4.5.20.45_LGE.zip
2013-01-27 23:46 - 2013-01-28 00:02 - 00000000 ____D C:\Users\Jon\Documents\Euro Truck Simulator 2
2013-01-27 02:39 - 2013-01-27 02:39 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
2013-01-27 01:51 - 2013-01-27 01:58 - 00000000 ____D C:\Users\Jon\Documents\SEGA Mega Drive Classics
2013-01-26 21:41 - 2013-01-26 21:40 - 01081760 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-01-26 21:41 - 2013-01-26 21:40 - 00960416 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-01-26 21:41 - 2013-01-26 21:40 - 00308640 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-01-26 21:41 - 2013-01-26 21:40 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-01-26 21:41 - 2013-01-26 21:40 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-01-26 21:41 - 2013-01-26 21:40 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-01-26 21:40 - 2013-01-26 21:40 - 00000000 ____D C:\Program Files\Java
2013-01-26 21:30 - 2013-02-13 17:00 - 00000000 ____D C:\Users\Jon\AppData\Roaming\.minecraft
2013-01-26 21:30 - 2013-01-26 21:30 - 00263186 ____A C:\Users\Jon\Desktop\Minecraft.exe
2013-01-26 21:00 - 2013-01-26 21:04 - 00000000 ____D C:\Users\Jon\AppData\Roaming\NationRed
2013-01-26 20:42 - 2013-01-26 20:42 - 00000000 ____D C:\ProgramData\Remedy
2013-01-20 15:59 - 2013-01-20 15:59 - 00230320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2013-01-19 17:43 - 2013-01-19 17:43 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-01-19 17:43 - 2013-01-19 17:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-01-19 17:43 - 2008-07-12 08:18 - 04992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
2013-01-19 17:43 - 2008-07-12 08:18 - 03851784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-01-19 17:43 - 2008-07-12 08:18 - 01942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
2013-01-19 17:43 - 2008-07-12 08:18 - 01493528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-01-19 17:43 - 2008-07-12 08:18 - 00540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
2013-01-19 17:43 - 2008-07-12 08:18 - 00467984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-01-19 05:31 - 2013-01-19 05:31 - 00000000 ____D C:\Users\Jon\Documents\Gaslamp Games
2013-01-19 03:06 - 2013-01-19 03:06 - 00000000 ____D C:\Users\Jon\AppData\Local\2K Games
2013-01-19 03:06 - 2013-01-19 03:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-01-19 01:07 - 2013-01-19 01:07 - 00013057 ____A C:\Users\Jon\Desktop\Lyd - Snarvei.lnk
==================== One Month Modified Files and Folders =======
2013-02-18 21:40 - 2013-02-18 21:40 - 00000000 ____D C:\FRST
2013-02-18 21:00 - 2012-12-23 05:30 - 00000000 ____D C:\users\Jon
2013-02-18 21:00 - 2012-12-23 05:29 - 01848220 ____A C:\Windows\WindowsUpdate.log
2013-02-18 20:56 - 2009-07-14 10:16 - 00492494 ____A C:\Windows\System32\perfh014.dat
2013-02-18 20:56 - 2009-07-14 10:16 - 00094284 ____A C:\Windows\System32\perfc014.dat
2013-02-18 20:56 - 2009-07-14 06:13 - 01355478 ____A C:\Windows\System32\PerfStringBackup.INI
2013-02-18 20:53 - 2013-02-18 20:53 - 00000781 ____A C:\Windows\setupact.log
2013-02-18 20:53 - 2013-02-18 20:53 - 00000000 ____A C:\Windows\setuperr.log
2013-02-18 20:35 - 2012-12-23 06:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-02-18 20:15 - 2013-02-18 20:15 - 00001568 ____A C:\Users\Jon\Desktop\RKreport[5]_SC_02182013_02d2015.txt
2013-02-18 20:13 - 2013-02-18 20:13 - 00002666 ____A C:\Users\Jon\Desktop\RKreport[4]_D_02182013_02d2013.txt
2013-02-18 20:12 - 2013-02-18 11:14 - 00000000 ____D C:\Users\Jon\Desktop\RK_Quarantine
2013-02-18 20:10 - 2013-02-18 20:10 - 00002625 ____A C:\Users\Jon\Desktop\RKreport[3]_S_02182013_02d2010.txt
2013-02-18 20:08 - 2012-12-23 07:49 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner
2013-02-18 20:07 - 2013-02-18 20:07 - 00798208 ____A C:\Users\Jon\Desktop\RogueKiller (1).exe
2013-02-18 19:59 - 2013-02-18 19:59 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Jon\Desktop\tdsskiller (1).exe
2013-02-18 11:21 - 2009-07-14 05:45 - 00013440 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-02-18 11:21 - 2009-07-14 05:45 - 00013440 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-02-18 11:18 - 2013-02-18 11:18 - 00002792 ____A C:\Users\Jon\Desktop\RKreport[2]_D_02182013_02d1118.txt
2013-02-18 11:15 - 2013-02-18 11:15 - 00002737 ____A C:\Users\Jon\Desktop\RKreport[1]_S_02182013_02d1115.txt
2013-02-18 11:13 - 2013-02-18 11:13 - 00798208 ____A C:\Users\Jon\Downloads\RogueKiller.exe
2013-02-18 11:02 - 2012-12-23 08:03 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Winamp
2013-02-18 09:17 - 2013-02-18 07:25 - 00000000 ____D C:\Program Files (x86)\Trojan SVCHOSTRemoval Tool
2013-02-18 08:52 - 2012-12-26 16:59 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Skype
2013-02-18 08:48 - 2012-12-23 08:01 - 00000000 ____D C:\Users\Jon\AppData\Roaming\mIRC
2013-02-18 08:19 - 2013-01-28 18:16 - 00000000 ____D C:\Users\Jon\AppData\Roaming\DC++
2013-02-18 08:19 - 2013-01-28 18:16 - 00000000 ____D C:\Users\Jon\AppData\Local\DC++
2013-02-18 07:29 - 2013-01-09 12:08 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Media Player Classic
2013-02-18 07:29 - 2013-01-08 18:11 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Azureus
2013-02-18 07:29 - 2012-12-27 05:20 - 00000000 ____D C:\Users\Jon\Tracing
2013-02-18 07:29 - 2012-12-23 07:32 - 00000000 ____D C:\Users\Jon\AppData\Roaming\DAEMON Tools Lite
2013-02-18 07:29 - 2012-12-23 07:17 - 00000000 ____D C:\Users\Jon\AppData\Roaming\uTorrent
2013-02-18 07:29 - 2012-12-23 05:22 - 00000000 ____D C:\Windows\Panther
2013-02-18 07:26 - 2013-02-18 06:58 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-02-18 07:25 - 2013-02-18 07:25 - 00001365 ____A C:\Users\Jon\Desktop\Trojan SVCHOSTRemoval Tool.lnk
2013-02-18 07:23 - 2013-02-18 07:23 - 02729904 ____A (Security Stronghold ) C:\Users\Jon\Downloads\TrojanSVCHOSTRemovalTool.exe
2013-02-18 07:20 - 2013-02-18 07:20 - 00000000 ____D C:\Program Files\CCleaner
2013-02-18 07:19 - 2013-02-18 07:19 - 04189792 ____A (Piriform Ltd) C:\Users\Jon\Downloads\ccsetup327.exe
2013-02-18 07:13 - 2013-02-18 07:13 - 02237968 ____A (Kaspersky Lab ZAO) C:\Users\Jon\Downloads\tdsskiller.exe
2013-02-18 07:04 - 2013-02-18 07:03 - 19139088 ____A (Microsoft Corporation) C:\Users\Jon\Downloads\Windows-KB890830-x64-V4.17.exe
2013-02-18 06:58 - 2013-02-18 06:58 - 00002173 ____A C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-02-18 06:58 - 2013-02-18 06:58 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-02-18 06:57 - 2013-02-18 06:57 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Jon\Downloads\SpybotSD2.exe
2013-02-18 06:45 - 2013-02-16 06:48 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Spotify
2013-02-18 06:45 - 2013-01-16 13:15 - 00000982 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-02-18 06:45 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-02-18 06:01 - 2012-12-23 06:46 - 05455248 ____A C:\Windows\PE_File.dll
2013-02-18 06:01 - 2012-12-23 06:45 - 05465008 ____A C:\Windows\PE_Rom.dll
2013-02-18 05:59 - 2013-02-18 05:59 - 04331547 ____A C:\Users\Jon\Downloads\Rampage-IV-Extreme-ASUS-3404.zip
2013-02-17 10:27 - 2013-02-17 10:26 - 49227190 ____A C:\Users\Jon\Downloads\DCPlusPlus-0.810.exe
2013-02-16 06:49 - 2013-02-16 06:49 - 00001757 ____A C:\Users\Jon\Desktop\Spotify.lnk
2013-02-16 06:49 - 2013-02-16 06:49 - 00000000 ____D C:\Users\Jon\AppData\Local\Spotify
2013-02-16 06:48 - 2013-02-16 06:48 - 00090624 ____A (Spotify Ltd) C:\Users\Jon\Downloads\SpotifySetup.exe
2013-02-14 19:33 - 2013-02-14 19:33 - 04873520 ____A C:\Users\Jon\Downloads\YTDSetup.exe
2013-02-14 09:08 - 2013-02-05 10:21 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-02-14 09:05 - 2013-02-13 10:47 - 00009216 __ASH C:\Users\Jon\Desktop\Thumbs.db
2013-02-14 03:17 - 2013-01-16 13:15 - 00000986 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-02-14 03:16 - 2009-07-14 05:45 - 00277968 ____A C:\Windows\System32\FNTCACHE.DAT
2013-02-14 03:00 - 2012-12-23 06:10 - 00000000 ____D C:\Users\Jon\AppData\Local\Deployment
2013-02-13 19:12 - 2013-02-13 19:12 - 00000000 ____D C:\Users\Jon\AppData\Local\DDMSettings
2013-02-13 17:29 - 2013-01-08 02:38 - 00000000 ____D C:\Users\Jon\Documents\StarCraft II
2013-02-13 17:00 - 2013-01-26 21:30 - 00000000 ____D C:\Users\Jon\AppData\Roaming\.minecraft
2013-02-13 16:57 - 2013-02-13 10:38 - 01333634 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-02-13 16:33 - 2012-12-23 07:23 - 00000000 ____D C:\Program Files (x86)\DivX
2013-02-13 16:33 - 2012-12-23 07:20 - 00000000 ____D C:\ProgramData\DivX
2013-02-13 16:32 - 2012-12-23 07:24 - 00000000 ____D C:\Program Files\DivX
2013-02-13 11:13 - 2013-02-13 11:13 - 00001912 ____A C:\Windows\epplauncher.mif
2013-02-13 11:13 - 2012-12-23 06:34 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-02-13 11:13 - 2012-12-23 06:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-02-13 10:57 - 2013-02-13 10:57 - 00000000 ____D C:\Users\Jon\AppData\Local\FLT
2013-02-13 10:57 - 2012-12-23 10:03 - 00000000 ____D C:\Users\Jon\Documents\my games
2013-02-13 10:48 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-02-13 08:28 - 2013-02-13 08:28 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-13 08:28 - 2013-02-13 08:28 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-13 08:28 - 2013-02-13 08:28 - 00000000 ____D C:\Program Files (x86)\Java
2013-02-13 08:28 - 2012-12-23 07:56 - 00861088 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-02-13 08:28 - 2012-12-23 07:56 - 00782240 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-02-11 16:42 - 2013-02-11 16:42 - 00000000 ____D C:\Users\Jon\AppData\Roaming\HackSlashLoot
2013-02-11 11:11 - 2012-12-23 06:05 - 00000000 ____D C:\ProgramData\Adobe
2013-02-11 11:10 - 2012-12-23 06:06 - 00697712 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-02-11 11:10 - 2012-12-23 06:06 - 00074096 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-02-10 23:01 - 2013-02-10 22:45 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Might & Magic Heroes VI
2013-02-10 23:01 - 2013-02-10 22:45 - 00000000 ____D C:\Users\Jon\AppData\Local\Ubisoft Game Launcher
2013-02-10 22:51 - 2013-02-10 22:45 - 00000000 ____D C:\Users\Jon\Documents\Might & Magic Heroes VI
2013-02-10 22:36 - 2013-02-10 22:36 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-02-10 22:36 - 2012-12-23 06:26 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2013-02-10 17:36 - 2013-02-10 17:36 - 00000000 ____D C:\Users\Jon\Desktop\Ny mappe
2013-02-10 08:12 - 2013-02-10 08:12 - 00001545 ____A C:\Users\Jon\Desktop\dont rain on my parade.txt
2013-02-09 07:13 - 2013-02-09 07:13 - 00001098 ____A C:\Users\Jon\Desktop\Heroes3 - Snarvei.lnk
2013-02-09 04:39 - 2013-02-09 04:09 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Omerta
2013-02-07 11:00 - 2013-02-07 11:00 - 00000000 ____D C:\Users\Jon\AppData\Local\Funcom
2013-02-06 06:09 - 2013-01-16 12:23 - 00000000 ____D C:\Users\Jon\Documents\EA Games
2013-02-06 06:09 - 2013-01-16 12:20 - 00000000 ____D C:\Users\Jon\AppData\Local\EA Games
2013-02-05 10:46 - 2013-02-05 10:46 - 00000000 ____D C:\Users\Jon\AppData\Local\PunkBuster
2013-02-05 10:46 - 2013-02-05 10:46 - 00000000 ____D C:\ProgramData\Orbit
2013-02-04 22:49 - 2012-12-26 17:06 - 70004024 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-02-04 15:13 - 2013-02-04 15:13 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Windows Live Writer
2013-02-04 15:13 - 2013-02-04 15:13 - 00000000 ____D C:\Users\Jon\AppData\Local\Windows Live Writer
2013-02-04 15:13 - 2012-12-26 16:09 - 00000000 ____D C:\Users\Jon\AppData\Local\Windows Live
2013-02-04 13:21 - 2012-12-23 07:25 - 00000000 ____D C:\Users\Jon\AppData\Roaming\DivX
2013-02-04 02:21 - 2013-02-04 02:21 - 00000000 ____D C:\ProgramData\TERA
2013-02-03 04:53 - 2013-02-03 04:53 - 00000000 ____D C:\Users\Jon\AppData\Local\SCE
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\ProgramData\ATI
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-02-03 01:48 - 2013-02-03 01:48 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-02-03 01:48 - 2012-12-23 06:06 - 00000000 ____D C:\ProgramData\AMD
2013-02-03 01:47 - 2012-12-25 19:46 - 00000000 ____D C:\Program Files\ATI Technologies
2013-02-03 01:43 - 2013-02-03 01:41 - 153548912 ____A (Advanced Micro Devices, Inc.) C:\Users\Jon\Downloads\13-1_vista_win7_win8_64_dd_ccc_whql.exe
2013-01-30 11:53 - 2012-12-23 06:46 - 00273840 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2013-01-30 06:15 - 2013-01-28 15:31 - 00000000 ____D C:\users\NeroMediaHomeUser.4
2013-01-30 04:42 - 2013-01-30 04:42 - 00000000 ____D C:\ProgramData\Steam
2013-01-29 07:15 - 2012-12-30 07:28 - 00419840 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2013-01-29 07:15 - 2012-12-30 07:28 - 00413696 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2013-01-29 07:15 - 2012-12-30 07:28 - 00133632 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2013-01-29 07:15 - 2012-12-30 07:28 - 00110592 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2013-01-29 03:26 - 2013-01-29 03:25 - 00000000 ____D C:\xenomorph
2013-01-28 18:16 - 2013-01-28 18:15 - 00000000 ____D C:\Program Files (x86)\DC++
2013-01-28 18:16 - 2012-12-23 05:30 - 00000000 ____D C:\Users\Jon\AppData\Local\VirtualStore
2013-01-28 15:41 - 2013-01-28 15:41 - 00000000 ____D C:\Users\NeroMediaHomeUser.4\AppData\Roaming\Nero
2013-01-28 15:31 - 2013-01-28 15:31 - 00000020 ___SH C:\Users\NeroMediaHomeUser.4\ntuser.ini
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Start-meny
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Skrivere
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Mine dokumenter
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Maler
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Lokale innstillinger
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Mine bilder
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Min musikk
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\Documents\Intern video
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\AppData\Local\Logg
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 __SHD C:\Users\NeroMediaHomeUser.4\AndrMask
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\NeroMediaHomeUser.4\AppData\Local\Nero
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\Jon\AppData\Roaming\Nero
2013-01-28 15:31 - 2013-01-28 15:31 - 00000000 ____D C:\Users\Jon\AppData\Local\Nero
2013-01-28 15:31 - 2013-01-28 15:29 - 00000000 ____D C:\ProgramData\Nero
2013-01-28 15:30 - 2013-01-28 15:29 - 00000000 ____D C:\Program Files (x86)\Nero
2013-01-28 15:29 - 2013-01-28 15:29 - 00002383 ____A C:\Users\Public\Desktop\Nero MediaHome 4.lnk
2013-01-28 15:22 - 2013-01-28 15:21 - 85139100 ____A C:\Users\Jon\Downloads\NMH-4.5.20.45_LGE.zip
2013-01-28 14:49 - 2012-12-23 05:57 - 00000028 ____A C:\Users\Jon\Desktop\hgp.txt
2013-01-28 00:02 - 2013-01-27 23:46 - 00000000 ____D C:\Users\Jon\Documents\Euro Truck Simulator 2
2013-01-27 07:01 - 2012-12-26 16:59 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-01-27 07:01 - 2012-12-26 16:55 - 00000000 ____D C:\ProgramData\Skype
2013-01-27 07:01 - 2012-12-26 16:55 - 00000000 ____D C:\Program Files (x86)\Windows Live
2013-01-27 02:39 - 2013-01-27 02:39 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP
2013-01-27 01:58 - 2013-01-27 01:51 - 00000000 ____D C:\Users\Jon\Documents\SEGA Mega Drive Classics
2013-01-26 21:40 - 2013-01-26 21:41 - 01081760 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-01-26 21:40 - 2013-01-26 21:41 - 00960416 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-01-26 21:40 - 2013-01-26 21:41 - 00308640 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-01-26 21:40 - 2013-01-26 21:41 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-01-26 21:40 - 2013-01-26 21:41 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-01-26 21:40 - 2013-01-26 21:41 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-01-26 21:40 - 2013-01-26 21:40 - 00000000 ____D C:\Program Files\Java
2013-01-26 21:30 - 2013-01-26 21:30 - 00263186 ____A C:\Users\Jon\Desktop\Minecraft.exe
2013-01-26 21:04 - 2013-01-26 21:00 - 00000000 ____D C:\Users\Jon\AppData\Roaming\NationRed
2013-01-26 20:42 - 2013-01-26 20:42 - 00000000 ____D C:\ProgramData\Remedy
2013-01-20 18:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-01-20 15:59 - 2013-01-20 15:59 - 00230320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2013-01-20 15:59 - 2012-08-30 22:03 - 00130008 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2013-01-19 17:43 - 2013-01-19 17:43 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-01-19 17:43 - 2013-01-19 17:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-01-19 05:31 - 2013-01-19 05:31 - 00000000 ____D C:\Users\Jon\Documents\Gaslamp Games
2013-01-19 03:06 - 2013-01-19 03:06 - 00000000 ____D C:\Users\Jon\AppData\Local\2K Games
2013-01-19 03:06 - 2013-01-19 03:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-01-19 01:07 - 2013-01-19 01:07 - 00013057 ____A C:\Users\Jon\Desktop\Lyd - Snarvei.lnk
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-02-13 16:52:28
Restore point made on: 2013-02-17 01:48:40
==================== Memory info ===========================
Percentage of memory in use: 7%
Total physical RAM: 16324.66 MB
Available physical RAM: 15112.61 MB
Total Pagefile: 16322.81 MB
Available Pagefile: 15107.84 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: () (Fixed) (Total:931.41 GB) (Free:868.53 GB) NTFS
2 Drive d: (Usortert) (Fixed) (Total:1397.26 GB) (Free:295.38 GB) NTFS
3 Drive e: (Spel) (Fixed) (Total:931.51 GB) (Free:642.02 GB) NTFS
4 Drive f: (Nedlasta) (Fixed) (Total:1863.01 GB) (Free:1552.56 GB) NTFS
5 Drive g: (Steam Platform) (Fixed) (Total:1863.01 GB) (Free:419.03 GB) NTFS
6 Drive I: (GRMCULXFRER_NO_DVD) (CDROM) (Total:2.9 GB) (Free:0 GB) UDF
7 Drive j: (KINGSTON) (Removable) (Total:7.23 GB) (Free:7.23 GB) FAT32
8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
9 Drive y: (Reservert av systemet) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disknr. Status Str. Ledig Dyn GPT
-------- ------------- ------- ------- --- ---
Disk 0 Tilkoblet 931 G byte 0 byte
Disk 1 Tilkoblet 1397 G byte 0 byte
Disk 2 Tilkoblet 931 G byte 0 byte
Disk 3 Tilkoblet 1863 G byte 0 byte
Disk 4 Tilkoblet 1863 G byte 0 byte
Disk 5 Tilkoblet 7424 M byte 0 byte
Partitions of Disk 0:
===============
Disk-ID: CB25002E
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 100 M 1024 K byte
Partisjon 2 Prim‘r 931 G 101 M byte
==================================================================================
Disk: 0
Partisjon 1
Type : 07
Skjult: Nei
Aktiv : Ja
Forskyvning I byte: 1048576
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 1 Y Reservert a NTFS Partisjon 100 M OK
=========================================================
Disk: 0
Partisjon 2
Type : 07
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 105906176
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 2 C NTFS Partisjon 931 G OK
=========================================================
Partitions of Disk 1:
===============
Disk-ID: 35878E53
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 1397 G 1024 K byte
==================================================================================
Disk: 1
Partisjon 1
Type : 07
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 1048576
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 3 D Usortert NTFS Partisjon 1397 G OK
=========================================================
Partitions of Disk 2:
===============
Disk-ID: FF6A79A0
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 931 G 1024 K byte
==================================================================================
Disk: 2
Partisjon 1
Type : 07
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 1048576
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 4 E Spel NTFS Partisjon 931 G OK
=========================================================
Partitions of Disk 3:
===============
Disk-ID: BF7BA5D6
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 1863 G 1024 K byte
==================================================================================
Disk: 3
Partisjon 1
Type : 07
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 1048576
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 5 F Nedlasta NTFS Partisjon 1863 G OK
=========================================================
Partitions of Disk 4:
===============
Disk-ID: BF7BA5D7
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 1863 G 1024 K byte
==================================================================================
Disk: 4
Partisjon 1
Type : 07
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 1048576
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 6 G Steam Platf NTFS Partisjon 1863 G OK
=========================================================
Partitions of Disk 5:
===============
Disk-ID: 04030201
Partisjonsnr. Type Str. Forskyvning
------------- ---------------- ------- -----------
Partisjon 1 Prim‘r 7422 M 1580 K byte
==================================================================================
Disk: 5
Partisjon 1
Type : 0B
Skjult: Nei
Aktiv : Nei
Forskyvning I byte: 1617920
Volumnr. Bks Etikett Fs Type Str. Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volum 7 J KINGSTON FAT32 Flyttbar 7422 M OK
=========================================================
Last Boot: 2013-02-13 02:48
==================== End Of Log =============================