This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Zbot.gen!Y

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!

Microsoft security essentials informed me last week or so that my PC was infected with the PWS:Win32/Zbot.gen!Y virus or trojan or whatever it is! My virusscanner then allows me to quarantine or remove the item, which seems succesfull. However, every time I reboot, the infection turns up again, sometimes even without a reboot. I read that this infection is a real thread (password stealer) so I guess I should be worried. I would appreciate any help.


I performed this OTL check thing and here are the results:



OTL Extras logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS

Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Burn With ImgTool…] – C:\Program Files (x86)\ImgTool Burn\ImgTool.exe -c -d "%l" (Jörg4Anna)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Pixum EasyBook] – "C:\Program Files (x86)\Pixum\Pixum EasyBook\Pixum EasyBook.exe" "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0907-000001000000}" = 7-Zip 9.07 (x64 edition)
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7AAC-C5D5-B89B-EBA1-D4DFC5E46D6C}" = AMD Drag and Drop Transcoding
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{9221C55E-0D1E-BA0E-5219-0564AF763AE7}" = ATI Catalyst Install Manager
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{A39FD4D2-002C-49F9-A13D-C15BC435D92E}" = Microsoft Antimalware Service NL-NL Language Pack
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{E1D6317F-4893-6517-838B-ECC5489D1711}" = ccc-utility64
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"HashTab" = HashTab 3.0.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.3
"Microsoft Security Essentials" = Microsoft Security Essentials
"SereneScreen Marine Aquarium 3_is1" = SereneScreen Marine Aquarium 3
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WinRAR archiver" = WinRAR

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02993992-FF7E-03C0-3BF7-E892F2CD2B8F}" = Catalyst Control Center HydraVision Full
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10F5387D-1728-423A-A578-B00982CF2646}" = Windows Live Messenger
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1BD6AE96-4742-4498-9D03-9451C7E5A214}" = Windows Live aanmeldhulp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live - Hulpprogramma voor uploaden
"{218E787C-BADD-2284-AF4E-A1FA0D56772C}" = Catalyst Control Center Graphics Full Existing
"{21F791BA-E80A-0EEF-9B63-105EB939A5B2}" = CCC Help English
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2A8F82E8-7B86-4AFD-BFBC-2BA4C2CF52DB}" = Windows Live Call
"{34AFE453-F544-4269-89C9-CAB7F0744963}" = Nuance OmniPage 17
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D122AF9-1E02-4035-8003-334D378C1B62}_is1" = PDF OCR 3.2
"{44B49543-F839-46ED-61B9-3C91D71C7355}" = Catalyst Control Center Graphics Full New
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{562B9CA4-6E52-4F87-ACEC-912FC004F1F0}" = Windows Live Essentials
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58401B8E-0889-63C2-1E06-7C6530426411}" = Catalyst Control Center Graphics Previews Vista
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6530EB5E-F2BE-45D3-906B-E4AFFF2D1588}" = Windows Live Apparaatbeheer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{72736F5F-520D-472A-88CC-7B02872FD34E}" = ATI Catalyst Registration
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7775B0BF-EC23-00B3-2E0F-D3FE89939C06}" = Catalyst Control Center Core Implementation
"{7AAAB55F-BB15-CEF4-9174-4AF79272D9EE}" = Catalyst Control Center Graphics Light
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90110413-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E1477E-810A-4185-BD9E-1A803498EFB3}" = OpenOffice.org 3.0
"{AC76BA86-7AD7-1043-7B44-A93000000001}" = Adobe Reader 9.3 - Nederlands
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = De Sims™ 3
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE6B96AF-83ED-9054-0B21-A68AF2EAF106}" = Catalyst Control Center InstallProxy
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D903102F-8294-97B5-3416-67DA5A71C87F}" = Catalyst Control Center Graphics Previews Common
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31043}" = Nero 7 Premium
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DFDB7828-15CF-4507-4998-D0B17A356705}" = ccc-core-static
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EF901A4B-A25A-4962-83C6-C6691D062ED9}" = Nero Mega Plugin Pack
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BSPlayerf" = BS.Player FREE
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DreamAqua" = Dream Aquarium
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 4.1.1 Professional
"Emilsoft FireBackup" = Emilsoft FireBackup
"FTD Skin_is1" = FTD Skin 3.8.5
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.1.6
"LogMeIn Hamachi" = LogMeIn Hamachi
"Messenger Plus! Live" = Messenger Plus! Live
"Miro" = Miro
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"NewsLeecher_is1" = NewsLeecher v3.9 Beta 6
"Pixum EasyBook" = Pixum EasyBook
"Plants vs. Zombies" = Plants vs. Zombies
"PunkBusterSvc" = PunkBuster Services
"qt7lite_is1" = QT Lite 3.0.0 BETA 3
"QuickPar" = QuickPar 0.9
"Spesoft Audio Converter_is1" = Spesoft Audio Converter 2.20
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"UltraISO_is1" = UltraISO Premium V9.35
"Universal Extractor_is1" = Universal Extractor 1.6
"Windows 7 - Codec Pack" = Windows 7 Codec Pack 2.2.0
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 14-7-2010 14:00:30 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

Error - 14-7-2010 15:04:16 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

Error - 14-7-2010 16:07:37 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7600.16450,
tijdstempel: 0x4aebab8d Naam van module met fout: ntdll.dll, versie: 6.1.7600.16559,
tijdstempel: 0x4ba9b802 Uitzonderingscode: 0xc0000374 Foutoffset: 0x00000000000c6df2
Id
van proces met fout: 0x624 Starttijd van toepassing met fout: 0x01cb235032d96b42
Pad
naar toepassing met fout: C:\Windows\Explorer.EXE Pad naar module met fout: C:\Windows\SYSTEM32\ntdll.dll
Rapport-id:
7204f30c-8f83-11df-95ed-0022158ec84f

Error - 14-7-2010 16:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

Error - 14-7-2010 17:05:54 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x5a4 Starttijd van toepassing met fout: 0x01cb23984e08bf4a
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 9679f28b-8f8b-11df-b7d6-0022158ec84f

Error - 14-7-2010 17:09:04 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0x1174 Starttijd van toepassing met fout: 0x01cb2398827f9038
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 07e0052e-8f8c-11df-b7d6-0022158ec84f

Error - 14-7-2010 17:12:08 | Computer Name = GEBRUIK-XSGU41S | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: spoolsv.exe, versie: 6.1.7600.16385,
tijdstempel: 0x4a5bd3d1 Naam van module met fout: TPVMMon.dll, versie: [removed],
tijdstempel: 0x4a2faae7 Uitzonderingscode: 0xc0000005 Foutoffset: 0x000000000000863e
Id
van proces met fout: 0xeb4 Starttijd van toepassing met fout: 0x01cb2398ef8e66e8
Pad
naar toepassing met fout: C:\Windows\System32\spoolsv.exe Pad naar module met fout:
C:\Windows\System32\TPVMMon.dll Rapport-id: 757c0138-8f8c-11df-b7d6-0022158ec84f

Error - 14-7-2010 17:13:37 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

Error - 14-7-2010 18:02:52 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

Error - 14-7-2010 19:01:48 | Computer Name = GEBRUIK-XSGU41S | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Het uitpakken van een basislijst uit het CAB-bestand voor automatische
updates is mislukt op <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
met de fout: Een benodigd certificaat valt niet binnen de geldigheidsduur als gekeken
wordt naar de huidige systeemklok of de tijdstempel in het ondertekende bestand.
.

[ System Events ]
Error - 3-4-2010 3:04:57 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.

Error - 3-4-2010 9:57:37 | Computer Name = GEBRUIK-XSGU41S | Source = volsnap | ID = 393245
Description = De schaduwkopieën van volume C: zijn afgebroken tijdens de detectie.

Error - 3-4-2010 9:57:54 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci

Error - 3-4-2010 9:58:00 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.

Error - 3-4-2010 10:01:04 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.

Error - 3-4-2010 10:04:08 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.

Error - 4-4-2010 17:17:03 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: johci

Error - 4-4-2010 17:17:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 1 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.

Error - 4-4-2010 17:20:14 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7031
Description = De Print Spooler-service is onverwacht gestopt. Dit is 2 keer gebeurd.
De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd: Service
opnieuw starten.

Error - 4-4-2010 16:21:27 | Computer Name = GEBRUIK-XSGU41S | Source = Service Control Manager | ID = 7034
Description = De Print Spooler-service is onverwacht beëindigd. Dit is nu 3 keer
gebeurd.


< End of report >



OTL logfile created on: 23-7-2010 11:10:10 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Gebruiker\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 91,21 Gb Free Space | 9,79% Space Free | Partition Type: NTFS
Drive D: | 1181,64 Gb Total Space | 361,69 Gb Free Space | 30,61% Space Free | Partition Type: NTFS
Drive E: | 10,69 Gb Total Space | 10,61 Gb Free Space | 99,24% Space Free | Partition Type: NTFS
Drive F: | 4,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 931,50 Gb Total Space | 6,33 Gb Free Space | 0,68% Space Free | Partition Type: NTFS

Computer Name: GEBRUIK-XSGU41S
Current User Name: Gebruiker
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Users\Gebruiker\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16400_none_4209f94e2b866170\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll (Logitech, Inc.)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (vmx_svga) – C:\Windows\SysNative\DRIVERS\vmx_svga.sys File not found
DRV:64bit: - (VMAUDIO) VMware VMaudio (VMAUDIO) (WDM) – C:\Windows\SysNative\drivers\vmaudio.sys File not found
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (vmmouse) – C:\Windows\SysNative\drivers\vmmouse.sys (VMware, Inc.)
DRV:64bit: - (vm3dmp) – C:\Windows\SysNative\drivers\vm3dmp.sys (VMware, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (EuGdiDrv) – C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (vcrdrx64) – C:\Windows\SysNative\drivers\vcrdrx64.sys (VIA Technologies, Inc.)
DRV:64bit: - (epmntdrv) – C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (nvamacpi) – C:\Windows\SysNative\drivers\nvamacpi.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LUsbFilt) – C:\Windows\SysNative\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ioatdma2) Intel® – C:\Windows\SysNative\drivers\qd262x64.sys (Intel Corporation)
DRV:64bit: - (ioatdma1) – C:\Windows\SysNative\drivers\qd162x64.sys (Intel Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (johci) – C:\Windows\SysNative\drivers\johci.sys (JMicron )
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (MegaSR1) – C:\Windows\SysNative\drivers\MegaSR1.sys (LSI Corporation, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (viamrx64) – C:\Windows\SysNative\drivers\viamrx64.sys (VIA Technologies Inc.,Ltd)
DRV:64bit: - (WinTVCIUSB) – C:\Windows\SysNative\drivers\hcw11.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (ViPrtX64) – C:\Windows\SysNative\drivers\ViPrtX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (ViBusX64) – C:\Windows\SysNative\drivers\ViBusX64.sys (VIA Technologies, Inc.)
DRV:64bit: - (wisdpen) – C:\Windows\SysNative\drivers\wisdpen.sys (Wacom Technology)
DRV:64bit: - (wacomhidfilter) – C:\Windows\SysNative\drivers\wacomhidfilter.sys (Wacom Technology)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmHidLo) – C:\Windows\SysNative\drivers\WmHidLo.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (ioatdma) Intel® – C:\Windows\SysNative\drivers\qd260x64.sys (Intel Corporation)
DRV:64bit: - (Pnp680) – C:\Windows\SysNative\drivers\PnP680.sys (Silicon Image, Inc)
DRV:64bit: - (SiFilter) – C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc)
DRV:64bit: - (SiRemFil) – C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc)
DRV:64bit: - (SI3132) – C:\Windows\SysNative\drivers\SI3132.sys (Silicon Image, Inc)
DRV:64bit: - (Ltn_rc_64) – C:\Windows\SysNative\drivers\Ltn_rc_64.sys (Liteon)
DRV:64bit: - (Ltn_stkrc_64) – C:\Windows\SysNative\drivers\Ltn_stkrc_64.sys (LITEON)
DRV:64bit: - (Ser2at) – C:\Windows\SysNative\drivers\ser2at64.sys (Prolific Technology Inc.)
DRV:64bit: - (Si3531) – C:\Windows\SysNative\drivers\Si3531.sys (Silicon Image, Inc)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IAMTVE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTVE.sys (Intel Corporation)
DRV:64bit: - (IAMTXPE) Stuurprogramma voor Intel® – C:\Windows\SysNative\drivers\IAMTXPE.sys (Intel Corporation)
DRV:64bit: - (SI3114r) – C:\Windows\SysNative\drivers\SI3114r.sys (Silicon Image, Inc)
DRV:64bit: - (hcw99rc) – C:\Windows\SysNative\drivers\hcw99rc.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WacomVTHid) – C:\Windows\SysNative\drivers\WacomVTHid.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\drivers\WacomVKHid.sys (Wacom Technology)
DRV:64bit: - (SI3112r) – C:\Windows\SysNative\drivers\SI3112r.sys (Silicon Image, Inc)
DRV:64bit: - (SISAGP) – C:\Windows\SysNative\drivers\SISAGPX.SYS (Silicon Integrated Systems Corporation)
DRV:64bit: - (SI3114) – C:\Windows\SysNative\drivers\SI3114.sys (Silicon Image, Inc.)
DRV:64bit: - (SI3124) – C:\Windows\SysNative\drivers\SI3124.sys (Silicon Image, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (Si3124r5) – C:\Windows\SysNative\drivers\Si3124r5.sys (Silicon Image, Inc)
DRV:64bit: - (hptmv) – C:\Windows\SysNative\drivers\hptmv.sys (HighPoint Technologies, Inc.)
DRV:64bit: - (viaagp1) – C:\Windows\SysNative\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (EuGdiDrv) – C:\Windows\SysWOW64\EuGdiDrv.sys ()
DRV - (epmntdrv) – C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (ISODrive) – C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys (EZB Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.nl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://ssl.scroogle.org/"


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-06-28 16:13:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-02-03 22:52:37 | 000,000,000 | —D | M]

[2009-11-02 23:00:47 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Extensions
[2009-11-03 06:13:49 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\mozilla\Firefox\Profiles\1rz4vho0.default\extensions
[2009-11-02 23:00:34 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2009-10-16 20:42:18 | 000,001,892 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bolcom-nl.xml
[2009-10-16 20:42:18 | 000,004,558 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\marktplaats-nl.xml
[2009-10-16 20:42:18 | 000,001,111 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\vandale-nl.xml
[2009-10-16 20:42:18 | 000,001,049 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-nl.xml
[2009-10-16 20:42:18 | 000,000,802 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-nl.xml

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Create 5\Bin\ZeonIEFavClient.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Nuance OmniPage 17-reminder] C:\Program Files (x86)\Nuance\OmniPage17\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{BE5AD94C-D8D5-367F-D7DB-61CD876E67D5}] C:\Users\Gebruiker\AppData\Roaming\Edamcy\qued.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [OpAgent] File not found
O4 - HKCU..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Tools\VSock SDK\bin\win32\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} http://www.navigram.com/engine/v911/Navigram.cab (Navigram Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-20 13:20:10 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010-07-21 20:27:57 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Documents\Call of Juarez - Bound in Blood
[2010-07-16 22:17:08 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010-07-16 22:16:22 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010-07-16 22:14:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010-07-16 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe Media Player
[2010-07-16 22:12:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2010-07-16 22:07:05 | 000,000,000 | —D | C] – C:\Users\Gebruiker\Desktop\Adobe CS5
[2010-07-14 04:05:54 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010-07-01 21:18:54 | 000,000,000 | —D | C] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-06-30 22:02:00 | 000,000,000 | —D | C] – C:\Program Files\TeamSpeak 3 Client
[2010-06-24 06:50:07 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-06-24 06:50:07 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-06-24 06:50:07 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-06-24 06:50:07 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-06-24 06:50:07 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-06-24 06:50:07 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-06-24 06:50:07 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-07-23 11:07:04 | 002,621,440 | -HS- | M] () – C:\Users\Gebruiker\NTUSER.DAT
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:42:44 | 000,013,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-07-23 10:35:35 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-07-23 10:35:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-07-23 09:40:23 | 008,393,242 | -H– | M] () – C:\Users\Gebruiker\AppData\Local\IconCache.db
[2010-07-22 21:09:20 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010-07-22 21:09:18 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010-07-18 21:38:44 | 001,552,290 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-07-18 21:38:44 | 000,703,386 | —- | M] () – C:\Windows\SysNative\perfh013.dat
[2010-07-18 21:38:44 | 000,616,298 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-07-18 21:38:44 | 000,135,608 | —- | M] () – C:\Windows\SysNative\perfc013.dat
[2010-07-18 21:38:44 | 000,107,934 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-07-17 10:13:04 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2010-07-17 09:34:16 | 004,859,256 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-07-16 22:17:08 | 000,066,104 | —- | M] () – C:\Users\Gebruiker\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-07-05 22:53:51 | 000,027,648 | —- | M] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | M] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | M] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-06-29 22:31:36 | 000,001,037 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-07-16 17:13:58 | 000,000,000 | R— | C] () – C:\Users\Gebruiker\AppData\Roaming\BeIgD.txt
[2010-07-05 22:24:20 | 000,027,648 | —- | C] () – C:\Users\Gebruiker\Documents\Notulen AGN bijeenkomst nr 18.doc
[2010-07-05 06:52:22 | 000,780,288 | —- | C] () – C:\Users\Gebruiker\Documents\Woord vooraf.doc
[2010-06-30 22:02:01 | 000,000,967 | —- | C] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-05-15 00:31:09 | 000,000,403 | —- | C] () – C:\Windows\MAXLINK.INI
[2010-02-20 15:51:28 | 000,000,392 | —- | C] () – C:\Windows\ODBC.INI
[2010-01-09 21:24:59 | 000,014,848 | —- | C] () – C:\Windows\SysWow64\EuEpmGdi.dll
[2010-01-09 21:24:59 | 000,014,216 | —- | C] () – C:\Windows\SysWow64\epmntdrv.sys
[2010-01-09 21:24:59 | 000,008,456 | —- | C] () – C:\Windows\SysWow64\EuGdiDrv.sys
[2009-11-21 11:47:21 | 001,581,906 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009-10-22 21:15:56 | 000,143,872 | —- | C] () – C:\Windows\SysWow64\libmpeg2_ff.dll
[2009-10-22 21:01:22 | 004,835,652 | —- | C] () – C:\Windows\SysWow64\libavcodec.dll
[2009-10-17 01:58:06 | 000,183,296 | —- | C] () – C:\Windows\SysWow64\ff_samplerate.dll
[2009-10-17 01:57:06 | 000,146,944 | —- | C] () – C:\Windows\SysWow64\ff_tremor.dll
[2009-10-17 01:04:24 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\ff_libmad.dll
[2009-10-17 01:04:08 | 000,113,152 | —- | C] () – C:\Windows\SysWow64\ff_unrar.dll
[2009-10-17 01:03:48 | 000,257,024 | —- | C] () – C:\Windows\SysWow64\ff_libdts.dll
[2009-10-17 01:03:44 | 000,142,848 | —- | C] () – C:\Windows\SysWow64\ff_liba52.dll
[2009-10-17 01:03:40 | 000,484,864 | —- | C] () – C:\Windows\SysWow64\ff_libfaad2.dll
[2009-10-17 00:10:10 | 000,281,748 | —- | C] () – C:\Windows\SysWow64\ff_kernelDeint.dll
[2009-10-16 22:53:32 | 000,100,864 | —- | C] () – C:\Windows\SysWow64\ff_wmv9.dll
[2009-10-16 22:53:20 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009-10-16 21:40:42 | 000,957,047 | —- | C] () – C:\Windows\SysWow64\ff_x264.dll
[2009-10-16 21:38:20 | 000,914,464 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009-10-16 21:35:50 | 000,311,204 | —- | C] () – C:\Windows\SysWow64\TomsMoComp_ff.dll
[2009-10-16 21:08:54 | 000,611,638 | —- | C] () – C:\Windows\SysWow64\libmplayer.dll
[2009-10-16 21:04:28 | 001,632,375 | —- | C] () – C:\Windows\SysWow64\ffmpegmt.dll
[2009-10-07 03:56:03 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\OGAAddin.dll
[2009-10-07 03:43:15 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009-10-07 03:43:15 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009-10-07 03:43:13 | 002,378,752 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2009-08-03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2009-08-03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2009-08-03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-01-11 00:17:32 | 000,163,840 | —- | C] () – C:\Windows\SysWow64\ts.dll
[2009-01-11 00:16:56 | 000,148,480 | —- | C] () – C:\Windows\SysWow64\mkx.dll
[2009-01-11 00:16:50 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\avi.dll
[2009-01-11 00:16:14 | 000,141,312 | —- | C] () – C:\Windows\SysWow64\mp4.dll
[2009-01-11 00:15:54 | 000,120,832 | —- | C] () – C:\Windows\SysWow64\ogm.dll
[2009-01-11 00:15:44 | 000,159,744 | —- | C] () – C:\Windows\SysWow64\mmfinfo.dll
[2009-01-11 00:15:32 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\avss.dll
[2009-01-11 00:15:28 | 000,246,784 | —- | C] () – C:\Windows\SysWow64\dxr.dll
[2009-01-11 00:15:12 | 000,097,280 | —- | C] () – C:\Windows\SysWow64\avs.dll
[2009-01-11 00:14:08 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\mkzlib.dll
[2009-01-11 00:14:06 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\mkunicode.dll
[2008-12-04 00:11:50 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2008-11-06 18:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2008-11-06 18:34:00 | 000,000,416 | —- | C] () – C:\Windows\SysWow64\dtu100.dll.manifest
[2007-10-13 11:30:20 | 000,000,137 | —- | C] () – C:\Windows\SysWow64\Registration.ini
[2007-07-10 19:10:12 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest

========== LOP Check ==========

[2010-02-28 18:03:40 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Belastingdienst
[2010-02-08 00:02:36 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer
[2009-11-03 20:28:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\BSplayer Pro
[2010-04-23 20:35:11 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Edamcy
[2009-12-23 23:47:28 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\gtk-2.0
[2009-11-03 20:05:22 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Leadertech
[2009-11-04 21:00:02 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\NewsLeecher
[2010-05-15 00:31:10 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Nuance
[2009-11-04 21:01:08 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\OpenOffice.org
[2009-12-23 23:28:13 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Participatory Culture Foundation
[2009-12-27 22:53:12 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\PCF-VLC
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\ScanSoft
[2010-01-10 16:16:50 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Spesoft Audio Converter
[2010-07-01 21:20:59 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\TS3Client
[2010-07-23 10:36:25 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Uwgy
[2010-05-15 00:24:57 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\YCanPDF
[2010-05-15 00:33:00 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Zeon
[2010-07-18 18:06:10 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007-03-12 19:59:00 | 000,299,008 | —- | M] () – C:\navigram_register.exe


< MD5 for: AGP440.SYS >
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009-07-14 03:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009-07-14 03:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009-07-14 03:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009-07-14 03:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_e0c941a8b0e04b56\iaStor.sys
[2009-02-11 17:26:18 | 000,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Windows\SysWow64\DriverStore\FileRepository\iastor.inf_amd64_neutral_7009a7672ee571e2\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009-07-14 03:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009-07-14 03:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009-07-14 03:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009-07-14 03:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009-09-15 08:38:11 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=132DFCE35CFE831BA59E6359E1673CE3 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_94cf52d00bb79db2\scecli.dll
[2009-07-14 03:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009-07-14 03:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\SysWOW64\scecli.dll
[2009-09-15 07:59:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=53B13B258970B6B5A1FE09F26EB3B3A6 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.20527_none_9f23fd2240185fad\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9B013599
< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hi, Thanks for the help so far! Just performed the malwarebyte scan, it did remove something, hope thats sufficient, so here´s the result: All in all, I really haven´t noticed anything " strange" or something while working with my PC, it doens´t seem slower or anything, just the fact that my virus scanner (microsoft essentials) kept popping up, informing me about this infection everytime after a reboot. I guess I´ll do a reboot now and see whether the infection seems gone. Is there anyting else I should do now? Thanks a lot! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Databaseversie: 4347 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 25-7-2010 23:18:19 mbam-log-2010-07-25 (23-18-19).txt Scantype: Snelle scan Objecten gescand: 130622 Verstreken tijd: 3 minuut/minuten, 58 seconde(n) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 0 Registerwaarden geïnfecteerd: 0 Registerdata geïnfecteerd: 0 Mappen geïnfecteerd: 0 Bestanden geïnfecteerd: 1 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registersleutels geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerwaarden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerdata geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Mappen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Bestanden geïnfecteerd: C:\Users\Gebruiker\Local Settings\Temporary Internet Files\udRemove.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Hi there, Just rebooted and I got the usual message from microsoft virus scanner about this infection …. :angry: Any idea´s? Thanks in advance.
Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi, I tried Kasperky´s virus scanner online, but it worked very slowly. I let it run overnight but eventually, for some reason, a reboot had happened, maybe after the scan was complete, I wasn´t there at the moment so I don´t know. I haven´t found any log and there´s no report when I visit the Kaspersky´s online scanner. Isn´t there another option I might try which doens´t take 24 hours or so. Very likely that it will reboot again. Thanks in advance!
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Hi, Here´s the result from the ESET online scan. Important: I just checked the history of my standard virus scanner (microsoft security essentials) and today it reported infection by " exploit:Win32/Pdfjsc.J" in stead of the usual "Zbot.gen!Y". This is getting weird… (well, for me it is). I´m still hoping you can help me out with this! Thanks in advance! ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial= # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-07-27 08:26:49 # local_time=2010-07-27 10:26:49 (+0100, West-Europa (zomertijd)) # country="Netherlands" # lang=9 # osver=6.1.7600 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5891 16776573 100 100 43877 10713206 0 0 # compatibility_mode=8192 67108863 100 0 152 152 0 0 # scanned=413143 # found=13 # cleaned=0 # scan_time=7381 removed locations of threats
You need to remove everything it shows bad. We don't support any systems with illegal someway installed.
Hi, I deleted all the files that were reported to be threats, but the trojan is still there, after every reboot I get a message about it. I edited my previous post a bit. I hope I can still get some help.
You should be able to view what MSE found. I use it on my home pc so I'll look at MSE when I get home and see how to find them.
Hi, Have you looked into MSE and how to get that file location? I looked for it but couldn´t find anything, just this notification that i´m infected and the action I had chosen. I can make a screenshot if you like. Anyway, still infected. Cheers

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI