This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

yieldmanager ads

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear WhattheTech,

I am having issues with, what I believe to be, yieldmanager adware.
There are extra ads on certain sites that i browse (in firefox not in chrome).
The ads are either at the top of the screen or at the bottom right.
All ads come from yieldmanager sites that should not be there.

the log to my hijackthis is the following:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:07:33, on 2-7-2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Users\Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\G Data\TotalCare\GUI\GDSC.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe
C:\HiJackThis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ubvu.vu.nl/ubvu.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 64.191.17.101:8888
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: G Data WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\WebFilter\AvkWebIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: G Data WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\WebFilter\AvkWebIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Valentine\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: nmklo
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe
O23 - Service: G Data Filesystem Monitor (AVKWCtl) - G Data Software AG - C:\Program Files (x86)\G Data\TotalCare\AVK\AVKWCtlX64.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: G Data Backup Service (GDBackupSvc) - G Data Software AG - C:\Program Files (x86)\G Data\TotalCare\AVKBackup\AVKBackupService.exe
O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
O23 - Service: G Data Tuner Service (GDTunerSvc) - G Data Software AG - C:\Program Files (x86)\G Data\TotalCare\AVKTuner\AVKTunerService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11024 bytes

I hope I have given enough information, and I hope someone can help me.

Thanks in advance!

Valentine

p.s. (edit) I have ran Malwarebytes anti-malware, windows security essentials (which is on monitoring too) and g data totalcare. None find anything at the moment.
Hi

Please do the following:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Here's the output that I got back:


OTL logfile created on: 3-7-2010 21:52:35 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Valentine\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 73,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 71,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 466,12 Gb Free Space | 50,04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VALENTINE-PC
Current User Name: Valentine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Valentine\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
PRC - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe (G Data Software AG)
PRC - C:\Program Files (x86)\G Data\TotalCare\AVK\AVK.exe (G Data Software AG)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files (x86)\Last.fm\LastFM.exe (Last.fm)
PRC - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Valentine\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TeamViewer5) – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AVKProxy) – C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
SRV - (GDBackupSvc) – C:\Program Files (x86)\G Data\TotalCare\AVKBackup\AVKBackupService.exe (G Data Software AG)
SRV - (GDScan) – C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVKService) – C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe (G Data Software AG)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AVKWCtl) – C:\Program Files (x86)\G Data\TotalCare\AVK\AVKWCtlX64.exe (G Data Software AG)
SRV - (GDTunerSvc) – C:\Program Files (x86)\G Data\TotalCare\AVKTuner\AVKTunerService.exe (G Data Software AG)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009-07-14 05:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009-07-14 05:20:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (GRD) – C:\Windows\SysNative\drivers\GRD.sys (G Data Software)
DRV:64bit: - (GDBehave) – C:\Windows\SysNative\drivers\GDBehave.sys (G Data Software AG)
DRV:64bit: - (HookCentre) – C:\Windows\SysNative\drivers\HookCentre.sys (G Data Software AG)
DRV:64bit: - (GDMnIcpt) – C:\Windows\SysNative\drivers\MiniIcpt.sys (G Data Software AG)
DRV:64bit: - (gdwfpcd) – C:\Windows\SysNative\drivers\gdwfpcd64.sys (G DATA Software AG)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (DVDRIVER) – C:\Windows\SysNative\drivers\dvdriver.sys (Eagletron Inc.)
DRV:64bit: - (AtcL001) – C:\Windows\SysNative\drivers\l160x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LVUVC64) Logitech Webcam 500(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3E CF EE 46 00 ED CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.17.101:8888

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {b8d51471-15f1-46cd-a600-448a6b103c2d}:1.4.1
FF - prefs.js..extensions.enabledItems: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e}:0.6.4.1
FF - prefs.js..extensions.enabledItems: {d0dd74f3-16cc-0c20-d048-9958cfd14f32}:[removed]
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170633FE}:20.1.0.4
FF - prefs.js..network.proxy.autoconfig_url: "http://www.ubvu.vu.nl/ubvu.pac"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 3.6 Beta 4\components [2010-06-28 21:09:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 3.6 Beta 4\plugins [2010-06-28 21:09:20 | 000,000,000 | —D | M]

[2002-01-01 01:36:19 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Mozilla\Extensions
[2010-07-01 12:18:51 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Mozilla\Firefox\Profiles\dc9lrbgn.default\extensions
[2010-01-21 00:47:40 | 000,000,000 | —D | M] (Gmail Notifier) – C:\Users\Valentine\AppData\Roaming\Mozilla\Firefox\Profiles\dc9lrbgn.default\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
[2010-06-26 20:22:57 | 000,000,000 | —D | M] (RSFind! Mod) – C:\Users\Valentine\AppData\Roaming\Mozilla\Firefox\Profiles\dc9lrbgn.default\extensions\{b8d51471-15f1-46cd-a600-448a6b103c2d}

O1 HOSTS File: ([2010-05-01 19:14:17 | 000,001,392 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O2:64bit: - BHO: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIEx64.dll (G Data Software AG)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIE.dll (G Data Software AG)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIEx64.dll (G Data Software AG)
O3 - HKLM\..\Toolbar: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIE.dll (G Data Software AG)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe (G Data Software AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (nmklo) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O27:64bit: - HKLM IFEO\1: Debugger - C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\1: Debugger - C:\Windows\system32\svchost.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\Shell - "" = AutoRun
O33 - MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:64bit: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32:64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32:64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32:64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32:64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32:64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\Windows\SysWow64\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 90 Days ==========

[2010-07-01 23:58:33 | 000,000,000 | —D | C] – C:\HiJackThis
[2010-07-01 12:19:56 | 000,000,000 | —D | C] – C:\Users\Valentine\Tracing
[2010-07-01 12:12:44 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\New folder
[2010-07-01 10:59:20 | 000,106,224 | —- | C] (G Data Software) – C:\Windows\SysNative\drivers\GRD.sys
[2010-07-01 10:48:50 | 000,040,392 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\GDBehave.sys
[2010-07-01 10:48:29 | 000,049,096 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\HookCentre.sys
[2010-07-01 10:48:09 | 000,084,936 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\MiniIcpt.sys
[2010-07-01 10:48:06 | 000,048,584 | —- | C] (G DATA Software AG) – C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\ProgramData\G DATA
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\G Data
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\G Data
[2010-07-01 10:45:00 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Local\Downloaded Installations
[2010-07-01 10:25:23 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2010-06-30 03:00:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010-06-20 22:37:58 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010-06-20 14:58:25 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\WebDrive
[2010-06-20 14:57:06 | 000,000,000 | -H-D | C] – C:\ProgramData\WebDrive
[2010-06-20 14:56:52 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2010-06-20 14:55:05 | 000,000,000 | —D | C] – C:\Users\Valentine\Desktop\meeneemportfolio
[2010-06-19 02:31:34 | 000,000,000 | –SD | C] – C:\Users\Valentine\Documents\My Shapes
[2010-06-19 02:14:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2010-06-19 02:12:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2010-06-19 00:09:54 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\OneNote Notebooks
[2010-06-16 13:35:17 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\AVS4YOU
[2010-06-16 13:34:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2010-06-16 13:33:58 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2010-06-16 13:33:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2010-06-16 13:19:48 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Real
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Local\Real
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010-06-16 13:19:45 | 000,060,273 | —- | C] (Open Source Software community project) – C:\Windows\SysWow64\pthreadGC2.dll
[2010-06-15 17:55:54 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Ubisoft
[2010-06-15 17:55:54 | 000,000,000 | —D | C] – C:\ProgramData\Ubisoft
[2010-06-11 23:49:56 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Foxit Software
[2010-06-11 23:21:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Foxit Software
[2010-06-10 22:49:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010-06-07 15:00:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mass Effect 2
[2010-05-28 23:15:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\LogiShrd
[2010-05-28 23:15:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\LogiShrd
[2010-05-25 10:09:56 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010-05-25 10:09:56 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010-05-25 10:09:56 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010-05-25 10:08:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010-05-25 10:07:49 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010-05-25 10:07:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010-05-21 11:36:32 | 000,039,240 | —- | C] (Eagletron Inc.) – C:\Windows\SysNative\drivers\dvdriver.sys
[2010-05-21 11:36:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Eagletron
[2010-05-08 18:00:47 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2010-05-08 17:58:05 | 000,000,000 | —D | C] – C:\ATI
[2010-05-08 17:52:31 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\Settlers7
[2010-05-08 17:00:28 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010-05-08 17:00:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ubisoft
[2010-05-08 16:59:45 | 000,000,000 | —D | C] – C:\Users\Public\Documents\DAEMON Tools Images
[2010-05-05 13:14:13 | 000,000,000 | —D | C] – C:\Users\Valentine\Desktop\pics
[2010-04-28 21:04:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAEMON Tools Lite
[2010-04-28 16:34:59 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Malwarebytes
[2010-04-28 16:34:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-04-28 16:34:48 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010-04-28 16:34:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010-04-28 16:34:48 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010-04-28 16:15:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010-04-28 16:01:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010-04-22 13:20:17 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\Charley
[2010-04-07 04:13:00 | 000,455,168 | —- | C] (AMD) – C:\Windows\SysNative\atieclxx.exe
[2010-04-07 04:12:18 | 000,202,752 | —- | C] (AMD) – C:\Windows\SysNative\atiesrxx.exe
[2010-04-07 04:10:56 | 000,120,320 | —- | C] (AMD) – C:\Windows\SysNative\atitmm64.dll
[2010-04-07 04:10:40 | 000,421,376 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atipdl64.dll
[2010-04-07 04:10:32 | 000,356,352 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\atipdlxx.dll
[2010-04-07 04:10:18 | 000,278,528 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\Oemdspif.dll
[2010-04-07 04:10:12 | 000,012,288 | —- | C] (AMD) – C:\Windows\SysNative\atimuixx.dll
[2010-04-07 04:10:08 | 000,059,392 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atiedu64.dll
[2010-04-07 04:10:00 | 000,043,520 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\ati2edxx.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Valentine\Documents\*.tmp files -> C:\Users\Valentine\Documents\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010-07-03 21:54:34 | 004,718,592 | -HS- | M] () – C:\Users\Valentine\NTUSER.DAT
[2010-07-03 21:49:37 | 000,001,080 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1162709218-2031985647-1085955036-1001UA.job
[2010-07-03 21:49:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-07-03 21:49:24 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2010-07-03 09:23:57 | 000,001,028 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1162709218-2031985647-1085955036-1001Core.job
[2010-07-02 12:23:59 | 000,010,190 | —- | M] () – C:\Users\Valentine\Documents\Werkdagen.docx
[2010-07-02 05:56:38 | 005,102,286 | —- | M] () – C:\Users\Valentine\Desktop\CIMG1902.JPG
[2010-07-02 03:40:16 | 000,014,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-07-02 03:40:16 | 000,014,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-07-02 01:41:18 | 000,455,965 | —- | M] () – C:\Users\Valentine\Desktop\weak.png
[2010-07-01 23:58:33 | 000,002,977 | —- | M] () – C:\Users\Valentine\Desktop\HiJackThis.lnk
[2010-07-01 12:15:15 | 000,012,103 | —- | M] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf.xlsx
[2010-07-01 12:15:05 | 000,094,632 | —- | M] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf
[2010-07-01 10:59:20 | 000,106,224 | —- | M] (G Data Software) – C:\Windows\SysNative\drivers\GRD.sys
[2010-07-01 10:59:06 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-07-01 10:59:06 | 000,618,714 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-07-01 10:59:06 | 000,107,034 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-07-01 10:53:59 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-07-01 10:53:48 | 3220,529,152 | -HS- | M] () – C:\hiberfil.sys
[2010-07-01 10:52:53 | 001,428,192 | -H– | M] () – C:\Users\Valentine\AppData\Local\IconCache.db
[2010-07-01 10:48:50 | 000,040,392 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\GDBehave.sys
[2010-07-01 10:48:29 | 000,049,096 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\HookCentre.sys
[2010-07-01 10:48:29 | 000,002,029 | —- | M] () – C:\Users\Public\Desktop\G Data TotalCare 2011.lnk
[2010-07-01 10:48:09 | 000,084,936 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\MiniIcpt.sys
[2010-07-01 10:48:06 | 000,048,584 | —- | M] (G DATA Software AG) – C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2010-06-28 09:58:54 | 000,006,258 | —- | M] () – C:\Users\Valentine\Documents\charley foto saar.png
[2010-06-26 10:42:27 | 000,287,779 | —- | M] () – C:\Users\Valentine\Documents\CLA-Workbook-DEC-09-4th-edition.pdf
[2010-06-24 10:25:50 | 000,043,008 | —- | M] () – C:\Users\Valentine\Documents\grammar ex. for tls lesson.doc
[2010-06-24 10:25:09 | 000,038,400 | —- | M] () – C:\Users\Valentine\Documents\tls grammar.doc
[2010-06-24 10:24:44 | 000,156,160 | —- | M] () – C:\Users\Valentine\Documents\Tesol exam Charlotte Ambagtsheer eind product.doc
[2010-06-24 10:22:47 | 000,031,744 | —- | M] () – C:\Users\Valentine\Documents\Charlotte lijst metawerk.doc
[2010-06-24 10:20:14 | 000,014,347 | —- | M] () – C:\Users\Valentine\Documents\Didiclass assignment jaar 2.docx
[2010-06-22 17:04:48 | 000,011,869 | —- | M] () – C:\Users\Valentine\Documents\Opdracht didiclass jaar 2.docx
[2010-06-22 16:46:47 | 000,020,586 | —- | M] () – C:\Users\Valentine\Documents\reflectie jaar 2 luzac college.docx
[2010-06-22 16:23:19 | 000,014,896 | —- | M] () – C:\Users\Valentine\Documents\Curriculum Vitae. engels Charlotte.docx
[2010-06-22 11:57:07 | 000,017,807 | —- | M] () – C:\Users\Valentine\Documents\reflectie jaar 2.docx
[2010-06-22 11:28:53 | 000,039,127 | —- | M] () – C:\Users\Valentine\Documents\cijfer overzicht jaar 2.docx
[2010-06-22 11:25:52 | 000,239,616 | —- | M] () – C:\Users\Valentine\Documents\Verslag cck prestatie 2.doc
[2010-06-22 11:22:59 | 000,014,116 | —- | M] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer..docx
