![]() |
|
Post Reply
|
| Author | |
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Topic: Rensning af vens maskinePosted: 12 Juli 2012 at 18:30 |
|
Hej Sidder her og ordner en maskine igennem teamviewer, som at der er lidt af hvert på. Håber at du har tid til at hjælpe mig med at rense den Programmerne er kørt i denne rækkefølge. Mbam, sas, eset online scanner, cf og dds. MVH. Malwarebytes Anti-Malware 1.62.0.1300 SUPERAntiSpyware Scan Log C:\Program Files (x86)\AskTBar\bar\2.bin\A5POPSWT.DLL Win32/Toolbar.AskSBar application cleaned by deleting - quarantined ComboFix 12-07-12.02 - Per Nygaard Olesen 12-07-2012 16:55:31.1.2 - x64 DDS (Ver_2011-08-26.01) - NTFSAMD64 |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 12 Juli 2012 at 19:49 |
|
Hejsa :-)
Godt at du gider hjælpe en ven, kammerat eller bekendt - thumbs up! Det må være noget af det værste jeg har set længe… Inden fix burde du afinstallere alle de utålige og useriøse toolbars som din bekendte har installeret - og alt andet du finder overflødigt. Herefter foreslår jeg følgende -> jeg er lidt hård i fixet, men jeg mener, at det er nødvendigt. Jeg er ikke sikker på, at du har genstartet computeren mellem mbam, sas, eset og cf, men du skal i hvert fald genstarte efter dette fix. Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript Killall:: DDS:: uStart Page = hxxp://home.sweetim.com/?st=4&barid={35AE9E06-7FF6-11E1-B302-206A8A1A3264} mStart Page = hxxp://home.sweetim.com/?st=4&barid={35AE9E06-7FF6-11E1-B302-206A8A1A3264} uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DK&userid=e4c44a96-dc5f-40b9-9fd3-0b5220c49ab8&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms} mURLSearchHooks: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files (x86)\WiseConvert\prxtbWise.dll mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll mURLSearchHooks: Game Master 2.1 Toolbar: {22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - C:\Program Files (x86)\Game_Master_2.1\prxtbGam0.dll mURLSearchHooks: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\prxtbNCH_.dll mURLSearchHooks: WiseConvert 2.1 Toolbar: {ecce0073-a837-45a2-95b9-600420505f7e} - C:\Program Files (x86)\WiseConvert_2.1\prxtbWis0.dll mURLSearchHooks: Game Master 2.2 Toolbar: {d8215d9c-81ed-4e53-b420-bfcdbac4734d} - C:\Program Files (x86)\Game_Master_2.2\prxtbGam0.dll mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll mURLSearchHooks: Translator 3.1 Toolbar: {3eec3c07-13c6-4b41-87c6-40b425a0b0a2} - C:\Program Files (x86)\Translator_3.1\prxtbTra0.dll mURLSearchHooks: express-files Toolbar: {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files (x86)\express-files\prxtbexpr.dll mURLSearchHooks: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV0.dll BHO: Game Master 2.1 Toolbar: {22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - C:\Program Files (x86)\Game_Master_2.1\prxtbGam0.dll BHO: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - Babylon toolbar helper BHO: Linkury SmartbarEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll BHO: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\prxtbNCH_.dll BHO: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV0.dll BHO: Translator 3.1 Toolbar: {3eec3c07-13c6-4b41-87c6-40b425a0b0a2} - C:\Program Files (x86)\Translator_3.1\prxtbTra0.dll BHO: Bcool Class: {3f5b3cad-8864-41dd-aa25-a3ec7fb2c821} - C:\ProgramData\Bcool\bhoclass.dll BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll BHO: express-files Toolbar: {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files (x86)\express-files\prxtbexpr.dll BHO: Search Results Toolbar: {94366e2c-9923-431c-b0d6-747447dd0f2b} - C:\Program Files (x86)\searchresults1\searchresultsDx.dll BHO: Babylon IE plugin: {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - Babylon IE plugin BHO: Bcool Class: {b0113a7b-1065-4458-953f-06e3ec094afe} - C:\ProgramData\Bcool\bhoclass.dll BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll BHO: Wincore Mediabar: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll BHO: Game Master 2.2 Toolbar: {d8215d9c-81ed-4e53-b420-bfcdbac4734d} - C:\Program Files (x86)\Game_Master_2.2\prxtbGam0.dll BHO: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files (x86)\WiseConvert\prxtbWise.dll BHO: WiseConvert 2.1 Toolbar: {ecce0073-a837-45a2-95b9-600420505f7e} - C:\Program Files (x86)\WiseConvert_2.1\prxtbWis0.dll BHO: SweetPacks Browser Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll TB: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files (x86)\WiseConvert\prxtbWise.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll TB: Linkury Smartbar: {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll TB: Game Master 2.1 Toolbar: {22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - C:\Program Files (x86)\Game_Master_2.1\prxtbGam0.dll TB: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\prxtbNCH_.dll TB: SweetPacks Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll TB: WiseConvert 2.1 Toolbar: {ecce0073-a837-45a2-95b9-600420505f7e} - C:\Program Files (x86)\WiseConvert_2.1\prxtbWis0.dll TB: Game Master 2.2 Toolbar: {d8215d9c-81ed-4e53-b420-bfcdbac4734d} - C:\Program Files (x86)\Game_Master_2.2\prxtbGam0.dll TB: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll TB: Translator 3.1 Toolbar: {3eec3c07-13c6-4b41-87c6-40b425a0b0a2} - C:\Program Files (x86)\Translator_3.1\prxtbTra0.dll TB: express-files Toolbar: {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files (x86)\express-files\prxtbexpr.dll TB: Search Results Toolbar: {94366e2c-9923-431c-b0d6-747447dd0f2b} - C:\Program Files (x86)\searchresults1\searchresultsDx.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\googletoolbar1.dll TB: Wincore Mediabar: {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll TB: FLV Runner Toolbar: {3bbd3c14-4c16-4989-8366-95bc9179779d} - C:\Program Files (x86)\FLV_Runner\prxtbFLV0.dll uRun: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe uRun: [Smart PC Cleaner] C:\Program Files (x86)\Smart PC Cleaner\SPCLauncher.exe uRun: [Computer Updater] "C:\Program Files (x86)\Computer Updater\ComputerUp-dater.Exe" /boot uRun: [Media Finder] "C:\Program Files (x86)\Media Finder\Media Finder.exe" /opentotray uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED uRun: [Browser Infrastructure Helper] C:\Users\Per Nygaard Olesen\AppData\Local\Smartbar\Application\Linkury.exe startup mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe mRun: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe StartupFolder: C:\Users\PERNYG~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\SOCIAL~1.LNK - C:\Program Files (x86)\Socialbox\Socialbox.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html mRun-x64: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun-x64: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe mRun-x64: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe Folder:: C:\Program Files (x86)\Optimizer Pro C:\Program Files (x86)\Smart PC Cleaner C:\Program Files (x86)\Computer Updater C:\Program Files (x86)\Media Finder C:\Program Files (x86)\uTorrent C:\Users\Per Nygaard Olesen\AppData\Local\Smartbar C:\Program Files (x86)\EgisTec MyWinLockerSuite C:\Program Files (x86)\EgisTec IPS C:\Program Files (x86)\SweetIM C:\Program Files (x86)\Socialbox C:\Program Files (x86)\Searchcore Toolbar C:\Vdefs C:\Program Files (x86)\TorrentSearch C:\Program Files (x86)\AskTBar C:\ProgramData\OptimizerPro Tag så fat i den nye fil med musen, og før den hen over ComboFix-filen, hvorefter du "giver slip" med musen. http://www.fromsej.saknet.dk/billeder/swfcombo.gif Så skulle ComboFix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse. Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt Indholdet af denne fil må du gerne lægge herind. |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 13 Juli 2012 at 21:46 |
|
Hejsa Mange tak for at du vil hjælpe, det er jeg MEGET taknemlig for! Her er CF log ComboFix 12-07-12.02 - Per Nygaard Olesen 13-07-2012 20:58:35.2.2 - x64 |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 14 Juli 2012 at 07:27 |
|
Lidt mere oprydning…. Inden du kører fixet, så check venligst disse fire mapper og se efter om der er noget værdifuldt i dem:
C:\c71c5183811ec9e4c13275454020bfa2 C:\7837f1a1feb4160e5d C:\fdc8b677164ad9d818e6b466e2d0 C:\2684a05f658bd80ba778ae7688be76 Hvis du ikke finder noget værdifuldt, så kør nedenstående fix. Hvis du vil beholde mapperne, så skal de fjernes fra fixet ******************************************** Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript Killall:: Folder:: c:\programdata\bProtectorForWindows c:\program files (x86)\PriceGong C:\c71c5183811ec9e4c13275454020bfa2 C:\7837f1a1feb4160e5d C:\fdc8b677164ad9d818e6b466e2d0 C:\2684a05f658bd80ba778ae7688be76 C:\searchplugins c:\programdata\IBUpdaterService c:\program files (x86)\EgisTec MyWinLocker File:: c:\progra~3\BPROTE~1\22453~1.59\protector.dll c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe Registry:: [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mwlDaemon"="" Driver:: MWLService MyWinLocker Service Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem. Tag så fat i den nye fil med musen, og før den hen over ComboFix-filen, hvorefter du "giver slip" med musen. http://www.fromsej.saknet.dk/billeder/swfcombo.gif Så skulle ComboFix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse. Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt Indholdet af denne fil må du gerne lægge herind. |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 14 Juli 2012 at 22:26 |
|
Hej ComboFix 12-07-14.01 - Per Nygaard Olesen 14-07-2012 21:27:16.3.2 - x64 |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 14 Juli 2012 at 23:47 |
|
Det hjælper, men jeg synes nu stadig der dukker lidt op. Tag lige en fuld scanning med en opdateret Malwarebytes, og derefter en tur med ESET online scanner - det bør kunne få ryddet lidt bedre op end det jeg gør manuelt
![]() Både Malwarebytes og ESET laver logs, som du skal være velkommen til at lægge ind i næste indlæg. |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 16 Juli 2012 at 00:41 |
|
Hej Malwarebytes Anti-Malware (Prøveversion) 1.62.0.1300 C:\Program Files (x86)\1ClickDownload\1ClickSettingsManager.exe Win32/Adware.1ClickDownload.E application cleaned by deleting - quarantined |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 16 Juli 2012 at 07:58 |
|
Ja, det er jo det gode ved renseprogrammer som Malwarebytes - de er grundige, og det skrider fremad
![]() Fik du kørt en tur med ESET? Slet den version af Combofix, der ligger på computeren - hent en ny - kør en almindelige tur med den nye Combofix og læg log'en herind. Vi skal nok nå i bund... |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 16 Juli 2012 at 19:43 |
|
Ja Det lyder rigtig godt! Combofix kan jeg ikke få til at virke, den starter, kør, genstarter, men der kommer ingen log, har kigget i combofix's mapper, men ingen log. Men kørte DDS istedet, så her kommer en log fra den . |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 17 Juli 2012 at 12:29 |
|
Prøv at afinstallere ComboFix ved at gå til Start - skriv Kør - og i "Kør-tekstfeltet" skrive combofix /uninstall - og klikke OK.
Hent derefter en ny og prøv igen. Hvis det ikke virker, så hent og kør OTL i stedet: http://oldtimer.geekstogo.com/OTL.exe
|
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 19 Juli 2012 at 01:52 |
|
Hej
Undskyld at jeg ikke har sendt logs endnu, men har ikke kunnet få fat på ejeren.
|
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 19 Juli 2012 at 07:53 |
|
Helt i orden
![]() |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 19 Juli 2012 at 19:41 |
|
Hej OTL logfile created on: 19-07-2012 19:27:59 - Run 1 |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 19 Juli 2012 at 19:43 |
|
OTL Extras logfile created on: 19-07-2012 19:27:59 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Per Nygaard Olesen\Documents\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy 4,00 Gb Total Physical Memory | 2,89 Gb Available Physical Memory | 72,23% Memory free 7,99 Gb Paging File | 6,83 Gb Available in Paging File | 85,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 452,97 Gb Total Space | 123,23 Gb Free Space | 27,21% Space Free | Partition Type: NTFS Drive D: | 79,04 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: PERNYGAARDOLESE | User Name: Per Nygaard Olesen | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl[@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "UpdatesDisableNotify" = 0 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{021AB714-45BD-4D0F-8811-38E4522845E2}" = rport=445 | protocol=6 | dir=out | app=system | "{10946055-E926-4155-B617-0C77694F4723}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{14104414-8CEB-4D54-8F1E-0CE1DDAFEE5C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{188FA1A4-75A6-4D1A-BEC1-7CCA23BDB186}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{203A79FC-7685-4943-A937-D9D94A13D2C5}" = rport=138 | protocol=17 | dir=out | app=system | "{251DDEE8-6246-48FE-8E41-06EDFDAF2277}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3BE75A32-5D4D-4FBB-BCB1-3D0907CECBC6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{4AB7EF3B-C50C-45E9-9F0E-CD5E0A7843E0}" = rport=137 | protocol=17 | dir=out | app=system | "{4FD81208-F6C1-454B-8F7D-06EEE60B6142}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{5A641962-ECD6-42F0-90C8-369DC5F93642}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{5F0FB1B8-54A2-4242-9EFE-309611391693}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6C7E0AC8-F509-450D-A9FC-E5DF3DCFC296}" = lport=137 | protocol=17 | dir=in | app=system | "{6CB2FCC4-D1B7-4B63-B0F1-C6A5C58D8E28}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8552D73F-6EF3-4B17-9B18-1EA6382C0176}" = lport=2869 | protocol=6 | dir=in | app=system | "{B338472A-BF4B-4D85-9693-A20668352CA7}" = rport=139 | protocol=6 | dir=out | app=system | "{B8932147-D17F-4B1F-BC53-E36C331657DC}" = lport=139 | protocol=6 | dir=in | app=system | "{BC95E523-FE19-41AC-81E2-FE9ADAADB9C9}" = lport=138 | protocol=17 | dir=in | app=system | "{C86D2F28-B28C-4909-A638-92A450839DCC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D55A5EB3-1AB5-4542-97C2-FC317AB214E3}" = lport=445 | protocol=6 | dir=in | app=system | "{DD554F3E-6FB2-4B65-B4C1-6BF8815B9881}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E7FA0CC2-3144-4AEB-87D3-91EC9EACDA4B}" = lport=2869 | protocol=6 | dir=in | app=system | "{ED5440DE-C073-43C4-B7EF-742ABA692AFF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{F6E7DD59-9E33-45F3-9583-32A9E9B91DD9}" = lport=10243 | protocol=6 | dir=in | app=system | "{FBE58778-457E-4586-9715-19D0C9D9D2C6}" = rport=10243 | protocol=6 | dir=out | app=system | "{FC63199E-03AF-4398-A0F0-DDADF0038273}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{097FFCAD-8F95-4812-9E0F-7396EA3EE3A4}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | "{190EE5DF-E210-4518-88C0-C2245B99FC50}" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe | "{1A0D503C-4197-4590-B16F-6851D574F6D5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{1AD98166-2AE9-498C-8093-78C0B0D5B494}" = protocol=6 | dir=out | app=system | "{1C8276D2-936C-4AD8-B33D-20BC316AEB66}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{259A4079-5983-482A-A632-15C6F6F472AD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{28EBC097-8B4B-456B-B36F-2F4F8D7B8714}" = protocol=17 | dir=in | app=c:\program files (x86)\sony ericsson\update engine\sony ericsson update engine.exe | "{2A184ADB-6F4E-4180-89C1-D6956FACFBCC}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{329D47A2-E689-46F2-A404-111DA5D7F59B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{363D86BD-9064-4F83-A533-F21BABC4F495}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{3761289E-6727-4EA5-90A8-80964FB363A2}" = protocol=6 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{3B4FB919-A408-45EF-9881-AEF65258F73C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{3E803A62-1A55-4B0F-8F30-3869B3E5C597}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{4FA6EBD9-7A81-4249-B1E0-2AD88B7B651B}" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\mediabar\datamngr\toolbar\dtuser.exe | "{516EF422-45CB-4F57-8E14-3D15CBCD5A4A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{648527A8-4EC8-4205-A369-878661BC0E7B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{68A35C91-C509-43C7-9F9E-78B8264321BB}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "{712161B1-11FC-4EB2-A48F-6A6E4D82C8EE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{7CE5CD3C-7AD2-444B-8C1D-82E19A038632}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{8255416C-34A0-4C80-AE6E-E085D513C403}" = protocol=6 | dir=in | app=c:\program files (x86)\sony ericsson\update engine\sony ericsson update engine.exe | "{8AD553B1-63F0-4F13-B234-5BB780D826B0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{8B94FDA4-A802-4D0B-A50B-E21FD1EE1B16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8C4A1B94-6990-4639-A4CE-7C00D277CF4A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{8D8FA73D-266D-495F-81DB-BAC0AECA4187}" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe | "{8F761119-37D6-4937-9883-ABC5873FFE59}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{90FAB182-4DFF-4D79-92B7-B9D887FB2CEA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{94273EF5-D594-46DA-A413-B20D69B5C919}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{97C651BC-9750-4084-85AB-6E46605E42D1}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{9D3DE7C5-CECF-4B9A-9D25-DCF7D58D0982}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{9FF2EED9-C408-459F-B0A9-070B62D64721}" = protocol=17 | dir=in | app=c:\program files (x86)\windows searchqu toolbar\datamngr\toolbar\dtuser.exe | "{A1336016-F413-4F51-9105-73B8D41E428E}" = protocol=6 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{AE30D8DE-0AFF-44B7-8603-0C8F94B4F1AA}" = protocol=17 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{B011A881-2D0B-4C12-A58A-629BF4BD6074}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B0D9A2CF-BBDF-43FA-8258-720FC59C644A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{B5A052FA-0974-467B-84F3-ED9A7DDE617E}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{C6134BAF-A8F7-4F22-8E4A-0AA42EB15202}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{CD8A4C07-751F-4EC7-B171-9E190CAC228B}" = protocol=17 | dir=in | app=c:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe | "{D0C5C1E7-4152-4F82-B635-C2DCA21B9463}" = protocol=6 | dir=in | app=c:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe | "{DD398451-2859-4E68-B987-ABEF8ABAE09F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{DFCE84F5-75F5-44FD-9B3D-89039D75AD04}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe | "{F118A7D3-7939-439D-937F-1B37240AD1EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{F545EA57-428F-4195-8B72-7FFB1931B367}" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\mediabar\datamngr\toolbar\dtuser.exe | "{FC0F2AA6-F0F5-4B0B-8B65-0C1A1AB06E67}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | "TCP Query User{297127A3-DAF6-4EF4-A49F-4F8A02B02D68}C:\users\per nygaard olesen\appdata\local\directdownloader\directdownloader.exe" = protocol=6 | dir=in | app=c:\users\per nygaard olesen\appdata\local\directdownloader\directdownloader.exe | "TCP Query User{480B3FA2-4516-4FA7-B2C6-C5C9DEFE5516}C:\program files (x86)\torrentsearch\easydownload.exe" = protocol=6 | dir=in | app=c:\program files (x86)\torrentsearch\easydownload.exe | "TCP Query User{4D9EC00A-1EF4-4D0A-AA6C-FAD628181213}C:\program files (x86)\imesh applications\imesh\imesh.exe" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe | "TCP Query User{6E47D19B-0F05-4338-823D-6A7E99D9CB7C}C:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe | "TCP Query User{876CB776-4766-4562-AA6D-9CE740D0099F}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{0D09E713-40BE-4960-904C-72CD0E413CB8}C:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\per nygaard olesen\appdata\roaming\spotify\spotify.exe | "UDP Query User{30395546-1A20-4FEF-A46B-DF8D43B23CDF}C:\program files (x86)\imesh applications\imesh\imesh.exe" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe | "UDP Query User{53DFC287-2D75-4B29-9CDC-7A2EFD62D9CA}C:\users\per nygaard olesen\appdata\local\directdownloader\directdownloader.exe" = protocol=17 | dir=in | app=c:\users\per nygaard olesen\appdata\local\directdownloader\directdownloader.exe | "UDP Query User{72BB0990-C691-43C0-9109-E238FD31E04E}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{F42DE7E0-0381-473A-B924-31B1CDAB7131}C:\program files (x86)\torrentsearch\easydownload.exe" = protocol=17 | dir=in | app=c:\program files (x86)\torrentsearch\easydownload.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver "{A0158415-15CA-B2A0-928D-E755DD506C0D}" = ATI Catalyst Install Manager "{AD136254-E6F2-EAE8-7E36-9D65E13B0A7E}" = ccc-utility64 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{CE6D49CE-ED18-47E1-8449-037BC7181450}" = Windows Live Family Safety "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources "{F83E9BF0-B8D8-3D68-9E07-7505290C2202}" = Microsoft .NET Framework 4 Client Profile DAN Language Pack "CCleaner" = CCleaner "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DAN Language Pack" = Microsoft .NET Framework 4 Client Profile DAN sprogpakke [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh "{01A1F857-F5C6-0842-333A-FA7806FAF70A}" = CCC Help Danish "{038EBE9A-2AD4-9B6D-C7FB-377FF5112C16}" = CCC Help Swedish "{08840099-3121-798D-88BB-76C5087890AF}" = CCC Help Czech "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1D7E84F5-7AA3-CD1F-3EA1-975313E9293A}" = CCC Help Portuguese "{1ED4CA4A-2ABA-9302-D7F3-A0597294828B}" = Catalyst Control Center Graphics Light "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{22037905-EB4C-3427-DD8C-6ABBBE306B0D}" = CCC Help Polish "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{284B8BD0-0046-288F-79E3-160F17D18904}" = CCC Help Spanish "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{2B33E393-D2DE-E00C-95A2-96AB49FC2DBB}" = CCC Help Norwegian "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{37E6B486-08A4-3383-29BB-BD0591BD0E9D}" = Catalyst Control Center Core Implementation "{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management "{401F4EB7-FDF4-1B7A-54F6-5EE7CF0C0F8F}" = CCC Help Chinese Standard "{414C790F-E24E-461B-983A-2AD84474DE4B}_is1" = Media Finder 1.0.9.23 "{427DB714-23EF-6CBC-4DD1-015674AF8AB7}" = CCC Help Finnish "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery "{4493F494-3E4D-E35C-BF37-1EF22539DCE3}" = CCC Help Korean "{45A2D49C-8124-4015-A8B3-073A827EC5C1}" = Windows Live Sync "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B744C85-DBB1-4038-B989-4721EB22C582}" = Windows Live Messenger "{51F026FA-5146-4232-A8BA-1364740BD053}" = Acer Crystal Eye webcam "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser "{573EC8CA-E2FD-B1F7-4DAB-671AD39888A7}" = CCC Help Japanese "{5869CFDE-54D8-D3F1-A8F5-4FCA8A910BFB}" = Catalyst Control Center Graphics Previews Common "{5B5CF192-F4BB-A213-CE03-7C8FB7A5E3E2}" = Catalyst Control Center Graphics Full New "{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR "{679A43C5-1A03-CF8F-B73E-C4A095C2687D}" = CCC Help French "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6DA399FC-350F-41AC-8CA6-B9F8496753BE}_is1" = Media Finder 1.0.9.29 "{703A59AA-E839-47BF-90BE-932A15B2D216}" = Drive 3 professional KatBS "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite "{781E0319-15CD-4A4C-A47E-D9FFF697E7A1}" = Messenger Companion "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7B037B61-22B4-C382-DCD9-05DB38D1149D}" = CCC Help Italian "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management "{81E6A85A-EF55-F1F4-3CBB-BE01F03CE3F3}" = CCC Help Hungarian "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8D705770-8266-3A59-3AD8-6E666EC4CF77}" = CCC Help Thai "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{93884E34-FD8F-46A9-A4D4-402868A5D51F}_is1" = CopyToDVD "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9B379492-5FDE-4483-9CEE-4E9CA23EF237}" = Linkury Smartbar "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9E0FC21F-1DC1-0B4C-E8E0-74420102C75B}" = CCC Help Chinese Traditional "{A479E320-40DB-BDA6-6CEB-A08C9DEDE80C}" = ccc-core-static "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{ABEE079E-648E-488B-8301-0C3DB48C1BCE}_is1" = Acer GameZone Console "{B1B7FDAA-9DC3-2408-18B2-9B4CB8CF0F80}" = CCC Help German "{B3A4B5A9-C9CA-7C40-F58A-9BC514BAC3BA}" = Socialbox "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{BCFDADA0-04B1-6335-6362-BB854A216C23}" = CCC Help Russian "{C214A856-F569-0065-714F-8D2A4A092C6C}" = CCC Help Turkish "{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder "{C2B9C70F-165E-450D-9EC1-F7B160016291}" = Living 3D Dolphin "{C9413C02-2978-BC8B-D67C-6FF88ADBD1A3}" = CCC Help English "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery "{D0485C2A-6BED-4E6A-8517-A1ED3F990AB2}" = Catalyst Control Center Graphics Full Existing "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D78667E4-E8EB-2B30-5029-29B9C3367B85}" = CCC Help Dutch "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker "{DB17E288-610C-45DC-E160-E7EB09A1FA88}" = Catalyst Control Center Localization All "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E45E3860-CDA5-93DF-8DAA-9AC4E556BF11}" = CCC Help Greek "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10 "{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.079 "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F623B2D2-9070-FF31-F47A-287802544F71}" = Catalyst Control Center InstallProxy "{FC635D8E-FFBA-4B2C-BE68-A37D56BDFB74}" = Catalyst Control Center - Branding "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "1ClickDownload" = 1ClickDownloader "Acer Registration" = Acer Registration "Acer Screensaver" = Acer ScreenSaver "Acer Welcome Center" = Welcome Center "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Burn My Files_is1" = Burn My Files "com.socialbox.socialbox" = Socialbox "Doxillion" = Doxillion Document Converter "DVDFab 8 Qt_is1" = DVDFab 8.1.8.5 (24/05/2012) Qt "ESET Online Scanner" = ESET Online Scanner v3 "ExpressZip" = Express Zip File Compression Software "Google Chrome" = Google Chrome "Graboid Video" = Graboid Video 3.12 "Identity Card" = Identity Card "InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9 "LManager" = Launch Manager "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300 "Optimizer Pro_is1" = Optimizer Pro v3.0 "PhotoPad" = PhotoPad Image Editor "Pixillion" = Pixillion Image Converter "PriceGong" = PriceGong 2.6.4 "Prism" = Prism Video File Converter "RewardsArcade" = RewardsArcade "Translator_3.1 Toolbar" = Translator 3.1 Toolbar "Update Engine" = Sony Ericsson Update Engine "uTorrent" = µTorrent "uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar "vfd-ob" = VideoFileDownload "VideoPerformer" = VideoPerformer "Vuze_Remote Toolbar" = Vuze Remote Toolbar "WavePad" = WavePad Sound Editor "Wincore MediaBar" = Wincore MediaBar "WinLiveSuite" = Windows Live Essentials "WiseConvert Toolbar" = WiseConvert Toolbar "wxDownload Fast_is1" = wxDownload Fast 0.6.0 ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "DirectDownloader" = DirectDownloader "fTalk" = fTalk "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 13-07-2012 20:18:59 | Computer Name = PerNygaardOlese | Source = Application Error | ID = 1000 Description = Navn på program med fejl: easydownload.exe, version: 0.0.0.0, tidsstempel: 0x4b1ae3c6 Navn på modul med fejl: InstallOptions.dll, version: 0.0.0.0, tidsstempel: 0x4b1ae3a4 Undtagelseskode: 0xc0000005 Forskydning med fejl 0x00001235 Proces-id 0xc90 Programmets starttidspunkt 0x01cd61563ea5e11b Programsti: C:\Program Files (x86)\TorrentSearch\easydownload.exe Modulsti: C:\Users\PERNYG~1\AppData\Local\Temp\nsb470F.tmp\InstallOptions.dll Rapport-id: 818917cf-cd49-11e1-bce9-a89a70f98afe Error - 13-07-2012 20:24:59 | Computer Name = PerNygaardOlese | Source = Application Error | ID = 1000 Description = Navn på program med fejl: easydownload.exe, version: 0.0.0.0, tidsstempel: 0x4b1ae3c6 Navn på modul med fejl: InstallOptions.dll, version: 0.0.0.0, tidsstempel: 0x4b1ae3a4 Undtagelseskode: 0xc0000005 Forskydning med fejl 0x00001235 Proces-id 0xc48 Programmets starttidspunkt 0x01cd6157160a83cf Programsti: C:\Program Files (x86)\TorrentSearch\easydownload.exe Modulsti: C:\Users\PERNYG~1\AppData\Local\Temp\nsyC958.tmp\InstallOptions.dll Rapport-id: 5804b6a9-cd4a-11e1-bce9-a89a70f98afe Error - 13-07-2012 20:27:26 | Computer Name = PerNygaardOlese | Source = Application Error | ID = 1000 Description = Navn på program med fejl: easydownload.exe, version: 0.0.0.0, tidsstempel: 0x4b1ae3c6 Navn på modul med fejl: InstallOptions.dll, version: 0.0.0.0, tidsstempel: 0x4b1ae3a4 Undtagelseskode: 0xc0000005 Forskydning med fejl 0x00001235 Proces-id 0x3b4 Programmets starttidspunkt 0x01cd61576cfeda11 Programsti: C:\Program Files (x86)\TorrentSearch\easydownload.exe Modulsti: C:\Users\PERNYG~1\AppData\Local\Temp\nsz31D.tmp\InstallOptions.dll Rapport-id: afa024cd-cd4a-11e1-bce9-a89a70f98afe Error - 13-07-2012 20:43:09 | Computer Name = PerNygaardOlese | Source = MsiInstaller | ID = 11706 Description = Error - 13-07-2012 20:43:24 | Computer Name = PerNygaardOlese | Source = MsiInstaller | ID = 11706 Description = Error - 14-07-2012 04:08:50 | Computer Name = PerNygaardOlese | Source = SideBySide | ID = 16842832 Description = Det lykkedes ikke at oprette aktiveringskontekst for "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Der opstod fejl i manifest- eller politikfilen "" på linje . En komponentversion, der er påkrævet af programmet, er i konflikt med en anden komponentversion, der allerede er aktiv. Komponenter i konflikt er:. Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error - 14-07-2012 15:07:48 | Computer Name = PerNygaardOlese | Source = MsiInstaller | ID = 11706 Description = Error - 14-07-2012 15:07:58 | Computer Name = PerNygaardOlese | Source = MsiInstaller | ID = 11706 Description = Error - 14-07-2012 15:21:29 | Computer Name = PerNygaardOlese | Source = MsiInstaller | ID = 11706 Description = Error - 14-07-2012 16:03:18 | Computer Name = PerNygaardOlese | Source = Application Hang | ID = 1002 Description = Programmet iexplore.exe version 9.0.8112.16447 afbrød kommunikationen med Windows og blev afsluttet. Hvis du vil se, om der findes flere oplysninger om problemet, kan du læse om problemets historik via Løsningscenter. Proces-id: 13c8 Starttidspunkt: 01cd61fba4436c26 Afslutningstidspunkt: 34 Programsti: C:\Program Files (x86)\Internet Explorer\iexplore.exe Rapport-id: Error - 14-07-2012 18:30:24 | Computer Name = PerNygaardOlese | Source = SideBySide | ID = 16842832 Description = Det lykkedes ikke at oprette aktiveringskontekst for "c:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe". Der opstod fejl i manifest- eller politikfilen "" på linje . En komponentversion, der er påkrævet af programmet, er i konflikt med en anden komponentversion, der allerede er aktiv. Komponenter i konflikt er:. Komponent 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponent 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. [ Media Center Events ] Error - 17-05-2012 18:37:43 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 00:37:43 - Det lykkedes ikke at hente Directory. Fejl: Invalid security token. Error - 17-05-2012 18:42:14 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 00:40:34 - Det lykkedes ikke at hente MCEClientUX. Fejl: Den underliggende forbindelse blev lukket: Der opstod en uventet fejl ved modtagelse.. Error - 17-05-2012 18:43:59 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 00:43:54 - Det lykkedes ikke at hente Broadband. Fejl: Handlingen fik timeout Error - 17-05-2012 19:44:03 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 01:44:03 - Det lykkedes ikke at hente Directory. Fejl: Anmodningen mislykkedes med HTTP-status 401: Unauthorized. Error - 17-05-2012 19:44:05 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 01:44:05 - Det lykkedes ikke at hente MCEClientUX. Fejl: Anmodningen mislykkedes med HTTP-status 401: Unauthorized. Error - 17-05-2012 19:44:07 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 01:44:06 - Det lykkedes ikke at hente Broadband. Fejl: Anmodningen mislykkedes med HTTP-status 401: Unauthorized. Error - 17-05-2012 20:44:18 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 02:44:17 - Det lykkedes ikke at hente UpdateableMarkup-2.cab. Fejl: HTTP status 404: Den URL, der blev anmodet om, findes ikke på serveren. Error - 17-05-2012 21:47:43 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 03:47:42 - Det lykkedes ikke at hente MCEClientUX. Fejl: Handlingen fik timeout Error - 28-05-2012 03:19:26 | Computer Name = PerNygaardOlese | Source = MCUpdate | ID = 0 Description = 09:19:25 - Det lykkedes ikke at hente MCEClientUX. Fejl: Anmodningen mislykkedes med HTTP-status 503: Service Unavailable. [ System Events ] Error - 19-07-2012 10:05:43 | Computer Name = PerNygaardOlese | Source = bowser | ID = 8003 Description = Error - 19-07-2012 10:17:43 | Computer Name = PerNygaardOlese | Source = bowser | ID = 8003 Description = Error - 19-07-2012 11:03:04 | Computer Name = PerNygaardOlese | Source = EventLog | ID = 6008 Description = Den foregående systemlukning kl. 17:00:10 d. ?19-?07-?2012 var uventet. Error - 19-07-2012 11:03:07 | Computer Name = PerNygaardOlese | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Det trådløse udvidelsesmodul kunne ikke startes. Modulsti: C:\Windows\system32\athExt.dll Fejlkode: 126 Error - 19-07-2012 11:03:07 | Computer Name = PerNygaardOlese | Source = Service Control Manager | ID = 7023 Description = Tjenesten Windows Defender blev afbrudt med følgende fejl: %%126 Error - 19-07-2012 11:08:41 | Computer Name = PerNygaardOlese | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Det trådløse udvidelsesmodul kunne ikke startes. Modulsti: C:\Windows\system32\athExt.dll Fejlkode: 126 Error - 19-07-2012 11:18:07 | Computer Name = PerNygaardOlese | Source = Service Control Manager | ID = 7030 Description = Tjenesten PEVSystemStart er markeret som en interaktiv tjeneste. Systemet er dog konfigureret til ikke at tillade interaktive tjenester. Denne tjeneste fungerer muligvis ikke korrekt. Error - 19-07-2012 11:21:41 | Computer Name = PerNygaardOlese | Source = Service Control Manager | ID = 7030 Description = Tjenesten PEVSystemStart er markeret som en interaktiv tjeneste. Systemet er dog konfigureret til ikke at tillade interaktive tjenester. Denne tjeneste fungerer muligvis ikke korrekt. Error - 19-07-2012 11:40:18 | Computer Name = PerNygaardOlese | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000 Description = Det trådløse udvidelsesmodul kunne ikke startes. Modulsti: C:\Windows\system32\athExt.dll Fejlkode: 126 Error - 19-07-2012 11:40:22 | Computer Name = PerNygaardOlese | Source = Service Control Manager | ID = 7023 Description = Tjenesten Windows Defender blev afbrudt med følgende fejl: %%126 < End of report > |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 19 Juli 2012 at 21:52 |
|
Jeg vil anbefale, at du afinstallerer iMesh (fildeling), Optimizer Pro, Socialbox og Mediafinder.
Start OTL ved at højreklikke på OTL og vælg - Kør som Administrator. Kopier nedenstånde med fed skrift ind i feltet “Custom Scans/Fixes” :Files C:\Program Files (x86)\iMesh Applications\MediaBar C:\Program Files (x86)\Media Finder C:\Program Files (x86)\Optimizer Pro C:\torrent.exe :OTL IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=1&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=58&systemid=2&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=341&systemid=406&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=410&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=421&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=331121&systemid=426&sr=0&q={searchTerms} IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2431}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutCzz0FyEyC0AtC0BtC0FtD0A0B0C0D0AtN0D0TzutBtDtCtBtDyCtByB&cr=932070906 IE:64bit: - HKLM\..\SearchScopes\{CB03958E-0F7B-4EBD-8932-76E262BB598F}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutCzz0FyEyC0AtC0BtC0FtD0A0B0C0D0AtN0D0TzutBtDtCtBtDyDtBzy&cr=1383126692 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startsearcher.com IE - HKLM\..\URLSearchHook: {3eec3c07-13c6-4b41-87c6-40b425a0b0a2} - No CLSID value found IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {CB03958E-0F7B-4EBD-8932-76E262BB598F} IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{0DCCE3E2-3B2A-B5FC-7262-15311048F93C}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=128&systemid=431&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB IE - HKLM\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{7B85464E-98A5-205E-B0F1-47BE032CC381}: "URL" = http://search.toggle.com/?lang=da&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=1&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=58&systemid=2&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=410&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=421&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=331121&systemid=426&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2431}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutCzz0FyEyC0AtC0BtC0FtD0A0B0C0D0AtN0D0TzutBtDtCtBtDyCtByB&cr=932070906 IE - HKLM\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XPman000&ptnrS=XPman000&ptb=3E70BB1C-7231-4DAC-897D-B669009879E0&psa=&ind=2012060718&st=sb&n=77ed9c2e&searchfor={searchTerms} IE - HKLM\..\SearchScopes\{CB03958E-0F7B-4EBD-8932-76E262BB598F}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutCzz0FyEyC0AtC0BtC0FtD0A0B0C0D0AtN0D0TzutBtDtCtBtDyDtBzy&cr=1383126692 IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DK&userid=e4c44a96-dc5f-40b9-9fd3-0b5220c49ab8&affid=110774&searchtype=hp&babsrc=lnkry_nt IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Per Nygaard Olesen\Downloads\X-Men First Class 2011 R5 LiNE READNFO XViD - IMAGiNE IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3196716 IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DK&userid=e4c44a96-dc5f-40b9-9fd3-0b5220c49ab8&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DK&userid=e4c44a96-dc5f-40b9-9fd3-0b5220c49ab8&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes,Backup.Old.DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IE IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{0DCCE3E2-3B2A-B5FC-7262-15311048F93C}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=DK&userid=e4c44a96-dc5f-40b9-9fd3-0b5220c49ab8&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&babsrc=SP_ss&mntrId=fc14bcda00000000000018f46a1b1f0a IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IE IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{3E31FAB8-FAFA-438C-9403-FD0F6B2286D2}: "URL" = http://dk.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20120416,0,0,0,0 IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{4C806E0C-1C55-49A7-B469-EF45716E76BF}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3196716 IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{70BA3E6B-1059-2266-0B2C-40E4A85231B8}: "URL" = http://www.ddlstart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=750&product_id=872&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=DK&install_date=20120714&user_guid=B4F3B0107DDA4BC6B1D0441752532364&machine_id=09fab60729ec16eef3270901bc96569b&browser=IE&os=win&os_version=6.1-x64-SP1&iesrc={referrer:source} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{73ccfd25-abe2-4bdf-ac5d-28a470a4d234}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=&src=crm&q={searchTerms}&locale= IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={F33C0D91-4D76-4887-8074-96B557DD71BE}&mid=30e34ae0807e47d08a0d2a01a70b1e18-1b4bb1d9d8d9596888a52772ae612d66e73517b2&lang=da&ds=AVG&pr=fr&d=2012-06-14 06:37:04&v=10.0.0.7&sap=dsp&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=1&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=58&systemid=2&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IE IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=410&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2421}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=101&systemid=421&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=331121&systemid=426&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2431}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=128&systemid=431&sr=0&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XPman000&ptnrS=XPman000&ptb=3E70BB1C-7231-4DAC-897D-B669009879E0&psa=&ind=2012060718&st=sb&n=77ed9c2e&searchfor={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD}: "URL" = http://www.ask.com/web?l=dis&o=16552&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^US&apn_ptnrs=^A9T&apn_uid=2405993292344300&p2=^A9T^YYYYYY^YY^US&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{CB03958E-0F7B-4EBD-8932-76E262BB598F}: "URL" = http://search.toggle.com/?lang=da&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb139/?search={searchTerms}&loc=IB_DS&a=6OyyYlxxl3&i=26 IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\{E74F4F6D-3C25-49AA-83E4-FCBCCC924285}: "URL" = http://start.funmoods.com/results.php?f=4&a=irtest1&q={searchTerms} IE - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\SearchScopes\Google: "URL" = http://www.google.com/search?sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&q=%s FF - HKLM\Software\MozillaPlugins\@ei.TelevisionFanatic.com/Plugin: C:\Program Files (x86)\TelevisionFanaticEI\Installr\e.bin\NP64EISB.dll File not found FF - HKLM\Software\MozillaPlugins\@ei.VideoScavenger_1e.com/Plugin: C:\Program Files (x86)\VideoScavenger_1eEI\Installr\9.bin\NP1eEISB.dll File not found CHR - homepage: http://search.imesh.net CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&appid=0&systemid=1&sr=0&q={searchTerms} CHR - default_search_provider: suggest_url = CHR - plugin: 2YourFace Util (Enabled) = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmblfngognklgemafekefcdjcnkdhmdm\1.0_0\2YourFace_Util.dll CHR - plugin: Download Helper (Enabled) = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai\1.1.0_0\plugin/download_helper.dll CHR - plugin: Fun Web Products Plugin Stub (Enabled) = C:\Program Files (x86)\FunWebProducts\Installr\1.bin\NPFunWeb.dll CHR - plugin: TelevisionFanatic Installer Plugin Stub (Enabled) = C:\Program Files (x86)\TelevisionFanaticEI\Installr\d.bin\NP64EISB.dll CHR - plugin: VideoScavenger Installer Plugin Stub (Enabled) = C:\Program Files (x86)\VideoScavenger_1eEI\Installr\8.bin\NP1eEISB.dll CHR - Extension: Bcool = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0\ CHR - Extension: PriceGong = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.5_0\ CHR - Extension: YouTube = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: FunDial = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\ CHR - Extension: Google-sgning = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: General Crawler = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\ CHR - Extension: Funmoods = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.6.0_0\ CHR - Extension: Funmoods = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.6.0_0\funmoods\ CHR - Extension: SweetIM for Facebook = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0\Copy of CHR - Extension: SweetIM for Facebook = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0\ CHR - Extension: Media Finder plugin = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai\1.1.0_0\ CHR - Extension: FBPHOTOZOOM = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid\1.9_0\ CHR - Extension: Bcool = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnkkfjdnhgkjefnnohgfackfninikjo\1.0_0\ CHR - Extension: uTorrentControl2 = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\ CHR - Extension: GoPhoto.it = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.1_0\ CHR - Extension: Gmail = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: OneClickDownload = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.0\ CHR - Extension: Bcool = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhcekcffkpnaednoeoegnmnjdlnjjmg\1.0_0\ CHR - Extension: PriceGong = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.5_0\ CHR - Extension: FunDial = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\ CHR - Extension: General Crawler = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\ CHR - Extension: Funmoods = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.6.0_0\ CHR - Extension: Funmoods = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.6.0_0\funmoods\ CHR - Extension: SweetIM for Facebook = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0\Copy of CHR - Extension: SweetIM for Facebook = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0\ CHR - Extension: Media Finder plugin = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai\1.1.0_0\ CHR - Extension: FBPHOTOZOOM = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid\1.9_0\ CHR - Extension: Bcool = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnkkfjdnhgkjefnnohgfackfninikjo\1.0_0\ CHR - Extension: uTorrentControl2 = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\ CHR - Extension: GoPhoto.it = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.1_0\ CHR - Extension: OneClickDownload = C:\Users\Per Nygaard Olesen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco\1.0\ O2:64bit: - BHO: (Plugin for Media Finder) - {AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} - C:\Users\Per Nygaard Olesen\AppData\Roaming\Media Finder\Extensions\IEPlugin64.dll (Media Finder) O2:64bit: - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\BROWSE~1.DLL (iMesh, Inc) O2 - BHO: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll () O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O2 - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\BROWSE~1.DLL (iMesh, Inc) O3:64bit: - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{37483b40-c254-4a72-bda4-22ee90182c1e} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{3eec3c07-13c6-4b41-87c6-40b425a0b0a2} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{88ac3cb6-596b-4217-964c-b6757ef9602d} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{d8215d9c-81ed-4e53-b420-bfcdbac4734d} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{ecce0073-a837-45a2-95b9-600420505f7e} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - !{EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll () O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000\..\Toolbar\WebBrowser: (uTorrentControl2 Toolbar) - {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O4:64bit: - HKLM..\Run: [mwlDaemon] File not found O4 - HKLM..\Run: [DATAMNGR] C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE (iMesh, Inc) O4 - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000..\Run: [Media Finder] C:\Program Files (x86)\Media Finder\Media Finder.exe (Media Finder) O4 - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro) O4 - HKU\S-1-5-21-2287247610-3281163716-1847787813-1000..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) O4 - Startup: C:\Users\Per Nygaard Olesen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Socialbox.lnk = C:\Program Files (x86)\Socialbox\Socialbox.exe () O8:64bit: - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html () O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html () [2012-07-19 17:12:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe [2012-07-19 17:12:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2012-07-19 17:12:23 | 000,000,000 | ---D | C] -- C:\ComboFix [2012-07-19 17:12:20 | 000,000,000 | ---D | C] -- C:\Qoobox [2012-07-19 17:11:06 | 004,582,475 | R--- | C] (Swearware) -- C:\Users\Per Nygaard Olesen\Documents\Desktop\ComboFix.exe [2012-07-19 11:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Socialbox [2012-07-14 02:37:17 | 000,000,000 | ---D | C] -- C:\Users\Per Nygaard Olesen\AppData\Roaming\Optimizer Pro [2012-07-14 02:35:23 | 000,000,000 | ---D | C] -- C:\Users\Per Nygaard Olesen\AppData\Local\DirectDownloader [2012-07-14 02:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxDownload Fast [2012-07-14 02:27:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\wxDownload Fast [2012-07-14 02:26:59 | 000,000,000 | ---D | C] -- C:\ProgramData\WxDFastUpdater [2012-07-14 02:22:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent [2012-07-14 02:09:46 | 000,000,000 | ---D | C] -- C:\ProgramData\OptimizerPro [2012-07-14 02:09:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro [2012-07-14 02:09:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Optimizer Pro [2012-07-14 02:07:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Media Finder [2012-07-14 01:52:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TorrentSearch [2012-07-01 23:13:15 | 000,000,000 | ---D | C] -- C:\Users\Per Nygaard Olesen\Documents\MyTorrents [2012-06-27 18:29:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gophoto.it [2012-06-23 15:51:04 | 000,000,000 | ---D | C] -- C:\Users\Per Nygaard Olesen\Documents\searchplugins [2012-07-19 18:25:00 | 000,000,384 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterRefreshTask.job [2012-07-19 18:25:00 | 000,000,376 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterRefreshTask.job [2012-07-19 17:41:04 | 000,000,997 | ---- | M] () -- C:\Users\Per Nygaard Olesen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Socialbox.lnk [2012-07-19 17:40:22 | 000,000,404 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterLogonTask.job [2012-07-19 17:40:22 | 000,000,396 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterLogonTask.job [2012-07-14 02:22:06 | 000,000,975 | ---- | M] () -- C:\Users\Per Nygaard Olesen\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [2012-07-14 02:22:06 | 000,000,951 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012-07-10 19:37:14 | 000,184,886 | ---- | M] () -- C:\torrent.exe [2012-06-27 18:29:06 | 000,302,425 | ---- | M] () -- C:\Users\Per Nygaard Olesen\AppData\Local\funmoods-speeddial.crx [2012-06-27 18:29:06 | 000,031,470 | ---- | M] () -- C:\Users\Per Nygaard Olesen\AppData\Local\funmoods.crx [2012-07-19 17:12:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2012-07-19 17:12:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2012-07-19 17:12:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2012-07-19 17:12:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2012-07-19 17:12:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2012-07-19 11:55:07 | 000,000,997 | ---- | C] () -- C:\Users\Per Nygaard Olesen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Socialbox.lnk [2012-07-14 02:27:00 | 000,000,404 | -H-- | C] () -- C:\Windows\tasks\WxDFastUpdaterLogonTask.job [2012-07-14 02:27:00 | 000,000,384 | -H-- | C] () -- C:\Windows\tasks\WxDFastUpdaterRefreshTask.job [2012-07-14 02:22:06 | 000,000,951 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012-07-14 02:09:48 | 000,000,376 | -H-- | C] () -- C:\Windows\tasks\OptimizerProUpdaterRefreshTask.job [2012-07-14 02:09:47 | 000,000,396 | -H-- | C] () -- C:\Windows\tasks\OptimizerProUpdaterLogonTask.job [2012-07-10 19:37:14 | 000,184,886 | ---- | C] () -- C:\torrent.exe [2012-07-01 11:32:40 | 000,000,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Socialbox.lnk [2012-06-23 15:50:53 | 000,000,044 | ---- | C] () -- C:\Users\Per Nygaard Olesen\Documents\Track01.cda [2012-05-29 16:55:21 | 000,302,425 | ---- | C] () -- C:\Users\Per Nygaard Olesen\AppData\Local\funmoods-speeddial.crx [2012-05-29 16:55:19 | 000,031,470 | ---- | C] () -- C:\Users\Per Nygaard Olesen\AppData\Local\funmoods.crx [2012-05-02 12:50:45 | 000,000,084 | ---- | C] () -- C:\Users\Per Nygaard Olesen\wxDownloadFast.ini :Commands [CREATERESTOREPOINT] [emptytemp] [Reboot] Luk alle andre åbne vinduer og klik på “Run Fix”. Efter genstart åbnes en logfil, kopier den herind i dit næste indlæg. Ellers ligger den her: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log Fortæl mig også, hvordan computeren kører…. |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 19 Juli 2012 at 23:50 |
|
Hej All processes killed |
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 20 Juli 2012 at 07:42 |
|
Det lyder godt - så mener jeg, at vi bør holde med rensning her. Næste trin bør være at installere en form for beskyttelse - eksempelvis MSE eller Avast. Hvis din kammerat er typen, der ikke kan lide beskyttelsesprogrammer, så vil jeg anbefale MSE, da den ikke forstyrrer og integrerer sig godt i Win7. Avast er også god, men jeg har på fornemmelsen, at din kammerat vil foretrække noget, der syner som en del af Windows. Du kunne også lægge ConnectSafe ind som DNS.
Jeg har ikke fjernet de downloadede film/torrents - som eksempelvis: Ice.Age.4.Continental.Drift.2012.CAM.XviD-HOPE Men.in.Black.3.2012.TS.NEW.SOURCE.XViD-26K savita_bhabhi_interview_with_the_film_star …, men det kan du jo gøre, hvis du vil. De kan være inficerede(?) Du kan afslutte oprydningen ved at køre OTL og klikke på "Clean up". Du kan også vente en uges tid og se om computeren fortsætter med at køre godt - og så lave den sidste oprydning. God fornøjelse ![]() |
|
![]() |
|
Black Power
Senior Member
Joined: 23 Marts 2010 Location: Denmark Status: Offline Points: 257 |
Posted: 21 Juli 2012 at 23:49 |
|
Okay
Så vil min ven og jeg gerne have lov til at sige mange tusind tak for din hjælp! Den er virkelig værdsat!
|
|
![]() |
|
forumforvalter
Admin Group
Boss Joined: 01 Oktober 2003 Status: Offline Points: 583 |
Posted: 22 Juli 2012 at 07:16 |
|
Det var så lidt
Jeg lukker - du laver bare en ny tråd, hvis der dukker spørgsmål op.
|
|
![]() |
|
Post Reply
|
|
|
Tweet
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |