happy camper
Topic Starter
Hi!
Microsoft security essentials informed me last week or so that my PC was infected with the PWS:Win32/Zbot.gen!Y virus or trojan or whatever it is! My virusscanner then allows me to quarantine or remove the item, which seems succesfull. However, every time I reboot, the infection turns up again, sometimes even without a reboot. I read that this infection is a real thread (password stealer) so I guess I should be worried. I would appreciate any help.
I performed this OTL check thing and here are the results:
OTL Extras logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0907-000001000000}" = 7-Zip 9.07 (x64 edition)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7AAC-C5D5-B89B-EBA1-D4DFC5E46D6C}" = AMD Drag and Drop Transcoding
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{9221C55E-0D1E-BA0E-5219-0564AF763AE7}" = ATI Catalyst Install Manager
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{A39FD4D2-002C-49F9-A13D-C15BC435D92E}" = Microsoft Antimalware Service NL-NL Language Pack
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{E1D6317F-4893-6517-838B-ECC5489D1711}" = ccc-utility64
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"HashTab" = HashTab 3.0.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.3
"Microsoft Security Essentials" = Microsoft Security Essentials
"SereneScreen Marine Aquarium 3_is1" = SereneScreen Marine Aquarium 3
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02993992-FF7E-03C0-3BF7-E892F2CD2B8F}" = Catalyst Control Center HydraVision Full
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10F5387D-1728-423A-A578-B00982CF2646}" = Windows Live Messenger
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1BD6AE96-4742-4498-9D03-9451C7E5A214}" = Windows Live aanmeldhulp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live - Hulpprogramma voor uploaden
"{218E787C-BADD-2284-AF4E-A1FA0D56772C}" = Catalyst Control Center Graphics Full Existing
"{21F791BA-E80A-0EEF-9B63-105EB939A5B2}" = CCC Help English
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2A8F82E8-7B86-4AFD-BFBC-2BA4C2CF52DB}" = Windows Live Call
"{34AFE453-F544-4269-89C9-CAB7F0744963}" = Nuance OmniPage 17
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D122AF9-1E02-4035-8003-334D378C1B62}_is1" = PDF OCR 3.2
"{44B49543-F839-46ED-61B9-3C91D71C7355}" = Catalyst Control Center Graphics Full New
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{562B9CA4-6E52-4F87-ACEC-912FC004F1F0}" = Windows Live Essentials
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58401B8E-0889-63C2-1E06-7C6530426411}" = Catalyst Control Center Graphics Previews Vista
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6530EB5E-F2BE-45D3-906B-E4AFFF2D1588}" = Windows Live Apparaatbeheer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7775B0BF-EC23-00B3-2E0F-D3FE89939C06}" = Catalyst Control Center Core Implementation
"{7AAAB55F-BB15-CEF4-9174-4AF79272D9EE}" = Catalyst Control Center Graphics Light
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90110413-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E1477E-810A-4185-BD9E-1A803498EFB3}" = OpenOffice.org 3.0
"{AC76BA86-7AD7-1043-7B44-A93000000001}" = Adobe Reader 9.3 - Nederlands
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = De Sims™ 3
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE6B96AF-83ED-9054-0B21-A68AF2EAF106}" = Catalyst Control Center InstallProxy
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D903102F-8294-97B5-3416-67DA5A71C87F}" = Catalyst Control Center Graphics Previews Common
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31043}" = Nero 7 Premium
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DFDB7828-15CF-4507-4998-D0B17A356705}" = ccc-core-static
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EF901A4B-A25A-4962-83C6-C6691D062ED9}" = Nero Mega Plugin Pack
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BSPlayerf" = BS.Player FREE
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DreamAqua" = Dream Aquarium
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 4.1.1 Professional
"Emilsoft FireBackup" = Emilsoft FireBackup
"FTD Skin_is1" = FTD Skin 3.8.5
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.1.6
"LogMeIn Hamachi" = LogMeIn Hamachi
"Messenger Plus! Live" = Messenger Plus! Live
"Miro" = Miro
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"NewsLeecher_is1" = NewsLeecher v3.9 Beta 6
"Pixum EasyBook" = Pixum EasyBook
"Plants vs. Zombies" = Plants vs. Zombies
"PunkBusterSvc" = PunkBuster Services
"qt7lite_is1" = QT Lite 3.0.0 BETA 3
"QuickPar" = QuickPar 0.9
"Spesoft Audio Converter_is1" = Spesoft Audio Converter 2.20
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UltraISO_is1" = UltraISO Premium V9.35
"Universal Extractor_is1" = Universal Extractor 1.6
"Windows 7 - Codec Pack" = Windows 7 Codec Pack 2.2.0
"WinLiveSuite_Wave3" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14-7-2010 14:00:30 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 15:04:16 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 16:07:37 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7600.16450,
tijdstempel: 0x4aebab8d Naam van module met fout: ntdll.dll, versie: 6.1.7600.16559,
tijdstempel: 0x4ba9b802 Uitzonderingscode: 0xc0000374 Foutoffset: 0x00000000000c6df2
Id
van proces met fout: 0x624 Starttijd van toepassing met fout: 0x01cb235032d96b42
Pad
naar toepassing met fout: C:\Windows\Explorer.EXE Pad naar module met fout: C:\Windows\SYSTEM32\ntdll.dll
Rapport-id:
7204f30c-8f83-11df-95ed-0022158ec84f
Error - 14-7-2010 16:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 17:05:54 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x5a4 Starttijd van toepassing met fout: 0x01cb23984e08bf4a
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 9679f28b-8f8b-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:09:04 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x1174 Starttijd van toepassing met fout: 0x01cb2398827f9038
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 07e0052e-8f8c-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0xeb4 Starttijd van toepassing met fout: 0x01cb2398ef8e66e8
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 757c0138-8f8c-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:13:37 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 18:02:52 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 19:01:48 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
[ System Events ]
Error - 3-4-2010 3:04:57 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
Error - 3-4-2010 9:57:37 | Computer Name = GEBRUIK-XSGU41S | Source = volsnap | ID = 393245
Description = De schaduwkopieën van volume C: zijn afgebroken tijdens de detectie.
Error - 3-4-2010 9:57:54 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci
Error - 3-4-2010 9:58:00 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 3-4-2010 10:01:04 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 3-4-2010 10:04:08 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
Error - 4-4-2010 17:17:03 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci
Error - 4-4-2010 17:17:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 4-4-2010 17:20:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 4-4-2010 16:21:27 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
< End of report >
OTL logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
========== Modules (SafeList) ==========
MOD - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16400_none_4209f94e2b866170\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll (Logitech, Inc.)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (vmx_svga) – C:\Windows\SysNative\DRIVERS\vmx_svga.sys File not found
DRV:64bit: - (VMAUDIO) VMware VMaudio (VMAUDIO) (WDM) – C:\Windows\SysNative\drivers\vmaudio.sys File not found
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (vmmouse) – C:\Windows\SysNative\drivers\vmmouse.sys (VMware, Inc.)
DRV:64bit: - (vm3dmp) – C:\Windows\SysNative\drivers\vm3dmp.sys (VMware, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (EuGdiDrv) – C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (vcrdrx64) – C:\Windows\SysNative\drivers\vcrdrx64.sys (VIA Technologies, Inc.)
DRV:64bit: - (epmntdrv) – C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (nvamacpi) – C:\Windows\SysNative\drivers\nvamacpi.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LUsbFilt) – C:\Windows\SysNative\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ioatdma2) Intel® – C:\Windows\SysNative\drivers\qd262x64.sys (Intel Corporation)
DRV:64bit: - (ioatdma1) – C:\Windows\SysNative\drivers\qd162x64.sys (Intel Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (johci) – C:\Windows\SysNative\drivers\johci.sys (JMicron )
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (MegaSR1) – C:\Windows\SysNative\drivers\MegaSR1.sys (LSI Corporation, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (viamrx64) – C:\Windows\SysNative\drivers\viamrx64.sys (VIA Technologies Inc.,Ltd)
DRV:64bit: - (WinTVCIUSB) – C:\Windows\SysNative\drivers\hcw11.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ViPrtX64) – C:\Windows\SysNative\drivers\ViPrtX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (ViBusX64) – C:\Windows\SysNative\drivers\ViBusX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (wisdpen) – C:\Windows\SysNative\drivers\wisdpen.sys (Wacom Technology)
DRV:64bit: - (wacomhidfilter) – C:\Windows\SysNative\drivers\wacomhidfilter.sys (Wacom Technology)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmHidLo) – C:\Windows\SysNative\drivers\WmHidLo.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (ioatdma) Intel® – C:\Windows\SysNative\drivers\qd260x64.sys (Intel Corporation)
DRV:64bit: - (Pnp680) – C:\Windows\SysNative\drivers\PnP680.sys (Silicon Image, Inc)
DRV:64bit: - (SiFilter) – C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc)
DRV:64bit: - (SiRemFil) – C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc)
DRV:64bit: - (SI3132) – C:\Windows\SysNative\drivers\SI3132.sys (Silicon Image, Inc)
DRV:64bit: - (Ltn_rc_64) – C:\Windows\SysNative\drivers\Ltn_rc_64.sys (Liteon)
DRV:64bit: - (Ltn_stkrc_64) – C:\Windows\SysNative\drivers\Ltn_stkrc_64.sys (LITEON)
DRV:64bit: - (Ser2at) – C:\Windows\SysNative\drivers\ser2at64.sys (Prolific Technology Inc.)
DRV:64bit: - (Si3531) – C:\Windows\SysNative\drivers\Si3531.sys (Silicon Image, Inc)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IAMTVE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTVE.sys (Intel Corporation)
DRV:64bit: - (IAMTXPE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTXPE.sys (Intel Corporation)
DRV:64bit: - (SI3114r) – C:\Windows\SysNative\drivers\SI3114r.sys (Silicon Image, Inc)
DRV:64bit: - (hcw99rc) – C:\Windows\SysNative\drivers\hcw99rc.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WacomVTHid) – C:\Windows\SysNative\drivers\WacomVTHid.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\drivers\WacomVKHid.sys (Wacom Technology)
DRV:64bit: - (SI3112r) – C:\Windows\SysNative\drivers\SI3112r.sys (Silicon Image, Inc)
DRV:64bit: - (SISAGP) – C:\Windows\SysNative\drivers\SISAGPX.SYS (Silicon Integrated Systems Corporation)
DRV:64bit: - (SI3114) – C:\Windows\SysNative\drivers\SI3114.sys (Silicon Image, Inc.)
DRV:64bit: - (SI3124) – C:\Windows\SysNative\drivers\SI3124.sys (Silicon Image, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (Si3124r5) – C:\Windows\SysNative\drivers\Si3124r5.sys (Silicon Image, Inc)
DRV:64bit: - (hptmv) – C:\Windows\SysNative\drivers\hptmv.sys (HighPoint Technologies, Inc.)
DRV:64bit: - (viaagp1) – C:\Windows\SysNative\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (EuGdiDrv) – C:\Windows\SysWOW64\EuGdiDrv.sys ()
DRV - (epmntdrv) – C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (ISODrive) – C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.nl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://ssl.scroogle.org/"
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-06-28 16:13:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-02-03 22:52:37 | 000,000,000 | —D | M]
[2009-11-02 23:00:47 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Extensions
[2009-11-03 06:13:49 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Firefox\Profiles\1rz4vho0.default\extensions
[2009-11-02 23:00:34 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2009-10-16 20:42:18 | 000,001,892 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bolcom-nl.xml
[2009-10-16 20:42:18 | 000,004,558 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\marktplaats-nl.xml
[2009-10-16 20:42:18 | 000,001,111 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\vandale-nl.xml
[2009-10-16 20:42:18 | 000,001,049 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-nl.xml
[2009-10-16 20:42:18 | 000,000,802 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-nl.xml
O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Nuance OmniPage 17-reminder] C:\Program Files (x86)\Nuance\OmniPage17\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{BE5AD94C-D8D5-367F-D7DB-61CD876E67D5}] C:\Users\Gebruiker\AppData\Roaming\Edamcy\qued.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [OpAgent] File not found
O4 - HKCU..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} http://www.navigram.com/engine/v911/Navigram.cab (Navigram Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-20 13:20:10 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010-07-21 20:27:57 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Documents\Call of Juarez - Bound in Blood
[2010-07-16 22:17:08 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010-07-16 22:16:22 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010-07-16 22:14:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010-07-16 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe Media Player
[2010-07-16 22:12:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2010-07-16 22:07:05 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Desktop\Adobe CS5
[2010-07-14 04:05:54 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010-07-01 21:18:54 | 000,000,000 | —D | C] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-06-30 22:02:00 | 000,000,000 | —D | C] – C:\Program Files\TeamSpeak 3 Client
[2010-06-24 06:50:07 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-06-24 06:50:07 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-06-24 06:50:07 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-06-24 06:50:07 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-06-24 06:50:07 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-06-24 06:50:07 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010-07-23 11:07:04 | 002,621,440 | -HS- | M] () – C:\Users\Gebruiker\NTUSER.DAT
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:35:35 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-07-23 10:35:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-07-23 09:40:23 | 008,393,242 | -H– | M] () – C:\Users\Gebruiker\AppData\Local\IconCache.db
[2010-07-22 21:09:20 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010-07-22 21:09:18 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010-07-18 21:38:44 | 001,552,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-07-18 21:38:44 | 000,703,386 | —- | M] () – C:\Windows\SysNative\perfh013.dat
[2010-07-18 21:38:44 | 000,616,298 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-07-18 21:38:44 | 000,135,608 | —- | M] () – C:\Windows\SysNative\perfc013.dat
[2010-07-18 21:38:44 | 000,107,934 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-07-17 10:13:04 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2010-07-17 09:34:16 | 004,859,256 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-07-16 22:17:08 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-07-05 22:53:51 | 000,027,648 | —- | M] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | M] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | M] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-06-29 22:31:36 | 000,001,037 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010-07-16 17:13:58 | 000,000,000 | R— | C] () – C:\Users\Gebruiker\AppData\Roaming\BeIgD.txt
[2010-07-05 22:24:20 | 000,027,648 | —- | C] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | C] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | C] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-05-15 00:31:09 | 000,000,403 | —- | C] () – C:\Windows\MAXLINK.INI
[2010-02-20 15:51:28 | 000,000,392 | —- | C] () – C:\Windows\ODBC.INI
[2010-01-09 21:24:59 | 000,014,848 | —- | C] () – C:\Windows\SysWow64\EuEpmGdi.dll
[2010-01-09 21:24:59 | 000,014,216 | —- | C] () – C:\Windows\SysWow64\epmntdrv.sys
[2010-01-09 21:24:59 | 000,008,456 | —- | C] () – C:\Windows\SysWow64\EuGdiDrv.sys
[2009-11-21 11:47:21 | 001,581,906 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009-10-22 21:15:56 | 000,143,872 | —- | C] () – C:\Windows\SysWow64\libmpeg2_ff.dll
[2009-10-22 21:01:22 | 004,835,652 | —- | C] () – C:\Windows\SysWow64\libavcodec.dll
[2009-10-17 01:58:06 | 000,183,296 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2009-10-17 01:57:06 | 000,146,944 | —- | C] () – C:\Windows\SysWow64\ff_tremor.dll
[2009-10-17 01:04:24 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2009-10-17 01:04:08 | 000,113,152 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2009-10-17 01:03:48 | 000,257,024 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2009-10-17 01:03:44 | 000,142,848 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2009-10-17 01:03:40 | 000,484,864 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2009-10-17 00:10:10 | 000,281,748 | —- | C] () – C:\Windows\SysWow64\ff_kernelDeint.dll
[2009-10-16 22:53:32 | 000,100,864 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2009-10-16 22:53:20 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009-10-16 21:40:42 | 000,957,047 | —- | C] () – C:\Windows\SysWow64\ff_x264.dll
[2009-10-16 21:38:20 | 000,914,464 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009-10-16 21:35:50 | 000,311,204 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2009-10-16 21:08:54 | 000,611,638 | —- | C] () – C:\Windows\SysWow64\libmplayer.dll
[2009-10-16 21:04:28 | 001,632,375 | —- | C] () – C:\Windows\SysWow64\ffmpegmt.dll
[2009-10-07 03:56:03 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\OGAAddin.dll
[2009-10-07 03:43:15 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009-10-07 03:43:15 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009-10-07 03:43:13 | 002,378,752 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2009-08-03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-01-11 00:17:32 | 000,163,840 | —- | C] () – C:\Windows\SysWow64\ts.dll
[2009-01-11 00:16:56 | 000,148,480 | —- | C] () – C:\Windows\SysWow64\mkx.dll
[2009-01-11 00:16:50 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\avi.dll
[2009-01-11 00:16:14 | 000,141,312 | —- | C] () – C:\Windows\SysWow64\mp4.dll
[2009-01-11 00:15:54 | 000,120,832 | —- | C] () – C:\Windows\SysWow64\ogm.dll
[2009-01-11 00:15:44 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\mmfinfo.dll
[2009-01-11 00:15:32 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\avss.dll
[2009-01-11 00:15:28 | 000,246,784 | —- | C] () – C:\Windows\SysWow64\dxr.dll
[2009-01-11 00:15:12 | 000,097,280 | —- | C] () – C:\Windows\SysWow64\avs.dll
[2009-01-11 00:14:08 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\mkzlib.dll
[2009-01-11 00:14:06 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\mkunicode.dll
[2008-12-04 00:11:50 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2008-11-06 18:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2008-11-06 18:34:00 | 000,000,416 | —- | C] () – C:\Windows\SysWow64\dtu100.dll.manifest
[2007-10-13 11:30:20 | 000,000,137 | —- | C] () – C:\Windows\SysWow64\Registration.ini
[2007-07-10 19:10:12 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
========== LOP Check ==========
[2010-02-28 18:03:40 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Belastingdienst
[2010-02-08 00:02:36 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer
[2009-11-03 20:28:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer Pro
[2010-04-23 20:35:11 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Edamcy
[2009-12-23 23:47:28 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\gtk-2.0
[2009-11-03 20:05:22 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Leadertech
[2009-11-04 21:00:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\NewsLeecher
[2010-05-15 00:31:10 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Nuance
[2009-11-04 21:01:08 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\OpenOffice.org
[2009-12-23 23:28:13 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Participatory Culture Foundation
[2009-12-27 22:53:12 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\PCF-VLC
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\ScanSoft
[2010-01-10 16:16:50 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Spesoft Audio Converter
[2010-07-01 21:20:59 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-07-23 10:36:25 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Uwgy
[2010-05-15 00:24:57 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\YCanPDF
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Zeon
[2010-07-18 18:06:10 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007-03-12 19:59:00 | 000,299,008 | —- | M] () – C:\navigram_register.exe
< MD5 for: AGP440.SYS >
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009-07-14 03:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: IASTOR.SYS >
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_e0c941a8b0e04b56\iaStor.sys
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iastor.inf_amd64_neutral_7009a7672ee571e2\iaStor.sys
< MD5 for: IASTORV.SYS >
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009-07-14 03:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009-09-15 08:38:11 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=132DFCE35CFE831BA59E6359E1673CE3 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_94cf52d00bb79db2\scecli.dll
[2009-07-14 03:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009-07-14 03:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_9f23fd2240185fad\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9B013599
< End of report >
Microsoft security essentials informed me last week or so that my PC was infected with the PWS:Win32/Zbot.gen!Y virus or trojan or whatever it is! My virusscanner then allows me to quarantine or remove the item, which seems succesfull. However, every time I reboot, the infection turns up again, sometimes even without a reboot. I read that this infection is a real thread (password stealer) so I guess I should be worried. I would appreciate any help.
I performed this OTL check thing and here are the results:
OTL Extras logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0907-000001000000}" = 7-Zip 9.07 (x64 edition)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7AAC-C5D5-B89B-EBA1-D4DFC5E46D6C}" = AMD Drag and Drop Transcoding
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{9221C55E-0D1E-BA0E-5219-0564AF763AE7}" = ATI Catalyst Install Manager
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{A39FD4D2-002C-49F9-A13D-C15BC435D92E}" = Microsoft Antimalware Service NL-NL Language Pack
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{E1D6317F-4893-6517-838B-ECC5489D1711}" = ccc-utility64
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"HashTab" = HashTab 3.0.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.3
"Microsoft Security Essentials" = Microsoft Security Essentials
"SereneScreen Marine Aquarium 3_is1" = SereneScreen Marine Aquarium 3
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02993992-FF7E-03C0-3BF7-E892F2CD2B8F}" = Catalyst Control Center HydraVision Full
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10F5387D-1728-423A-A578-B00982CF2646}" = Windows Live Messenger
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1BD6AE96-4742-4498-9D03-9451C7E5A214}" = Windows Live aanmeldhulp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live - Hulpprogramma voor uploaden
"{218E787C-BADD-2284-AF4E-A1FA0D56772C}" = Catalyst Control Center Graphics Full Existing
"{21F791BA-E80A-0EEF-9B63-105EB939A5B2}" = CCC Help English
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2A8F82E8-7B86-4AFD-BFBC-2BA4C2CF52DB}" = Windows Live Call
"{34AFE453-F544-4269-89C9-CAB7F0744963}" = Nuance OmniPage 17
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D122AF9-1E02-4035-8003-334D378C1B62}_is1" = PDF OCR 3.2
"{44B49543-F839-46ED-61B9-3C91D71C7355}" = Catalyst Control Center Graphics Full New
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{562B9CA4-6E52-4F87-ACEC-912FC004F1F0}" = Windows Live Essentials
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58401B8E-0889-63C2-1E06-7C6530426411}" = Catalyst Control Center Graphics Previews Vista
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6530EB5E-F2BE-45D3-906B-E4AFFF2D1588}" = Windows Live Apparaatbeheer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7775B0BF-EC23-00B3-2E0F-D3FE89939C06}" = Catalyst Control Center Core Implementation
"{7AAAB55F-BB15-CEF4-9174-4AF79272D9EE}" = Catalyst Control Center Graphics Light
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90110413-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E1477E-810A-4185-BD9E-1A803498EFB3}" = OpenOffice.org 3.0
"{AC76BA86-7AD7-1043-7B44-A93000000001}" = Adobe Reader 9.3 - Nederlands
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = De Sims™ 3
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE6B96AF-83ED-9054-0B21-A68AF2EAF106}" = Catalyst Control Center InstallProxy
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D903102F-8294-97B5-3416-67DA5A71C87F}" = Catalyst Control Center Graphics Previews Common
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31043}" = Nero 7 Premium
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DFDB7828-15CF-4507-4998-D0B17A356705}" = ccc-core-static
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EF901A4B-A25A-4962-83C6-C6691D062ED9}" = Nero Mega Plugin Pack
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BSPlayerf" = BS.Player FREE
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DreamAqua" = Dream Aquarium
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 4.1.1 Professional
"Emilsoft FireBackup" = Emilsoft FireBackup
"FTD Skin_is1" = FTD Skin 3.8.5
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.1.6
"LogMeIn Hamachi" = LogMeIn Hamachi
"Messenger Plus! Live" = Messenger Plus! Live
"Miro" = Miro
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"NewsLeecher_is1" = NewsLeecher v3.9 Beta 6
"Pixum EasyBook" = Pixum EasyBook
"Plants vs. Zombies" = Plants vs. Zombies
"PunkBusterSvc" = PunkBuster Services
"qt7lite_is1" = QT Lite 3.0.0 BETA 3
"QuickPar" = QuickPar 0.9
"Spesoft Audio Converter_is1" = Spesoft Audio Converter 2.20
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UltraISO_is1" = UltraISO Premium V9.35
"Universal Extractor_is1" = Universal Extractor 1.6
"Windows 7 - Codec Pack" = Windows 7 Codec Pack 2.2.0
"WinLiveSuite_Wave3" = Windows Live Essentials
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14-7-2010 14:00:30 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 15:04:16 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 16:07:37 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7600.16450,
tijdstempel: 0x4aebab8d Naam van module met fout: ntdll.dll, versie: 6.1.7600.16559,
tijdstempel: 0x4ba9b802 Uitzonderingscode: 0xc0000374 Foutoffset: 0x00000000000c6df2
Id
van proces met fout: 0x624 Starttijd van toepassing met fout: 0x01cb235032d96b42
Pad
naar toepassing met fout: C:\Windows\Explorer.EXE Pad naar module met fout: C:\Windows\SYSTEM32\ntdll.dll
Rapport-id:
7204f30c-8f83-11df-95ed-0022158ec84f
Error - 14-7-2010 16:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 17:05:54 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x5a4 Starttijd van toepassing met fout: 0x01cb23984e08bf4a
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 9679f28b-8f8b-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:09:04 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x1174 Starttijd van toepassing met fout: 0x01cb2398827f9038
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 07e0052e-8f8c-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0xeb4 Starttijd van toepassing met fout: 0x01cb2398ef8e66e8
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 757c0138-8f8c-11df-b7d6-0022158ec84f
Error - 14-7-2010 17:13:37 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 18:02:52 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
Error - 14-7-2010 19:01:48 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.
[ System Events ]
Error - 3-4-2010 3:04:57 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
Error - 3-4-2010 9:57:37 | Computer Name = GEBRUIK-XSGU41S | Source = volsnap | ID = 393245
Description = De schaduwkopieën van volume C: zijn afgebroken tijdens de detectie.
Error - 3-4-2010 9:57:54 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci
Error - 3-4-2010 9:58:00 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 3-4-2010 10:01:04 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 3-4-2010 10:04:08 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
Error - 4-4-2010 17:17:03 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci
Error - 4-4-2010 17:17:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 4-4-2010 17:20:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.
Error - 4-4-2010 16:21:27 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.
< End of report >
OTL logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS
Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
========== Modules (SafeList) ==========
MOD - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16400_none_4209f94e2b866170\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll (Logitech, Inc.)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (vmx_svga) – C:\Windows\SysNative\DRIVERS\vmx_svga.sys File not found
DRV:64bit: - (VMAUDIO) VMware VMaudio (VMAUDIO) (WDM) – C:\Windows\SysNative\drivers\vmaudio.sys File not found
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (vmmouse) – C:\Windows\SysNative\drivers\vmmouse.sys (VMware, Inc.)
DRV:64bit: - (vm3dmp) – C:\Windows\SysNative\drivers\vm3dmp.sys (VMware, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (EuGdiDrv) – C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (vcrdrx64) – C:\Windows\SysNative\drivers\vcrdrx64.sys (VIA Technologies, Inc.)
DRV:64bit: - (epmntdrv) – C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (nvamacpi) – C:\Windows\SysNative\drivers\nvamacpi.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LUsbFilt) – C:\Windows\SysNative\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ioatdma2) Intel® – C:\Windows\SysNative\drivers\qd262x64.sys (Intel Corporation)
DRV:64bit: - (ioatdma1) – C:\Windows\SysNative\drivers\qd162x64.sys (Intel Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (johci) – C:\Windows\SysNative\drivers\johci.sys (JMicron )
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (MegaSR1) – C:\Windows\SysNative\drivers\MegaSR1.sys (LSI Corporation, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (viamrx64) – C:\Windows\SysNative\drivers\viamrx64.sys (VIA Technologies Inc.,Ltd)
DRV:64bit: - (WinTVCIUSB) – C:\Windows\SysNative\drivers\hcw11.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ViPrtX64) – C:\Windows\SysNative\drivers\ViPrtX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (ViBusX64) – C:\Windows\SysNative\drivers\ViBusX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (wisdpen) – C:\Windows\SysNative\drivers\wisdpen.sys (Wacom Technology)
DRV:64bit: - (wacomhidfilter) – C:\Windows\SysNative\drivers\wacomhidfilter.sys (Wacom Technology)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmHidLo) – C:\Windows\SysNative\drivers\WmHidLo.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (ioatdma) Intel® – C:\Windows\SysNative\drivers\qd260x64.sys (Intel Corporation)
DRV:64bit: - (Pnp680) – C:\Windows\SysNative\drivers\PnP680.sys (Silicon Image, Inc)
DRV:64bit: - (SiFilter) – C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc)
DRV:64bit: - (SiRemFil) – C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc)
DRV:64bit: - (SI3132) – C:\Windows\SysNative\drivers\SI3132.sys (Silicon Image, Inc)
DRV:64bit: - (Ltn_rc_64) – C:\Windows\SysNative\drivers\Ltn_rc_64.sys (Liteon)
DRV:64bit: - (Ltn_stkrc_64) – C:\Windows\SysNative\drivers\Ltn_stkrc_64.sys (LITEON)
DRV:64bit: - (Ser2at) – C:\Windows\SysNative\drivers\ser2at64.sys (Prolific Technology Inc.)
DRV:64bit: - (Si3531) – C:\Windows\SysNative\drivers\Si3531.sys (Silicon Image, Inc)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IAMTVE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTVE.sys (Intel Corporation)
DRV:64bit: - (IAMTXPE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTXPE.sys (Intel Corporation)
DRV:64bit: - (SI3114r) – C:\Windows\SysNative\drivers\SI3114r.sys (Silicon Image, Inc)
DRV:64bit: - (hcw99rc) – C:\Windows\SysNative\drivers\hcw99rc.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WacomVTHid) – C:\Windows\SysNative\drivers\WacomVTHid.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\drivers\WacomVKHid.sys (Wacom Technology)
DRV:64bit: - (SI3112r) – C:\Windows\SysNative\drivers\SI3112r.sys (Silicon Image, Inc)
DRV:64bit: - (SISAGP) – C:\Windows\SysNative\drivers\SISAGPX.SYS (Silicon Integrated Systems Corporation)
DRV:64bit: - (SI3114) – C:\Windows\SysNative\drivers\SI3114.sys (Silicon Image, Inc.)
DRV:64bit: - (SI3124) – C:\Windows\SysNative\drivers\SI3124.sys (Silicon Image, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (Si3124r5) – C:\Windows\SysNative\drivers\Si3124r5.sys (Silicon Image, Inc)
DRV:64bit: - (hptmv) – C:\Windows\SysNative\drivers\hptmv.sys (HighPoint Technologies, Inc.)
DRV:64bit: - (viaagp1) – C:\Windows\SysNative\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (EuGdiDrv) – C:\Windows\SysWOW64\EuGdiDrv.sys ()
DRV - (epmntdrv) – C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (ISODrive) – C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.nl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://ssl.scroogle.org/"
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-06-28 16:13:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-02-03 22:52:37 | 000,000,000 | —D | M]
[2009-11-02 23:00:47 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Extensions
[2009-11-03 06:13:49 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Firefox\Profiles\1rz4vho0.default\extensions
[2009-11-02 23:00:34 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2009-10-16 20:42:18 | 000,001,892 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bolcom-nl.xml
[2009-10-16 20:42:18 | 000,004,558 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\marktplaats-nl.xml
[2009-10-16 20:42:18 | 000,001,111 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\vandale-nl.xml
[2009-10-16 20:42:18 | 000,001,049 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-nl.xml
[2009-10-16 20:42:18 | 000,000,802 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-nl.xml
O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Nuance OmniPage 17-reminder] C:\Program Files (x86)\Nuance\OmniPage17\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{BE5AD94C-D8D5-367F-D7DB-61CD876E67D5}] C:\Users\Gebruiker\AppData\Roaming\Edamcy\qued.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [OpAgent] File not found
O4 - HKCU..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} http://www.navigram.com/engine/v911/Navigram.cab (Navigram Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-20 13:20:10 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010-07-21 20:27:57 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Documents\Call of Juarez - Bound in Blood
[2010-07-16 22:17:08 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010-07-16 22:16:22 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010-07-16 22:14:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010-07-16 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe Media Player
[2010-07-16 22:12:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2010-07-16 22:07:05 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Desktop\Adobe CS5
[2010-07-14 04:05:54 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010-07-01 21:18:54 | 000,000,000 | —D | C] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-06-30 22:02:00 | 000,000,000 | —D | C] – C:\Program Files\TeamSpeak 3 Client
[2010-06-24 06:50:07 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-06-24 06:50:07 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-06-24 06:50:07 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-06-24 06:50:07 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-06-24 06:50:07 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-06-24 06:50:07 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010-07-23 11:07:04 | 002,621,440 | -HS- | M] () – C:\Users\Gebruiker\NTUSER.DAT
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:35:35 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-07-23 10:35:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-07-23 09:40:23 | 008,393,242 | -H– | M] () – C:\Users\Gebruiker\AppData\Local\IconCache.db
[2010-07-22 21:09:20 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010-07-22 21:09:18 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010-07-18 21:38:44 | 001,552,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-07-18 21:38:44 | 000,703,386 | —- | M] () – C:\Windows\SysNative\perfh013.dat
[2010-07-18 21:38:44 | 000,616,298 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-07-18 21:38:44 | 000,135,608 | —- | M] () – C:\Windows\SysNative\perfc013.dat
[2010-07-18 21:38:44 | 000,107,934 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-07-17 10:13:04 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2010-07-17 09:34:16 | 004,859,256 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-07-16 22:17:08 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-07-05 22:53:51 | 000,027,648 | —- | M] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | M] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | M] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-06-29 22:31:36 | 000,001,037 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010-07-16 17:13:58 | 000,000,000 | R— | C] () – C:\Users\Gebruiker\AppData\Roaming\BeIgD.txt
[2010-07-05 22:24:20 | 000,027,648 | —- | C] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | C] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | C] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-05-15 00:31:09 | 000,000,403 | —- | C] () – C:\Windows\MAXLINK.INI
[2010-02-20 15:51:28 | 000,000,392 | —- | C] () – C:\Windows\ODBC.INI
[2010-01-09 21:24:59 | 000,014,848 | —- | C] () – C:\Windows\SysWow64\EuEpmGdi.dll
[2010-01-09 21:24:59 | 000,014,216 | —- | C] () – C:\Windows\SysWow64\epmntdrv.sys
[2010-01-09 21:24:59 | 000,008,456 | —- | C] () – C:\Windows\SysWow64\EuGdiDrv.sys
[2009-11-21 11:47:21 | 001,581,906 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009-10-22 21:15:56 | 000,143,872 | —- | C] () – C:\Windows\SysWow64\libmpeg2_ff.dll
[2009-10-22 21:01:22 | 004,835,652 | —- | C] () – C:\Windows\SysWow64\libavcodec.dll
[2009-10-17 01:58:06 | 000,183,296 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2009-10-17 01:57:06 | 000,146,944 | —- | C] () – C:\Windows\SysWow64\ff_tremor.dll
[2009-10-17 01:04:24 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2009-10-17 01:04:08 | 000,113,152 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2009-10-17 01:03:48 | 000,257,024 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2009-10-17 01:03:44 | 000,142,848 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2009-10-17 01:03:40 | 000,484,864 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2009-10-17 00:10:10 | 000,281,748 | —- | C] () – C:\Windows\SysWow64\ff_kernelDeint.dll
[2009-10-16 22:53:32 | 000,100,864 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2009-10-16 22:53:20 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009-10-16 21:40:42 | 000,957,047 | —- | C] () – C:\Windows\SysWow64\ff_x264.dll
[2009-10-16 21:38:20 | 000,914,464 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009-10-16 21:35:50 | 000,311,204 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2009-10-16 21:08:54 | 000,611,638 | —- | C] () – C:\Windows\SysWow64\libmplayer.dll
[2009-10-16 21:04:28 | 001,632,375 | —- | C] () – C:\Windows\SysWow64\ffmpegmt.dll
[2009-10-07 03:56:03 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\OGAAddin.dll
[2009-10-07 03:43:15 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009-10-07 03:43:15 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009-10-07 03:43:13 | 002,378,752 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2009-08-03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-01-11 00:17:32 | 000,163,840 | —- | C] () – C:\Windows\SysWow64\ts.dll
[2009-01-11 00:16:56 | 000,148,480 | —- | C] () – C:\Windows\SysWow64\mkx.dll
[2009-01-11 00:16:50 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\avi.dll
[2009-01-11 00:16:14 | 000,141,312 | —- | C] () – C:\Windows\SysWow64\mp4.dll
[2009-01-11 00:15:54 | 000,120,832 | —- | C] () – C:\Windows\SysWow64\ogm.dll
[2009-01-11 00:15:44 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\mmfinfo.dll
[2009-01-11 00:15:32 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\avss.dll
[2009-01-11 00:15:28 | 000,246,784 | —- | C] () – C:\Windows\SysWow64\dxr.dll
[2009-01-11 00:15:12 | 000,097,280 | —- | C] () – C:\Windows\SysWow64\avs.dll
[2009-01-11 00:14:08 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\mkzlib.dll
[2009-01-11 00:14:06 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\mkunicode.dll
[2008-12-04 00:11:50 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2008-11-06 18:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2008-11-06 18:34:00 | 000,000,416 | —- | C] () – C:\Windows\SysWow64\dtu100.dll.manifest
[2007-10-13 11:30:20 | 000,000,137 | —- | C] () – C:\Windows\SysWow64\Registration.ini
[2007-07-10 19:10:12 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
========== LOP Check ==========
[2010-02-28 18:03:40 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Belastingdienst
[2010-02-08 00:02:36 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer
[2009-11-03 20:28:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer Pro
[2010-04-23 20:35:11 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Edamcy
[2009-12-23 23:47:28 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\gtk-2.0
[2009-11-03 20:05:22 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Leadertech
[2009-11-04 21:00:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\NewsLeecher
[2010-05-15 00:31:10 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Nuance
[2009-11-04 21:01:08 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\OpenOffice.org
[2009-12-23 23:28:13 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Participatory Culture Foundation
[2009-12-27 22:53:12 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\PCF-VLC
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\ScanSoft
[2010-01-10 16:16:50 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Spesoft Audio Converter
[2010-07-01 21:20:59 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-07-23 10:36:25 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Uwgy
[2010-05-15 00:24:57 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\YCanPDF
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Zeon
[2010-07-18 18:06:10 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007-03-12 19:59:00 | 000,299,008 | —- | M] () – C:\navigram_register.exe
< MD5 for: AGP440.SYS >
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009-07-14 03:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: IASTOR.SYS >
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_e0c941a8b0e04b56\iaStor.sys
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iastor.inf_amd64_neutral_7009a7672ee571e2\iaStor.sys
< MD5 for: IASTORV.SYS >
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009-07-14 03:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009-09-15 08:38:11 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=132DFCE35CFE831BA59E6359E1673CE3 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_94cf52d00bb79db2\scecli.dll
[2009-07-14 03:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009-07-14 03:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_9f23fd2240185fad\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9B013599
< End of report >