[2010-06-22 11:18:23 | 000,015,441 | —- | M] () – C:\Users\Valentine\Documents\Pap jaar 2 Charlotte.docx
[2010-06-22 11:12:13 | 000,018,550 | —- | M] () – C:\Users\Valentine\Documents\Formulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-22 10:58:58 | 000,054,535 | —- | M] () – C:\Users\Valentine\Documents\CCK Charlotte Ambagtsheer.docx
[2010-06-22 10:48:35 | 000,012,436 | —- | M] () – C:\Users\Valentine\Documents\profiel keuze Charlotte Ambagtsheer.docx
[2010-06-22 09:13:16 | 003,876,406 | —- | M] () – C:\Users\Valentine\Documents\SCAN0011.pdf omzetten portfolio.pdf
[2010-06-21 16:48:16 | 000,022,141 | —- | M] () – C:\Users\Valentine\Documents\pops, paps etc jaar 2 Charlotte a.docx
[2010-06-21 14:40:49 | 000,010,087 | —- | M] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer.docx
[2010-06-20 16:31:59 | 000,000,162 | -H– | M] () – C:\Users\Valentine\Documents\~$rmulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 16:27:39 | 000,010,193 | —- | M] () – C:\Users\Valentine\Documents\Feedback 360.docx
[2010-06-20 15:41:45 | 000,000,162 | -H– | M] () – C:\Users\Valentine\Desktop\~$esis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-20 14:54:23 | 000,032,204 | —- | M] () – C:\Users\Valentine\Desktop\EHVA portfolio migreren.zip
[2010-06-19 10:48:13 | 003,021,336 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-06-19 03:30:19 | 000,296,960 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-19 03:28:22 | 000,252,928 | —- | M] () – C:\Users\Valentine\Documents\scriptie conceptual model.vsd
[2010-06-19 02:31:31 | 000,110,488 | —- | M] () – C:\Users\Valentine\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-06-19 02:14:33 | 000,000,039 | —- | M] () – C:\Windows\vbaddin.ini
[2010-06-19 00:09:53 | 000,001,320 | —- | M] () – C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010-06-18 22:24:54 | 000,129,536 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 4 18 juni.doc
[2010-06-18 21:37:45 | 000,069,120 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 3 16 juni.doc
[2010-06-18 14:32:12 | 000,119,296 | —- | M] () – C:\Users\Valentine\Documents\Beoordelingsformulier wpl jaar 2 Charlotte Ambagtsheer.doc
[2010-06-17 21:44:23 | 000,002,080 | —- | M] () – C:\Users\Valentine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010-06-17 21:44:23 | 000,002,056 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010-06-17 20:46:35 | 000,001,176 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010-06-16 23:59:26 | 000,051,712 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 2.doc
[2010-06-16 13:35:07 | 000,001,307 | —- | M] () – C:\Users\Valentine\Desktop\AVS4YOU Software Navigator.lnk
[2010-06-16 13:25:40 | 000,000,555 | —- | M] () – C:\Users\Valentine\Documents\GSC_0192.wmv
[2010-06-13 10:37:21 | 000,122,880 | —- | M] () – C:\Users\Valentine\Documents\Metawerk onderzoek C en m Aangepast.doc
[2010-06-11 22:35:37 | 000,010,720 | —- | M] () – C:\Users\Valentine\Documents\stocks.docx
[2010-06-11 14:40:25 | 000,119,296 | —- | M] () – C:\Users\Valentine\Documents\Metawerk onderzoek Charlotte and Marit.doc
[2010-06-10 13:48:41 | 000,010,923 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad, Charley.docx
[2010-06-10 13:35:38 | 000,010,737 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad..docx
[2010-06-10 13:33:38 | 000,010,734 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad.docx
[2010-06-10 12:17:13 | 000,035,840 | —- | M] () – C:\Users\Public\Documents\CV Charley Ambagtsheer.doc
[2010-06-10 11:38:17 | 000,036,864 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842.doc
[2010-06-10 11:37:59 | 000,017,238 | —- | M] () – C:\Users\Valentine\Documents\Scriptie Proposal.docx
[2010-06-07 16:10:14 | 000,035,840 | —- | M] () – C:\Users\Valentine\Documents\CV Charley Ambagtsheer.doc
[2010-06-07 12:23:01 | 000,030,720 | —- | M] () – C:\Users\Valentine\Documents\doc formulier.doc
[2010-06-07 12:22:19 | 000,030,720 | —- | M] () – C:\Users\Valentine\Documents\Inschrijving_Nieuwe_Patient.doc
[2010-06-03 17:50:34 | 000,010,425 | —- | M] () – C:\Users\Valentine\Documents\Feedback lesson.docx
[2010-06-03 17:40:02 | 000,028,672 | —- | M] () – C:\Users\Valentine\Documents\Presentation_sheet_students.doc
[2010-06-03 17:37:16 | 000,031,232 | —- | M] () – C:\Users\Valentine\Documents\presentation sheet charlotte and vincent.doc
[2010-06-02 21:27:52 | 000,045,754 | —- | M] () – C:\Users\Valentine\Documents\word order oefening.docx
[2010-06-02 16:43:29 | 000,010,691 | —- | M] () – C:\Users\Valentine\Documents\motivatie Montesorri.docx
[2010-06-02 16:20:41 | 000,011,581 | —- | M] () – C:\Users\Valentine\Documents\word order sheet.docx
[2010-06-02 14:56:25 | 000,168,296 | —- | M] () – C:\Users\Valentine\Documents\Charlotte cck conclusie.docx
[2010-06-02 14:54:15 | 000,011,068 | —- | M] () – C:\Users\Valentine\Documents\conclusie groep cck.docx
[2010-05-31 15:33:50 | 000,009,031 | —- | M] () – C:\Users\Valentine\Documents\foto Charley.jpg
[2010-05-31 13:22:51 | 000,069,120 | —- | M] () – C:\Users\Valentine\Documents\lesson plan Charlotte and Vincent.doc
[2010-05-20 22:58:56 | 000,014,149 | —- | M] () – C:\Users\Valentine\Documents\lamp.docx
[2010-05-20 21:45:40 | 000,000,181 | —- | M] () – C:\Users\Valentine\Documents\lit.gif
[2010-05-17 18:53:57 | 004,303,859 | —- | M] () – C:\Users\Valentine\Desktop\The LoveMachine.mp3
[2010-05-16 22:31:24 | 000,279,261 | —- | M] () – C:\Users\Valentine\Documents\Valentijn Crouwel CV.pdf
[2010-05-16 00:12:39 | 000,013,656 | —- | M] () – C:\Users\Valentine\Documents\Valentijn Crouwel CV.docx
[2010-05-13 13:03:11 | 000,028,220 | —- | M] () – C:\Users\Valentine\Documents\TTP 2 Charlotte AMbagtsheer 13 Mei.docx
[2010-05-13 12:53:05 | 000,030,245 | —- | M] () – C:\Users\Valentine\Desktop\ttp 2 charley 13.04.docx
[2010-05-07 21:52:46 | 000,041,872 | —- | M] () – C:\Windows\SysWow64\xfcodec.dll
[2010-05-07 21:52:46 | 000,027,536 | —- | M] () – C:\Windows\SysNative\xfcodec64.dll
[2010-05-02 20:02:27 | 000,013,175 | —- | M] () – C:\Users\Valentine\Documents\Tell me about your life in Amsterdam and what you do.docx
[2010-04-29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-04-29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010-04-28 18:06:49 | 000,096,677 | —- | M] () – C:\Windows\SysWow64\f2a4df47.exe
[2010-04-28 16:34:52 | 000,001,023 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-04-28 16:31:34 | 000,011,382 | -HS- | M] () – C:\Users\Valentine\AppData\Local\P4xmA30dNI
[2010-04-28 16:31:34 | 000,011,382 | -HS- | M] () – C:\ProgramData\P4xmA30dNI
[2010-04-28 16:08:03 | 000,000,036 | —- | M] () – C:\Users\Valentine\AppData\Local\housecall.guid.cache
[2010-04-21 20:51:12 | 000,054,399 | —- | M] () – C:\Users\Valentine\Documents\Prestatie 1 CHARLEY.docx
[2010-04-18 17:47:10 | 000,052,776 | —- | M] () – C:\Users\Valentine\Documents\metawerk charlotte en marit.!!!.docx
[2010-04-18 15:48:43 | 000,023,274 | —- | M] () – C:\Users\Valentine\Documents\abv verslag 2010 charley.docx
[2010-04-18 10:50:35 | 000,017,321 | —- | M] () – C:\Users\Valentine\Documents\metawerk onderzoek.docx
[2010-04-17 13:27:44 | 000,010,432 | —- | M] () – C:\Users\Valentine\Documents\vaal vraag meta.docx
[2010-04-14 16:42:28 | 000,076,157 | —- | M] () – C:\Users\Valentine\Documents\TTP 2 charley.docx
[2010-04-07 04:16:34 | 000,038,400 | —- | M] () – C:\Windows\SysNative\atiapfxx.blb
[2010-04-07 04:13:00 | 000,455,168 | —- | M] (AMD) – C:\Windows\SysNative\atieclxx.exe
[2010-04-07 04:12:18 | 000,202,752 | —- | M] (AMD) – C:\Windows\SysNative\atiesrxx.exe
[2010-04-07 04:10:56 | 000,120,320 | —- | M] (AMD) – C:\Windows\SysNative\atitmm64.dll
[2010-04-07 04:10:40 | 000,421,376 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysNative\atipdl64.dll
[2010-04-07 04:10:32 | 000,356,352 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\atipdlxx.dll
[2010-04-07 04:10:18 | 000,278,528 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\Oemdspif.dll
[2010-04-07 04:10:12 | 000,012,288 | —- | M] (AMD) – C:\Windows\SysNative\atimuixx.dll
[2010-04-07 04:10:08 | 000,059,392 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysNative\atiedu64.dll
[2010-04-07 04:10:00 | 000,043,520 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\ati2edxx.dll
[2010-04-07 03:46:50 | 000,055,296 | —- | M] (AMD) – C:\Windows\SysNative\coinst.dll
[2010-04-07 03:25:00 | 000,515,424 | —- | M] () – C:\Windows\SysNative\atiumd6a.cap
[2010-04-07 03:20:44 | 000,515,424 | —- | M] () – C:\Windows\SysWow64\atiumdva.cap
[2010-04-06 16:57:13 | 000,030,208 | —- | M] () – C:\Users\Valentine\Desktop\ServiceMarketing_Assignment_1_group4F.doc
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Valentine\Documents\*.tmp files -> C:\Users\Valentine\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-07-02 14:57:52 | 005,102,286 | —- | C] () – C:\Users\Valentine\Desktop\CIMG1902.JPG
[2010-07-02 01:41:17 | 000,455,965 | —- | C] () – C:\Users\Valentine\Desktop\weak.png
[2010-07-01 23:58:33 | 000,002,977 | —- | C] () – C:\Users\Valentine\Desktop\HiJackThis.lnk
[2010-07-01 12:13:33 | 000,012,103 | —- | C] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf.xlsx
[2010-07-01 11:52:19 | 000,094,632 | —- | C] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf
[2010-07-01 10:48:29 | 000,002,029 | —- | C] () – C:\Users\Public\Desktop\G Data TotalCare 2011.lnk
[2010-06-28 09:58:54 | 000,006,258 | —- | C] () – C:\Users\Valentine\Documents\charley foto saar.png
[2010-06-26 10:42:26 | 000,287,779 | —- | C] () – C:\Users\Valentine\Documents\CLA-Workbook-DEC-09-4th-edition.pdf
[2010-06-24 10:25:49 | 000,043,008 | —- | C] () – C:\Users\Valentine\Documents\grammar ex. for tls lesson.doc
[2010-06-24 10:25:09 | 000,038,400 | —- | C] () – C:\Users\Valentine\Documents\tls grammar.doc
[2010-06-24 10:24:43 | 000,156,160 | —- | C] () – C:\Users\Valentine\Documents\Tesol exam Charlotte Ambagtsheer eind product.doc
[2010-06-24 10:12:10 | 000,014,347 | —- | C] () – C:\Users\Valentine\Documents\Didiclass assignment jaar 2.docx
[2010-06-23 16:24:09 | 000,031,744 | —- | C] () – C:\Users\Valentine\Documents\Charlotte lijst metawerk.doc
[2010-06-22 17:04:47 | 000,011,869 | —- | C] () – C:\Users\Valentine\Documents\Opdracht didiclass jaar 2.docx
[2010-06-22 16:23:19 | 000,014,896 | —- | C] () – C:\Users\Valentine\Documents\Curriculum Vitae. engels Charlotte.docx
[2010-06-22 16:07:45 | 000,020,586 | —- | C] () – C:\Users\Valentine\Documents\reflectie jaar 2 luzac college.docx
[2010-06-22 11:57:07 | 000,017,807 | —- | C] () – C:\Users\Valentine\Documents\reflectie jaar 2.docx
[2010-06-22 11:28:53 | 000,039,127 | —- | C] () – C:\Users\Valentine\Documents\cijfer overzicht jaar 2.docx
[2010-06-22 11:25:51 | 000,239,616 | —- | C] () – C:\Users\Valentine\Documents\Verslag cck prestatie 2.doc
[2010-06-22 09:13:15 | 003,876,406 | —- | C] () – C:\Users\Valentine\Documents\SCAN0011.pdf omzetten portfolio.pdf
[2010-06-21 16:48:16 | 000,022,141 | —- | C] () – C:\Users\Valentine\Documents\pops, paps etc jaar 2 Charlotte a.docx
[2010-06-21 16:37:28 | 000,014,116 | —- | C] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer..docx
[2010-06-21 14:40:49 | 000,010,087 | —- | C] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer.docx
[2010-06-21 14:40:09 | 000,012,436 | —- | C] () – C:\Users\Valentine\Documents\profiel keuze Charlotte Ambagtsheer.docx
[2010-06-21 13:38:49 | 000,015,441 | —- | C] () – C:\Users\Valentine\Documents\Pap jaar 2 Charlotte.docx
[2010-06-20 16:31:59 | 000,000,162 | -H– | C] () – C:\Users\Valentine\Documents\~$rmulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 16:26:52 | 000,010,193 | —- | C] () – C:\Users\Valentine\Documents\Feedback 360.docx
[2010-06-20 16:13:05 | 000,018,550 | —- | C] () – C:\Users\Valentine\Documents\Formulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 15:41:45 | 000,000,162 | -H– | C] () – C:\Users\Valentine\Desktop\~$esis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-20 14:54:23 | 000,032,204 | —- | C] () – C:\Users\Valentine\Desktop\EHVA portfolio migreren.zip
[2010-06-19 03:28:21 | 000,252,928 | —- | C] () – C:\Users\Valentine\Documents\scriptie conceptual model.vsd
[2010-06-19 00:09:53 | 000,001,320 | —- | C] () – C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010-06-18 22:25:04 | 000,296,960 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-18 21:38:29 | 000,129,536 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 4 18 juni.doc
[2010-06-18 14:32:11 | 000,119,296 | —- | C] () – C:\Users\Valentine\Documents\Beoordelingsformulier wpl jaar 2 Charlotte Ambagtsheer.doc
[2010-06-17 21:44:23 | 000,002,080 | —- | C] () – C:\Users\Valentine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010-06-17 21:44:23 | 000,002,056 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010-06-17 20:46:35 | 000,001,176 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010-06-17 00:00:19 | 000,069,120 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 3 16 juni.doc
[2010-06-16 13:35:07 | 000,001,307 | —- | C] () – C:\Users\Valentine\Desktop\AVS4YOU Software Navigator.lnk
[2010-06-16 13:25:36 | 000,000,555 | —- | C] () – C:\Users\Valentine\Documents\GSC_0192.wmv
[2010-06-16 13:19:46 | 000,084,480 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010-06-13 10:31:00 | 000,122,880 | —- | C] () – C:\Users\Valentine\Documents\Metawerk onderzoek C en m Aangepast.doc
[2010-06-12 15:05:45 | 000,051,712 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 2.doc
[2010-06-11 14:40:25 | 000,119,296 | —- | C] () – C:\Users\Valentine\Documents\Metawerk onderzoek Charlotte and Marit.doc
[2010-06-10 13:48:41 | 000,010,923 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad, Charley.docx
[2010-06-10 13:35:38 | 000,010,737 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad..docx
[2010-06-10 13:33:38 | 000,010,734 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad.docx
[2010-06-10 12:17:12 | 000,035,840 | —- | C] () – C:\Users\Public\Documents\CV Charley Ambagtsheer.doc
[2010-06-10 11:40:00 | 000,279,261 | —- | C] () – C:\Users\Valentine\Documents\Valentijn Crouwel CV.pdf
[2010-06-10 11:38:16 | 000,036,864 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842.doc
[2010-06-07 16:10:14 | 000,035,840 | —- | C] () – C:\Users\Valentine\Documents\CV Charley Ambagtsheer.doc
[2010-06-07 12:23:01 | 000,030,720 | —- | C] () – C:\Users\Valentine\Documents\doc formulier.doc
[2010-06-07 12:22:19 | 000,030,720 | —- | C] () – C:\Users\Valentine\Documents\Inschrijving_Nieuwe_Patient.doc
[2010-06-05 22:54:46 | 000,017,238 | —- | C] () – C:\Users\Valentine\Documents\Scriptie Proposal.docx
[2010-06-03 17:50:34 | 000,010,425 | —- | C] () – C:\Users\Valentine\Documents\Feedback lesson.docx
[2010-06-03 17:40:02 | 000,028,672 | —- | C] () – C:\Users\Valentine\Documents\Presentation_sheet_students.doc
[2010-06-03 17:37:15 | 000,031,232 | —- | C] () – C:\Users\Valentine\Documents\presentation sheet charlotte and vincent.doc
[2010-06-02 21:27:51 | 000,045,754 | —- | C] () – C:\Users\Valentine\Documents\word order oefening.docx
[2010-06-02 16:42:17 | 000,010,691 | —- | C] () – C:\Users\Valentine\Documents\motivatie Montesorri.docx
[2010-06-02 16:20:41 | 000,011,581 | —- | C] () – C:\Users\Valentine\Documents\word order sheet.docx
[2010-06-02 14:56:24 | 000,168,296 | —- | C] () – C:\Users\Valentine\Documents\Charlotte cck conclusie.docx
[2010-06-02 14:22:28 | 000,011,068 | —- | C] () – C:\Users\Valentine\Documents\conclusie groep cck.docx
[2010-05-31 15:33:50 | 000,009,031 | —- | C] () – C:\Users\Valentine\Documents\foto Charley.jpg
[2010-05-31 13:22:50 | 000,069,120 | —- | C] () – C:\Users\Valentine\Documents\lesson plan Charlotte and Vincent.doc
[2010-05-29 22:22:06 | 000,010,720 | —- | C] () – C:\Users\Valentine\Documents\stocks.docx
[2010-05-28 23:47:24 | 000,010,190 | —- | C] () – C:\Users\Valentine\Documents\Werkdagen.docx
[2010-05-28 23:31:28 | 000,000,000 | —- | C] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2010-05-28 23:15:08 | 000,034,068 | —- | C] () – C:\Windows\SysNative\Repository.reg
[2010-05-28 23:15:07 | 000,082,289 | —- | C] () – C:\Windows\SysNative\lvcoin64.ini
[2010-05-28 23:15:06 | 000,266,828 | —- | C] () – C:\Windows\SysNative\drivers\LVAFT.cfg
[2010-05-21 11:36:32 | 000,074,240 | —- | C] () – C:\Windows\trackerpod_server.exe
[2010-05-20 22:58:56 | 000,014,149 | —- | C] () – C:\Users\Valentine\Documents\lamp.docx
[2010-05-20 21:45:40 | 000,000,181 | —- | C] () – C:\Users\Valentine\Documents\lit.gif
[2010-05-19 23:48:34 | 004,303,859 | —- | C] () – C:\Users\Valentine\Desktop\The LoveMachine.mp3
[2010-05-14 20:11:54 | 000,013,656 | —- | C] () – C:\Users\Valentine\Documents\Valentijn Crouwel CV.docx
[2010-05-13 13:03:10 | 000,028,220 | —- | C] () – C:\Users\Valentine\Documents\TTP 2 Charlotte AMbagtsheer 13 Mei.docx
[2010-05-13 12:17:35 | 000,030,245 | —- | C] () – C:\Users\Valentine\Desktop\ttp 2 charley 13.04.docx
[2010-05-07 21:52:46 | 000,041,872 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2010-05-07 21:52:46 | 000,027,536 | —- | C] () – C:\Windows\SysNative\xfcodec64.dll
[2010-05-02 20:02:27 | 000,013,175 | —- | C] () – C:\Users\Valentine\Documents\Tell me about your life in Amsterdam and what you do.docx
[2010-04-28 18:06:48 | 000,096,677 | —- | C] () – C:\Windows\SysWow64\f2a4df47.exe
[2010-04-28 16:34:52 | 000,001,023 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-04-28 16:08:03 | 000,000,036 | —- | C] () – C:\Users\Valentine\AppData\Local\housecall.guid.cache
[2010-04-28 16:01:22 | 000,011,382 | -HS- | C] () – C:\Users\Valentine\AppData\Local\P4xmA30dNI
[2010-04-28 16:01:22 | 000,011,382 | -HS- | C] () – C:\ProgramData\P4xmA30dNI
[2010-04-21 20:51:41 | 000,054,535 | —- | C] () – C:\Users\Valentine\Documents\CCK Charlotte Ambagtsheer.docx
[2010-04-21 20:48:27 | 000,054,399 | —- | C] () – C:\Users\Valentine\Documents\Prestatie 1 CHARLEY.docx
[2010-04-18 17:47:10 | 000,052,776 | —- | C] () – C:\Users\Valentine\Documents\metawerk charlotte en marit.!!!.docx
[2010-04-17 13:27:44 | 000,010,432 | —- | C] () – C:\Users\Valentine\Documents\vaal vraag meta.docx
[2010-04-17 12:42:40 | 000,017,321 | —- | C] () – C:\Users\Valentine\Documents\metawerk onderzoek.docx
[2010-04-14 17:04:37 | 000,023,274 | —- | C] () – C:\Users\Valentine\Documents\abv verslag 2010 charley.docx
[2010-04-13 19:05:23 | 000,076,157 | —- | C] () – C:\Users\Valentine\Documents\TTP 2 charley.docx
[2010-04-07 04:16:34 | 000,038,400 | —- | C] () – C:\Windows\SysNative\atiapfxx.blb
[2010-04-07 03:25:00 | 000,515,424 | —- | C] () – C:\Windows\SysNative\atiumd6a.cap
[2010-04-07 03:20:44 | 000,515,424 | —- | C] () – C:\Windows\SysWow64\atiumdva.cap
[2010-04-06 16:35:26 | 000,030,208 | —- | C] () – C:\Users\Valentine\Desktop\ServiceMarketing_Assignment_1_group4F.doc
[2010-03-13 00:53:20 | 000,000,067 | —- | C] () – C:\Windows\Easy Video to DVD.INI
[2010-03-01 17:05:08 | 000,722,382 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010-01-13 20:34:07 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010-01-05 01:29:06 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth2.dll
[2010-01-05 01:29:06 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth1.dll
[2010-01-05 01:29:06 | 000,000,100 | —- | C] () – C:\Windows\SysWow64\prsgrc.dll
[2010-01-05 01:27:59 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2010-01-05 01:27:59 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2009-12-25 23:26:38 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008-10-07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008-10-07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll

========== LOP Check ==========

[2010-03-03 15:41:18 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Belastingdienst
[2009-12-25 22:27:25 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\DAEMON Tools Lite
[2010-07-03 21:59:30 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Dropbox
[2009-12-25 23:47:59 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\FlashFXP
[2010-06-11 23:49:56 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Foxit Software
[2009-12-03 23:25:33 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Sincell
[2009-12-03 23:16:08 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\TeamViewer
[2010-06-15 17:55:54 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Ubisoft
[2010-05-01 19:15:31 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\uTorrent
[2009-07-14 07:08:49 | 000,026,348 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009-07-14 03:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2002-01-01 10:25:59 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2002-01-01 01:50:33 | 000,203,316 | RHS- | M] () – C:\grldr
[2010-07-01 10:53:48 | 3220,529,152 | -HS- | M] () – C:\hiberfil.sys
[2010-05-02 15:27:34 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2006-12-02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2010-07-01 10:53:49 | 4294,041,600 | -HS- | M] () – C:\pagefile.sys
[2010-06-16 13:20:19 | 000,037,106 | —- | M] () – C:\StarBurn.log
[2002-01-01 01:50:47 | 000,000,003 | RHS- | M] () – C:\win7ldr

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2009-07-14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009-07-14 03:15:21 | 000,462,848 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\FirewallAPI.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\user32.dll /md5 >
[2009-07-14 03:11:24 | 000,833,024 | —- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 – C:\Windows\SysWOW64\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2009-07-14 03:16:20 | 000,206,336 | —- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D – C:\Windows\SysWOW64\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2009-07-14 03:11:26 | 000,004,608 | —- | M] (Microsoft Corporation) MD5=808AABDF9337312195CAFF76D1804786 – C:\Windows\SysWOW64\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >

OTL Extras logfile created on: 3-7-2010 21:52:35 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Valentine\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 73,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 71,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 466,12 Gb Free Space | 50,04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VALENTINE-PC
Current User Name: Valentine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{576A97E3-1A79-6215-49DE-AA358AF47420}" = ATI Catalyst Install Manager
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{AF51A2B6-3AAF-46C5-36A7-0E78B2D23E3E}" = ccc-utility64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{024FDD4C-B4EE-4CFC-696F-9A36B3BE4D41}" = Catalyst Control Center Graphics Previews Vista
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{05BC432D-819E-86AF-74A9-0622CAD08767}" = Catalyst Control Center Graphics Previews Common
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0A477437-2307-018D-3F3A-AFBDE1D4FF7A}" = Catalyst Control Center HydraVision Full
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 15
"{281D28EC-1357-4778-B2D7-DEA56D70EF96}" = Logitech High Quality Video
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{31B59248-4591-4ED7-BBE9-588C60F09FAC}" = G Data TotalCare 2011
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C2739CB-9E0F-8E06-F315-25F9E9AB2763}" = CCC Help English
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{43FC4C9A-9D17-9CAB-FA69-6588AFA5A1B2}" = Catalyst Control Center Core Implementation
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{828CFF5D-054C-D04A-3CB1-0788828CA236}" = Catalyst Control Center Graphics Light
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{85B0B11F-7EA3-D9DE-BB18-1B52CE1A3E3B}" = Catalyst Control Center Graphics Full Existing
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{87BB78C4-F36D-4D93-A7C7-F80F18219848}" = AMD DnD V1.0.19
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{91140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C916142-C18C-429D-BFED-40094A7E0BEB}" = The Settlers 7 - Paths to a Kingdom
"{9EEA0ED5-CB59-2F06-84A7-3F7B241521B8}" = Catalyst Control Center InstallProxy
"{A10D9B03-AABB-47D7-8A30-2FEA97E70BC7}" = Quake Live Mozilla Plugin
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D416328F-D3ED-4DFD-A8E0-C31466E8E039}" = Tube Toolbox
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DF9B7D24-4C6E-C773-3E58-D2FEF49ADD74}" = ccc-core-static
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EAD931B5-129D-2A7E-9FD2-522BF504EAF4}" = Catalyst Control Center Graphics Full New
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe® Flash® Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy MPEG AVI DIVX WMV RM to DVD_is1" = Easy MPEG/AVI/DIVX/WMV/RM to DVD 1.8.4
"ENTERPRISE" = Microsoft Office Enterprise 2007
"f2a4df47" = Contextual Tool Profithand
"ffdshow_is1" = ffdshow [rev 2975] [2009-05-28]
"Foxit Reader" = Foxit Reader
"JDownloader" = JDownloader
"LastFM_is1" = Last.fm 1.5.4.24567
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Nero 9 Lite_is1" = Nero 9.0.9.4 Lite
"Office14.VISIOR" = Microsoft Visio Premium 2010
"PunkBusterSvc" = PunkBuster Services
"RealAlt_is1" = Real Alternative 1.9.0
"TeamViewer 5" = TeamViewer 5
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xfire" = Xfire (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


hope this will give you some information!

cheers!
Shmoogie
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O20 - AppInit_DLLs: (nmklo) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O33 - MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\Shell - "" = AutoRun
    O33 - MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
    [2010-04-28 18:06:49 | 000,096,677 | —- | M] () – C:\Windows\SysWow64\f2a4df47.exe
    [2010-04-28 16:31:34 | 000,011,382 | -HS- | M] () – C:\Users\Valentine\AppData\Local\P4xmA30dNI
    [2010-04-28 16:31:34 | 000,011,382 | -HS- | M] () – C:\ProgramData\P4xmA30dNI
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log



NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4273 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4-7-2010 0:21:56 mbam-log-2010-07-04 (00-21-56).txt Scan type: Quick scan Objects scanned: 131192 Time elapsed: 4 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thats the malwarebytes file, going on to the next scan now
This is the OTL log: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:nmklo deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{005af190-f0f4-11de-a9ee-001bfc6cc42f}\ not found. File F:\autorun.exe not found. C:\Windows\SysWOW64\f2a4df47.exe moved successfully. C:\Users\Valentine\AppData\Local\P4xmA30dNI moved successfully. C:\ProgramData\P4xmA30dNI moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User: Default User User: Public User: Valentine ->Flash cache emptied: 208258 bytes Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Valentine ->Temp folder emptied: 120687297 bytes ->Temporary Internet Files folder emptied: 435158 bytes ->Java cache emptied: 31284124 bytes ->FireFox cache emptied: 36553502 bytes ->Google Chrome cache emptied: 362595554 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 155648 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1612054 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 1850758 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 529,00 mb OTL by OldTimer - Version 3.2.7.0 log created on 07042010_203044 Files\Folders moved on Reboot… C:\Users\Valentine\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… and the kaspersky log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, July 4, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, July 04, 2010 05:39:49 Records in database: 4249874 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ F:\ Scan statistics: Objects scanned: 222254 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 03:44:56 File name / Threat / Threats count C:\Program Files (x86)\megaman\megaman\weakness.exe Infected: Trojan-Downloader.Win32.Agent.degu 1 Selected area has been scanned. hope this helps:) thanks for the help and time so far. Shmoogie
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Program Files (x86)\megaman\megaman\weakness.exe
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a fresh OTL log and post in your next reply


Please advise how your computer is running now and if there are any outstanding issues
Here's the latest log after doing what you just told me to: All processes killed ========== FILES ========== C:\Program Files (x86)\megaman\megaman\weakness.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Valentine ->Temp folder emptied: 563064237 bytes ->Temporary Internet Files folder emptied: 226244 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 39768366 bytes ->Google Chrome cache emptied: 27241291 bytes ->Flash cache emptied: 959 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1570 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 65536 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 601,00 mb OTL by OldTimer - Version 3.2.7.0 log created on 07042010_221201 Files\Folders moved on Reboot… C:\Users\Valentine\AppData\Local\Temp\alm.log moved successfully. C:\Users\Valentine\AppData\Local\Temp\amt.log moved successfully. C:\Users\Valentine\AppData\Local\Temp\csxs-PHXS.log moved successfully. C:\Users\Valentine\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Valentine\AppData\Local\Temp\Photoshop Temp280300804 not found! Registry entries deleted on Reboot… apart from this I have reset firefox in safe mode disabled all my plugins and addons. Now I am seeing if it's fixed. So far no new popups though it seems my flash is disabled on firefox. I'll let you know if the problem persists! thanks in advance Shmoogie
OTL logfile created on: 5-7-2010 12:07:16 - Run 2
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Valentine\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 76,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 480,09 Gb Free Space | 51,54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VALENTINE-PC
Current User Name: Valentine
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Valentine\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Valentine\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\G Data\TotalCare\GUI\GDSC.exe (G Data Software AG)
PRC - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
PRC - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe (G Data Software AG)
PRC - C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe (G Data Software AG)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Valentine\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TeamViewer5) – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AVKProxy) – C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG)
SRV - (GDBackupSvc) – C:\Program Files (x86)\G Data\TotalCare\AVKBackup\AVKBackupService.exe (G Data Software AG)
SRV - (GDScan) – C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVKService) – C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe (G Data Software AG)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AVKWCtl) – C:\Program Files (x86)\G Data\TotalCare\AVK\AVKWCtlX64.exe (G Data Software AG)
SRV - (GDTunerSvc) – C:\Program Files (x86)\G Data\TotalCare\AVKTuner\AVKTunerService.exe (G Data Software AG)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009-07-14 05:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009-07-14 05:20:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (GRD) – C:\Windows\SysNative\drivers\GRD.sys (G Data Software)
DRV:64bit: - (GDBehave) – C:\Windows\SysNative\drivers\GDBehave.sys (G Data Software AG)
DRV:64bit: - (HookCentre) – C:\Windows\SysNative\drivers\HookCentre.sys (G Data Software AG)
DRV:64bit: - (GDMnIcpt) – C:\Windows\SysNative\drivers\MiniIcpt.sys (G Data Software AG)
DRV:64bit: - (gdwfpcd) – C:\Windows\SysNative\drivers\gdwfpcd64.sys (G DATA Software AG)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (DVDRIVER) – C:\Windows\SysNative\drivers\dvdriver.sys (Eagletron Inc.)
DRV:64bit: - (AtcL001) – C:\Windows\SysNative\drivers\l160x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LVUVC64) Logitech Webcam 500(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3E CF EE 46 00 ED CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.17.101:8888

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-07-04 22:23:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-07-04 22:23:01 | 000,000,000 | —D | M]

[2010-07-04 22:23:20 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Mozilla\Extensions
[2010-07-04 22:23:20 | 000,000,000 | —D | M] – C:\Users\Valentine\AppData\Roaming\Mozilla\Firefox\Profiles\9z7l7kkp.default\extensions
[2010-07-04 22:23:02 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2010-07-04 20:30:46 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIEx64.dll (G Data Software AG)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIE.dll (G Data Software AG)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIEx64.dll (G Data Software AG)
O3 - HKLM\..\Toolbar: (G Data WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files (x86)\G Data\TotalCare\Webfilter\AvkWebIE.dll (G Data Software AG)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe (G Data Software AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Valentine\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O27:64bit: - HKLM IFEO\1: Debugger - C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\1: Debugger - C:\Windows\system32\svchost.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010-07-04 22:23:16 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Mozilla
[2010-07-04 20:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2010-07-01 23:58:33 | 000,000,000 | —D | C] – C:\HiJackThis
[2010-07-01 12:19:56 | 000,000,000 | —D | C] – C:\Users\Valentine\Tracing
[2010-07-01 12:12:44 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\New folder
[2010-07-01 10:59:20 | 000,106,224 | —- | C] (G Data Software) – C:\Windows\SysNative\drivers\GRD.sys
[2010-07-01 10:48:50 | 000,040,392 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\GDBehave.sys
[2010-07-01 10:48:29 | 000,049,096 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\HookCentre.sys
[2010-07-01 10:48:09 | 000,084,936 | —- | C] (G Data Software AG) – C:\Windows\SysNative\drivers\MiniIcpt.sys
[2010-07-01 10:48:06 | 000,048,584 | —- | C] (G DATA Software AG) – C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\ProgramData\G DATA
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\G Data
[2010-07-01 10:47:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\G Data
[2010-07-01 10:45:00 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Local\Downloaded Installations
[2010-07-01 10:25:23 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2010-06-30 03:00:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010-06-24 03:00:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-06-24 03:00:24 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-06-24 03:00:24 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-06-24 03:00:24 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-06-24 03:00:24 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-06-24 03:00:24 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-06-24 03:00:24 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-06-24 03:00:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010-06-23 10:36:06 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010-06-23 10:36:03 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010-06-23 10:36:02 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010-06-23 10:36:02 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010-06-23 10:36:02 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010-06-23 10:36:02 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010-06-23 10:36:01 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010-06-23 10:36:01 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010-06-20 22:37:58 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010-06-20 14:58:25 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\WebDrive
[2010-06-20 14:57:06 | 000,000,000 | -H-D | C] – C:\ProgramData\WebDrive
[2010-06-20 14:56:52 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2010-06-20 14:55:05 | 000,000,000 | —D | C] – C:\Users\Valentine\Desktop\meeneemportfolio
[2010-06-19 02:33:50 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010-06-19 02:33:50 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010-06-19 02:33:50 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2010-06-19 02:33:50 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010-06-19 02:31:34 | 000,000,000 | –SD | C] – C:\Users\Valentine\Documents\My Shapes
[2010-06-19 02:14:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2010-06-19 02:12:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2010-06-19 00:09:54 | 000,000,000 | —D | C] – C:\Users\Valentine\Documents\OneNote Notebooks
[2010-06-16 13:35:17 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\AVS4YOU
[2010-06-16 13:34:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2010-06-16 13:33:59 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2010-06-16 13:33:59 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc70.dll
[2010-06-16 13:33:59 | 000,487,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp70.dll
[2010-06-16 13:33:59 | 000,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr70.dll
[2010-06-16 13:33:58 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3a.dll
[2010-06-16 13:33:58 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2010-06-16 13:33:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2010-06-16 13:19:48 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010-06-16 13:19:48 | 000,185,920 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2010-06-16 13:19:48 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2010-06-16 13:19:48 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Real
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Local\Real
[2010-06-16 13:19:47 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010-06-16 13:19:45 | 000,060,273 | —- | C] (Open Source Software community project) – C:\Windows\SysWow64\pthreadGC2.dll
[2010-06-15 17:55:54 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Ubisoft
[2010-06-15 17:55:54 | 000,000,000 | —D | C] – C:\ProgramData\Ubisoft
[2010-06-11 23:49:56 | 000,000,000 | —D | C] – C:\Users\Valentine\AppData\Roaming\Foxit Software
[2010-06-11 23:21:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Foxit Software
[2010-06-10 22:49:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010-06-07 15:00:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mass Effect 2
[1 C:\Users\Valentine\Documents\*.tmp files -> C:\Users\Valentine\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-07-05 12:09:14 | 004,718,592 | -HS- | M] () – C:\Users\Valentine\NTUSER.DAT
[2010-07-05 11:59:00 | 000,001,080 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1162709218-2031985647-1085955036-1001UA.job
[2010-07-05 09:58:27 | 000,014,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-07-05 09:58:27 | 000,014,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-07-05 09:51:16 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-07-05 09:51:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-07-05 09:51:05 | 3220,529,152 | -HS- | M] () – C:\hiberfil.sys
[2010-07-05 04:48:52 | 002,144,684 | -H– | M] () – C:\Users\Valentine\AppData\Local\IconCache.db
[2010-07-05 03:37:36 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2010-07-04 22:23:17 | 000,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2010-07-04 22:23:03 | 000,001,977 | —- | M] () – C:\Users\Valentine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010-07-04 22:17:47 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-07-04 22:17:47 | 000,618,714 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-07-04 22:17:47 | 000,107,034 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-07-04 20:30:46 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2010-07-04 09:30:42 | 000,001,028 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1162709218-2031985647-1085955036-1001Core.job
[2010-07-02 12:23:59 | 000,010,190 | —- | M] () – C:\Users\Valentine\Documents\Werkdagen.docx
[2010-07-02 05:56:38 | 005,102,286 | —- | M] () – C:\Users\Valentine\Desktop\CIMG1902.JPG
[2010-07-02 01:41:18 | 000,455,965 | —- | M] () – C:\Users\Valentine\Desktop\weak.png
[2010-07-01 23:58:33 | 000,002,977 | —- | M] () – C:\Users\Valentine\Desktop\HiJackThis.lnk
[2010-07-01 12:15:15 | 000,012,103 | —- | M] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf.xlsx
[2010-07-01 12:15:05 | 000,094,632 | —- | M] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf
[2010-07-01 10:59:20 | 000,106,224 | —- | M] (G Data Software) – C:\Windows\SysNative\drivers\GRD.sys
[2010-07-01 10:48:50 | 000,040,392 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\GDBehave.sys
[2010-07-01 10:48:29 | 000,049,096 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\HookCentre.sys
[2010-07-01 10:48:29 | 000,002,029 | —- | M] () – C:\Users\Public\Desktop\G Data TotalCare 2011.lnk
[2010-07-01 10:48:09 | 000,084,936 | —- | M] (G Data Software AG) – C:\Windows\SysNative\drivers\MiniIcpt.sys
[2010-07-01 10:48:06 | 000,048,584 | —- | M] (G DATA Software AG) – C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2010-06-28 09:58:54 | 000,006,258 | —- | M] () – C:\Users\Valentine\Documents\charley foto saar.png
[2010-06-26 10:42:27 | 000,287,779 | —- | M] () – C:\Users\Valentine\Documents\CLA-Workbook-DEC-09-4th-edition.pdf
[2010-06-24 10:25:50 | 000,043,008 | —- | M] () – C:\Users\Valentine\Documents\grammar ex. for tls lesson.doc
[2010-06-24 10:25:09 | 000,038,400 | —- | M] () – C:\Users\Valentine\Documents\tls grammar.doc
[2010-06-24 10:24:44 | 000,156,160 | —- | M] () – C:\Users\Valentine\Documents\Tesol exam Charlotte Ambagtsheer eind product.doc
[2010-06-24 10:22:47 | 000,031,744 | —- | M] () – C:\Users\Valentine\Documents\Charlotte lijst metawerk.doc
[2010-06-24 10:20:14 | 000,014,347 | —- | M] () – C:\Users\Valentine\Documents\Didiclass assignment jaar 2.docx
[2010-06-22 17:04:48 | 000,011,869 | —- | M] () – C:\Users\Valentine\Documents\Opdracht didiclass jaar 2.docx
[2010-06-22 16:46:47 | 000,020,586 | —- | M] () – C:\Users\Valentine\Documents\reflectie jaar 2 luzac college.docx
[2010-06-22 16:23:19 | 000,014,896 | —- | M] () – C:\Users\Valentine\Documents\Curriculum Vitae. engels Charlotte.docx
[2010-06-22 11:57:07 | 000,017,807 | —- | M] () – C:\Users\Valentine\Documents\reflectie jaar 2.docx
[2010-06-22 11:28:53 | 000,039,127 | —- | M] () – C:\Users\Valentine\Documents\cijfer overzicht jaar 2.docx
[2010-06-22 11:25:52 | 000,239,616 | —- | M] () – C:\Users\Valentine\Documents\Verslag cck prestatie 2.doc
[2010-06-22 11:22:59 | 000,014,116 | —- | M] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer..docx
[2010-06-22 11:18:23 | 000,015,441 | —- | M] () – C:\Users\Valentine\Documents\Pap jaar 2 Charlotte.docx
[2010-06-22 11:12:13 | 000,018,550 | —- | M] () – C:\Users\Valentine\Documents\Formulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-22 10:58:58 | 000,054,535 | —- | M] () – C:\Users\Valentine\Documents\CCK Charlotte Ambagtsheer.docx
[2010-06-22 10:48:35 | 000,012,436 | —- | M] () – C:\Users\Valentine\Documents\profiel keuze Charlotte Ambagtsheer.docx
[2010-06-22 09:13:16 | 003,876,406 | —- | M] () – C:\Users\Valentine\Documents\SCAN0011.pdf omzetten portfolio.pdf
[2010-06-21 16:48:16 | 000,022,141 | —- | M] () – C:\Users\Valentine\Documents\pops, paps etc jaar 2 Charlotte a.docx
[2010-06-21 14:40:49 | 000,010,087 | —- | M] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer.docx
[2010-06-20 16:31:59 | 000,000,162 | -H– | M] () – C:\Users\Valentine\Documents\~$rmulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 16:27:39 | 000,010,193 | —- | M] () – C:\Users\Valentine\Documents\Feedback 360.docx
[2010-06-20 15:41:45 | 000,000,162 | -H– | M] () – C:\Users\Valentine\Desktop\~$esis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-20 14:54:23 | 000,032,204 | —- | M] () – C:\Users\Valentine\Desktop\EHVA portfolio migreren.zip
[2010-06-19 10:48:13 | 003,021,336 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-06-19 03:30:19 | 000,296,960 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-19 03:28:22 | 000,252,928 | —- | M] () – C:\Users\Valentine\Documents\scriptie conceptual model.vsd
[2010-06-19 02:31:31 | 000,110,488 | —- | M] () – C:\Users\Valentine\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-06-19 02:14:33 | 000,000,039 | —- | M] () – C:\Windows\vbaddin.ini
[2010-06-19 00:09:53 | 000,001,320 | —- | M] () – C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010-06-18 22:24:54 | 000,129,536 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 4 18 juni.doc
[2010-06-18 21:37:45 | 000,069,120 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 3 16 juni.doc
[2010-06-18 14:32:12 | 000,119,296 | —- | M] () – C:\Users\Valentine\Documents\Beoordelingsformulier wpl jaar 2 Charlotte Ambagtsheer.doc
[2010-06-17 20:46:35 | 000,001,176 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010-06-16 23:59:26 | 000,051,712 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 2.doc
[2010-06-16 13:35:07 | 000,001,307 | —- | M] () – C:\Users\Valentine\Desktop\AVS4YOU Software Navigator.lnk
[2010-06-16 13:25:40 | 000,000,555 | —- | M] () – C:\Users\Valentine\Documents\GSC_0192.wmv
[2010-06-13 10:37:21 | 000,122,880 | —- | M] () – C:\Users\Valentine\Documents\Metawerk onderzoek C en m Aangepast.doc
[2010-06-11 22:35:37 | 000,010,720 | —- | M] () – C:\Users\Valentine\Documents\stocks.docx
[2010-06-11 14:40:25 | 000,119,296 | —- | M] () – C:\Users\Valentine\Documents\Metawerk onderzoek Charlotte and Marit.doc
[2010-06-10 13:48:41 | 000,010,923 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad, Charley.docx
[2010-06-10 13:35:38 | 000,010,737 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad..docx
[2010-06-10 13:33:38 | 000,010,734 | —- | M] () – C:\Users\Valentine\Documents\Motivatie De Weldaad.docx
[2010-06-10 12:17:13 | 000,035,840 | —- | M] () – C:\Users\Public\Documents\CV Charley Ambagtsheer.doc
[2010-06-10 11:38:17 | 000,036,864 | —- | M] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842.doc
[2010-06-10 11:37:59 | 000,017,238 | —- | M] () – C:\Users\Valentine\Documents\Scriptie Proposal.docx
[2010-06-07 16:10:14 | 000,035,840 | —- | M] () – C:\Users\Valentine\Documents\CV Charley Ambagtsheer.doc
[2010-06-07 12:23:01 | 000,030,720 | —- | M] () – C:\Users\Valentine\Documents\doc formulier.doc
[2010-06-07 12:22:19 | 000,030,720 | —- | M] () – C:\Users\Valentine\Documents\Inschrijving_Nieuwe_Patient.doc
[1 C:\Users\Valentine\Documents\*.tmp files -> C:\Users\Valentine\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-07-04 22:23:17 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010-07-04 22:23:03 | 000,001,977 | —- | C] () – C:\Users\Valentine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010-07-02 14:57:52 | 005,102,286 | —- | C] () – C:\Users\Valentine\Desktop\CIMG1902.JPG
[2010-07-02 01:41:17 | 000,455,965 | —- | C] () – C:\Users\Valentine\Desktop\weak.png
[2010-07-01 23:58:33 | 000,002,977 | —- | C] () – C:\Users\Valentine\Desktop\HiJackThis.lnk
[2010-07-01 12:13:33 | 000,012,103 | —- | C] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf.xlsx
[2010-07-01 11:52:19 | 000,094,632 | —- | C] () – C:\Users\Valentine\Desktop\MarketWizards Sheet.pdf
[2010-07-01 10:48:29 | 000,002,029 | —- | C] () – C:\Users\Public\Desktop\G Data TotalCare 2011.lnk
[2010-06-28 09:58:54 | 000,006,258 | —- | C] () – C:\Users\Valentine\Documents\charley foto saar.png
[2010-06-26 10:42:26 | 000,287,779 | —- | C] () – C:\Users\Valentine\Documents\CLA-Workbook-DEC-09-4th-edition.pdf
[2010-06-24 10:25:49 | 000,043,008 | —- | C] () – C:\Users\Valentine\Documents\grammar ex. for tls lesson.doc
[2010-06-24 10:25:09 | 000,038,400 | —- | C] () – C:\Users\Valentine\Documents\tls grammar.doc
[2010-06-24 10:24:43 | 000,156,160 | —- | C] () – C:\Users\Valentine\Documents\Tesol exam Charlotte Ambagtsheer eind product.doc
[2010-06-24 10:12:10 | 000,014,347 | —- | C] () – C:\Users\Valentine\Documents\Didiclass assignment jaar 2.docx
[2010-06-23 16:24:09 | 000,031,744 | —- | C] () – C:\Users\Valentine\Documents\Charlotte lijst metawerk.doc
[2010-06-22 17:04:47 | 000,011,869 | —- | C] () – C:\Users\Valentine\Documents\Opdracht didiclass jaar 2.docx
[2010-06-22 16:23:19 | 000,014,896 | —- | C] () – C:\Users\Valentine\Documents\Curriculum Vitae. engels Charlotte.docx
[2010-06-22 16:07:45 | 000,020,586 | —- | C] () – C:\Users\Valentine\Documents\reflectie jaar 2 luzac college.docx
[2010-06-22 11:57:07 | 000,017,807 | —- | C] () – C:\Users\Valentine\Documents\reflectie jaar 2.docx
[2010-06-22 11:28:53 | 000,039,127 | —- | C] () – C:\Users\Valentine\Documents\cijfer overzicht jaar 2.docx
[2010-06-22 11:25:51 | 000,239,616 | —- | C] () – C:\Users\Valentine\Documents\Verslag cck prestatie 2.doc
[2010-06-22 09:13:15 | 003,876,406 | —- | C] () – C:\Users\Valentine\Documents\SCAN0011.pdf omzetten portfolio.pdf
[2010-06-21 16:48:16 | 000,022,141 | —- | C] () – C:\Users\Valentine\Documents\pops, paps etc jaar 2 Charlotte a.docx
[2010-06-21 16:37:28 | 000,014,116 | —- | C] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer..docx
[2010-06-21 14:40:49 | 000,010,087 | —- | C] () – C:\Users\Valentine\Documents\Pop aanvang jaar 3 Charlotte Ambagtsheer.docx
[2010-06-21 14:40:09 | 000,012,436 | —- | C] () – C:\Users\Valentine\Documents\profiel keuze Charlotte Ambagtsheer.docx
[2010-06-21 13:38:49 | 000,015,441 | —- | C] () – C:\Users\Valentine\Documents\Pap jaar 2 Charlotte.docx
[2010-06-20 16:31:59 | 000,000,162 | -H– | C] () – C:\Users\Valentine\Documents\~$rmulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 16:26:52 | 000,010,193 | —- | C] () – C:\Users\Valentine\Documents\Feedback 360.docx
[2010-06-20 16:13:05 | 000,018,550 | —- | C] () – C:\Users\Valentine\Documents\Formulier POP jaar 2 Charlotte Ambagtsheer, Stage Luzac College.docx
[2010-06-20 15:41:45 | 000,000,162 | -H– | C] () – C:\Users\Valentine\Desktop\~$esis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-20 14:54:23 | 000,032,204 | —- | C] () – C:\Users\Valentine\Desktop\EHVA portfolio migreren.zip
[2010-06-19 03:28:21 | 000,252,928 | —- | C] () – C:\Users\Valentine\Documents\scriptie conceptual model.vsd
[2010-06-19 00:09:53 | 000,001,320 | —- | C] () – C:\Users\Valentine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2010-06-18 22:25:04 | 000,296,960 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 5 18 juni.doc
[2010-06-18 21:38:29 | 000,129,536 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 4 18 juni.doc
[2010-06-18 14:32:11 | 000,119,296 | —- | C] () – C:\Users\Valentine\Documents\Beoordelingsformulier wpl jaar 2 Charlotte Ambagtsheer.doc
[2010-06-17 20:46:35 | 000,001,176 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010-06-17 00:00:19 | 000,069,120 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 3 16 juni.doc
[2010-06-16 13:35:07 | 000,001,307 | —- | C] () – C:\Users\Valentine\Desktop\AVS4YOU Software Navigator.lnk
[2010-06-16 13:25:36 | 000,000,555 | —- | C] () – C:\Users\Valentine\Documents\GSC_0192.wmv
[2010-06-16 13:19:46 | 000,084,480 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010-06-13 10:31:00 | 000,122,880 | —- | C] () – C:\Users\Valentine\Documents\Metawerk onderzoek C en m Aangepast.doc
[2010-06-12 15:05:45 | 000,051,712 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842 versie 2.doc
[2010-06-11 14:40:25 | 000,119,296 | —- | C] () – C:\Users\Valentine\Documents\Metawerk onderzoek Charlotte and Marit.doc
[2010-06-10 13:48:41 | 000,010,923 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad, Charley.docx
[2010-06-10 13:35:38 | 000,010,737 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad..docx
[2010-06-10 13:33:38 | 000,010,734 | —- | C] () – C:\Users\Valentine\Documents\Motivatie De Weldaad.docx
[2010-06-10 12:17:12 | 000,035,840 | —- | C] () – C:\Users\Public\Documents\CV Charley Ambagtsheer.doc
[2010-06-10 11:40:00 | 000,279,261 | —- | C] () – C:\Users\Valentine\Documents\Valentijn Crouwel CV.pdf
[2010-06-10 11:38:16 | 000,036,864 | —- | C] () – C:\Users\Valentine\Desktop\Thesis Proposal Valentijn Crouwel 1600842.doc
[2010-06-07 16:10:14 | 000,035,840 | —- | C] () – C:\Users\Valentine\Documents\CV Charley Ambagtsheer.doc
[2010-06-07 12:23:01 | 000,030,720 | —- | C] () – C:\Users\Valentine\Documents\doc formulier.doc
[2010-06-07 12:22:19 | 000,030,720 | —- | C] () – C:\Users\Valentine\Documents\Inschrijving_Nieuwe_Patient.doc
[2010-06-05 22:54:46 | 000,017,238 | —- | C] () – C:\Users\Valentine\Documents\Scriptie Proposal.docx
[2010-05-07 21:52:46 | 000,041,872 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2010-03-13 00:53:20 | 000,000,067 | —- | C] () – C:\Windows\Easy Video to DVD.INI
[2010-03-01 17:05:08 | 000,722,382 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010-01-13 20:34:07 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010-01-05 01:29:06 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth2.dll
[2010-01-05 01:29:06 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\grcauth1.dll
[2010-01-05 01:29:06 | 000,000,100 | —- | C] () – C:\Windows\SysWow64\prsgrc.dll
[2010-01-05 01:27:59 | 000,001,025 | —- | C] () – C:\Windows\SysWow64\sysprs7.dll
[2010-01-05 01:27:59 | 000,000,205 | —- | C] () – C:\Windows\SysWow64\lsprst7.dll
[2009-12-25 23:26:38 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008-10-07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008-10-07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008-10-07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
< End of report >


p.s. i reinstalled firefox and it seems to be gone now… might have been an add on or plugin that had been corrupted?? because before i reinstalled firefox even after all the changes it was still there…
Hi

Looks good

Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 15 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Sun Jave cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.



Let me know if you have any other issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI