searchqu
11 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Download and run OTL
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under Custom Scan paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90 - Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- When the scan completes, it will open two notepad windows. OTL.txt and Extras.txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- You may need two posts to fit them both in.
Run aswMBR
Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
Click to load external image (Posted Image)
On completion of the scan click save log, save it to your desktop and post in your next reply
Click to load external image (Posted Image)
Logs to include with next post:
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Thank you for willing to help me! Here are the 3 logs you requested:
aswMBR version 0.9.6.399 Copyright© 2011 AVAST Software
Run date: 2011-06-16 10:46:21
—————————–
10:46:21.699 OS Version: Windows 6.1.7600
10:46:21.700 Number of processors: 2 586 0x1C0A
10:46:21.786 ComputerName: DIEKAT UserName:
10:46:24.794 Initialize success
10:46:35.276 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
10:46:35.284 Disk 0 Vendor: WDC_WD2500BEVT-80A23T0 01.01A01 Size: 238475MB BusType: 11
10:46:37.384 Disk 0 MBR read successfully
10:46:37.393 Disk 0 MBR scan
10:46:37.403 Disk 0 Windows 7 default MBR code
10:46:39.420 Disk 0 scanning sectors +488397168
10:46:40.149 Disk 0 scanning C:\windows\system32\drivers
10:46:47.371 Service scanning
10:46:49.531 Disk 0 trace - called modules:
10:46:49.567 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys
10:46:49.582 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8648a030]
10:46:49.599 3 CLASSPNP.SYS[8998359e] -> nt!IofCallDriver -> [0x856d41e0]
10:46:49.616 5 ACPI.sys[892973b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85fe0908]
10:46:49.634 Scan finished successfully
10:51:00.505 Disk 0 MBR has been saved successfully to "D:\Users\Katrien\Documents\MBR.dat"
10:51:00.528 The log file has been saved successfully to "D:\Users\Katrien\Documents\aswMBR.txt"
OTL logfile created on: 16/06/2011 10:45:44 a.m. - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = D:\Users\Katrien\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001409 | Country: Nieuw-Zeeland | Language: ENZ | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 47.97% Memory free
4.00 Gb Paging File | 2.64 Gb Available in Paging File | 65.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 75.10 Gb Free Space | 75.10% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 101.75 Gb Free Space | 86.33% Space Free | Partition Type: NTFS
Drive F: | 44.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 7.41 Gb Total Space | 5.02 Gb Free Space | 67.67% Space Free | Partition Type: FAT32
Computer Name: DIEKAT | User Name: Katrien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Windows\System32\AsusService.exe ()
PRC - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
PRC - C:\Program Files\EeePC\SHE\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Modules (SafeList) ==========
MOD - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AsusService) – C:\Windows\System32\AsusService.exe ()
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (LMIRfsClientNP) – C:\windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) – C:\Windows\System32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (MBB Incorporated)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) Vodafone K3805-z CDC-ACM driver (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) Vodafone K3805-z DC Enumerator (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (AsUpIO) – C:\Windows\System32\drivers\AsUpIO.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (kbfiltr) – C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\..\URLSearchHook: {40f5f417-32bb-4296-9446-c1e0094e7d82} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: [removed]:1.19.1
FF - prefs.js..extensions.enabledItems: [removed]:3.0.1
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/12 18:58:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/04/21 01:31:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/06 16:13:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/06 16:13:26 | 000,000,000 | —D | M]
[2011/06/12 20:50:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Extensions
[2011/06/02 18:12:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions
[2011/02/03 17:33:51 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2010/12/13 13:01:32 | 000,000,000 | —D | M] (Woordenboek Nederlands) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2011/03/24 00:24:21 | 000,005,529 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\SearchquWebSearch.xml
[2011/02/06 19:07:47 | 000,001,196 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\winamp-search.xml
[2011/05/13 14:16:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2011/06/12 18:58:45 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/05/06 16:13:17 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/12/09 22:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/05/06 16:13:21 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/06 16:13:21 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/06 16:13:21 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/06 16:13:21 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/03/24 00:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
[2011/05/06 16:13:21 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/06/11 09:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [HotkeyMon] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [HotkeyService] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SuperHybridEngine] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 09:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/12/09 05:25:38 | 000,000,118 | R— | M] () - F:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell - "" = AutoRun
O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe – [2010/11/19 08:37:28 | 000,274,432 | R— | M] (Vodafone)
O33 - MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\Shell - "" = AutoRun
O33 - MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe – [2010/11/19 08:37:28 | 000,274,432 | R— | M] (Vodafone)
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/06/12 20:08:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/06/07 10:07:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/05/30 09:14:51 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\Diskdump.sys
[2010/03/04 19:36:25 | 000,013,880 | —- | C] ( ) – C:\windows\System32\drivers\kbfiltr.sys
========== Files - Modified Within 30 Days ==========
[2011/06/16 10:51:00 | 000,000,512 | —- | M] () – D:\Users\Katrien\Documents\MBR.dat
[2011/06/16 10:34:09 | 000,706,882 | —- | M] () – C:\windows\System32\perfh00C.dat
[2011/06/16 10:34:09 | 000,703,644 | —- | M] () – C:\windows\System32\perfh013.dat
[2011/06/16 10:34:09 | 000,701,560 | —- | M] () – C:\windows\System32\perfh010.dat
[2011/06/16 10:34:09 | 000,656,288 | —- | M] () – C:\windows\System32\perfh007.dat
[2011/06/16 10:34:09 | 000,628,460 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/06/16 10:34:09 | 000,137,164 | —- | M] () – C:\windows\System32\perfc013.dat
[2011/06/16 10:34:09 | 000,134,364 | —- | M] () – C:\windows\System32\perfc00C.dat
[2011/06/16 10:34:09 | 000,133,764 | —- | M] () – C:\windows\System32\perfc007.dat
[2011/06/16 10:34:09 | 000,131,368 | —- | M] () – C:\windows\System32\perfc010.dat
[2011/06/16 10:34:09 | 000,110,612 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/06/16 10:32:05 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/16 10:00:05 | 000,001,046 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/16 09:19:50 | 000,001,042 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/16 05:47:18 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/16 05:47:18 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/16 05:38:08 | 1609,965,568 | -HS- | M] () – C:\hiberfil.sys
[2011/06/16 05:38:06 | 232,849,702 | —- | M] () – C:\windows\MEMORY.DMP
[2011/06/15 10:11:11 | 118,554,137 | —- | M] () – C:\windows\System32\drivers\AVG\incavi.avm
[2011/06/12 20:08:58 | 000,001,206 | —- | M] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/12 18:58:46 | 000,000,899 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/12 17:06:10 | 000,001,048 | —- | M] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2011/06/02 18:58:28 | 000,072,278 | —- | M] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | M] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | M] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:37:24 | 000,059,380 | —- | M] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/05/30 09:14:30 | 000,001,009 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
========== Files Created - No Company Name ==========
[2011/06/12 20:08:58 | 000,001,206 | —- | C] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/02 18:58:28 | 000,072,278 | —- | C] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | C] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | C] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:41:49 | 000,059,380 | —- | C] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/04/20 18:58:15 | 000,650,752 | —- | C] () – C:\windows\System32\xvidcore.dll
[2011/04/20 18:58:15 | 000,240,640 | —- | C] () – C:\windows\System32\xvidvfw.dll
[2011/03/30 23:50:36 | 000,005,120 | —- | C] () – C:\Users\Katrien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/16 12:18:33 | 000,000,474 | —- | C] () – C:\Users\Katrien\AppData\Roaming\Poladroid prefs.plist
[2010/12/03 17:08:54 | 000,208,274 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2010/10/22 08:36:20 | 000,203,264 | —- | C] () – C:\Users\Katrien\AppData\Local\GetToolbar.exe
[2010/10/16 00:15:43 | 000,001,048 | —- | C] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2010/10/15 23:37:13 | 000,087,552 | —- | C] () – C:\windows\System32\cpwmon2k.dll
[2010/10/15 20:37:25 | 000,006,144 | —- | C] () – C:\windows\System32\drivers\ASUSHWIO.SYS
[2010/04/21 08:45:14 | 000,013,931 | —- | C] () – C:\windows\System32\RaCoInst.dat
[2010/03/24 18:39:34 | 000,224,680 | —- | C] () – C:\windows\System32\AsusService.exe
[2010/03/24 18:39:34 | 000,025,616 | —- | C] () – C:\windows\AsAcpiSvrLang.ini
[2010/03/24 17:55:13 | 000,131,368 | —- | C] () – C:\ProgramData\FullRemove.exe
[2010/03/24 13:33:51 | 000,011,448 | —- | C] () – C:\windows\System32\drivers\AsUpIO.sys
[2010/03/24 13:33:45 | 000,001,769 | —- | C] () – C:\windows\Language_trs.ini
[2010/03/24 12:43:38 | 000,004,692 | —- | C] () – C:\windows\System32\drivers\SamSfPa.dat
[2010/03/01 10:59:00 | 000,408,168 | —- | C] () – C:\windows\System32\easyUpdatusAPIU.dll
[2010/03/01 10:59:00 | 000,212,215 | —- | C] () – C:\windows\System32\nvcoproc.bin
[2009/10/26 15:38:22 | 000,000,176 | —- | C] () – C:\windows\explorer.exe.config
[2009/07/27 10:35:09 | 000,703,644 | —- | C] () – C:\windows\System32\perfh013.dat
[2009/07/27 10:35:09 | 000,341,322 | —- | C] () – C:\windows\System32\perfi013.dat
[2009/07/27 10:35:09 | 000,137,164 | —- | C] () – C:\windows\System32\perfc013.dat
[2009/07/27 10:35:09 | 000,043,068 | —- | C] () – C:\windows\System32\perfd013.dat
[2009/07/27 10:23:34 | 000,706,882 | —- | C] () – C:\windows\System32\perfh00C.dat
[2009/07/27 10:23:34 | 000,344,522 | —- | C] () – C:\windows\System32\perfi00C.dat
[2009/07/27 10:23:34 | 000,134,364 | —- | C] () – C:\windows\System32\perfc00C.dat
[2009/07/27 10:23:34 | 000,038,160 | —- | C] () – C:\windows\System32\perfd00C.dat
[2009/07/27 10:12:00 | 000,701,560 | —- | C] () – C:\windows\System32\perfh010.dat
[2009/07/27 10:12:00 | 000,335,478 | —- | C] () – C:\windows\System32\perfi010.dat
[2009/07/27 10:12:00 | 000,131,368 | —- | C] () – C:\windows\System32\perfc010.dat
[2009/07/27 10:12:00 | 000,037,534 | —- | C] () – C:\windows\System32\perfd010.dat
[2009/07/27 10:01:28 | 000,656,288 | —- | C] () – C:\windows\System32\perfh007.dat
[2009/07/27 10:01:28 | 000,295,922 | —- | C] () – C:\windows\System32\perfi007.dat
[2009/07/27 10:01:28 | 000,133,764 | —- | C] () – C:\windows\System32\perfc007.dat
[2009/07/27 10:01:28 | 000,038,104 | —- | C] () – C:\windows\System32\perfd007.dat
[2009/07/14 16:57:37 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/14 16:33:53 | 000,330,888 | —- | C] () – C:\windows\System32\FNTCACHE.DAT
[2009/07/14 14:05:48 | 000,628,460 | —- | C] () – C:\windows\System32\perfh009.dat
[2009/07/14 14:05:48 | 000,291,294 | —- | C] () – C:\windows\System32\perfi009.dat
[2009/07/14 14:05:48 | 000,110,612 | —- | C] () – C:\windows\System32\perfc009.dat
[2009/07/14 14:05:48 | 000,031,548 | —- | C] () – C:\windows\System32\perfd009.dat
[2009/07/14 14:05:05 | 000,000,741 | —- | C] () – C:\windows\System32\NOISE.DAT
[2009/07/14 14:04:11 | 000,215,943 | —- | C] () – C:\windows\System32\dssec.dat
[2009/07/14 11:55:01 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/14 11:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 11:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll
[2009/06/11 09:26:10 | 000,673,088 | —- | C] () – C:\windows\System32\mlang.dat
========== LOP Check ==========
[2010/04/21 09:26:43 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\ASUS WebStorage
[2010/10/15 21:55:23 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\AVG10
[2011/04/21 15:15:51 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\Canon
[2011/02/06 17:54:13 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\DeepBurner
[2011/06/16 09:21:35 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\Dropbox
[2011/02/09 19:52:34 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\GetRightToGo
[2011/01/18 11:56:21 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\IrfanView
[2010/10/16 00:15:57 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\Template
[2011/02/09 19:30:42 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\Uniblue
[2011/02/17 21:08:55 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\Vodafone
[2010/10/15 21:15:40 | 000,000,000 | —D | M] – C:\Users\Katrien\AppData\Roaming\VoiceCommand
[2010/12/30 12:50:23 | 000,032,606 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2009/07/14 13:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 13:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/14 13:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/14 13:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\System32\drivers\atapi.sys
[2009/07/14 13:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/14 13:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/14 13:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\System32\cngaudit.dll
[2009/07/14 13:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: IASTOR.SYS >
[2009/06/05 13:43:16 | 000,330,264 | —- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 – C:\Windows\System32\drivers\iaStor.sys
< MD5 for: IASTORV.SYS >
[2011/03/11 17:38:51 | 000,332,160 | —- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011/03/11 17:43:55 | 000,332,160 | —- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 – C:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 17:43:55 | 000,332,160 | —- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0033117673c16921\iaStorV.sys
[2011/03/11 17:43:55 | 000,332,160 | —- | M] (Intel Corporation) MD5=71F1A494FEDF4B33C02C4A6A28D6D9E9 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_aef580fde910b4b0\iaStorV.sys
[2011/03/11 17:28:00 | 000,332,160 | —- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2009/07/14 13:20:36 | 000,332,352 | —- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 13:20:36 | 000,332,352 | —- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
[2011/03/11 17:52:21 | 000,332,160 | —- | M] (Intel Corporation) MD5=B9039A34C2F8769490DCC494E2402445 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_afae2d45020c148b\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2009/07/14 13:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\System32\netlogon.dll
[2009/07/14 13:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVRAID.SYS >
[2009/07/14 13:20:44 | 000,117,312 | —- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvraid.sys
[2009/07/14 13:20:44 | 000,117,312 | —- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvraid.sys
[2011/03/11 17:39:00 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=B3E25EE28883877076E0E1FF877D02E0 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvraid.sys
[2011/03/11 17:28:10 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=E3B840350A72CA6F39BD2BEF85A2BCFB – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvraid.sys
[2011/03/11 17:44:01 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=F1B0BED906F97E16F6D0C3629D2F21C6 – C:\Windows\System32\drivers\nvraid.sys
[2011/03/11 17:44:01 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=F1B0BED906F97E16F6D0C3629D2F21C6 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvraid.sys
[2011/03/11 17:44:01 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=F1B0BED906F97E16F6D0C3629D2F21C6 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvraid.sys
[2011/03/11 17:52:25 | 000,117,120 | —- | M] (NVIDIA Corporation) MD5=FCD5C3542A85EEBA7D0833B7E5086C10 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2011/03/11 17:39:00 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/11 17:44:01 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 – C:\Windows\System32\drivers\nvstor.sys
[2011/03/11 17:44:01 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_38e464dbe521cc7f\nvstor.sys
[2011/03/11 17:44:01 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=4520B63899E867F354EE012D34E11536 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_39bef1ad20475e88\nvstor.sys
[2011/03/11 17:28:10 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2011/03/11 17:52:25 | 000,143,744 | —- | M] (NVIDIA Corporation) MD5=8A7583A3B58D3EEB28BB26626526BC91 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_3a779df43942be63\nvstor.sys
[2009/07/14 13:20:44 | 000,142,416 | —- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 13:20:44 | 000,142,416 | —- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009/07/14 13:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\System32\scecli.dll
[2009/07/14 13:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/14 13:15:21 | 000,462,848 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\FirewallAPI.dll
[2009/07/14 13:16:21 | 000,284,672 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\WWanAPI.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
[2011/04/14 21:28:30 | 000,134,480 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\Windows\System32\drivers\AVGIDSDriver.sys
[2011/04/05 00:59:56 | 000,297,168 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2011/04/23 07:36:05 | 000,026,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2011/03/29 15:06:51 | 000,076,288 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbccgp.sys
[2011/03/29 15:06:34 | 000,005,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/03/29 15:06:43 | 000,043,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbehci.sys
[2011/03/29 15:07:26 | 000,258,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbhub.sys
[2011/03/29 15:06:47 | 000,284,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/03/29 15:06:37 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbuhci.sys
< End of report >
OTL Extras logfile created on: 16/06/2011 10:45:45 a.m. - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = D:\Users\Katrien\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001409 | Country: Nieuw-Zeeland | Language: ENZ | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 47.97% Memory free
4.00 Gb Paging File | 2.64 Gb Available in Paging File | 65.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 75.10 Gb Free Space | 75.10% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 101.75 Gb Free Space | 86.33% Space Free | Partition Type: NTFS
Drive F: | 44.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 7.41 Gb Total Space | 5.02 Gb Free Space | 67.67% Space Free | Partition Type: FAT32
Computer Name: DIEKAT | User Name: Katrien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23DA4222-E517-42B3-8F97-9CFD49E2A732}" = AVG 2011
"{2617FA1F-0C04-3ABB-AF64-7D5B6620C341}" = Microsoft .NET Framework 4 Client Profile NLD Language Pack
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2ADE2157-7A5E-122C-B51D-EB8A01B15943}" = DeepBurner v1.9.0.228
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{38E5A3B1-ADF1-47E0-8024-76310A30EB36}" = LiveUpdate
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5158F1F5-FA1B-4D49-B546-55A5004B89BD}" = Microsoft Works
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5D112C61-C8D0-4718-8DD7-B9115EB9AF90}" = LogMeIn
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband Lite
"{71C0E38E-09F2-4386-9977-404D4F6640CD}" = Hotkey Service
"{859D40CF-8491-44AD-8FA8-7389CB418C64}" = 32 Bit HP CIO Components Installer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}" = Ralink RT2860 Wireless LAN Card
"{91D2C605-AD2B-44C8-A0A1-9B116B3C91CB}" = AVG 2011
"{946135EF-3A4C-494F-AE05-1312913DF880}" = Dr.Eee
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-0413-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1043-7B44-A94000000001}" = Adobe Reader 9.4.4 - Nederlands
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}" = SRS Premium Sound Control Panel
"{E8FF78D0-4D1C-4B2D-AC80-670F135F5461}" = Poladroid
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F011B8F1-BCCD-4E73-84F8-CB2F2D258755}" = Canon Utilities Digital Photo Professional 1.0
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASUS WebStorage" = ASUS WebStorage
"AVG" = AVG 2011
"B5C82F3814F82FB37F1513B3185399BD88892B08" = Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0)
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Eee Docking_is1" = Eee Docking 3.6.2
"iLivid" = iLivid
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"InstallShield_{946135EF-3A4C-494F-AE05-1312913DF880}" = Dr.Eee
"InstallShield_{F011B8F1-BCCD-4E73-84F8-CB2F2D258755}" = Canon Utilities Digital Photo Professional 1.0
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile NLD Language Pack" = Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD
"Mozilla Firefox 4.0.1 (x86 en-GB)" = Mozilla Firefox 4.0.1 (x86 en-GB)
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA.Updatus" = NVIDIA Updatus
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Soulseek2" = SoulSeek 157 NS 13e
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.4
"Winamp" = Winamp
"Xvid Video Codec 1.3.1" = Xvid Video Codec
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Winamp Detect" = Winamp Applicatie Detect
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Hope this is what you need, thank you!
Kind regards
Katrien
Please disable this program and leave it disabled until we are done.
SPYBOT TEATIMER• Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
• On the left hand side, click on Tools, then click on the Resident Icon in the list.
• Uncheck the Resident TeaTimer (Protection of overall system settings) active box.
• Click on the System Startup icon in the List
• Uncheck the "TeaTimer" box and click OK at any prompts.
• If Teatimer gives you a warning that changes were made, click Allow Change when prompted.
• Exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).
===================================================
OK, let’s get rid of this mess.• Hold down the Windows key and press R to open a run box
• type the following text into the run box
appwiz.cpl
• This will open your Programs And Features• A list of installed programs will appear
• Remove the following programs:
Searchqu 406 MediaBar
SaveVid Plug-in
Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406 FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406" FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" [2011/03/24 00:24:21 | 000,005,529 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\SearchquWebSearch.xml [2011/03/24 00:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll () O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD) O20 - AppInit_DLLs: (C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD) O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell - "" = AutoRun O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe – [2010/11/19 08:37:28 | 000,274,432 | R— | M] (Vodafone) O33 - MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\Shell - "" = AutoRun O33 - MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe – [2010/11/19 08:37:28 | 000,274,432 | R— | M] (Vodafone) O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup_vmb_lite.exe /checkApplicationPresence :Files C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe ipconfig /flushdns /c :Reg [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AutoUpdateDisableNotify" =dword:00000000 :Commands [resethosts] [emptyflash] [purity] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Download Malwarebytes-Anti-Malware
Click here
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- Copy and paste the contents of that report in your next reply and exit MBAM.
Logs to include in next post:
OTL fix log
New OTL log
Mbam.txt
Please let me know how it is running now
Thanks
Satchfan
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named datamngrUI.exe was found!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage
Prefs.js: "http://www.searchqu.com/web?src=ffb&systemid=406&q=" removed from keyword.URL
C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\SearchquWebSearch.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
File C:\Program Files\Windows iLivid Toolbar\ToolBar\searchqudtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI3C8A~1\Datamngr\datamngr.dll deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully.
File C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{618de20e-37c5-11e0-8083-1c4bd617a95e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{618de20e-37c5-11e0-8083-1c4bd617a95e}\ not found.
File move failed. F:\setup_vmb_lite.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ebc0505-fb91-11df-9700-1c4bd617a95e}\ not found.
File "H:\WD SmartWare.exe" autoplay=true not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File move failed. F:\setup_vmb_lite.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\setup_vmb_lite.exe /checkApplicationPresence not found.
========== FILES ==========
File\Folder C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
D:\Users\Katrien\Downloads\cmd.bat deleted successfully.
D:\Users\Katrien\Downloads\cmd.txt deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AutoUpdateDisableNotify" |dword:00000000 /E : value set successfully!
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 321 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: Katrien
->Flash cache emptied: 87831 bytes
User: Public
User: UpdatusUser
Total Flash Files Cleaned = 0.00 mb
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 242128 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Katrien
->Temp folder emptied: 89471367 bytes
->Temporary Internet Files folder emptied: 337483717 bytes
->Java cache emptied: 1239285 bytes
->FireFox cache emptied: 56152302 bytes
->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 86791644 bytes
RecycleBin emptied: 3146179804 bytes
Total Files Cleaned = 3,545.00 mb
OTL by OldTimer - Version 3.2.24.0 log created on 06172011_221238
Files\Folders moved on Reboot…
File move failed. F:\setup_vmb_lite.exe scheduled to be moved on reboot.
C:\windows\temp\HS.log moved successfully.
Registry entries deleted on Reboot…
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6875
Windows 6.1.7600
Internet Explorer 9.0.8112.16421
17/06/2011 10:40:31 p.m.
mbam-log-2011-06-17 (22-40-31).txt
Scan type: Quick scan
Objects scanned: 164389
Time elapsed: 6 minute(s), 2 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790772B6765E5B3FAB96 (Malware.Trace) -> Value: SRS_IT_E8790772B6765E5B3FAB96 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790772B6765E5A30A197 (Malware.Trace) -> Value: SRS_IT_E8790772B6765E5A30A197 -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 17/06/2011 10:44:33 p.m. - Run 2
OTL by OldTimer - Version 3.2.24.0 Folder = D:\Users\Katrien\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001409 | Country: Nieuw-Zeeland | Language: ENZ | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 48.01% Memory free
4.00 Gb Paging File | 2.74 Gb Available in Paging File | 68.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 76.99 Gb Free Space | 76.99% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 100.36 Gb Free Space | 85.15% Space Free | Partition Type: NTFS
Drive F: | 44.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 931.51 Gb Total Space | 786.46 Gb Free Space | 84.43% Space Free | Partition Type: NTFS
Drive I: | 7.41 Gb Total Space | 5.02 Gb Free Space | 67.67% Space Free | Partition Type: FAT32
Computer Name: DIEKAT | User Name: Katrien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Windows\System32\AsusService.exe ()
PRC - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
PRC - C:\Program Files\EeePC\SHE\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Modules (SafeList) ==========
MOD - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AsusService) – C:\Windows\System32\AsusService.exe ()
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (LMIRfsClientNP) – C:\windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) – C:\Windows\System32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (MBB Incorporated)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) Vodafone K3805-z CDC-ACM driver (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) Vodafone K3805-z DC Enumerator (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (AsUpIO) – C:\Windows\System32\drivers\AsUpIO.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (kbfiltr) – C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\..\URLSearchHook: {40f5f417-32bb-4296-9446-c1e0094e7d82} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: [removed]:1.19.1
FF - prefs.js..extensions.enabledItems: [removed]:3.0.1
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/12 18:58:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/04/21 01:31:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/06 16:13:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/06 16:13:26 | 000,000,000 | —D | M]
[2011/06/12 20:50:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Extensions
[2011/06/02 18:12:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions
[2011/02/03 17:33:51 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2010/12/13 13:01:32 | 000,000,000 | —D | M] (Woordenboek Nederlands) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2011/02/06 19:07:47 | 000,001,196 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\winamp-search.xml
[2011/05/13 14:16:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2011/06/12 18:58:45 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/05/06 16:13:17 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/12/09 22:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/05/06 16:13:21 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/06 16:13:21 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/06 16:13:21 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/06 16:13:21 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/05/06 16:13:21 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/06/17 22:13:16 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HotkeyMon] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [HotkeyService] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SuperHybridEngine] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 09:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/12/09 05:25:38 | 000,000,118 | R— | M] () - F:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/17 22:31:53 | 000,000,000 | —D | C] – C:\Users\Katrien\AppData\Roaming\Malwarebytes
[2011/06/17 22:31:37 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2011/06/17 22:31:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/17 22:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/06/17 22:31:32 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2011/06/17 22:31:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/17 05:11:05 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2011/06/17 05:11:00 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript.dll
[2011/06/17 05:11:00 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2011/06/17 05:10:59 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2011/06/16 13:41:13 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2011/06/12 20:08:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/06/07 10:07:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/05/30 09:14:51 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\Diskdump.sys
[2010/03/04 19:36:25 | 000,013,880 | —- | C] ( ) – C:\windows\System32\drivers\kbfiltr.sys
========== Files - Modified Within 30 Days ==========
[2011/06/17 22:31:58 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 22:31:58 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 22:31:37 | 000,001,033 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/17 22:24:47 | 000,001,042 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/17 22:24:19 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/17 22:24:17 | 1609,965,568 | -HS- | M] () – C:\hiberfil.sys
[2011/06/17 22:13:16 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2011/06/17 22:00:08 | 000,001,046 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/17 21:32:57 | 118,878,779 | —- | M] () – C:\windows\System32\drivers\AVG\incavi.avm
[2011/06/17 13:18:30 | 000,706,882 | —- | M] () – C:\windows\System32\perfh00C.dat
[2011/06/17 13:18:30 | 000,703,644 | —- | M] () – C:\windows\System32\perfh013.dat
[2011/06/17 13:18:30 | 000,701,560 | —- | M] () – C:\windows\System32\perfh010.dat
[2011/06/17 13:18:30 | 000,656,288 | —- | M] () – C:\windows\System32\perfh007.dat
[2011/06/17 13:18:30 | 000,628,460 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/06/17 13:18:30 | 000,137,164 | —- | M] () – C:\windows\System32\perfc013.dat
[2011/06/17 13:18:30 | 000,134,364 | —- | M] () – C:\windows\System32\perfc00C.dat
[2011/06/17 13:18:30 | 000,133,764 | —- | M] () – C:\windows\System32\perfc007.dat
[2011/06/17 13:18:30 | 000,131,368 | —- | M] () – C:\windows\System32\perfc010.dat
[2011/06/17 13:18:30 | 000,110,612 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/06/16 10:51:00 | 000,000,512 | —- | M] () – D:\Users\Katrien\Documents\MBR.dat
[2011/06/16 05:38:06 | 232,849,702 | —- | M] () – C:\windows\MEMORY.DMP
[2011/06/12 20:08:58 | 000,001,206 | —- | M] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/12 18:58:46 | 000,000,899 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/12 17:06:10 | 000,001,048 | —- | M] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2011/06/02 18:58:28 | 000,072,278 | —- | M] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | M] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | M] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:37:24 | 000,059,380 | —- | M] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/05/30 09:14:30 | 000,001,009 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2011/06/17 22:31:37 | 000,001,033 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/16 10:51:00 | 000,000,512 | —- | C] () – D:\Users\Katrien\Documents\MBR.dat
[2011/06/12 20:08:58 | 000,001,206 | —- | C] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/02 18:58:28 | 000,072,278 | —- | C] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | C] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | C] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:41:49 | 000,059,380 | —- | C] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/04/20 18:58:15 | 000,650,752 | —- | C] () – C:\windows\System32\xvidcore.dll
[2011/04/20 18:58:15 | 000,240,640 | —- | C] () – C:\windows\System32\xvidvfw.dll
[2011/03/30 23:50:36 | 000,005,120 | —- | C] () – C:\Users\Katrien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/16 12:18:33 | 000,000,474 | —- | C] () – C:\Users\Katrien\AppData\Roaming\Poladroid prefs.plist
[2010/12/03 17:08:54 | 000,208,274 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2010/10/22 08:36:20 | 000,203,264 | —- | C] () – C:\Users\Katrien\AppData\Local\GetToolbar.exe
[2010/10/16 00:15:43 | 000,001,048 | —- | C] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2010/10/15 23:37:13 | 000,087,552 | —- | C] () – C:\windows\System32\cpwmon2k.dll
[2010/10/15 20:37:25 | 000,006,144 | —- | C] () – C:\windows\System32\drivers\ASUSHWIO.SYS
[2010/04/21 08:45:14 | 000,013,931 | —- | C] () – C:\windows\System32\RaCoInst.dat
[2010/03/24 18:39:34 | 000,224,680 | —- | C] () – C:\windows\System32\AsusService.exe
[2010/03/24 18:39:34 | 000,025,616 | —- | C] () – C:\windows\AsAcpiSvrLang.ini
[2010/03/24 17:55:13 | 000,131,368 | —- | C] () – C:\ProgramData\FullRemove.exe
[2010/03/24 13:33:51 | 000,011,448 | —- | C] () – C:\windows\System32\drivers\AsUpIO.sys
[2010/03/24 13:33:45 | 000,001,769 | —- | C] () – C:\windows\Language_trs.ini
[2010/03/24 12:43:38 | 000,004,692 | —- | C] () – C:\windows\System32\drivers\SamSfPa.dat
[2010/03/01 10:59:00 | 000,408,168 | —- | C] () – C:\windows\System32\easyUpdatusAPIU.dll
[2010/03/01 10:59:00 | 000,212,215 | —- | C] () – C:\windows\System32\nvcoproc.bin
[2009/10/26 15:38:22 | 000,000,176 | —- | C] () – C:\windows\explorer.exe.config
[2009/07/27 10:35:09 | 000,703,644 | —- | C] () – C:\windows\System32\perfh013.dat
[2009/07/27 10:35:09 | 000,341,322 | —- | C] () – C:\windows\System32\perfi013.dat
[2009/07/27 10:35:09 | 000,137,164 | —- | C] () – C:\windows\System32\perfc013.dat
[2009/07/27 10:35:09 | 000,043,068 | —- | C] () – C:\windows\System32\perfd013.dat
[2009/07/27 10:23:34 | 000,706,882 | —- | C] () – C:\windows\System32\perfh00C.dat
[2009/07/27 10:23:34 | 000,344,522 | —- | C] () – C:\windows\System32\perfi00C.dat
[2009/07/27 10:23:34 | 000,134,364 | —- | C] () – C:\windows\System32\perfc00C.dat
[2009/07/27 10:23:34 | 000,038,160 | —- | C] () – C:\windows\System32\perfd00C.dat
[2009/07/27 10:12:00 | 000,701,560 | —- | C] () – C:\windows\System32\perfh010.dat
[2009/07/27 10:12:00 | 000,335,478 | —- | C] () – C:\windows\System32\perfi010.dat
[2009/07/27 10:12:00 | 000,131,368 | —- | C] () – C:\windows\System32\perfc010.dat
[2009/07/27 10:12:00 | 000,037,534 | —- | C] () – C:\windows\System32\perfd010.dat
[2009/07/27 10:01:28 | 000,656,288 | —- | C] () – C:\windows\System32\perfh007.dat
[2009/07/27 10:01:28 | 000,295,922 | —- | C] () – C:\windows\System32\perfi007.dat
[2009/07/27 10:01:28 | 000,133,764 | —- | C] () – C:\windows\System32\perfc007.dat
[2009/07/27 10:01:28 | 000,038,104 | —- | C] () – C:\windows\System32\perfd007.dat
[2009/07/14 16:57:37 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/14 16:33:53 | 000,330,888 | —- | C] () – C:\windows\System32\FNTCACHE.DAT
[2009/07/14 14:05:48 | 000,628,460 | —- | C] () – C:\windows\System32\perfh009.dat
[2009/07/14 14:05:48 | 000,291,294 | —- | C] () – C:\windows\System32\perfi009.dat
[2009/07/14 14:05:48 | 000,110,612 | —- | C] () – C:\windows\System32\perfc009.dat
[2009/07/14 14:05:48 | 000,031,548 | —- | C] () – C:\windows\System32\perfd009.dat
[2009/07/14 14:05:05 | 000,000,741 | —- | C] () – C:\windows\System32\NOISE.DAT
[2009/07/14 14:04:11 | 000,215,943 | —- | C] () – C:\windows\System32\dssec.dat
[2009/07/14 11:55:01 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/14 11:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 11:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll
[2009/06/11 09:26:10 | 000,673,088 | —- | C] () – C:\windows\System32\mlang.dat
< End of report >
The 3 logs, hope all is fine!
Greetings
Katrien
Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL IE - HKCU\..\URLSearchHook: {40f5f417-32bb-4296-9446-c1e0094e7d82} - Reg Error: Key error. File not found FF - prefs.js..browser.search.defaultenginename: "Web Search" FF - prefs.js..browser.search.selectedEngine: "Web Search" :Commands [purity] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Update and run Malwarebytes again
===================================================
Include both logs and please let me know how things are now
Thanks
Satchfan
everything seems to be all good again. I can choose my own homepage without it changing automatically back to searchqu so that's awesome. And the anti-malware software didn't find any infections on the last scan, so that seems to be all good as well. I thank you so much for your help and very clear instructions, you've been great! Please let me know if everything is in fact in order again, it looks so to my unknowing eyes, but you never know with these bugs. Again, thank you very much, your help is very much appreciated,
Greetings Katrien
Here are the Logs:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{40f5f417-32bb-4296-9446-c1e0094e7d82} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40f5f417-32bb-4296-9446-c1e0094e7d82}\ not found.
Prefs.js: "Web Search" removed from browser.search.defaultenginename
Prefs.js: "Web Search" removed from browser.search.selectedEngine
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Katrien
->Temp folder emptied: 414484 bytes
->Temporary Internet Files folder emptied: 53299214 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 62047718 bytes
->Flash cache emptied: 945 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 135 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 110.00 mb
OTL by OldTimer - Version 3.2.24.0 log created on 06182011_173440
Files\Folders moved on Reboot…
File\Folder C:\Users\Katrien\AppData\Local\Temp\JET9E40.tmp not found!
C:\windows\temp\HS.log moved successfully.
Registry entries deleted on Reboot…
OTL logfile created on: 18/06/2011 5:46:50 p.m. - Run 3
OTL by OldTimer - Version 3.2.24.0 Folder = D:\Users\Katrien\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001409 | Country: Nieuw-Zeeland | Language: ENZ | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 51.90% Memory free
4.00 Gb Paging File | 2.86 Gb Available in Paging File | 71.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 76.75 Gb Free Space | 76.75% Space Free | Partition Type: NTFS
Drive D: | 117.87 Gb Total Space | 100.36 Gb Free Space | 85.15% Space Free | Partition Type: NTFS
Drive F: | 44.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 7.41 Gb Total Space | 5.02 Gb Free Space | 67.67% Space Free | Partition Type: FAT32
Computer Name: DIEKAT | User Name: Katrien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Windows\System32\AsusService.exe ()
PRC - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
PRC - C:\Program Files\EeePC\SHE\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Modules (SafeList) ==========
MOD - D:\Users\Katrien\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (VmbService) – C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Vodafone)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AsusService) – C:\Windows\System32\AsusService.exe ()
SRV - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (LMIRfsClientNP) – C:\windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) – C:\Windows\System32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (MBB Incorporated)
DRV - (vodafone_K3805-z_cdc_ecm) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_ecm.sys (Vodafone)
DRV - (vodafone_K3805-z_cdc_acm) Vodafone K3805-z CDC-ACM driver (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_cdc_acm.sys (Vodafone)
DRV - (vodafone_K3805-z_dc_enum) Vodafone K3805-z DC Enumerator (ZTE) – C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys (Vodafone)
DRV - (vodafone_K3805-z_cpo) – C:\Windows\System32\drivers\vodafone_K3805-z_cpo.sys (Vodafone)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (AsUpIO) – C:\Windows\System32\drivers\AsUpIO.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (kbfiltr) – C:\Windows\System32\drivers\kbfiltr.sys ( )
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://msn.co.nz/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-NZ
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 56 7F 1A CA DC 2C CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.19.1
FF - prefs.js..extensions.enabledItems: [removed]:3.0.1
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/12 18:58:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/04/21 01:31:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/06 16:13:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/06 16:13:26 | 000,000,000 | —D | M]
[2011/06/12 20:50:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Extensions
[2011/06/02 18:12:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions
[2011/02/03 17:33:51 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2010/12/13 13:01:32 | 000,000,000 | —D | M] (Woordenboek Nederlands) – C:\Users\Katrien\AppData\Roaming\mozilla\Firefox\Profiles\xwyxriz8.default\extensions\[removed]
[2011/02/06 19:07:47 | 000,001,196 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Mozilla\Firefox\Profiles\xwyxriz8.default\searchplugins\winamp-search.xml
[2011/05/13 14:16:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2011/06/12 18:58:45 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2011/05/06 16:13:17 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/12/09 22:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/05/06 16:13:21 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/06 16:13:21 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/06 16:13:21 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/06 16:13:21 | 000,001,180 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/05/06 16:13:21 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2011/06/17 22:13:16 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HotkeyMon] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [HotkeyService] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SuperHybridEngine] C:\windows\System32\AsusSender.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Katrien\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 09:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/12/09 05:25:38 | 000,000,118 | R— | M] () - F:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell - "" = AutoRun
O33 - MountPoints2\{618de20e-37c5-11e0-8083-1c4bd617a95e}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe – [2010/11/19 08:37:28 | 000,274,432 | R— | M] (Vodafone)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/17 22:31:53 | 000,000,000 | —D | C] – C:\Users\Katrien\AppData\Roaming\Malwarebytes
[2011/06/17 22:31:37 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2011/06/17 22:31:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/17 22:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/06/17 22:31:32 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2011/06/17 22:31:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/17 05:11:05 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2011/06/17 05:11:00 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript.dll
[2011/06/17 05:11:00 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2011/06/17 05:10:59 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2011/06/16 13:41:13 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2011/06/12 20:08:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/06/12 20:08:37 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/06/07 10:07:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/05/30 09:14:51 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\Diskdump.sys
[2010/03/04 19:36:25 | 000,013,880 | —- | C] ( ) – C:\windows\System32\drivers\kbfiltr.sys
========== Files - Modified Within 30 Days ==========
[2011/06/18 17:46:32 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 17:46:32 | 000,009,920 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/18 17:41:47 | 000,001,042 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/18 17:38:57 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/18 17:38:41 | 1609,965,568 | -HS- | M] () – C:\hiberfil.sys
[2011/06/18 17:16:01 | 000,001,046 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/18 09:46:47 | 118,939,292 | —- | M] () – C:\windows\System32\drivers\AVG\incavi.avm
[2011/06/17 22:31:37 | 000,001,033 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/17 22:13:16 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2011/06/17 13:18:30 | 000,706,882 | —- | M] () – C:\windows\System32\perfh00C.dat
[2011/06/17 13:18:30 | 000,703,644 | —- | M] () – C:\windows\System32\perfh013.dat
[2011/06/17 13:18:30 | 000,701,560 | —- | M] () – C:\windows\System32\perfh010.dat
[2011/06/17 13:18:30 | 000,656,288 | —- | M] () – C:\windows\System32\perfh007.dat
[2011/06/17 13:18:30 | 000,628,460 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/06/17 13:18:30 | 000,137,164 | —- | M] () – C:\windows\System32\perfc013.dat
[2011/06/17 13:18:30 | 000,134,364 | —- | M] () – C:\windows\System32\perfc00C.dat
[2011/06/17 13:18:30 | 000,133,764 | —- | M] () – C:\windows\System32\perfc007.dat
[2011/06/17 13:18:30 | 000,131,368 | —- | M] () – C:\windows\System32\perfc010.dat
[2011/06/17 13:18:30 | 000,110,612 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/06/16 10:51:00 | 000,000,512 | —- | M] () – D:\Users\Katrien\Documents\MBR.dat
[2011/06/16 05:38:06 | 232,849,702 | —- | M] () – C:\windows\MEMORY.DMP
[2011/06/12 20:08:58 | 000,001,206 | —- | M] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/12 18:58:46 | 000,000,899 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk
[2011/06/12 17:06:10 | 000,001,048 | —- | M] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2011/06/02 18:58:28 | 000,072,278 | —- | M] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | M] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | M] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:37:24 | 000,059,380 | —- | M] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/05/30 09:14:30 | 000,001,009 | —- | M] () – C:\Users\Katrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/05/29 09:11:30 | 000,039,984 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2011/06/17 22:31:37 | 000,001,033 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/16 10:51:00 | 000,000,512 | —- | C] () – D:\Users\Katrien\Documents\MBR.dat
[2011/06/12 20:08:58 | 000,001,206 | —- | C] () – C:\Users\Katrien\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/02 18:58:28 | 000,072,278 | —- | C] () – D:\Users\Katrien\Documents\id achter.jpg
[2011/06/02 18:55:12 | 000,080,805 | —- | C] () – D:\Users\Katrien\Documents\id-voor.jpg
[2011/06/02 18:53:19 | 000,054,258 | —- | C] () – D:\Users\Katrien\Documents\handtekening1.jpg
[2011/06/02 18:41:49 | 000,059,380 | —- | C] () – D:\Users\Katrien\Documents\handtekening.jpg
[2011/04/20 18:58:15 | 000,650,752 | —- | C] () – C:\windows\System32\xvidcore.dll
[2011/04/20 18:58:15 | 000,240,640 | —- | C] () – C:\windows\System32\xvidvfw.dll
[2011/03/30 23:50:36 | 000,005,120 | —- | C] () – C:\Users\Katrien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/16 12:18:33 | 000,000,474 | —- | C] () – C:\Users\Katrien\AppData\Roaming\Poladroid prefs.plist
[2010/12/03 17:08:54 | 000,208,274 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2010/10/22 08:36:20 | 000,203,264 | —- | C] () – C:\Users\Katrien\AppData\Local\GetToolbar.exe
[2010/10/16 00:15:43 | 000,001,048 | —- | C] () – C:\Users\Katrien\AppData\Roaming\wklnhst.dat
[2010/10/15 23:37:13 | 000,087,552 | —- | C] () – C:\windows\System32\cpwmon2k.dll
[2010/10/15 20:37:25 | 000,006,144 | —- | C] () – C:\windows\System32\drivers\ASUSHWIO.SYS
[2010/04/21 08:45:14 | 000,013,931 | —- | C] () – C:\windows\System32\RaCoInst.dat
[2010/03/24 18:39:34 | 000,224,680 | —- | C] () – C:\windows\System32\AsusService.exe
[2010/03/24 18:39:34 | 000,025,616 | —- | C] () – C:\windows\AsAcpiSvrLang.ini
[2010/03/24 17:55:13 | 000,131,368 | —- | C] () – C:\ProgramData\FullRemove.exe
[2010/03/24 13:33:51 | 000,011,448 | —- | C] () – C:\windows\System32\drivers\AsUpIO.sys
[2010/03/24 13:33:45 | 000,001,769 | —- | C] () – C:\windows\Language_trs.ini
[2010/03/24 12:43:38 | 000,004,692 | —- | C] () – C:\windows\System32\drivers\SamSfPa.dat
[2010/03/01 10:59:00 | 000,408,168 | —- | C] () – C:\windows\System32\easyUpdatusAPIU.dll
[2010/03/01 10:59:00 | 000,212,215 | —- | C] () – C:\windows\System32\nvcoproc.bin
[2009/10/26 15:38:22 | 000,000,176 | —- | C] () – C:\windows\explorer.exe.config
[2009/07/27 10:35:09 | 000,703,644 | —- | C] () – C:\windows\System32\perfh013.dat
[2009/07/27 10:35:09 | 000,341,322 | —- | C] () – C:\windows\System32\perfi013.dat
[2009/07/27 10:35:09 | 000,137,164 | —- | C] () – C:\windows\System32\perfc013.dat
[2009/07/27 10:35:09 | 000,043,068 | —- | C] () – C:\windows\System32\perfd013.dat
[2009/07/27 10:23:34 | 000,706,882 | —- | C] () – C:\windows\System32\perfh00C.dat
[2009/07/27 10:23:34 | 000,344,522 | —- | C] () – C:\windows\System32\perfi00C.dat
[2009/07/27 10:23:34 | 000,134,364 | —- | C] () – C:\windows\System32\perfc00C.dat
[2009/07/27 10:23:34 | 000,038,160 | —- | C] () – C:\windows\System32\perfd00C.dat
[2009/07/27 10:12:00 | 000,701,560 | —- | C] () – C:\windows\System32\perfh010.dat
[2009/07/27 10:12:00 | 000,335,478 | —- | C] () – C:\windows\System32\perfi010.dat
[2009/07/27 10:12:00 | 000,131,368 | —- | C] () – C:\windows\System32\perfc010.dat
[2009/07/27 10:12:00 | 000,037,534 | —- | C] () – C:\windows\System32\perfd010.dat
[2009/07/27 10:01:28 | 000,656,288 | —- | C] () – C:\windows\System32\perfh007.dat
[2009/07/27 10:01:28 | 000,295,922 | —- | C] () – C:\windows\System32\perfi007.dat
[2009/07/27 10:01:28 | 000,133,764 | —- | C] () – C:\windows\System32\perfc007.dat
[2009/07/27 10:01:28 | 000,038,104 | —- | C] () – C:\windows\System32\perfd007.dat
[2009/07/14 16:57:37 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/14 16:33:53 | 000,330,888 | —- | C] () – C:\windows\System32\FNTCACHE.DAT
[2009/07/14 14:05:48 | 000,628,460 | —- | C] () – C:\windows\System32\perfh009.dat
[2009/07/14 14:05:48 | 000,291,294 | —- | C] () – C:\windows\System32\perfi009.dat
[2009/07/14 14:05:48 | 000,110,612 | —- | C] () – C:\windows\System32\perfc009.dat
[2009/07/14 14:05:48 | 000,031,548 | —- | C] () – C:\windows\System32\perfd009.dat
[2009/07/14 14:05:05 | 000,000,741 | —- | C] () – C:\windows\System32\NOISE.DAT
[2009/07/14 14:04:11 | 000,215,943 | —- | C] () – C:\windows\System32\dssec.dat
[2009/07/14 11:55:01 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/14 11:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/14 11:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll
[2009/06/11 09:26:10 | 000,673,088 | —- | C] () – C:\windows\System32\mlang.dat
< End of report >
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6875
Windows 6.1.7600
Internet Explorer 9.0.8112.16421
18/06/2011 6:00:26 p.m.
mbam-log-2011-06-18 (18-00-26).txt
Scan type: Quick scan
Objects scanned: 164301
Time elapsed: 4 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
We’ll do an online scan to be certain everything is as it seems before clearing up.
Run ESET Online Scan
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.
Satchfan
Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:
===================================================
Uninstall OTL
- Double-click OTL.exe
- Click the CleanUp! button.
- Select Yes when the Begin cleanup Process? prompt appears.
- If you are prompted to reboot during the cleanup, select Yes.
- The tool will delete itself once it finishes, if not delete it by yourself.
===================================================
Create a Restore Point• click Start, right-click Computer, and then Properties.
• in the left pane, click System protection. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
• click the System Protection tab, and then click Create.
• in the System Protection dialog box, type a description, and then click Create.
Remove old restore points• click Start button and in the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.
• if prompted, select the drive that you want to clean up, and then click OK.
• in the Disk Cleanup for (drive letter) dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
• if prompted, select the drive that you want to clean up, and then click OK.
• click the More Options tab, under System Restore and Shadow Copies, click Clean up.
• in the Disk Cleanup dialog box, click Delete.
• click Delete Files, and then click OK.
===================================================
Uninstall Java
The version you have is old and therefore vulnerable to infections. • from the Start menu, select Control Panel.
• in Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
• select Java 1.6.0_22(and any other versions that exist) and click Uninstall. Alternatively, right-click the program and select Uninstall.
Install the latest version of Java from here
===================================================
Recommended programs
Although Spybot Search & Destroy is a good program, it is not robust enough to deal with today’s intruders and infections. I suggest you install the following program:
SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.
===================================================
Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.
===================================================
It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.
FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.
===================================================
MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
===================================================
I also recommend that you read the following:
How to prevent malware by miekiemoes
Safe computing
Satchfan
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI