DDS (Ver_10-03-17.01) - NTFSX64
Run by Christoffer at 1:21:40,44 on 2010-06-04
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.46.1053.18.4095.2673 [GMT 2:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
C:\Program Files (x86)\AVG\AVG9\avgam.exe
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\ProgramData\Google\Google Toolbar\Update\gtbFAC5.tmp.exe
C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Christoffer\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&m=imedia_s3720&r=173601109516p0355v1l5y48310451
uDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&m=imedia_s3720&r=173601109516p0355v1l5y48310451
mDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&m=imedia_s3720&r=173601109516p0355v1l5y48310451
mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=041d&m=imedia_s3720&r=173601109516p0355v1l5y48310451
mLocal Page = c:\windows\syswow64\blank.htm
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files (x86)\avg\avg9\toolbar\IEToolbar.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files (x86)\avg\avg9\avgssie.dll
BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files (x86)\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files (x86)\avg\avg9\toolbar\IEToolbar.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files (x86)\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AVG9_TRAY] c:\progra~2\avg\avg9\avgtray.exe
mRunOnce: [{054A0513-3E59-4c06-B932-D5A2EBF46C55}] "c:\programdata\google\google toolbar\update\gtbFAC5.tmp.exe" /au /sid:S-1-5-21-1135370957-644880291-2889927811-1000 /q /child
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files (x86)\avg\avg9\avgpp.dll
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
AppInit_DLLs-X64: avgrssta.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\christ~1\appdata\roaming\mozilla\firefox\profiles\xew522ux.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://se.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_se&p=
FF - component: c:\program files (x86)\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files (x86)\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files (x86)\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files (x86)\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files (x86)\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.27\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrw7a;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSwa.sys [2010-6-2 27144]
R0 AvgRkx64;avgrkx64.sys;c:\windows\system32\drivers\avgrkx64.sys [2010-6-2 56008]
R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\PxHlpa64.sys [2010-1-8 55024]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6a.sys [2010-6-2 29976]
R1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\system32\drivers\avgldx64.sys [2010-6-2 269320]
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\system32\drivers\avgmfx64.sys [2010-6-2 35536]
R1 AvgTdiA;AVG Network Redirector x64;c:\windows\system32\drivers\avgtdia.sys [2010-6-2 317520]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312]
R2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\avg\avg9\avgemc.exe [2010-6-2 916760]
R2 avg9wd;AVG WatchDog;c:\program files (x86)\avg\avg9\avgwdsvc.exe [2010-6-2 308064]
R2 avgfws9;AVG Firewall;c:\program files (x86)\avg\avg9\avgfws9.exe [2010-6-3 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files (x86)\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-6-2 5888008]
R2 Greg_Service;GRegService;c:\program files (x86)\packard bell\registration\GregHSRW.exe [2009-6-4 1150496]
R2 Updater Service;Updater Service;c:\program files\packard bell\packard bell updater\UpdaterService.exe [2009-8-15 240160]
R3 AVGIDSDriverw7a;AVG9IDSDriver;c:\program files (x86)\avg\avg9\identity protection\agent\driver\platform_win764\AVGIDSDriver.sys [2010-6-2 132616]
R3 AVGIDSFilterw7a;AVG9IDSFilter;c:\program files (x86)\avg\avg9\identity protection\agent\driver\platform_win764\AVGIDSFilter.sys [2010-6-2 35848]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-6-3 86120]
S2 gupdate;Tjänsten Google Update (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-1-29 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\avg\avg9\toolbar\ToolbarBroker.exe [2010-6-2 430152]
S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-3 1255736]
=============== Created Last 30 ================
2010-06-03 21:33:51 20 ----a-w- c:\windows\syswow64\SYSTEM
2010-06-03 03:11:57 14336 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-06-03 03:07:12 51712 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-06-03 03:07:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-06-03 02:47:26 0 d-----w- c:\windows\syswow64\Wat
2010-06-03 02:47:25 0 d-----w- c:\windows\system32\Wat
2010-06-03 02:42:03 78680 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-06-03 02:42:03 74072 ----a-w- c:\windows\syswow64\XAPOFX1_4.dll
2010-06-03 02:42:03 530776 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-06-03 02:42:03 528216 ----a-w- c:\windows\syswow64\XAudio2_6.dll
2010-06-03 02:42:02 238936 ----a-w- c:\windows\syswow64\xactengine3_6.dll
2010-06-03 02:42:02 176984 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-06-03 02:42:01 24920 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-06-03 02:42:01 22360 ----a-w- c:\windows\syswow64\X3DAudio1_7.dll
2010-06-03 02:38:53 0 d-----w- c:\windows\syswow64\directx
2010-06-03 02:16:48 86120 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2010-06-03 02:16:48 22528 ----a-w- c:\windows\system32\nvhdap64.dll
2010-06-03 02:15:27 0 d-----w- c:\program files (x86)\NVIDIA Corporation
2010-06-03 01:46:11 0 d-----w- c:\program files\TeamSpeak 3 Client
2010-06-02 06:41:17 12976 ----a-w- c:\windows\system32\avgrssta.dll
2010-06-02 06:41:16 27144 ----a-w- c:\windows\system32\drivers\AVGIDSwa.sys
2010-06-02 06:41:15 56008 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
2010-06-02 06:41:14 317520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2010-06-02 06:41:10 269320 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2010-06-02 06:41:08 35536 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2010-06-02 06:41:07 0 d-----w- c:\windows\system32\drivers\Avg
2010-06-02 06:41:04 0 d-----w- c:\programdata\AVG Security Toolbar
2010-06-02 06:39:33 29976 ----a-w- c:\windows\system32\drivers\avgfwd6a.sys
2010-06-02 06:17:45 294912 ----a-w- c:\windows\system32\browserchoice.exe
2010-06-02 05:29:58 5509008 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-02 05:29:57 3954568 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-06-02 05:29:57 3899280 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-06-02 05:28:11 716800 ----a-w- c:\windows\syswow64\jscript.dll
2010-06-02 05:27:45 12867072 ----a-w- c:\windows\syswow64\shell32.dll
2010-06-02 05:27:42 1446912 ----a-w- c:\windows\system32\lsasrv.dll
2010-06-02 05:27:41 96768 ----a-w- c:\windows\syswow64\sspicli.dll
2010-06-02 05:27:41 22016 ----a-w- c:\windows\syswow64\secur32.dll
2010-06-02 05:27:41 153160 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-06-02 05:25:11 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-06-02 05:25:11 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-06-02 05:25:10 464896 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-02 05:25:10 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-02 05:25:09 139264 ----a-w- c:\windows\system32\cabview.dll
2010-06-02 05:25:09 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-06-02 05:23:44 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-06-02 05:23:44 2048 ----a-w- c:\windows\system32\tzres.dll
2010-06-02 05:13:53 65536 --sha-w- c:\users\christoffer\ntuser.dat{885780cb-6e05-11df-95db-002511ab8a9f}.TM.blf
2010-06-02 05:13:53 524288 --sha-w- c:\users\christoffer\ntuser.dat{885780cb-6e05-11df-95db-002511ab8a9f}.TMContainer00000000000000000002.regtrans-ms
2010-06-02 05:13:53 524288 --sha-w- c:\users\christoffer\ntuser.dat{885780cb-6e05-11df-95db-002511ab8a9f}.TMContainer00000000000000000001.regtrans-ms
2010-05-29 17:57:30 0 d-----w- c:\program files (x86)\common files\Blizzard Entertainment
2010-05-29 11:05:08 0 d-----w- c:\program files\Microsoft Security Essentials
2010-05-05 08:48:36 524288 --sha-w- c:\users\christoffer\ntuser.dat{423fb040-5820-11df-960f-002511ab8a9f}.TMContainer00000000000000000002.regtrans-ms
2010-05-05 08:48:36 524288 --sha-w- c:\users\christoffer\ntuser.dat{423fb040-5820-11df-960f-002511ab8a9f}.TMContainer00000000000000000001.regtrans-ms
2010-05-05 08:48:35 65536 --sha-w- c:\users\christoffer\ntuser.dat{423fb040-5820-11df-960f-002511ab8a9f}.TM.blf
==================== Find3M ====================
2010-06-03 07:38:15 617232 ----a-w- c:\windows\system32\perfh01D.dat
2010-06-03 07:38:15 120596 ----a-w- c:\windows\system32\perfc01D.dat
2010-04-07 16:58:10 658536 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-04-03 16:42:00 159336 ----a-w- c:\windows\system32\nvvsvc.exe
2010-04-03 16:42:00 1515624 ----a-w- c:\windows\system32\nvsvcr.dll
2010-04-03 16:42:00 14828648 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 16:42:00 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 16:42:00 1067624 ----a-w- c:\windows\system32\nvsvc64.dll
2010-03-08 21:59:59 612352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 21:33:56 427520 ----a-w- c:\windows\syswow64\vbscript.dll
2009-10-20 10:00:23 37052 ----a-w- c:\windows\inf\perflib\041d\perfd.dat
2009-10-20 10:00:23 37052 ----a-w- c:\windows\inf\perflib\041d\perfc.dat
2009-10-20 10:00:23 294764 ----a-w- c:\windows\inf\perflib\041d\perfi.dat
2009-10-20 10:00:23 294764 ----a-w- c:\windows\inf\perflib\041d\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-06-11 15:12:00 776614 ----a-w- c:\program files (x86)\common files\packardbell.ico
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-02-03 10:35:19 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 05:12:52 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-01-26 13:43:44 245760 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 1:21:56,32 ===============