This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe eats up CPU usage 100% [Solved]

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Note of Eric: Start of OTL..Txt file
————————————————————————————————————————————————————————————————————————-



OTL logfile created on: 30-12-2011 11:42:49 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eric\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

952,13 Mb Total Physical Memory | 228,38 Mb Available Physical Memory | 23,99% Memory free
2,11 Gb Paging File | 0,71 Gb Available in Paging File | 33,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,65 Gb Total Space | 27,04 Gb Free Space | 38,82% Space Free | Partition Type: NTFS
Drive D: | 69,64 Gb Total Space | 49,81 Gb Free Space | 71,53% Space Free | Partition Type: NTFS
Drive E: | 4,23 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 48,83 Gb Total Space | 33,47 Gb Free Space | 68,55% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 48,11 Gb Free Space | 98,52% Space Free | Partition Type: NTFS
Drive I: | 410,15 Gb Total Space | 168,56 Gb Free Space | 41,10% Space Free | Partition Type: NTFS
Drive J: | 97,65 Gb Total Space | 73,70 Gb Free Space | 75,47% Space Free | Partition Type: NTFS
Drive K: | 97,65 Gb Total Space | 57,67 Gb Free Space | 59,05% Space Free | Partition Type: NTFS
Drive L: | 39,06 Gb Total Space | 17,93 Gb Free Space | 45,91% Space Free | Partition Type: NTFS
Drive M: | 9,77 Gb Total Space | 9,08 Gb Free Space | 92,92% Space Free | Partition Type: NTFS
Drive N: | 78,13 Gb Total Space | 48,89 Gb Free Space | 62,57% Space Free | Partition Type: NTFS
Drive O: | 48,83 Gb Total Space | 41,46 Gb Free Space | 84,90% Space Free | Partition Type: NTFS
Drive P: | 52,61 Gb Total Space | 35,24 Gb Free Space | 66,99% Space Free | Partition Type: NTFS
Drive Q: | 3,73 Gb Total Space | 2,80 Gb Free Space | 75,04% Space Free | Partition Type: FAT32

Computer Name: FLAPPIE | User Name: Eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Eric\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - c:\Program Files\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Users\Eric\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
PRC - C:\Windows\System32\lxeacoms.exe ( )
PRC - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files\Apoint2K\Hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
PRC - C:\Windows\System32\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Acer\Mobility Center\MobilityService.exe ()
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\m14xcglq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCoreGecko9.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
MOD - C:\Windows\System32\spool\drivers\w32x86\3\lxeadatr.dll ()
MOD - C:\Windows\System32\LXEAsmr.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
MOD - C:\Windows\System32\LXEAsm.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3006.0__3036420f80dd6947\Framework.Library.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3006.0__4df5dcab8860d239\Framework.Utility.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3006.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll ()
MOD - C:\Program Files\Launch Manager\PowerUtl.dll ()


========== Win32 Services (SafeList) ==========

SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (TuneUp.Defrag) – C:\Windows\System32\TuneUpDefragService.exe (TuneUp Software GmbH)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (lxea_device) – C:\Windows\System32\lxeacoms.exe ( )
SRV - (lxeaCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ETService) – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (MobilityService) – C:\Acer\Mobility Center\MobilityService.exe ()
SRV - (PSI_SVC_2) – C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (PSINAflt) – C:\Windows\System32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINProt) – C:\Windows\System32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\Windows\System32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\Windows\System32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\Windows\System32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (npf) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\Windows\System32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) – C:\Windows\System32\drivers\s0016unic.sys (MCCI Corporation)
DRV - (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) – C:\Windows\System32\drivers\s0016nd5.sys (MCCI Corporation)
DRV - (s0016mdfl) – C:\Windows\System32\drivers\s0016mdfl.sys (MCCI Corporation)
DRV - (s0016mdm) – C:\Windows\System32\drivers\s0016mdm.sys (MCCI Corporation)
DRV - (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) – C:\Windows\System32\drivers\s0016mgmt.sys (MCCI Corporation)
DRV - (s0016obex) – C:\Windows\System32\drivers\s0016obex.sys (MCCI Corporation)
DRV - (s0016bus) Sony Ericsson Device 0016 driver (WDM) – C:\Windows\System32\drivers\s0016bus.sys (MCCI Corporation)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (seehcri) – C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (TpChoice) – C:\Windows\System32\drivers\TpChoice.sys (Alps Electric Co., Ltd.)
DRV - (regi) – C:\Windows\System32\drivers\regi.sys (InterVideo)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://descargar.benjaminstrahs.com/nl/ind…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://descargar.benjaminstrahs.com/nl/index.php?rvs=google
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=extensa_5230
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://descargar.benjaminstrahs.com/nl/ind…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Search the Web"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..keyword.URL: "http://nl.search.yahoo.com/search?ei=utf-8&fr=panda&type=panda2_0yatb&p="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: G:\SonyMedia Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Panda Security\Panda ID Protect\Firefox [2011-05-18 18:55:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011-12-19 10:19:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-11-18 12:54:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-12-29 11:42:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-11-05 17:56:41 | 000,000,000 | —D | M]

[2011-06-27 11:17:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Eric\AppData\Roaming\mozilla\Extensions
[2011-06-27 11:17:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Eric\AppData\Roaming\mozilla\Extensions\[removed]
[2011-12-27 15:47:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions
[2011-12-22 04:33:35 | 000,000,000 | —D | M] (Flagfox) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011-06-12 20:18:34 | 000,000,000 | —D | M] (jZip Toolbar) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{1e48c56f-08cd-43aa-a6ef-c1ec891551ab}
[2011-11-29 23:25:40 | 000,000,000 | —D | M] (Ad-Aware Security Toolbar) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2011-10-22 16:28:27 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2011-12-25 13:29:00 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011-07-30 20:52:07 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(109)
[2011-12-27 15:47:51 | 000,000,000 | —D | M] (Vuze Remote Community Toolbar) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011-08-06 19:06:50 | 000,000,000 | —D | M] (Babylon) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\[removed]
[2011-12-20 18:05:48 | 000,000,000 | —D | M] (Woordenboek Nederlands) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\[removed]
[2011-09-18 15:03:25 | 000,000,000 | —D | M] (Cooliris) – C:\Users\Eric\AppData\Roaming\mozilla\Firefox\Profiles\m14xcglq.default\extensions\piclens@cooliris(103).com
[2011-08-06 19:05:49 | 000,000,457 | —- | M] () – C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\m14xcglq.default\searchplugins\Benjaminstrahs.xml
[2011-08-13 16:26:42 | 000,002,506 | —- | M] () – C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\m14xcglq.default\searchplugins\SearchResults.xml
[2011-12-27 15:46:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011-11-12 21:07:12 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011-11-18 12:54:06 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011-12-19 10:19:09 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
() (No name found) – C:\USERS\ERIC\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\M14XCGLQ.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) – C:\USERS\ERIC\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\M14XCGLQ.DEFAULT\EXTENSIONS\[removed]
[2011-05-02 00:43:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011-12-21 08:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011-10-03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011-01-31 23:28:22 | 000,001,110 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\adaradar.xml
[2011-10-17 19:14:28 | 000,002,149 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
[2011-10-02 20:50:41 | 000,002,230 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011-12-21 05:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011-05-23 19:20:25 | 000,001,949 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011-08-13 16:26:42 | 000,002,506 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
[2011-12-21 05:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\3.0.40624.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\14.0.835.202\gears.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.31.137.7_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Babylon Chrome OCR = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\
CHR - Extension: AT_MariahCarey = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\eodbbhbmhfemocgkhhihfjnkifmcjmoi\3_0\
CHR - Extension: SiteAdvisor = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: DivX HiQ = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\

Hosts file not found
O2 - BHO: (Lexmark Werkbalk) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O2 - BHO: (Lexmark ) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Werkbalk) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (no name) - {1e48c56f-08cd-43aa-a6ef-c1ec891551ab} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Werkbalk) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Werkbalk) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Panda Security URL Filtering] C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DA38F3A-DA8C-44BA-8035-8578D212F291}: DhcpNameServer = 192.168.2.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI83E4~1\Datamngr\datamngr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\WI83E4~1\Datamngr\IEBHO.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Toco Toucan.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Toco Toucan.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2011-09-03 17:58:50 | 000,000,000 | —D | M] - G:\AutoCAD R14 – [ NTFS ]
O32 - AutoRun File - [2011-09-03 18:23:50 | 000,000,000 | —D | M] - G:\autorun – [ NTFS ]
O32 - AutoRun File - [2009-10-14 20:42:28 | 000,000,011 | —- | M] () - G:\AUTORUN_.INF – [ NTFS ]
O32 - AutoRun File - [2011-05-09 23:27:06 | 000,000,000 | —D | M] - H:\autorun – [ NTFS ]
O32 - AutoRun File - [2011-12-29 01:51:39 | 000,000,000 | —D | M] - I:\autorun – [ NTFS ]
O32 - AutoRun File - [2009-11-23 14:01:49 | 000,000,000 | -H-D | M] - J:\autorun – [ NTFS ]
O32 - AutoRun File - [2008-10-24 18:00:29 | 000,000,000 | —D | M] - K:\autorun – [ NTFS ]
O32 - AutoRun File - [2009-10-13 22:14:05 | 000,000,000 | —D | M] - M:\autorun – [ NTFS ]
O32 - AutoRun File - [2008-10-24 18:01:50 | 000,000,000 | —D | M] - N:\autorun – [ NTFS ]
O32 - AutoRun File - [2009-10-30 20:19:55 | 000,000,011 | —- | M] () - N:\AUTORUN_.INF – [ NTFS ]
O32 - AutoRun File - [2008-10-24 18:02:14 | 000,000,000 | —D | M] - P:\autorun – [ NTFS ]
O32 - AutoRun File - [2002-10-17 08:56:50 | 000,000,036 | RH– | M] () - P:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011-12-30 11:08:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Eric\Desktop\HiJackThis.exe
[2011-12-30 11:06:01 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Eric\Desktop\OTL.exe
[2011-12-30 02:05:54 | 000,000,000 | —D | C] – C:\Users\Eric\Desktop\tdsskiller
[2011-12-29 21:16:47 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2011-12-29 21:16:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager
[2011-12-29 21:16:36 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2011-12-29 11:47:43 | 000,000,000 | —D | C] – C:\Users\Eric\Option
[2011-12-29 02:23:07 | 000,000,000 | —D | C] – C:\Users\Eric\Desktop\;
[2011-12-29 00:24:05 | 000,000,000 | —D | C] – C:\Program Files\WhatsRunning
[2011-12-28 15:14:12 | 000,000,000 | R–D | C] – C:\Users\Eric\Desktop\Werk Informatie
[2011-12-28 14:46:39 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{356BFA0E-A974-4C0B-87A2-5CA468C61BFD}
[2011-12-28 14:46:27 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{1F930C0F-8AF0-4A8E-8883-379FCCE66F99}
[2011-12-27 15:24:17 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{1EA59925-6272-4E27-A213-E5F397185156}
[2011-12-27 15:24:04 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{B104CA73-F9D8-420F-9166-821C45FCDE70}
[2011-12-25 14:01:44 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011-12-25 14:01:42 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011-12-25 14:01:42 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011-12-25 14:01:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011-12-25 14:01:41 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011-12-25 14:01:37 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011-12-25 13:48:10 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011-12-25 13:48:07 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011-12-25 13:47:33 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011-12-25 13:47:22 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011-12-25 01:46:22 | 000,000,000 | R–D | C] – C:\Users\Eric\Desktop\Programma`s
[2011-12-23 14:52:26 | 001,578,288 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Eric\Desktop\TDSSKiller.exe
[2011-12-22 01:44:53 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{2FA96FB4-04A1-4F93-ADCA-690FB1E0E21C}
[2011-12-22 01:43:46 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{1774AFE4-373C-420B-9742-2C41BF69B0DF}
[2011-12-20 18:32:57 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{4777B860-BFCB-4EB0-AB19-56D838C38C6D}
[2011-12-20 18:32:42 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{F58B6BB7-6200-4955-970E-17B84500E91C}
[2011-12-18 16:26:40 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{9B524C78-53EC-40BD-9FAC-C54CE21B24F8}
[2011-12-18 16:26:23 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{32F7A5CC-DE1D-4C36-9AEC-729CA2A4741B}
[2011-12-17 15:38:16 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{8694148E-21CC-42B5-813E-8E57302F01FE}
[2011-12-17 15:38:05 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{60448CF0-2960-4D36-9D28-E3BC9D8BF18A}
[2011-12-16 18:50:04 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{E5DB840C-FBEE-4353-B960-47D9D4A842F9}
[2011-12-16 18:49:47 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{55329513-9174-4C09-8AC2-E113470C1259}
[2011-12-12 18:27:23 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{5E7E942C-13B1-44DF-9723-BF38098D8C98}
[2011-12-12 18:27:01 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{BE47ED1D-A0B6-4F96-A4DF-CE3105BE6CE3}
[2011-12-07 21:48:53 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{E49A195C-FD39-4B86-AAD0-4188576A699B}
[2011-12-07 21:48:34 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{3973E85E-3EBE-4520-A17E-8910D94D8134}
[2011-12-06 23:54:19 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{98249B1E-34D1-4D1C-A394-5999EC0598B4}
[2011-12-06 23:54:02 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{4FDD1274-B050-4742-BCBF-AAAE7DB23049}
[2011-12-04 16:25:16 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{7464FBB7-F19B-4606-9C7B-A4E409D19122}
[2011-12-04 16:25:00 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{976794CD-704D-491E-AE58-D9A67134BA1D}
[2011-12-03 15:17:22 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{417F24F0-5F3C-4463-8806-2F8A695E3515}
[2011-12-03 15:17:06 | 000,000,000 | —D | C] – C:\Users\Eric\AppData\Local\{FE203CFA-52BB-4F31-B3E9-92072BC76491}
[2011-10-09 00:05:40 | 000,442,368 | —- | C] ( ) – C:\Windows\System32\lxeacoin.dll
[2011-10-08 23:59:16 | 000,356,352 | —- | C] ( ) – C:\Windows\System32\LXEAhcp.dll
[2011-10-08 23:59:14 | 000,847,872 | —- | C] ( ) – C:\Windows\System32\lxeausb1.dll
[2011-10-08 23:59:14 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxeainpa.dll
[2011-10-08 23:59:14 | 000,344,064 | —- | C] ( ) – C:\Windows\System32\lxeaiesc.dll
[2011-10-08 23:59:13 | 001,048,576 | —- | C] ( ) – C:\Windows\System32\lxeaserv.dll
[2011-10-08 23:59:12 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxeapmui.dll
[2011-10-08 23:59:12 | 000,577,536 | —- | C] ( ) – C:\Windows\System32\lxealmpm.dll
[2011-10-08 23:59:06 | 000,324,264 | —- | C] ( ) – C:\Windows\System32\lxeaih.exe
[2011-10-08 23:59:05 | 000,688,128 | —- | C] ( ) – C:\Windows\System32\lxeahbn3.dll
[2011-10-08 23:59:01 | 000,598,696 | —- | C] ( ) – C:\Windows\System32\lxeacoms.exe
[2011-10-08 23:59:00 | 000,802,816 | —- | C] ( ) – C:\Windows\System32\lxeacomc.dll
[2011-10-08 23:59:00 | 000,372,736 | —- | C] ( ) – C:\Windows\System32\lxeacomm.dll
[2011-10-08 23:58:59 | 000,373,416 | —- | C] ( ) – C:\Windows\System32\lxeacfg.exe
[2011-06-26 01:16:54 | 000,148,736 | —- | C] (Avanquest Software) – C:\ProgramData\hpeACA5.dll
[2011-06-26 01:00:11 | 000,148,736 | —- | C] (Avanquest Software) – C:\ProgramData\hpe603B.dll
[2011-04-29 21:25:40 | 000,049,152 | —- | C] ( ) – C:\Windows\Interop.IWshRuntimeLibrary.dll
[2011-02-11 10:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2 D:\Documents\*.tmp files -> D:\Documents\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011-12-30 11:14:03 | 000,001,046 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-12-30 11:10:36 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011-12-30 11:10:36 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011-12-30 11:08:55 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Eric\Desktop\HiJackThis.exe
[2011-12-30 11:05:33 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Eric\Desktop\OTL.exe
[2011-12-30 10:54:46 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2011-12-30 10:54:14 | 000,001,042 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-12-30 10:52:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011-12-30 10:52:42 | 999,141,376 | -HS- | M] () – C:\hiberfil.sys
[2011-12-30 02:10:10 | 001,558,406 | —- | M] () – C:\Users\Eric\Desktop\tdsskiller.zip
[2011-12-30 02:09:31 | 001,578,288 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Eric\Desktop\TDSSKiller.exe
[2011-12-29 18:58:42 | 000,192,512 | —- | M] () – C:\Users\Eric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-12-29 03:38:21 | 000,003,208 | —- | M] () – D:\Documents\cc_20111229_033815.reg
[2011-12-27 15:46:49 | 000,000,874 | —- | M] () – C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011-12-26 04:15:53 | 000,001,980 | —- | M] () – D:\Documents\cc_20111226_041549.reg
[2011-12-25 15:01:06 | 000,723,382 | —- | M] () – C:\Windows\System32\perfh013.dat
[2011-12-25 15:01:06 | 000,633,886 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011-12-25 15:01:06 | 000,151,122 | —- | M] () – C:\Windows\System32\perfc013.dat
[2011-12-25 15:01:05 | 000,118,772 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011-12-25 14:19:49 | 003,732,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011-12-25 14:07:54 | 000,000,129 | —- | M] () – C:\Windows\System32\MRT.INI
[2011-12-23 17:15:00 | 000,000,392 | —- | M] () – C:\Windows\tasks\Easy Onderhoud.job
[2011-12-17 20:32:27 | 000,002,405 | —- | M] () – C:\Users\Eric\Desktop\Boog Griek - Snelkoppeling.lnk
[2011-12-17 14:51:15 | 000,000,952 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2011-12-15 23:54:31 | 000,000,464 | —- | M] () – D:\Documents\cc_20111215_235425.reg
[2011-12-13 18:30:43 | 000,000,064 | —- | M] () – C:\Windows\System32\rp_stats.dat
[2011-12-13 18:30:43 | 000,000,044 | —- | M] () – C:\Windows\System32\rp_rules.dat
[2 D:\Documents\*.tmp files -> D:\Documents\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011-12-30 02:10:01 | 001,558,406 | —- | C] () – C:\Users\Eric\Desktop\tdsskiller.zip
[2011-12-29 22:29:45 | 999,141,376 | -HS- | C] () – C:\hiberfil.sys
[2011-12-29 03:38:18 | 000,003,208 | —- | C] () – D:\Documents\cc_20111229_033815.reg
[2011-12-26 04:15:51 | 000,001,980 | —- | C] () – D:\Documents\cc_20111226_041549.reg
[2011-12-17 20:32:27 | 000,002,405 | —- | C] () – C:\Users\Eric\Desktop\Boog Griek - Snelkoppeling.lnk
[2011-12-15 23:54:28 | 000,000,464 | —- | C] () – D:\Documents\cc_20111215_235425.reg
[2011-12-03 15:58:53 | 000,000,874 | —- | C] () – C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011-12-03 15:58:53 | 000,000,862 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011-12-02 23:32:36 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011-12-02 23:32:36 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011-11-14 19:57:16 | 000,192,512 | —- | C] () – C:\Users\Eric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-11-05 01:19:31 | 000,444,283 | —- | C] () – C:\Program Files\Common Files\WinPcapNmap.exe
[2011-10-22 18:29:08 | 000,098,344 | —- | C] () – C:\Windows\unTMV.exe
[2011-10-09 00:05:44 | 000,040,960 | —- | C] () – C:\Windows\System32\lxeavs.dll
[2011-10-09 00:05:31 | 000,086,016 | —- | C] () – C:\Windows\System32\lxeagcfg.dll
[2011-10-09 00:05:29 | 000,294,912 | —- | C] () – C:\Windows\System32\lxeacui.dll
[2011-10-09 00:05:29 | 000,110,592 | —- | C] () – C:\Windows\System32\lxeacuir.dll
[2011-10-08 23:59:49 | 000,000,044 | -H– | C] () – C:\Windows\System32\lxearwrd.ini
[2011-10-08 23:59:16 | 000,331,776 | —- | C] () – C:\Windows\System32\LXEAinst.dll
[2011-10-08 23:59:12 | 000,057,344 | —- | C] () – C:\Windows\System32\lxeajswr.dll
[2011-10-08 23:59:09 | 000,262,144 | —- | C] () – C:\Windows\System32\lxeainsb.dll
[2011-10-08 23:59:07 | 000,110,592 | —- | C] () – C:\Windows\System32\lxeainsr.dll
[2011-10-08 23:59:06 | 000,323,584 | —- | C] () – C:\Windows\System32\lxeains.dll
[2011-10-08 23:59:05 | 000,208,896 | —- | C] () – C:\Windows\System32\lxeagrd.dll
[2011-10-08 23:59:04 | 000,090,112 | —- | C] () – C:\Windows\System32\lxeacub.dll
[2011-10-08 23:59:03 | 000,036,864 | —- | C] () – C:\Windows\System32\lxeacur.dll
[2011-10-08 23:59:02 | 000,253,952 | —- | C] () – C:\Windows\System32\lxeacu.dll
[2011-10-05 20:52:17 | 000,024,064 | —- | C] () – C:\Windows\System32\LXEAsmr.dll
[2011-10-05 20:52:11 | 000,299,008 | —- | C] () – C:\Windows\System32\LXEAsm.dll
[2011-07-31 19:19:38 | 000,043,520 | —- | C] () – C:\Windows\System32\Ltnet90n.dll
[2011-07-31 19:19:30 | 000,122,880 | —- | C] () – C:\Windows\System32\Lfkodak.dll
[2011-07-31 19:19:28 | 000,338,944 | —- | C] () – C:\Windows\System32\lffpx7.dll
[2011-07-31 19:19:28 | 000,088,576 | —- | C] () – C:\Windows\System32\lffpx90n.dll
[2011-07-31 14:22:10 | 000,000,129 | —- | C] () – C:\Windows\System32\MRT.INI
[2011-05-18 18:53:07 | 000,000,264 | —- | C] () – C:\Windows\System32\PSUNCpl.dat
[2011-05-01 02:08:46 | 000,000,952 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2011-04-29 21:14:00 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2011-04-29 21:14:00 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2011-04-29 21:14:00 | 000,005,120 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2011-04-29 18:35:04 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2011-04-29 18:34:08 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2011-04-29 14:27:38 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2011-04-29 14:27:38 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011-04-29 11:56:32 | 000,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2011-04-29 11:56:31 | 000,000,852 | —- | C] () – C:\Windows\System32\drivers\RTKHDRC0.dat
[2011-04-29 11:56:31 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2011-04-29 11:56:31 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2011-04-29 11:56:31 | 000,000,008 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2011-02-11 11:10:52 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2011-02-11 11:10:50 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2011-02-11 11:10:50 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2011-02-11 10:38:44 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2010-01-27 03:09:02 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2009-10-07 01:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009-10-07 01:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009-04-30 22:39:36 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009-02-12 10:41:09 | 000,723,382 | —- | C] () – C:\Windows\System32\perfh013.dat
[2009-02-12 10:41:09 | 000,336,440 | —- | C] () – C:\Windows\System32\perfi013.dat
[2009-02-12 10:41:09 | 000,151,122 | —- | C] () – C:\Windows\System32\perfc013.dat
[2009-02-12 10:41:09 | 000,041,976 | —- | C] () – C:\Windows\System32\perfd013.dat
[2009-02-12 02:58:46 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009-02-12 02:03:41 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2009-02-12 02:00:19 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIOFM4.dll
[2009-02-12 02:00:19 | 000,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN5.dll
[2008-05-14 09:29:02 | 000,872,448 | —- | C] () – C:\Windows\iconv.dll
[2008-05-14 09:29:02 | 000,743,424 | —- | C] () – C:\Windows\libxml2.dll
[2008-05-14 09:29:01 | 000,000,040 | —- | C] () – C:\Windows\Prelaunch.ini
[2006-11-02 13:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006-11-02 13:44:53 | 003,732,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006-11-02 11:33:01 | 000,633,886 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006-11-02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006-11-02 11:33:01 | 000,118,772 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006-11-02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006-11-02 11:25:26 | 000,557,568 | —- | C] () – C:\Windows\System32\hpotscl1.dll
[2006-11-02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006-11-02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006-11-02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006-11-02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006-11-02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001-12-26 16:12:30 | 000,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001-09-03 23:46:38 | 000,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001-07-30 16:33:56 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001-07-23 22:04:36 | 000,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2011-10-30 18:28:02 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Auslogics
[2011-12-15 23:49:04 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Azureus
[2011-08-06 17:33:07 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011-10-13 19:44:13 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Efzim
[2011-04-29 12:27:44 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\eSobi
[2011-04-30 02:03:54 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\GetRightToGo
[2011-05-01 00:19:17 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\GrabPro
[2011-10-14 18:20:17 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Ilnoy
[2011-05-01 02:09:03 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\InterVideo
[2011-12-29 11:33:28 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\JAM Software
[2011-11-13 21:23:32 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Leadertech
[2011-10-07 08:52:22 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\MediaBase
[2011-05-01 14:00:44 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Orbit
[2011-11-19 21:33:58 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Paibn
[2011-05-19 19:27:46 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Panda Security
[2011-05-01 00:19:40 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\ProgSense
[2011-07-31 22:53:25 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Publish Providers
[2011-05-01 16:20:11 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\RadarSync
[2011-10-22 18:30:17 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\SoftMaker
[2011-07-31 22:53:08 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Sony
[2011-08-02 21:41:37 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Sony Creative Software Inc
[2011-08-19 23:32:29 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Sony Network Entertainment International LLC
[2011-10-04 11:21:12 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011-05-18 18:54:30 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\SurfSecret Privacy Suite
[2011-05-01 20:21:00 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\SystemRequirementsLab
[2011-11-30 09:01:56 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Taudwi
[2011-11-04 22:36:50 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\TeamViewer
[2011-06-27 11:16:56 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\TomTom
[2011-04-30 00:48:47 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\TuneUp Software
[2011-11-05 02:15:40 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\VDownloader
[2011-05-03 21:06:52 | 000,000,000 | —D | M] – C:\Users\Eric\AppData\Roaming\Windows Live Writer
[2011-12-23 17:15:00 | 000,000,392 | —- | M] () – C:\Windows\Tasks\Easy Onderhoud.job
[2011-12-30 02:40:24 | 000,032,602 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011-07-26 19:30:18 | 000,000,000 | —- | M] () – C:\0x0304A000.sfl
[2011-12-17 14:41:06 | 000,011,816 | —- | M] () – C:\aaw7boot.log
[2006-09-18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009-04-10 22:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008-02-11 00:06:13 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006-09-18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011-12-30 10:52:42 | 999,141,376 | -HS- | M] () – C:\hiberfil.sys
[2011-12-30 10:52:33 | 1312,948,224 | -HS- | M] () – C:\pagefile.sys
[2009-07-25 01:33:24 | 000,011,162 | -HS- | M] () – C:\Patch.rev
[2009-02-12 12:48:38 | 000,000,148 | RHS- | M] () – C:\preload.rev
[2011-04-29 11:57:45 | 000,000,426 | —- | M] () – C:\RHDSetup.log
[2011-04-29 12:03:01 | 000,388,000 | —- | M] () – C:\vcredist_x86.log

< %systemroot%\Fonts\*.com >
[2006-11-02 13:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006-11-02 13:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006-11-02 13:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011-04-29 19:07:46 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006-09-18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008-01-21 03:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009-11-04 14:14:19 | 000,157,696 | —- | M] () – C:\Windows\system32\spool\prtprocs\w32x86\lxeadrpp.dll
[2006-10-26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011-05-13 14:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008-01-21 03:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008-01-21 04:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008-01-21 04:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008-01-21 04:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006-11-02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006-11-02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011-09-05 18:32:22 | 000,000,286 | -HS- | M] () – C:\Users\Eric\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011-12-30 11:08:55 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Eric\Desktop\HiJackThis.exe
[2011-12-30 11:05:33 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Eric\Desktop\OTL.exe
[2011-12-30 02:09:31 | 001,578,288 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Eric\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >
[2010-01-26 11:11:08 | 000,444,283 | —- | M] () – C:\Program Files\Common Files\WinPcapNmap.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-25 13:11:27

========== Alternate Data Streams ==========

@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:07BF512B

< End of report >

————————————————————————————————————————————————————————————————————————————
note of Eric: End of OTL.Txt file







Start of Extras.Txt file
————————————————————————————————————————————————————————————————————————————

OTL Extras logfile created on: 30-12-2011 11:17:56 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eric\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

952,13 Mb Total Physical Memory | 199,27 Mb Available Physical Memory | 20,93% Memory free
2,11 Gb Paging File | 0,73 Gb Available in Paging File | 34,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,65 Gb Total Space | 27,04 Gb Free Space | 38,83% Space Free | Partition Type: NTFS
Drive D: | 69,64 Gb Total Space | 49,81 Gb Free Space | 71,53% Space Free | Partition Type: NTFS
Drive E: | 4,23 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 48,83 Gb Total Space | 33,47 Gb Free Space | 68,55% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 48,11 Gb Free Space | 98,52% Space Free | Partition Type: NTFS
Drive I: | 410,15 Gb Total Space | 168,56 Gb Free Space | 41,10% Space Free | Partition Type: NTFS
Drive J: | 97,65 Gb Total Space | 73,70 Gb Free Space | 75,47% Space Free | Partition Type: NTFS
Drive K: | 97,65 Gb Total Space | 57,67 Gb Free Space | 59,05% Space Free | Partition Type: NTFS
Drive L: | 39,06 Gb Total Space | 17,93 Gb Free Space | 45,91% Space Free | Partition Type: NTFS
Drive M: | 9,77 Gb Total Space | 9,08 Gb Free Space | 92,92% Space Free | Partition Type: NTFS
Drive N: | 78,13 Gb Total Space | 48,89 Gb Free Space | 62,57% Space Free | Partition Type: NTFS
Drive O: | 48,83 Gb Total Space | 41,46 Gb Free Space | 84,90% Space Free | Partition Type: NTFS
Drive P: | 52,61 Gb Total Space | 35,24 Gb Free Space | 66,99% Space Free | Partition Type: NTFS
Drive Q: | 3,73 Gb Total Space | 2,80 Gb Free Space | 75,04% Space Free | Partition Type: FAT32

Computer Name: FLAPPIE | User Name: Eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3741765786-2799498056-3049370227-1003\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{075E9AFD-9625-40CE-9744-3A0DE49935DD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{07A6C4C5-D321-4E49-9FF6-2B91F55C49A3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{16F6B4E4-4D0D-468B-A972-010088117A82}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{1B961C18-DDB3-4B81-8845-B90759C8FCC0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{24A571D8-8DDB-45D2-8C98-F40188E4D9C6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{2B3EB4E6-D655-4750-9793-C209F2A416BF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2F928F21-73C2-4287-A543-3FD1B9D1D9B7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3905B2D6-D65D-4AF8-A761-35F1183AD8FD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{529A8547-3575-4C0B-8070-E6457B1D1AB5}" = lport=137 | protocol=17 | dir=in | app=system |
"{5B94692B-296B-41E9-A120-4D65C7106CB7}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{67036E7A-6CAE-4139-9EB7-0488E319B6D3}" = rport=139 | protocol=6 | dir=out | app=system |
"{67FFAD9D-1F66-416A-8E14-EA64D38FDC55}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6D09593A-36C4-4F6C-A4F0-E5523B120332}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{711A0768-0808-4A9C-973B-CCD3BCA6AD3B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{75B1B3C7-2685-4A72-BEDD-0E583D636E6A}" = lport=445 | protocol=6 | dir=in | app=system |
"{8C3F9132-5707-4FB9-9229-DDA014D1F9BB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A46D619F-6F25-4BF6-AB11-FC904433BB7A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B38D15EB-3E62-4A09-AF5F-9F8E69272C72}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B4A94F0E-79C5-4AD7-A0F5-93D49E75D2E3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BA037680-E9A5-44AE-8450-8FE08FE7421D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C5CC4D8C-510B-47F1-AF92-44A294BF6CDB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{C6A300FF-B398-4B23-A22E-64BBE0630F10}" = lport=138 | protocol=17 | dir=in | app=system |
"{C7555309-D84F-47BC-A509-94B105FED7E1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C8B2CF4B-68CF-4E4A-8F9B-07822584E127}" = lport=139 | protocol=6 | dir=in | app=system |
"{CDCDCC8E-E85A-48F0-A3D3-68BA278D1EB4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D023CC5A-DDA0-4BE3-B1FA-901E9B4D4F7C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7718325-6D14-4AEF-87A5-F2B76650CD1B}" = rport=138 | protocol=17 | dir=out | app=system |
"{D91EAB15-4727-4A0C-A126-8ADAC0AADC0C}" = rport=137 | protocol=17 | dir=out | app=system |
"{E8FC1DE5-2056-4B49-8075-48818EEE7362}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{ED263498-A9D3-4CCB-9EC6-BAA45B110982}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EDC141FE-BCA7-4B24-9052-B65A70EB76C3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F14F7E9D-239A-45E5-A4CC-C4BAA0E7652B}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{055E395E-6BC2-4867-846A-87362A18696C}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{062B7B84-6CD3-4B50-8AAB-2DA62998BA43}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0ED99B96-7792-42B4-81C8-A2C57235A4D6}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe |
"{203A4CDC-51FE-497E-93E0-24E8757390AF}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{26435265-A64E-4BB5-8BD1-D997337B47A9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{285703C1-3803-45B4-B613-2ACCF677D347}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{393D47CB-0643-4EF9-A769-D3751629017C}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe |
"{3A230561-4ECE-4C44-92CF-66C56D85B559}" = protocol=6 | dir=in | app=c:\program files\windows jzip toolbar\datamngr\toolbar\dtuser.exe |
"{3B7D037B-4D2A-4958-B97F-52210E1E72D3}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{3CC1A741-770B-4E2B-884D-759E1765497A}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{3CCB8720-5FA1-448B-AF91-A7782D00C6B8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3CF800DF-83C6-44D9-9C41-320D8A840171}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{3E009C1E-7047-4D1B-83D9-42131AA8A19D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{3F16DF5D-EEF4-4BEA-BADE-885446665B79}" = protocol=17 | dir=in | app=c:\program files\windows jzip toolbar\datamngr\toolbar\dtuser.exe |
"{4275F2C4-36FF-49D5-9046-921124403B1A}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{433B6229-FC4E-4593-8D30-FD5C3A49CEF3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{44908A2A-78E2-43E0-9402-A0C721E8146E}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{482D2EE8-0BF1-4F47-B913-7A010FACE72B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{565F9861-F9A0-4F38-953A-305EDC1AADCC}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{5C5D7EE0-C9E0-479B-86D6-618172E09CA8}" = protocol=17 | dir=in | app=c:\program files\adawaretb\dtuser.exe |
"{63E96C15-3546-4EFC-B565-C84CD1E879FC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6A906FAF-A856-488E-B7C7-D2C37F02E29A}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{6D4B19F5-E0A8-4D11-A161-4150FAFF2441}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6FEE90C1-55A7-4D62-A6A4-2B4E4645CC99}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{71585E31-D06A-435E-8D4F-96D20B4A4278}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{76DB08A3-35AA-4DC9-90B5-044E3A628186}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer.exe |
"{7A164F47-5BF3-49BD-9D3B-AA1E5034D02F}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7C5BC4DC-C74E-4DCB-9C46-DEB65868FDB6}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{90076CA3-A224-4AE0-83B9-B8CC30201117}" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{901C3BFA-B171-4D96-B827-DE9BE9DCEB09}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"{9432F76C-753D-4F23-A1E8-863D751AC4AD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{985E27BD-894B-4881-9388-4EBCAC25F48C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A0E50110-0893-4356-8ABB-A5AFC2CBED28}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{AC023FB5-F870-4999-8BE7-405774008E50}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B4937AD2-3A39-4996-84B3-28757C1DAE95}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version6\teamviewer_service.exe |
"{B6B97D58-1EB6-4A9E-85CE-BEB01714306E}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{BC930021-EDEC-4ED2-8C45-446C064AB5FF}" = protocol=6 | dir=out | app=system |
"{BD579D1A-5844-4171-94E9-41C72F52E61E}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{CE66AAED-AB29-4B08-ADB4-9987D7DDE8B1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D50B76AC-4F77-4794-A937-2760E2159694}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D5622DD9-1670-41E7-9417-EA78CF91BED3}" = protocol=6 | dir=in | app=c:\program files\adawaretb\dtuser.exe |
"{DEA0BCF3-C8F3-42F3-A8B4-156218E84DAC}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{E2B1B317-72C8-49A3-B57E-D4E422B271CD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E338983F-3A43-4586-B919-8D43FF65E38A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E5A156D8-2A40-4C85-8FD2-4CB30984BDAC}" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{E9E57608-1B1F-42A7-8F6D-87E9EC4D93E8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EBCDFC84-C58E-4AEC-81E4-ABC382124AB5}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{EE2CC251-4CDD-4874-ACE1-9FC91838DC79}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F978894F-02F9-4DA0-99A9-CB9D6AE2DD26}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FA2C33B9-6DA1-4D4E-9B32-7C4C3CD24376}" = dir=in | app=c:\windows\system32\lxeacoms.exe |
"TCP Query User{1AE14E9D-6A5E-4982-81EB-88176AE8CFB4}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{1EE10036-4A45-41BC-B21C-2E5820BEB291}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{B6A5C30E-F3E2-45CB-A4FD-077CAF7BCD7E}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{8A857037-12D4-4F38-98AB-08E018E0B108}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{943A4B46-65E0-446C-83B1-1CCDB59C7F65}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{A14A4545-3176-43BD-A1A8-B012B35D5776}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F895695-33CC-4203-9C47-25EF2AC9441C}" = Media Go
"{101738D7-D805-37A9-BB91-1F2C351782BF}" = Microsoft .NET Framework 3.5 Language Pack SP1 - nld
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Werkbalk
"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{48294D95-EE9A-4377-8213-44FC4265FB27}" = Windows Live Messenger
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{5590FCB1-AA19-4510-9FC1-BB6A8E0A14A5}" = Access Manager 2
"{55CCA8B6-977B-4CAC-8762-68394171E4AB}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}" = InterVideo WinDVD 8
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6669B6EE-2335-49FA-BDEF-4D3419AAFF68}" = Microsoft SQL Server Native Client
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6D592E30-11EC-11E0-859C-0013D3D69929}" = Vegas Pro 10.0
"{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2007
"{90120000-0015-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007
"{90120000-0016-0413-0000-0000000FF1CE}_HOMESTUDENTR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007
"{90120000-0018-0413-0000-0000000FF1CE}_HOMESTUDENTR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2007
"{90120000-0019-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2007
"{90120000-001A-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007
"{90120000-001B-0413-0000-0000000FF1CE}_HOMESTUDENTR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0413-0000-0000000FF1CE}_PROHYBRIDR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{2C95E7EE-FEA7-4B3A-A6E5-DF90A88B816A}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0413-0000-0000000FF1CE}_PROHYBRIDR_{2C95E7EE-FEA7-4B3A-A6E5-DF90A88B816A}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}_HOMESTUDENTR_{1D12BC91-360E-424C-97C4-813651313660}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0413-0000-0000000FF1CE}_PROHYBRIDR_{1D12BC91-360E-424C-97C4-813651313660}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0413-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2007
"{90120000-00A1-0413-0000-0000000FF1CE}_HOMESTUDENTR_{26257879-B20D-4D30-A429-B387A4890929}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90A40413-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A64A5576-D862-44F8-89DC-2B17FCC9B86E}" = Broadcom Gigabit Integrated Controller
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business-verbindingsonderdelen
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1043-7B44-A90000000001}" = Adobe Reader 9 - Nederlands
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}" = System Requirements Lab for Intel
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
"{D836006A-10F3-4069-B4FF-1A78D2B70234}" = Microsoft SQL Server Setup-ondersteuningsbestanden (Engels)
"{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}" = U3Launcher
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}" = Acer Product Registration
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E34F703A-1C9D-4B1F-ABBE-D7E8800B860D}" = Windows Live Sync
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5D03B2E-B2D4-477F-A60D-8E1969D821FA}" = Adobe Flash Player 10 ActiveX
"{E8E5ED05-E8CE-4313-A18C-49723394E0C9}" = Microsoft SQL Server VSS Writer
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.01.231
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"8461-7759-5462-8226" = Vuze
"adawaretb" = Ad-Aware Security Toolbar
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CCleaner" = CCleaner
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"conduitEngine" = Conduit Engine
"DivX Setup" = DivX Setup
"FLV Player2.0.25" = FLV Player
"GridVista" = Acer GridVista
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{5FEBF468-5AC2-4C66-AD80-DF85C085AA73}" = InterVideo WinDVD 8
"jZip" = jZip
"jZip 102 MediaBar" = Windows jZip Toolbar
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.6 (Standard)
"Lexmark S300-S400 Series" = Lexmark S300-S400 Series
"LManager" = Launch Manager
"Logitech Vid" = Logitech Vid HD
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Microsoft .NET Framework 3.5 Language Pack SP1 - nld" = Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Panda Identity Protect" = Panda Identity Protect 3.0.44
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"Picasa 3" = Picasa 3
"PROHYBRIDR" = 2007 Microsoft Office system
"Security Task Manager" = Security Task Manager 1.8d
"TeamViewer 6" = TeamViewer 6
"TomTom HOME" = TomTom HOME 2.8.2.2264
"Update Service" = Sony Ericsson Update Service
"VLC media player" = VLC media player 1.1.11
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


————————————————————————————————————————————————————————————————————————-
note of Eric:
End of Extras.Txt file
Hi Eric,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
aswMBR version 0.9.9.1124 Copyright© 2011 AVAST Software Run date: 2011-12-31 16:07:35 —————————– 16:07:35.807 OS Version: Windows 6.0.6002 Service Pack 2 16:07:35.807 Number of processors: 1 586 0x170A 16:07:35.807 ComputerName: FLAPPIE UserName: Eric 16:07:38.412 Initialize success 16:07:54.340 AVAST engine defs: 11123100 16:08:06.118 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 16:08:06.118 Disk 0 Vendor: WDC_WD1600BEVT-22ZCT0 11.01A11 Size: 152627MB BusType: 3 16:08:06.149 Disk 0 MBR read successfully 16:08:06.165 Disk 0 MBR scan 16:08:06.258 Disk 0 MBR:Alureon-G [Rtk] 16:08:06.258 Disk 0 TDL4@MBR code has been found 16:08:06.274 Disk 0 MBR hidden 16:08:06.305 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048 16:08:06.321 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 71317 MB offset 20482048 16:08:06.477 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 71308 MB offset 166539264 16:08:06.508 Disk 0 MBR [TDL4] **ROOTKIT** 16:08:06.523 Disk 0 trace - called modules: 16:08:06.523 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x88b6a4d0]<< 16:08:06.555 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88498988] 16:08:06.570 3 CLASSPNP.SYS[89ba18b3] -> nt!IofCallDriver -> [0x88bcd030] 16:08:06.570 \Driver\atapi[0x889a7690] -> IRP_MJ_CREATE -> 0x88b6a4d0 16:08:07.475 AVAST engine scan C:\Windows 16:08:20.673 AVAST engine scan C:\Windows\system32 16:11:39.214 AVAST engine scan C:\Windows\system32\drivers 16:11:57.091 AVAST engine scan C:\Users\Eric 16:21:05.338 AVAST engine scan C:\ProgramData 16:23:27.017 Scan finished successfully 16:24:19.355 Disk 0 MBR has been saved successfully to "D:\Documents\MBR.dat" 16:24:19.371 The log file has been saved successfully to "D:\Documents\aswMBR.txt" —————————————————————————————————————————————————————————————————————————————————————————————————————————————————————— 16:31:03.0688 1920 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 16:31:04.0156 1920 ============================================================ 16:31:04.0156 1920 Current date / time: 2011/12/31 16:31:04.0156 16:31:04.0156 1920 SystemInfo: 16:31:04.0156 1920 16:31:04.0156 1920 OS Version: 6.0.6002 ServicePack: 2.0 16:31:04.0156 1920 Product type: Workstation 16:31:04.0156 1920 ComputerName: FLAPPIE 16:31:04.0156 1920 UserName: Eric 16:31:04.0156 1920 Windows directory: C:\Windows 16:31:04.0156 1920 System windows directory: C:\Windows 16:31:04.0156 1920 Processor architecture: Intel x86 16:31:04.0156 1920 Number of processors: 1 16:31:04.0156 1920 Page size: 0x1000 16:31:04.0156 1920 Boot type: Normal boot 16:31:04.0156 1920 ============================================================ 16:31:09.0242 1920 Initialize success 16:31:23.0812 5628 ============================================================ 16:31:23.0812 5628 Scan started 16:31:23.0812 5628 Mode: Manual; 16:31:23.0812 5628 ============================================================ 16:31:27.0572 5628 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 16:31:27.0587 5628 ACPI - ok 16:31:27.0634 5628 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 16:31:27.0650 5628 adp94xx - ok 16:31:27.0743 5628 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 16:31:27.0743 5628 adpahci - ok 16:31:27.0774 5628 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 16:31:27.0774 5628 adpu160m - ok 16:31:27.0806 5628 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 16:31:27.0806 5628 adpu320 - ok 16:31:27.0884 5628 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 16:31:27.0899 5628 AFD - ok 16:31:27.0930 5628 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 16:31:27.0930 5628 agp440 - ok 16:31:27.0977 5628 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 16:31:27.0993 5628 aic78xx - ok 16:31:28.0040 5628 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 16:31:28.0040 5628 aliide - ok 16:31:28.0071 5628 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 16:31:28.0071 5628 amdagp - ok 16:31:28.0086 5628 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 16:31:28.0086 5628 amdide - ok 16:31:28.0118 5628 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 16:31:28.0118 5628 AmdK7 - ok 16:31:28.0149 5628 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 16:31:28.0149 5628 AmdK8 - ok 16:31:28.0196 5628 ApfiltrService (e8885f571251a058dca0f058341b04c1) C:\Windows\system32\DRIVERS\Apfiltr.sys 16:31:28.0211 5628 ApfiltrService - ok 16:31:28.0258 5628 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 16:31:28.0258 5628 arc - ok 16:31:28.0289 5628 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 16:31:28.0289 5628 arcsas - ok 16:31:28.0320 5628 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 16:31:28.0320 5628 AsyncMac - ok 16:31:28.0367 5628 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 16:31:28.0367 5628 atapi - ok 16:31:28.0430 5628 athr (d6ed40129c5f70a7485185bab27b8330) C:\Windows\system32\DRIVERS\athr.sys 16:31:28.0461 5628 athr - ok 16:31:28.0508 5628 b57nd60x (7d0f2bfa273831124fa08526af48af18) C:\Windows\system32\DRIVERS\b57nd60x.sys 16:31:28.0508 5628 b57nd60x - ok 16:31:28.0539 5628 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 16:31:28.0539 5628 Beep - ok 16:31:28.0617 5628 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 16:31:28.0617 5628 blbdrive - ok 16:31:28.0648 5628 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 16:31:28.0648 5628 bowser - ok 16:31:28.0726 5628 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 16:31:28.0742 5628 BrFiltLo - ok 16:31:28.0757 5628 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 16:31:28.0757 5628 BrFiltUp - ok 16:31:28.0788 5628 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 16:31:28.0804 5628 Brserid - ok 16:31:28.0835 5628 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 16:31:28.0835 5628 BrSerWdm - ok 16:31:28.0851 5628 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 16:31:28.0866 5628 BrUsbMdm - ok 16:31:28.0898 5628 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 16:31:28.0898 5628 BrUsbSer - ok 16:31:28.0929 5628 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 16:31:28.0929 5628 BTHMODEM - ok 16:31:28.0960 5628 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 16:31:28.0960 5628 cdfs - ok 16:31:29.0022 5628 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 16:31:29.0022 5628 cdrom - ok 16:31:29.0069 5628 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 16:31:29.0069 5628 circlass - ok 16:31:29.0116 5628 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 16:31:29.0132 5628 CLFS - ok 16:31:29.0163 5628 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 16:31:29.0163 5628 CmBatt - ok 16:31:29.0178 5628 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 16:31:29.0194 5628 cmdide - ok 16:31:29.0210 5628 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 16:31:29.0210 5628 Compbatt - ok 16:31:29.0241 5628 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 16:31:29.0256 5628 crcdisk - ok 16:31:29.0288 5628 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 16:31:29.0288 5628 Crusoe - ok 16:31:29.0366 5628 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 16:31:29.0381 5628 DfsC - ok 16:31:29.0444 5628 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 16:31:29.0459 5628 disk - ok 16:31:29.0490 5628 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys 16:31:29.0490 5628 DKbFltr - ok 16:31:29.0615 5628 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 16:31:29.0615 5628 drmkaud - ok 16:31:29.0678 5628 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 16:31:29.0693 5628 DXGKrnl - ok 16:31:29.0771 5628 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 16:31:29.0771 5628 E1G60 - ok 16:31:29.0834 5628 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 16:31:29.0834 5628 Ecache - ok 16:31:29.0912 5628 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 16:31:29.0912 5628 elxstor - ok 16:31:29.0990 5628 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 16:31:29.0990 5628 ErrDev - ok 16:31:30.0083 5628 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 16:31:30.0083 5628 exfat - ok 16:31:30.0130 5628 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 16:31:30.0146 5628 fastfat - ok 16:31:30.0161 5628 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 16:31:30.0177 5628 fdc - ok 16:31:30.0208 5628 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 16:31:30.0208 5628 FileInfo - ok 16:31:30.0302 5628 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 16:31:30.0302 5628 Filetrace - ok 16:31:30.0348 5628 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 16:31:30.0348 5628 flpydisk - ok 16:31:30.0380 5628 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 16:31:30.0380 5628 FltMgr - ok 16:31:30.0426 5628 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 16:31:30.0442 5628 Fs_Rec - ok 16:31:30.0473 5628 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 16:31:30.0473 5628 gagp30kx - ok 16:31:30.0536 5628 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 16:31:30.0551 5628 HdAudAddService - ok 16:31:30.0614 5628 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 16:31:30.0629 5628 HDAudBus - ok 16:31:30.0676 5628 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 16:31:30.0676 5628 HidBth - ok 16:31:30.0723 5628 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 16:31:30.0723 5628 HidIr - ok 16:31:30.0801 5628 HidUsb (e2b5bd48afcc0f0974fb44641b223250) C:\Windows\system32\DRIVERS\hidusb.sys 16:31:30.0801 5628 HidUsb - ok 16:31:30.0848 5628 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 16:31:30.0848 5628 HpCISSs - ok 16:31:30.0894 5628 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 16:31:30.0910 5628 HSFHWAZL - ok 16:31:30.0972 5628 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 16:31:31.0004 5628 HSF_DPV - ok 16:31:31.0066 5628 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys 16:31:31.0082 5628 HTTP - ok 16:31:31.0144 5628 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 16:31:31.0160 5628 i2omp - ok 16:31:31.0206 5628 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 16:31:31.0206 5628 i8042prt - ok 16:31:31.0253 5628 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 16:31:31.0269 5628 iaStorV - ok 16:31:31.0612 5628 igfx (dce0b53570703cce580d066f89ef58cd) C:\Windows\system32\DRIVERS\igdkmd32.sys 16:31:34.0233 5628 igfx - ok 16:31:34.0592 5628 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 16:31:34.0592 5628 iirsp - ok 16:31:34.0794 5628 int15 (c6e5276c00ebdeb096bb5ef4b797d1b6) C:\Windows\system32\drivers\int15.sys 16:31:34.0794 5628 int15 - ok 16:31:34.0966 5628 IntcAzAudAddService (23ebcee9aaa4d6c88728791fab462456) C:\Windows\system32\drivers\RTKVHDA.sys 16:31:35.0060 5628 IntcAzAudAddService - ok 16:31:35.0169 5628 IntcHdmiAddService (81486f0eb4238b65c317f97de246c4ac) C:\Windows\system32\drivers\IntcHdmi.sys 16:31:35.0169 5628 IntcHdmiAddService - ok 16:31:35.0231 5628 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 16:31:35.0231 5628 intelide - ok 16:31:35.0309 5628 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 16:31:35.0309 5628 intelppm - ok 16:31:35.0372 5628 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:31:35.0387 5628 IpFilterDriver - ok 16:31:35.0418 5628 IpInIp - ok 16:31:35.0465 5628 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 16:31:35.0481 5628 IPMIDRV - ok 16:31:35.0574 5628 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 16:31:35.0590 5628 IPNAT - ok 16:31:35.0621 5628 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys 16:31:35.0621 5628 irda - ok 16:31:35.0637 5628 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 16:31:35.0637 5628 IRENUM - ok 16:31:35.0715 5628 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 16:31:35.0715 5628 isapnp - ok 16:31:35.0762 5628 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 16:31:35.0762 5628 iScsiPrt - ok 16:31:35.0824 5628 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 16:31:35.0840 5628 iteatapi - ok 16:31:35.0886 5628 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 16:31:35.0902 5628 iteraid - ok 16:31:35.0933 5628 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 16:31:35.0933 5628 kbdclass - ok 16:31:35.0996 5628 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 16:31:35.0996 5628 kbdhid - ok 16:31:36.0230 5628 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 16:31:36.0245 5628 KSecDD - ok 16:31:36.0292 5628 Lbd - ok 16:31:36.0339 5628 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 16:31:36.0354 5628 lltdio - ok 16:31:36.0417 5628 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 16:31:36.0417 5628 LSI_FC - ok 16:31:36.0464 5628 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 16:31:36.0464 5628 LSI_SAS - ok 16:31:36.0495 5628 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 16:31:36.0495 5628 LSI_SCSI - ok 16:31:36.0526 5628 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 16:31:36.0542 5628 luafv - ok 16:31:36.0604 5628 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\Windows\system32\DRIVERS\LVPr2Mon.sys 16:31:36.0604 5628 LVPr2Mon - ok 16:31:36.0651 5628 MBAMSwissArmy - ok 16:31:36.0729 5628 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\Windows\system32\DRIVERS\mcdbus.sys 16:31:36.0729 5628 mcdbus - ok 16:31:36.0744 5628 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 16:31:36.0760 5628 megasas - ok 16:31:36.0854 5628 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 16:31:36.0885 5628 MegaSR - ok 16:31:36.0916 5628 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 16:31:36.0932 5628 Modem - ok 16:31:36.0963 5628 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 16:31:36.0978 5628 monitor - ok 16:31:37.0025 5628 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 16:31:37.0025 5628 mouclass - ok 16:31:37.0056 5628 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 16:31:37.0056 5628 mouhid - ok 16:31:37.0088 5628 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 16:31:37.0088 5628 MountMgr - ok 16:31:37.0134 5628 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 16:31:37.0134 5628 mpio - ok 16:31:37.0166 5628 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 16:31:37.0181 5628 mpsdrv - ok 16:31:37.0212 5628 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 16:31:37.0212 5628 Mraid35x - ok 16:31:37.0259 5628 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 16:31:37.0259 5628 MRxDAV - ok 16:31:37.0322 5628 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 16:31:37.0322 5628 mrxsmb - ok 16:31:37.0384 5628 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:31:37.0400 5628 mrxsmb10 - ok 16:31:37.0415 5628 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:31:37.0415 5628 mrxsmb20 - ok 16:31:37.0478 5628 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 16:31:37.0478 5628 msahci - ok 16:31:37.0524 5628 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 16:31:37.0540 5628 msdsm - ok 16:31:37.0571 5628 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 16:31:37.0587 5628 Msfs - ok 16:31:37.0618 5628 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 16:31:37.0618 5628 msisadrv - ok 16:31:37.0680 5628 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 16:31:37.0680 5628 MSKSSRV - ok 16:31:37.0727 5628 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 16:31:37.0727 5628 MSPCLOCK - ok 16:31:37.0758 5628 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 16:31:37.0758 5628 MSPQM - ok 16:31:37.0883 5628 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 16:31:37.0930 5628 MsRPC - ok 16:31:37.0961 5628 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 16:31:37.0961 5628 mssmbios - ok 16:31:37.0992 5628 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 16:31:37.0992 5628 MSTEE - ok 16:31:38.0180 5628 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 16:31:38.0226 5628 Mup - ok 16:31:38.0304 5628 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 16:31:38.0320 5628 NativeWifiP - ok 16:31:38.0351 5628 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 16:31:38.0367 5628 NDIS - ok 16:31:38.0429 5628 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 16:31:38.0429 5628 NdisTapi - ok 16:31:38.0445 5628 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 16:31:38.0445 5628 Ndisuio - ok 16:31:38.0492 5628 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 16:31:38.0492 5628 NdisWan - ok 16:31:38.0507 5628 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 16:31:38.0523 5628 NDProxy - ok 16:31:38.0554 5628 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 16:31:38.0554 5628 NetBIOS - ok 16:31:38.0585 5628 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 16:31:38.0585 5628 netbt - ok 16:31:38.0663 5628 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 16:31:38.0679 5628 nfrd960 - ok 16:31:38.0741 5628 npf (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys 16:31:38.0741 5628 npf - ok 16:31:38.0772 5628 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 16:31:38.0772 5628 Npfs - ok 16:31:38.0804 5628 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys 16:31:38.0850 5628 NSCIRDA - ok 16:31:38.0897 5628 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 16:31:38.0897 5628 nsiproxy - ok 16:31:38.0975 5628 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 16:31:39.0100 5628 Ntfs - ok 16:31:39.0147 5628 NTIDrvr (2757d2ba59aee155209e24942ab127c9) C:\Windows\system32\DRIVERS\NTIDrvr.sys 16:31:39.0147 5628 NTIDrvr - ok 16:31:39.0209 5628 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 16:31:39.0209 5628 ntrigdigi - ok 16:31:39.0287 5628 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 16:31:39.0303 5628 Null - ok 16:31:39.0334 5628 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 16:31:39.0350 5628 nvraid - ok 16:31:39.0396 5628 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 16:31:39.0396 5628 nvstor - ok 16:31:39.0443 5628 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 16:31:39.0443 5628 nv_agp - ok 16:31:40.0270 5628 NwlnkFlt - ok 16:31:40.0691 5628 NwlnkFwd - ok 16:31:41.0268 5628 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 16:31:41.0284 5628 ohci1394 - ok 16:31:41.0580 5628 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 16:31:41.0580 5628 Parport - ok 16:31:41.0814 5628 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 16:31:41.0814 5628 partmgr - ok 16:31:43.0234 5628 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 16:31:43.0234 5628 Parvdm - ok 16:31:43.0437 5628 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 16:31:43.0452 5628 pci - ok 16:31:43.0577 5628 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 16:31:43.0577 5628 pciide - ok 16:31:43.0686 5628 pcmcia (3bb2244f343b610c29c98035504c9b75) C:\Windows\system32\DRIVERS\pcmcia.sys 16:31:43.0733 5628 pcmcia - ok 16:31:43.0998 5628 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 16:31:44.0030 5628 PEAUTH - ok 16:31:44.0279 5628 PID_0928 (d2d2fa02b722336960eeae0ae7107891) C:\Windows\system32\DRIVERS\LV561AV.SYS 16:31:44.0295 5628 PID_0928 - ok 16:31:44.0638 5628 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 16:31:44.0638 5628 PptpMiniport - ok 16:31:44.0934 5628 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 16:31:44.0934 5628 Processor - ok 16:31:45.0137 5628 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 16:31:45.0137 5628 PSched - ok 16:31:45.0278 5628 PSINAflt (18b347125d597751b69ce8c6c03a4ba2) C:\Windows\system32\DRIVERS\PSINAflt.sys 16:31:45.0278 5628 PSINAflt - ok 16:31:45.0434 5628 PSINFile (072a5c1983b85504239c307d41d741be) C:\Windows\system32\DRIVERS\PSINFile.sys 16:31:45.0434 5628 PSINFile - ok 16:31:45.0574 5628 PSINKNC (f778579e0b47f0027cce47da1a64ef88) C:\Windows\system32\DRIVERS\psinknc.sys 16:31:45.0574 5628 PSINKNC - ok 16:31:45.0714 5628 PSINProc (0fb3436762e672800eb1c0578ac379c8) C:\Windows\system32\DRIVERS\PSINProc.sys 16:31:45.0730 5628 PSINProc - ok 16:31:45.0870 5628 PSINProt (7534273ca15900cdd1c3b392dd6b595b) C:\Windows\system32\DRIVERS\PSINProt.sys 16:31:45.0902 5628 PSINProt - ok 16:31:46.0058 5628 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 16:31:46.0089 5628 ql2300 - ok 16:31:46.0182 5628 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 16:31:46.0198 5628 ql40xx - ok 16:31:46.0416 5628 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 16:31:46.0416 5628 QWAVEdrv - ok 16:31:46.0494 5628 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 16:31:46.0510 5628 RasAcd - ok 16:31:46.0604 5628 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 16:31:46.0619 5628 Rasl2tp - ok 16:31:46.0713 5628 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 16:31:46.0713 5628 RasPppoe - ok 16:31:46.0760 5628 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 16:31:46.0775 5628 RasSstp - ok 16:31:46.0838 5628 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 16:31:46.0838 5628 rdbss - ok 16:31:46.0884 5628 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 16:31:46.0884 5628 RDPCDD - ok 16:31:47.0103 5628 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 16:31:47.0118 5628 rdpdr - ok 16:31:47.0150 5628 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 16:31:47.0150 5628 RDPENCDD - ok 16:31:47.0212 5628 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 16:31:47.0228 5628 RDPWD - ok 16:31:47.0274 5628 regi (001b4278407f4303efc902a2b16f2453) C:\Windows\system32\drivers\regi.sys 16:31:47.0274 5628 regi - ok 16:31:47.0384 5628 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 16:31:47.0384 5628 rspndr - ok 16:31:47.0462 5628 s0016bus (59509ad6cbc28f2c73056268985b3e48) C:\Windows\system32\DRIVERS\s0016bus.sys 16:31:47.0462 5628 s0016bus - ok 16:31:47.0508 5628 s0016mdfl (b98c3a6f91f4fba285af9606a240c6b4) C:\Windows\system32\DRIVERS\s0016mdfl.sys 16:31:47.0508 5628 s0016mdfl - ok 16:31:47.0571 5628 s0016mdm (8a83426f4fb7b5212825d9de76368b1a) C:\Windows\system32\DRIVERS\s0016mdm.sys 16:31:47.0571 5628 s0016mdm - ok 16:31:47.0633 5628 s0016mgmt (7a78bba97feb5e6d24c49e93a3bf7287) C:\Windows\system32\DRIVERS\s0016mgmt.sys 16:31:47.0633 5628 s0016mgmt - ok 16:31:47.0664 5628 s0016nd5 (34ef7b5f611957b73e7219dd5a222ad1) C:\Windows\system32\DRIVERS\s0016nd5.sys 16:31:47.0680 5628 s0016nd5 - ok 16:31:47.0742 5628 s0016obex (36792935847143e4a3cda0dc87248487) C:\Windows\system32\DRIVERS\s0016obex.sys 16:31:47.0742 5628 s0016obex - ok 16:31:47.0789 5628 s0016unic (927208754fb27fc3e7a659e77500c5d1) C:\Windows\system32\DRIVERS\s0016unic.sys 16:31:47.0789 5628 s0016unic - ok 16:31:47.0867 5628 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 16:31:47.0883 5628 sbp2port - ok 16:31:48.0023 5628 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 16:31:48.0039 5628 sdbus - ok 16:31:48.0086 5628 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 16:31:48.0086 5628 secdrv - ok 16:31:48.0179 5628 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys 16:31:48.0179 5628 seehcri - ok 16:31:48.0320 5628 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 16:31:48.0320 5628 Serenum - ok 16:31:48.0429 5628 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 16:31:48.0429 5628 Serial - ok 16:31:48.0538 5628 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 16:31:48.0538 5628 sermouse - ok 16:31:48.0616 5628 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 16:31:48.0616 5628 sffdisk - ok 16:31:48.0678 5628 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 16:31:48.0678 5628 sffp_mmc - ok 16:31:48.0741 5628 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 16:31:48.0741 5628 sffp_sd - ok 16:31:48.0772 5628 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 16:31:48.0772 5628 sfloppy - ok 16:31:48.0850 5628 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 16:31:48.0850 5628 sisagp - ok 16:31:48.0912 5628 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 16:31:48.0912 5628 SiSRaid2 - ok 16:31:48.0944 5628 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 16:31:48.0959 5628 SiSRaid4 - ok 16:31:49.0053 5628 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 16:31:49.0053 5628 Smb - ok 16:31:49.0100 5628 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 16:31:49.0100 5628 spldr - ok 16:31:49.0193 5628 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 16:31:49.0209 5628 srv - ok 16:31:49.0240 5628 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 16:31:49.0240 5628 srv2 - ok 16:31:49.0287 5628 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 16:31:49.0287 5628 srvnet - ok 16:31:49.0349 5628 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 16:31:49.0365 5628 swenum - ok 16:31:49.0427 5628 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 16:31:49.0427 5628 Symc8xx - ok 16:31:49.0458 5628 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 16:31:49.0458 5628 Sym_hi - ok 16:31:49.0505 5628 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 16:31:49.0505 5628 Sym_u3 - ok 16:31:49.0614 5628 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 16:31:49.0661 5628 Tcpip - ok 16:31:49.0708 5628 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 16:31:49.0724 5628 Tcpip6 - ok 16:31:49.0802 5628 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 16:31:49.0802 5628 tcpipreg - ok 16:31:49.0880 5628 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 16:31:49.0895 5628 TDPIPE - ok 16:31:49.0942 5628 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 16:31:49.0942 5628 TDTCP - ok 16:31:50.0020 5628 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 16:31:50.0020 5628 tdx - ok 16:31:50.0114 5628 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 16:31:50.0114 5628 TermDD - ok 16:31:50.0223 5628 TpChoice (3afff25eae28188fa4ecd292658be31b) C:\Windows\system32\DRIVERS\TpChoice.sys 16:31:50.0223 5628 TpChoice - ok 16:31:50.0441 5628 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 16:31:50.0441 5628 tssecsrv - ok 16:31:50.0535 5628 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 16:31:50.0535 5628 tunmp - ok 16:31:50.0613 5628 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys 16:31:50.0613 5628 tunnel - ok 16:31:50.0675 5628 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 16:31:50.0675 5628 uagp35 - ok 16:31:50.0753 5628 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 16:31:50.0753 5628 udfs - ok 16:31:50.0847 5628 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 16:31:50.0847 5628 uliagpkx - ok 16:31:50.0909 5628 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 16:31:50.0925 5628 uliahci - ok 16:31:50.0987 5628 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 16:31:51.0003 5628 UlSata - ok 16:31:51.0081 5628 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 16:31:51.0081 5628 ulsata2 - ok 16:31:51.0128 5628 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 16:31:51.0128 5628 umbus - ok 16:31:51.0284 5628 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 16:31:51.0284 5628 usbccgp - ok 16:31:51.0346 5628 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 16:31:51.0362 5628 usbcir - ok 16:31:51.0408 5628 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 16:31:51.0408 5628 usbehci - ok 16:31:51.0471 5628 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 16:31:51.0502 5628 usbhub - ok 16:31:51.0564 5628 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 16:31:51.0564 5628 usbohci - ok 16:31:51.0611 5628 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 16:31:51.0611 5628 usbprint - ok 16:31:51.0736 5628 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 16:31:51.0736 5628 usbscan - ok 16:31:51.0814 5628 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 16:31:51.0814 5628 USBSTOR - ok 16:31:51.0876 5628 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 16:31:51.0876 5628 usbuhci - ok 16:31:51.0923 5628 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 16:31:51.0939 5628 usbvideo - ok 16:31:52.0064 5628 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 16:31:52.0064 5628 vga - ok 16:31:52.0142 5628 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 16:31:52.0157 5628 VgaSave - ok 16:31:52.0188 5628 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 16:31:52.0204 5628 viaagp - ok 16:31:52.0235 5628 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 16:31:52.0266 5628 ViaC7 - ok 16:31:52.0376 5628 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 16:31:52.0376 5628 viaide - ok 16:31:52.0485 5628 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 16:31:52.0485 5628 volmgr - ok 16:31:52.0610 5628 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 16:31:52.0625 5628 volmgrx - ok 16:31:52.0688 5628 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 16:31:52.0703 5628 volsnap - ok 16:31:52.0766 5628 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 16:31:52.0766 5628 vsmraid - ok 16:31:52.0844 5628 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 16:31:52.0844 5628 WacomPen - ok 16:31:52.0875 5628 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 16:31:52.0890 5628 Wanarp - ok 16:31:52.0922 5628 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 16:31:52.0922 5628 Wanarpv6 - ok 16:31:52.0984 5628 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 16:31:52.0984 5628 Wd - ok 16:31:53.0109 5628 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 16:31:53.0124 5628 Wdf01000 - ok 16:31:53.0249 5628 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 16:31:53.0280 5628 winachsf - ok 16:31:53.0452 5628 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 16:31:53.0452 5628 WmiAcpi - ok 16:31:53.0561 5628 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 16:31:53.0577 5628 ws2ifsl - ok 16:31:53.0639 5628 WSDPrintDevice (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys 16:31:53.0639 5628 WSDPrintDevice - ok 16:31:53.0733 5628 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 16:31:53.0733 5628 WUDFRd - ok 16:31:53.0795 5628 MBR (0x1B8) (9a60a21600304533d523088c7b447e29) \Device\Harddisk0\DR0 16:31:53.0826 5628 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected 16:31:53.0826 5628 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0) 16:31:54.0404 5628 MBR (0x1B8) (3051207086651214e435112e51817dc5) \Device\Harddisk1\DR1 16:31:54.0404 5628 \Device\Harddisk1\DR1 - ok 16:31:54.0419 5628 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2 16:31:55.0683 5628 \Device\Harddisk2\DR2 - ok 16:31:55.0745 5628 Boot (0x1200) (c007ef22aeb5505e15057f0eafd7f2ce) \Device\Harddisk0\DR0\Partition0 16:31:55.0745 5628 \Device\Harddisk0\DR0\Partition0 - ok 16:31:55.0808 5628 Boot (0x1200) (8c94430cbbca631d15655f689c005bdc) \Device\Harddisk0\DR0\Partition1 16:31:55.0808 5628 \Device\Harddisk0\DR0\Partition1 - ok 16:31:55.0823 5628 Boot (0x1200) (82f2f1905f4092993ccc8abb2ad215d2) \Device\Harddisk1\DR1\Partition0 16:31:55.0823 5628 \Device\Harddisk1\DR1\Partition0 - ok 16:31:55.0854 5628 Boot (0x1200) (f753811b193dd9f08e0fb8340413bc7f) \Device\Harddisk1\DR1\Partition1 16:31:55.0854 5628 \Device\Harddisk1\DR1\Partition1 - ok 16:31:55.0886 5628 Boot (0x1200) (7c1ec62a27701d2b875c84bda7360339) \Device\Harddisk1\DR1\Partition2 16:31:55.0886 5628 \Device\Harddisk1\DR1\Partition2 - ok 16:31:55.0917 5628 Boot (0x1200) (9485c8c66f1fc826faa7525475858d20) \Device\Harddisk1\DR1\Partition3 16:31:55.0932 5628 \Device\Harddisk1\DR1\Partition3 - ok 16:31:55.0948 5628 Boot (0x1200) (9215829118ea853c3526351fe19707c4) \Device\Harddisk1\DR1\Partition4 16:31:55.0964 5628 \Device\Harddisk1\DR1\Partition4 - ok 16:31:55.0995 5628 Boot (0x1200) (191563b71319725a3b721672da8c1bc5) \Device\Harddisk1\DR1\Partition5 16:31:55.0995 5628 \Device\Harddisk1\DR1\Partition5 - ok 16:31:56.0026 5628 Boot (0x1200) (ce87b0809e7b5da108dc9b82469fede7) \Device\Harddisk1\DR1\Partition6 16:31:56.0026 5628 \Device\Harddisk1\DR1\Partition6 - ok 16:31:56.0088 5628 Boot (0x1200) (b9573251c65c7b56569b49b229df279a) \Device\Harddisk1\DR1\Partition7 16:31:56.0088 5628 \Device\Harddisk1\DR1\Partition7 - ok 16:31:56.0120 5628 Boot (0x1200) (79443fa00204897e5cafafb64c7a5043) \Device\Harddisk1\DR1\Partition8 16:31:56.0120 5628 \Device\Harddisk1\DR1\Partition8 - ok 16:31:56.0151 5628 Boot (0x1200) (9a2afcd3819836baf5aaa3d23f3964fd) \Device\Harddisk1\DR1\Partition9 16:31:56.0151 5628 \Device\Harddisk1\DR1\Partition9 - ok 16:31:56.0166 5628 Boot (0x1200) (2f6a7264f3edff4b402847e53adf56b8) \Device\Harddisk2\DR2\Partition0 16:31:56.0166 5628 \Device\Harddisk2\DR2\Partition0 - ok 16:31:56.0182 5628 ============================================================ 16:31:56.0182 5628 Scan finished 16:31:56.0182 5628 ============================================================ 16:31:56.0213 3036 Detected object count: 1 16:31:56.0213 3036 Actual detected object count: 1 16:32:47.0459 3036 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - skipped by user 16:32:47.0459 3036 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Skip 16:33:23.0916 3672 Deinitialize success

Attachments:

First of al I must thank you for helping me in this speed. I tried to follow the last instructions, but made a little mistake, I hope is not creating problems. As I was exited checking out my source control box, I noticed that your aswMBR program was the first to push ping.exe to the second place in cpu consumption. So first I waited after pushing fix. Then the program ordered to reboot ASAP. Which I did. but during reboot I realized that I forgot to save the log file first.. So instead I waited for the reboot to finish and made another scan, and saved that log file. If it is a problem, I`m very sorry, because you help me in days of holiday. So this log file is made after fix and reboot. Still Im gratefull for your help. Greetings, Eric van Es aswMBR version 0.9.9.1124 Copyright© 2011 AVAST Software Run date: 2011-12-31 16:07:35 —————————– 16:07:35.807 OS Version: Windows 6.0.6002 Service Pack 2 16:07:35.807 Number of processors: 1 586 0x170A 16:07:35.807 ComputerName: FLAPPIE UserName: Eric 16:07:38.412 Initialize success 16:07:54.340 AVAST engine defs: 11123100 16:08:06.118 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 16:08:06.118 Disk 0 Vendor: WDC_WD1600BEVT-22ZCT0 11.01A11 Size: 152627MB BusType: 3 16:08:06.149 Disk 0 MBR read successfully 16:08:06.165 Disk 0 MBR scan 16:08:06.258 Disk 0 MBR:Alureon-G [Rtk] 16:08:06.258 Disk 0 TDL4@MBR code has been found 16:08:06.274 Disk 0 MBR hidden 16:08:06.305 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048 16:08:06.321 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 71317 MB offset 20482048 16:08:06.477 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 71308 MB offset 166539264 16:08:06.508 Disk 0 MBR [TDL4] **ROOTKIT** 16:08:06.523 Disk 0 trace - called modules: 16:08:06.523 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x88b6a4d0]<< 16:08:06.555 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88498988] 16:08:06.570 3 CLASSPNP.SYS[89ba18b3] -> nt!IofCallDriver -> [0x88bcd030] 16:08:06.570 \Driver\atapi[0x889a7690] -> IRP_MJ_CREATE -> 0x88b6a4d0 16:08:07.475 AVAST engine scan C:\Windows 16:08:20.673 AVAST engine scan C:\Windows\system32 16:11:39.214 AVAST engine scan C:\Windows\system32\drivers 16:11:57.091 AVAST engine scan C:\Users\Eric 16:21:05.338 AVAST engine scan C:\ProgramData 16:23:27.017 Scan finished successfully 16:24:19.355 Disk 0 MBR has been saved successfully to "D:\Documents\MBR.dat" 16:24:19.371 The log file has been saved successfully to "D:\Documents\aswMBR.txt" aswMBR version 0.9.9.1124 Copyright© 2011 AVAST Software Run date: 2012-01-01 17:29:25 —————————– 17:29:25.016 OS Version: Windows 6.0.6002 Service Pack 2 17:29:25.016 Number of processors: 1 586 0x170A 17:29:25.031 ComputerName: FLAPPIE UserName: Eric 17:29:50.818 Initialize success 17:30:10.646 AVAST engine defs: 11123100 17:31:05.137 The log file has been saved successfully to "D:\Documents\aswMBR.txt" aswMBR version 0.9.9.1124 Copyright© 2011 AVAST Software Run date: 2012-01-01 17:58:36 —————————– 17:58:36.746 OS Version: Windows 6.0.6002 Service Pack 2 17:58:36.746 Number of processors: 1 586 0x170A 17:58:36.746 ComputerName: FLAPPIE UserName: Eric 17:58:58.180 Initialize success 17:59:12.610 AVAST engine defs: 11123100 17:59:15.013 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 17:59:15.013 Disk 0 Vendor: WDC_WD1600BEVT-22ZCT0 11.01A11 Size: 152627MB BusType: 3 17:59:15.075 Disk 0 MBR read successfully 17:59:15.075 Disk 0 MBR scan 17:59:15.091 Disk 0 unknown MBR code 17:59:15.153 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048 17:59:15.247 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 71317 MB offset 20482048 17:59:15.293 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 71308 MB offset 166539264 17:59:15.325 Disk 0 scanning sectors +312578048 17:59:15.403 Disk 0 scanning C:\Windows\system32\drivers 17:59:39.333 Service scanning 17:59:47.429 Modules scanning 18:00:06.539 Disk 0 trace - called modules: 18:00:06.586 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys 18:00:06.602 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87c2fac8] 18:00:06.602 3 CLASSPNP.SYS[89ba08b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x870e5468] 18:00:09.535 AVAST engine scan C:\Windows 18:00:20.050 AVAST engine scan C:\Windows\system32 18:09:02.478 Verifying 18:09:12.696 Disk 0 Windows 600 MBR fixed successfully 18:09:37.024 Verifying 18:09:47.071 Disk 0 Windows 600 MBR fixed successfully 18:10:22.155 AVAST engine scan C:\Windows\system32\drivers 18:10:58.878 AVAST engine scan C:\Users\Eric 18:22:35.106 AVAST engine scan C:\ProgramData 18:26:14.488 Scan finished successfully 19:08:10.581 Disk 0 MBR has been saved successfully to "D:\Documents\MBR.dat" 19:08:10.690 The log file has been saved successfully to "D:\Documents\aswMBR.txt" You said nothing about the MBR.dat file. so I zpped it as before, and attached it. ———————————————————————————————————————————————— ————————————————————————————————————————————————

Attachments:

Hi Eppikoe,

My pleasure :). And that is not a problem. Looks like aswMBR took care of the MBR infection, so that's all that I needed to see! Happy new years by the way!

Now let's take care of the PING.exe problem.

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 12-01-01.06 - Eric 01-01-2012 23:11:24.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.952.248 [GMT 1:00]
Gestart vanuit: c:\users\Eric\Desktop\ComboFix.exe
AV: Panda Cloud Antivirus *Disabled/Updated* {86971480-9989-6750-B122-681A86518D59}
SP: Panda Cloud Antivirus *Disabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\hpe603B.dll
c:\programdata\hpeACA5.dll
c:\programdata\SPL793C.tmp
c:\programdata\SPL8028.tmp
c:\users\Eric\Documents\~WRL0003.tmp
c:\users\Eric\Documents\~WRL0092.tmp
c:\users\Eric\Documents\~WRL2264.tmp
c:\users\Eric\Documents\~WRL3192.tmp
c:\users\Eric\Documents\~WRL3301.tmp
c:\users\Eric\Documents\~WRL4012.tmp
c:\windows\system\AC1ST15.DLL
d:\documents\~WRL0003.tmp
d:\documents\~WRL3301.tmp
P:\autorun.inf
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-12-01 to 2012-01-01 ))))))))))))))))))))))))))))))
.
.
2012-01-01 22:27 . 2012-01-01 22:27 ——– d—–w- c:\users\Eric\AppData\Local\temp
2012-01-01 21:43 . 2012-01-01 21:52 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3745D19D-65F1-4EA2-ABE3-24ADF63DA827}\offreg.dll
2012-01-01 21:43 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3745D19D-65F1-4EA2-ABE3-24ADF63DA827}\mpengine.dll
2011-12-29 20:16 . 2011-12-29 20:53 ——– d—–w- c:\programdata\SecTaskMan
2011-12-29 20:16 . 2011-12-29 20:16 ——– d—–w- c:\program files\Security Task Manager
2011-12-29 10:47 . 2011-12-29 10:47 ——– d—–w- c:\users\Eric\Option
2011-12-28 23:24 . 2011-12-28 23:33 ——– d—–w- c:\program files\WhatsRunning
2011-12-27 14:46 . 2011-12-21 07:24 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-27 14:46 . 2011-12-21 04:30 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2011-12-27 14:46 . 2011-12-21 04:30 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2011-12-27 14:46 . 2011-12-21 04:30 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2011-12-25 12:48 . 2011-10-27 08:01 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-25 12:48 . 2011-10-27 08:01 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-25 12:48 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-25 12:48 . 2011-11-23 13:37 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-25 12:47 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-25 12:47 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-17 23:49 . 2011-12-21 04:30 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-17 23:49 . 2011-12-21 04:30 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-12-17 22:40 . 2011-12-17 22:40 ——– d—–w- c:\users\MediaMaker\AppData\Local\Mozilla
2011-12-17 20:48 . 2011-12-17 20:48 ——– d—–w- c:\users\MediaMaker\AppData\Local\adaware
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-17 13:51 . 2011-05-01 01:08 952 –sha-w- c:\programdata\KGyGaAvL.sys
2011-11-29 22:30 . 2011-11-29 22:30 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-11-19 19:49 . 2011-04-29 23:48 306432 —-a-w- c:\windows\system32\TuneUpDefragService.exe
2011-11-18 11:45 . 2011-10-27 16:53 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-15 13:29 . 2011-05-18 18:18 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-10-31 13:07 . 2011-10-31 13:07 40960 —-a-r- c:\users\Eric\AppData\Roaming\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2010-01-26 10:11 . 2011-11-05 00:19 444283 —-a-w- c:\program files\Common Files\WinPcapNmap.exe
2011-12-21 07:24 . 2011-12-03 14:58 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-10-21 09:10 87440 —-a-w- c:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
2010-12-19 14:46 86696 —-a-w- c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54 175912 —-a-w- c:\program files\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
"{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}"= "c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll" [2010-12-19 86696]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\adawaretb\adawareDx.dll" [2011-10-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4}]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Malware Icon]
@="{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}"
[HKEY_CLASSES_ROOT\CLSID\{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}]
2011-05-09 10:45 288584 —-a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Suspect Icon]
@="{9AE343CB-BA45-4618-AF6A-0230EE6FC793}"
[HKEY_CLASSES_ROOT\CLSID\{9AE343CB-BA45-4618-AF6A-0230EE6FC793}]
2011-05-09 10:45 288584 —-a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-01-10 196608]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-07-25 875016]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2011-04-28 439616]
"Panda Security URL Filtering"="c:\programdata\Panda Security URL Filtering\Panda_URL_Filtering.exe" [2011-06-29 217256]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"EzPrint"="c:\program files\Lexmark S300-S400 Series\ezprint.exe" [2011-01-24 148280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-06-01 1501064]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
.
c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-5-1 576000]
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 135664]
R2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxeaserv.exe [2010-04-14 193192]
R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [2007-12-26 17968]
R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [2011-04-28 126024]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe [2010-04-14 598696]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2011-11-24 87552]
S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-04-28 140608]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704]
S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [2011-08-01 143624]
S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [2011-04-28 99400]
S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [2011-04-28 111176]
S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [2011-04-28 112712]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-04-22 92592]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhoud van de 'Gedeelde Taken' map
.
2011-12-23 c:\windows\Tasks\Easy Onderhoud.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-02-04 15:09]
.
2012-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 15:49]
.
2012-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 15:49]
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://descargar.benjaminstrahs.com/nl/index.php?rvs=google
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.254
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\m14xcglq.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://nl.search.yahoo.com/search?ei=utf-8&fr=panda&type=panda2_0yatb&p=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS VERWIJDERD - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-Metropolis - c:\windows\system32\sshnas21.dll
MSConfigStartUp-SNJQ66R8MU - c:\users\Eric\AppData\Local\Temp\Zgl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-01 23:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen …
.
scannen van verborgen autostart items …
.
scannen van verborgen bestanden …
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-01-01 23:35:44
ComboFix-quarantined-files.txt 2012-01-01 22:35
.
Pre-Run: 28.190.683.136 bytes beschikbaar
Post-Run: 27.907.620.864 bytes beschikbaar
.
- - End Of File - - D81C34C9D5DC1DA9A60A0A885B48BDD1
————————————————————————————————————————————————————–
It was not clear to me if you need this log to. I think better to send you both. So next the ComboFix.txt file
————————————————————————————————————————————————————–


ComboFix 12-01-01.06 - Eric 01-01-2012 23:11:24.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.952.248 [GMT 1:00]
Gestart vanuit: c:\users\Eric\Desktop\ComboFix.exe
AV: Panda Cloud Antivirus *Disabled/Updated* {86971480-9989-6750-B122-681A86518D59}
SP: Panda Cloud Antivirus *Disabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\hpe603B.dll
c:\programdata\hpeACA5.dll
c:\programdata\SPL793C.tmp
c:\programdata\SPL8028.tmp
c:\users\Eric\Documents\~WRL0003.tmp
c:\users\Eric\Documents\~WRL0092.tmp
c:\users\Eric\Documents\~WRL2264.tmp
c:\users\Eric\Documents\~WRL3192.tmp
c:\users\Eric\Documents\~WRL3301.tmp
c:\users\Eric\Documents\~WRL4012.tmp
c:\windows\system\AC1ST15.DLL
d:\documents\~WRL0003.tmp
d:\documents\~WRL3301.tmp
P:\autorun.inf
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-12-01 to 2012-01-01 ))))))))))))))))))))))))))))))
.
.
2012-01-01 22:27 . 2012-01-01 22:27 ——– d—–w- c:\users\Eric\AppData\Local\temp
2012-01-01 21:43 . 2012-01-01 21:52 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3745D19D-65F1-4EA2-ABE3-24ADF63DA827}\offreg.dll
2012-01-01 21:43 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3745D19D-65F1-4EA2-ABE3-24ADF63DA827}\mpengine.dll
2011-12-29 20:16 . 2011-12-29 20:53 ——– d—–w- c:\programdata\SecTaskMan
2011-12-29 20:16 . 2011-12-29 20:16 ——– d—–w- c:\program files\Security Task Manager
2011-12-29 10:47 . 2011-12-29 10:47 ——– d—–w- c:\users\Eric\Option
2011-12-28 23:24 . 2011-12-28 23:33 ——– d—–w- c:\program files\WhatsRunning
2011-12-27 14:46 . 2011-12-21 07:24 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-27 14:46 . 2011-12-21 04:30 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2011-12-27 14:46 . 2011-12-21 04:30 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2011-12-27 14:46 . 2011-12-21 04:30 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2011-12-25 12:48 . 2011-10-27 08:01 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-25 12:48 . 2011-10-27 08:01 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-25 12:48 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-25 12:48 . 2011-11-23 13:37 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-25 12:47 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-25 12:47 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-17 23:49 . 2011-12-21 04:30 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-17 23:49 . 2011-12-21 04:30 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-12-17 22:40 . 2011-12-17 22:40 ——– d—–w- c:\users\MediaMaker\AppData\Local\Mozilla
2011-12-17 20:48 . 2011-12-17 20:48 ——– d—–w- c:\users\MediaMaker\AppData\Local\adaware
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-17 13:51 . 2011-05-01 01:08 952 –sha-w- c:\programdata\KGyGaAvL.sys
2011-11-29 22:30 . 2011-11-29 22:30 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-11-19 19:49 . 2011-04-29 23:48 306432 —-a-w- c:\windows\system32\TuneUpDefragService.exe
2011-11-18 11:45 . 2011-10-27 16:53 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-15 13:29 . 2011-05-18 18:18 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-10-31 13:07 . 2011-10-31 13:07 40960 —-a-r- c:\users\Eric\AppData\Roaming\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2010-01-26 10:11 . 2011-11-05 00:19 444283 —-a-w- c:\program files\Common Files\WinPcapNmap.exe
2011-12-21 07:24 . 2011-12-03 14:58 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-10-21 09:10 87440 —-a-w- c:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
2010-12-19 14:46 86696 —-a-w- c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54 175912 —-a-w- c:\program files\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
"{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}"= "c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll" [2010-12-19 86696]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\adawaretb\adawareDx.dll" [2011-10-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4}]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Malware Icon]
@="{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}"
[HKEY_CLASSES_ROOT\CLSID\{F5D1CF73-C196-48F8-AAAC-B9181E22B4E6}]
2011-05-09 10:45 288584 —-a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Suspect Icon]
@="{9AE343CB-BA45-4618-AF6A-0230EE6FC793}"
[HKEY_CLASSES_ROOT\CLSID\{9AE343CB-BA45-4618-AF6A-0230EE6FC793}]
2011-05-09 10:45 288584 —-a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-01-10 196608]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-07-25 875016]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2011-04-28 439616]
"Panda Security URL Filtering"="c:\programdata\Panda Security URL Filtering\Panda_URL_Filtering.exe" [2011-06-29 217256]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"EzPrint"="c:\program files\Lexmark S300-S400 Series\ezprint.exe" [2011-01-24 148280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-06-01 1501064]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
.
c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-5-1 576000]
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 135664]
R2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxeaserv.exe [2010-04-14 193192]
R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [2007-12-26 17968]
R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [2011-04-28 126024]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe [2010-04-14 598696]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2011-11-24 87552]
S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-04-28 140608]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704]
S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [2011-08-01 143624]
S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [2011-04-28 99400]
S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [2011-04-28 111176]
S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [2011-04-28 112712]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-11-03 2358656]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-04-22 92592]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhoud van de 'Gedeelde Taken' map
.
2011-12-23 c:\windows\Tasks\Easy Onderhoud.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-02-04 15:09]
.
2012-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 15:49]
.
2012-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-29 15:49]
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://descargar.benjaminstrahs.com/nl/index.php?rvs=google
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.254
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\m14xcglq.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://nl.search.yahoo.com/search?ei=utf-8&fr=panda&type=panda2_0yatb&p=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS VERWIJDERD - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-Metropolis - c:\windows\system32\sshnas21.dll
MSConfigStartUp-SNJQ66R8MU - c:\users\Eric\AppData\Local\Temp\Zgl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-01 23:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen …
.
scannen van verborgen autostart items …
.
scannen van verborgen bestanden …
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-01-01 23:35:44
ComboFix-quarantined-files.txt 2012-01-01 22:35
.
Pre-Run: 28.190.683.136 bytes beschikbaar
Post-Run: 27.907.620.864 bytes beschikbaar
.
- - End Of File - - D81C34C9D5DC1DA9A60A0A885B48BDD1
Hi Eppikoe,

Both those logs are the same and they are what I needed to see.


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Make sure you choose not to install the trial version of Malwarebytes Antimalware Pro.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also please describe how your computer behaves at the moment.
Well, I have a feeling you know exactly what`s in the next file. But it is indeed a confirmation of your skills. Secretly I am convinced you have a hidden fire-wire connection build in your thumb or so. I have worked with computers from the time Sinclair sold the zx81 and learned all I know on machines from commodore 64. I learned a lot, as my occupation lies in electronics hardware. But with all I know I want to say to you "Chapeau' I love computers more than I love dogs. This laptop behaved as a slowly growing old dog. You made it a puppy again. If I compare myself with dogs, I would be waggling like a dog with seven tails. You made it possible to work with my flappie again. My finances don`t allow me to donate much now. But next month everything will be normal again, and whenever I will touch my 'puppy's keys remind me of this promise to donate, whenever How do I donate as a Dutch citizen with no credit card? But before I really start touching keys I wait till you say it`s ok Eric. ——————————————————————————————————————————- Malwarebytes Anti-Malware (-evaluatieversie-) 1.60.0.1800 www.malwarebytes.org Databaseversie: v2012.01.02.02 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Eric :: FLAPPIE [administrator] Realtime bescherming: Ingeschakeld 2-1-2012 13:50:56 mbam-log-2012-01-02 (13-50-56).txt Scantype: Snelle scan Ingeschakelde scanopties: Geheugen | Opstarten | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scanopties: P2P Objecten gescand: 187387 Verstreken tijd: 9 minuut/minuten, 12 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Bestanden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) (einde)
Hi Eric,

Well, I have a feeling you know exactly what`s in the next file. But it is indeed a confirmation of your skills. Secretly I am convinced you have a hidden fire-wire connection build in your thumb or so.

:rofl:

I have worked with computers from the time Sinclair sold the zx81 and learned all I know on machines from commodore 64. I learned a lot, as my occupation lies in electronics hardware.

Very impressive!

But with all I know I want to say to you "Chapeau'
I love computers more than I love dogs. This laptop behaved as a slowly growing old dog. You made it a puppy again.
If I compare myself with dogs, I would be waggling like a dog with seven tails.

My pleasure :). Glad that I could help.

You made it possible to work with my flappie again. My finances don`t allow me to donate much now. But next month everything will be normal again, and whenever I will touch my 'puppy's keys remind me of this promise to donate, whenever

I know that everyone's economic situation is tough right now, so don't worry about it.

How do I donate as a Dutch citizen with no credit card?

PayPal would be the only method.

But before I really start touching keys I wait till you say it`s ok

There are a few more things we need to do, Eric. We'll start by updating your software.

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 2.
  • Click on jre-7u2-windows-i586.exe if you are running 32-bit Windows or jre-7u2-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings

  • Click OK to leave the Java Control Panel.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer if required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader.
  • Make sure you uncheck Yes, install McAfee Security Scan Plus - optional if prompted.
Alternative Option: after uninstalling Adobe Reader, you could try downloading and installing SlimPDF Reader from >here< SlimPDF Reader comes with no bloatware and loads extremely quickly.

===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You were right. We have more to do. C:\downloads\Sony Vegas Pro 9 + Crack and KeyGen.rar multiple threats C:\Program Files\FoxTabAVIConverter\AviConverter.exe a variant of Win32/InstallCore.A application C:\Program Files\Windows jZip Toolbar\Datamngr\datamngrUI.exe a variant of Win32/Toolbar.SearchSuite application C:\Users\Eric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\3a481dd5-34e966e7 multiple threats C:\Users\Eric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\444ab797-3649dcb8 multiple threats C:\Users\Eric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\22c9da98-6b920552 multiple threats C:\Users\Eric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\157e02e-6fde62d3 multiple threats C:\Users\Eric\Desktop\Nieuwe map\SoftonicDownloader_voor_vdownloader.exe a variant of Win32/SoftonicDownloader.A application D:\Tools\RegistryReviverSetup.exe a variant of Win32/SlowPCfighter application D:\Tools\Acces Manager\AccessManager-nl.zip a variant of Win32/RegistryBooster application D:\Tools\Programs\SoftonicDownloader41217.exe a variant of Win32/SoftonicDownloader.A application D:\Tools\Programs\speedupmypc.exe Win32/SpeedUpMyPC application D:\Tools\Programs\DVD Programs\installer_xilisoft_mpeg_to_dvd_converter_3_0_36_0530_Nederlands_Dutch.exe Win32/Toggle application D:\Tools\Programs\DVD Programs\NERO\Nero 9.exe Win32/Toolbar.AskSBar application D:\Tools\Programs\Internet\installer_vlc_media_player_1_0_1_Nederlands_Dutch.exe Win32/Toggle application D:\Tools\Programs\Internet\MsgPlusLive-483 (2).exe a variant of Win32/Adware.CiDHelp application D:\Tools\Programs\Media Programs\installer_cool_edit_pro_Nederlands_Dutch.exe Win32/Toggle application D:\Tools\Systeem Tools\registrybooster.exe a variant of Win32/RegistryBooster application D:\Tools\Systeem Tools\unlocker1.9.0.exe Win32/Adware.ADON application L:\Programs\cnet_disk-defrag-setup_exe.exe a variant of Win32/InstallCore.D application L:\Programs\installer_messenger-nl-nl.exe Win32/Hoax.ArchSMS.KC application L:\Programs\jZipV1c.exe a variant of Win32/Toolbar.SearchSuite application L:\Programs\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application L:\Programs\DownLoad Programs\A Good Youtube DL\installer_free_youtube_download_2_3_3_66_Nederlands_Dutch.exe Win32/Toggle application N:\Backup_Programs (H)\Program Files\Automated Content Enhancer\4.1.0.5050\ACEIEAddOn.dll a variant of Win32/Adware.DoubleD.AQ application N:\Backup_Programs (H)\Program Files\Content Management Wizard\1.1.0.1820\CMWIE.dll a variant of Win32/Adware.DoubleD.AI application N:\Backup_Programs (H)\Program Files\Customized Platform Advancer\3.1.0.1540\CPAIEAddOn.dll a variant of Win32/Adware.DoubleD.AP application N:\Backup_Programs (H)\Program Files\HottieStar Toolbar\2.1.1.5200\FFToolbar\components\MVBCore.dll a variant of Win32/Adware.DoubleD.AL application N:\Backup_XP Installatie (I)\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{61ED7C60-7183-4440-B593-950782A51309}\Registry Reviver.msi a variant of Win32/SlowPCfighter application N:\Backup_XP Installatie (I)\Documents and Settings\All Users\Application Data\{73E0095D-24DB-442B-A7B7-45B559A23529}\OFFLINE\mFileBagIDE.dll\bag\CMWSetup.exe a variant of Win32/Adware.DoubleD.AI application N:\Backup_XP Installatie (I)\Documents and Settings\All Users\Application Data\{73E0095D-24DB-442B-A7B7-45B559A23529}\OFFLINE\mFileBagIDE.dll\bag\FFToolbar.xpi a variant of Win32/Adware.DoubleD.AL application N:\Backup_XP Installatie (I)\Documents and Settings\All Users\Application Data\{73E0095D-24DB-442B-A7B7-45B559A23529}\SetupArchive\FFB013D3\B94081D6\mvb0.dll Win32/Adware.DoubleD.AF application N:\Backup_XP Installatie (I)\Documents and Settings\Eigenaar\dwhelper\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application
Hi Eric,

It seems like you installed those programs intentionally, so I am not concerned. Am I right about that? I am, however, concerned about those Java cache entries, so let's get rid of them now.

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
I think I have missed something. During the scan I saw some red items passing by. It is my laptop, but my son used it some time ago too. In the log I see some things like multiple treats. It is of little importance if i have installed the programs you are talking about. If they are bad, I want to get them of my computer. Some things I don`t know where I can find them back. For instance did I find out what HottieStar Toolbar\2.1.1is on the internet. But I can`t find it back in my browser But anything you think I should loose, I will. It seems like you installed those programs intentionally, so I am not concerned. Am I right about that? Which programs are you talking about.If you think thy can cause problems, they are gone. I did not read all of all logs, because it is very difficult for me to understand exactly what each routine is meaning to do. But about your 'orders' ( sometimes my vocabulary leaves me with not the exact right word.) As I ran TFC, at the end it crashed. So I rebooted. I ran it again without problems
Hi Eric, The multiple threats were inside the Java cache which was cleared using TFC cleaner. The other things that ESET found are just setup files that your son may have downloaded in the past. They are located on different hard drives or partitions on your laptop which lead me to believe they are not currently installed on your computer and were simply backed up. So, nothing to worry about :)
Well I have deleted all the maps containing contaminated files. So, with some minor questions left, I have a speedy laptop again. I thank you very much for your time and efforts to help me. I would love to return this favor, but I can`t think of anything I could do. So, thank you very very much. Greeting you with my hat in my hand and a deep bow, Eric

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI