Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

[SID: 23621] HTTP Tidserv Request detected


  • This topic is locked This topic is locked

#1
Vladice

Vladice

    New Member

  • Member
  • Pip
  • 6 posts
Hello,

Since I removed the 'anti virus software' viruson my pc, using Malwarebytes, I get this message from Symantec that pops up every time I open my Internet Browser, which reads:

Symantec Endpoint Protection
[SID: 23621] HTTP Tidserv Request detected.

I've seen some topics handling this problem, but every solution was different and therefore I opened this new topic.

Any help would be greatly appreciated!


Toshiba Satellite A200
Windows Vista
  • 0

Advertisements


#2
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Hi, Vladice! Welcome to GeeksToGo! My name is BlackOxide and I will be assisting you with your Malware/Security problems. Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any queries or you are unsure about anything, just say and I'll help you out ;)

It may well be worth you printing/saving the instructions throughout the fix, so you have them to hand just incase you are unable to access this site.

Please note:
  • I am currently in training, so my replies will need to be quickly checked before I post them to you, so there may be a small delay in between.
  • Remember to post your logs, not attach them. So, any logs from any programs we run, should be just 'copied & pasted' into your reply.
  • Please only run the tools that I request. I know malware can be frustrating but running other tools in the meantime and between posts, only makes it harder for us to analyse and fix your PC in the long run.

OK, lets start :D

Please follow the steps below which will provide me with some logs ;)



1)
OTL Custom Scan
Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic


2)
GMER Rootkit Scanner
  • Posted Image GMER Rootkit Scanner - Download - Homepage
  • Download GMER
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
    Posted Image
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)

    NOTE - Not all of the tick boxes will be available if you are running a 64bit Operating System. You may also get an error message display on the screen when using a 64bit Operating System, this is normal, just click on OK and let it carry on.

    Posted Image
    Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the report into your Post.



In your next reply
Please post the contents of...
OTL logs
GMER log

  • 0

#3
Vladice

Vladice

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hello BlackOxide



First of all: thanks for your help!



I ran the OTL Custom scan and copied both logs into this post.



After this a tried to run the GMER Rootkit Scanner twice. Both times the
program crashed whithin 10 seconds and after 30 seconds I got a blue screen.



Here are the requested logs of OTL:



OTL logfile created on: 3-10-2010 22:13:32 - Run 1

OTL by OldTimer - Version 3.2.14.1 Folder = E:\Bureaublad

Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) -
Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18943)

Locale: 00000413 | Country: Nederland | Language: NLD | Date Format:
d-M-yyyy



3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 56,00%
Memory free

6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File
free

Paging file location(s): ?:\pagefile.sys [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program
Files

Drive C: | 116,21 Gb Total Space | 43,57 Gb Free Space | 37,49% Space Free |
Partition Type: NTFS

Drive D: | 1,46 Gb Total Space | 1,27 Gb Free Space | 86,59% Space Free |
Partition Type: NTFS

Drive E: | 115,21 Gb Total Space | 29,97 Gb Free Space | 26,01% Space Free |
Partition Type: NTFS

F: Drive not present or media not loaded

Drive G: | 931,51 Gb Total Space | 871,58 Gb Free Space | 93,57% Space Free
| Partition Type: NTFS

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Drive K: | 3,79 Gb Total Space | 3,79 Gb Free Space | 100,00% Space Free |
Partition Type: FAT32



Computer Name: S030518T

Current User Name: Frank Beurskens

Logged in as Administrator.



Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 90 Days

Output = Minimal

Quick Scan



========== Processes (SafeList) ==========



PRC - E:\Bureaublad\OTL.exe (OldTimer Tools)

PRC - C:\Users\Frank Beurskens\AppData\Roaming\Dropbox\bin\Dropbox.exe ()

PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee,
Inc.)

PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)

PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee,
Inc.)

PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee,
Inc.)

PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
(Symantec Corporation)

PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
(Symantec Corporation)

PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
(Symantec Corporation)

PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)

PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee,
Inc.)

PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)

PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec
Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec
Corporation)

PRC - C:\Windows\explorer.exe (Microsoft Corporation)

PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft
Corporation)

PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems
Inc.)

PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)

PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)

PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)

PRC - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
(TOSHIBA)

PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)

PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)

PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA
Corporation)

PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA
Corporation)

PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA
Corporation)

PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)

PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)

PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()

PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)

PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)





========== Modules (SafeList) ==========



MOD - E:\Bureaublad\OTL.exe (OldTimer Tools)

MOD -
C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.4148_non
e_4bf5400abf9d60b7\mfc90u.dll (Microsoft Corporation)

MOD -
C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_non
e_5090ab56bcba71c2\msvcr90.dll (Microsoft Corporation)

MOD -
C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_non
e_5090ab56bcba71c2\msvcp90.dll (Microsoft Corporation)

MOD -
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_non
e_d08d7da0442a985d\msvcr80.dll (Microsoft Corporation)

MOD -
C:\Windows\winsxs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_non
e_d1c738ec43578ea1\ATL80.dll (Microsoft Corporation)

MOD - C:\Windows\System32\AcSignIcon.dll (Autodesk, Inc.)

MOD - C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll
(Autodesk, Inc.)

MOD - C:\Users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
(Dropbox, Inc.)

MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)

MOD - C:\Users\Frank Beurskens\AppData\Roaming\Dropbox\bin\MSVCP71.dll
(Microsoft Corporation)

MOD - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
(Microsoft Corporation)

MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)

MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)

MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)

MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)

MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)

MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)

MOD -
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0
.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)

MOD - C:\Program Files\Microsoft Office\Office12\GrooveUtil.dll (Microsoft
Corporation)

MOD - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
(Microsoft Corporation)

MOD - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
(Microsoft Corporation)

MOD - C:\Program Files\Microsoft Office\Office12\GrooveNew.dll (Microsoft
Corporation)

MOD - C:\Users\Frank Beurskens\AppData\Roaming\Dropbox\bin\MSVCR71.dll
(Microsoft Corporation)

MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)

MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)

MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)

MOD - C:\Windows\System32\dbghelp.dll (Microsoft Corporation)

MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)

MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)





========== Win32 Services (SafeList) ==========



SRV - (TOSHIBA Bluetooth Service) -- c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtSrv.exe File not found

SRV - (Akamai) -- c:\Program Files\Common
Files\Akamai\netsession_win_062a651.dll ()

SRV - (InstallShield Licensing Service) -- C:\Program Files\Common
Files\InstallShield Shared\Service\InstallShield Licensing Service.exe
(Macrovision )

SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common
Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso
Software Inc.)

SRV - (Autodesk Licensing Service) -- C:\Program Files\Common Files\Autodesk
Shared\Service\AdskScSrv.exe (Autodesk)

SRV - (McShield) -- C:\Program Files\McAfee\VirusScan
Enterprise\Mcshield.exe (McAfee, Inc.)

SRV - (mfevtp) -- C:\Windows\System32\mfevtps.exe (McAfee, Inc.)

SRV - (McTaskManager) -- C:\Program Files\McAfee\VirusScan
Enterprise\VsTskMgr.exe (McAfee, Inc.)

SRV - (McAfeeEngineService) -- C:\Program Files\McAfee\VirusScan
Enterprise\EngineServer.exe (McAfee, Inc.)

SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft
Corporation)

SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec\Symantec Endpoint
Protection\Rtvscan.exe (Symantec Corporation)

SRV - (SmcService) -- C:\Program Files\Symantec\Symantec Endpoint
Protection\Smc.exe (Symantec Corporation)

SRV - (SNAC) -- C:\Program Files\Symantec\Symantec Endpoint
Protection\SNAC.EXE (Symantec Corporation)

SRV - (McAfeeFramework) -- C:\Program Files\McAfee\Common
Framework\FrameworkService.exe (McAfee, Inc.)

SRV - (LiveUpdate) -- C:\Program
Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)

SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SRV - (Adobe Version Cue CS4) -- C:\Program Files\Common Files\Adobe\Adobe
Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)

SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft
Corporation)

SRV - (TosCoSrv) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation)

SRV - (CFSvcs) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA
CORPORATION)

SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)

SRV - (TODDSrv) -- C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)





========== Driver Services (SafeList) ==========



DRV - (TpChoice) -- C:\Windows\System32\DRIVERS\TpChoice.sys File not found

DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found

DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found

DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found

DRV - (blbdrive) -- C:\Windows\System32\drivers\blbdrive.sys File not found

DRV - (NAVEX15) --
C:\ProgramData\Symantec\Definitions\VirusDefs\20101002.003\NAVEX15.SYS
(Symantec Corporation)

DRV - (NAVENG) --
C:\ProgramData\Symantec\Definitions\VirusDefs\20101002.003\NAVENG.SYS
(Symantec Corporation)

DRV - (WpsHelper) -- C:\Windows\System32\drivers\wpshelper.sys (Symantec
Corporation)

DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec
Corporation)

DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec
Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec
Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()

DRV - (mfehidk) -- C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)

DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)

DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)

DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)

DRV - (mfetdik) -- C:\Windows\System32\drivers\mfetdik.sys (McAfee, Inc.)

DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)

DRV - (SysPlant) -- C:\Windows\SYSTEM32\Drivers\SysPlant.sys (Symantec
Corporation)

DRV - (WPS) -- C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec
Corporation)

DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec
Corporation)

DRV - (SYMREDRV) -- C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec
Corporation)

DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec
Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)

DRV - (SRTSPX) -- C:\Windows\System32\drivers\srtspx.sys (Symantec
Corporation)

DRV - (SRTSPL) -- C:\Windows\System32\drivers\srtspl.sys (Symantec
Corporation)

DRV - (SRTSP) -- C:\Windows\System32\drivers\srtsp.sys (Symantec
Corporation)

DRV - (COH_Mon) -- C:\Windows\System32\drivers\COH_Mon.sys (Symantec
Corporation)

DRV - (Teefer2) -- C:\Windows\System32\drivers\Teefer2.sys (Symantec
Corporation)

DRV - (TermDD) -- C:\Windows\System32\drivers\termdd.sys ()

DRV - (adfs) -- C:\Windows\System32\drivers\adfs.sys (Adobe Systems, Inc.)

DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI
Technologies Inc.)

DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) --
C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)

DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)

DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek
Corporation )

DRV - (NETw4v32) Stuurprogramma voor Intel® --
C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)

DRV - (UVCFTR) -- C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony
Electronics Co., Ltd.)

DRV - (CplIR) -- C:\Windows\system32\DRIVERS\CplIR.SYS (COMPAL ELECTRONIC
INC.)

DRV - (tifm21) -- C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)

DRV - (KR10N) -- C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)

DRV - (KR10I) -- C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)

DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere
Systems)

DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic
Corporation)

DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)

DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)

DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)

DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics
Inc.)

DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel
Corporation)

DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)

DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise
Technology, Inc.)

DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies
Inc.,Ltd)

DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic
Corporation)

DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise
Technology, Inc.)

DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)

DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA
Corporation)

DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)

DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP
vortex GmbH)

DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon
Integrated Systems)

DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA
Corporation)

DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)

DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)

DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)

DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon
Integrated Systems Corp.)

DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard
Company)

DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)

DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated
Technology Express, Inc.)

DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated
Technology Express, Inc.)

DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)

DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)

DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)

DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)

DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic
Corporation)

DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)

DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic
Corporation)

DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies,
Inc.)

DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology,
Inc.)

DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories
Inc.)

DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) --
C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)

DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother
Industries Ltd.)

DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother
Industries, Ltd.)

DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother
Industries, Ltd.)

DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother
Industries Ltd.)

DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother
Industries Ltd.)

DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig
Innovative Technologies)

DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel
Corporation)

DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros
Communications, Inc.)

DRV - (tosrfec) -- C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA
Corporation)

DRV - (tdcmdpst) -- C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA
Corporation.)

DRV - (TVALZ) -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA
Corporation)

DRV - (LPCFilter) -- C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL
ELECTRONIC INC.)





========== Standard Registry (SafeList) ==========





========== Internet Explorer ==========



IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.nl



IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.archdaily.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyEnable" = 0







O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) -
C:\Windows\System32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (Groove GFS Browser Helper) -
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft
Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -
C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)

O2 - BHO: (Adobe PDF Conversion Toolbar Helper) -
{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} -
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
(Adobe Systems Incorporated)

O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
(Adobe Systems Incorporated)

O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [00TCrdMain] C:\Program
Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)

O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat
9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)

O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program
Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files\Common Files\Adobe\Adobe
Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems
Incorporated)

O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common
Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems
Incorporated)

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec
Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA
Corporation)

O4 - HKLM..\Run: [HWSetup] File not found

O4 - HKLM..\Run: [IME JPN 2007 Migration] C:\Program Files\Common
Files\microsoft shared\IME12\IMEJP\IMJPKLMG.EXE (Microsoft Corporation)

O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
()

O4 - HKLM..\Run: [Korean IME Migration] C:\Program Files\Common
Files\microsoft shared\IME12\IMEKR\IMKRMIG.EXE (Microsoft Corporation)

O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common
Framework\udaterui.exe (McAfee, Inc.)

O4 - HKLM..\Run: [Microsoft Pinyin IME Migration] C:\Program Files\Common
Files\microsoft shared\IME12\IMESC\IMSCMIG.EXE (Microsoft Corporation)

O4 - HKLM..\Run: [NDSTray.exe] File not found

O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)

O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan
Enterprise\SHSTAT.EXE (McAfee, Inc.)

O4 - HKLM..\Run: [SmoothView] C:\Program
Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)

O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI
Technologies\ATI.ACE\Core-Static\CLIStart.exe ()

O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe
(TOSHIBA)

O4 - HKLM..\Run: [SynTPStart] C:\Program
Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product
Information\topi.exe (TOSHIBA)

O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power
Saver\TPwrMain.exe (TOSHIBA Corporation)

O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows
Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKCU..\Run: [TOSCDSPD] File not found

O4 - Startup: C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\Dropbox.lnk = C:\Users\Frank
Beurskens\AppData\Roaming\Dropbox\bin\Dropbox.exe ()

O4 - Startup: C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk =
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft
Corporation)

O4 - Startup: C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OpenOffice.org 3.2 .lnk = C:\Program
Files\OpenOffice.org 3\program\quickstart.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
EnableLUA = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 149

O8 - Extra context menu item: Append Link Target to Existing PDF -
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
(Adobe Systems Incorporated)

O8 - Extra context menu item: Append to Existing PDF - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems
Incorporated)

O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems
Incorporated)

O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program
Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49}
- C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft
Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote -
{2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft
Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - File not
found

O9 - Extra Button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} -
File not found

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft
Corporation)

O9 - Extra Button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - File not
found

O13 - gopher Prefix: missing

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java
Plug-in 1.6.0_21)

O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java
Plug-in 1.6.0)

O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java
Plug-in 1.6.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java
Plug-in 1.6.0_21)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab
(Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
62.179.104.196 213.46.228.196

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD}
- C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
(Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} -
C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft
Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} -
C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL
(Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe
(Microsoft Corporation)

O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img22.jpg

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} -
C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
(Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010-08-19 10:55:09 | 000,000,000 | ---D | M] -
C:\Autodesk -- [ NTFS ]

O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () -
C:\autoexec.bat -- [ NTFS ]

O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Get_Started_for_Win.exe
-- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*



NetSvcs: FastUserSwitchingCompatibility - File not found

NetSvcs: Ias - File not found

NetSvcs: Nla - File not found

NetSvcs: Ntmssvc - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: SRService - File not found

NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)

NetSvcs: WmdmPmSp - File not found

NetSvcs: LogonHours - File not found

NetSvcs: PCAudit - File not found

NetSvcs: helpsvc - File not found

NetSvcs: uploadmgr - File not found



Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer
Institut Integrierte Schaltungen IIS)

Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft
Corporation)

Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)

Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)



MsConfig - StartUpReg: Camera Assistant Software - hkey= - key= -
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)

MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program
Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program
Files\DivX\DivX Update\DivXUpdate.exe ()

MsConfig - State: "startup" - 2



SafeBootMin: AppMgmt - Service

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: ccEvtMgr - C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SafeBootMin: ccSetMgr - C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: HelpSvc - Service

SafeBootMin: McAfeeEngineService - C:\Program Files\McAfee\VirusScan
Enterprise\EngineServer.exe (McAfee, Inc.)

SafeBootMin: NTDS - File not found

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: sacsvr - Service

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: Symantec Antivirus - C:\Program Files\Symantec\Symantec
Endpoint Protection\Rtvscan.exe (Symantec Corporation)

SafeBootMin: Symantec Antvirus - Service

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll
(Microsoft Corporation)

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus
controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk
controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host
controllers

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface
Devices

SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices



SafeBootNet: AppMgmt - Service

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: ccEvtMgr - C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SafeBootNet: ccSetMgr - C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe (Symantec Corporation)

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: HelpSvc - Service

SafeBootNet: Messenger - Service

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: NTDS - File not found

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: rdsessmgr - Service

SafeBootNet: sacsvr - Service

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: SmcService - C:\Program Files\Symantec\Symantec Endpoint
Protection\Smc.exe (Symantec Corporation)

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: Symantec Antivirus - C:\Program Files\Symantec\Symantec
Endpoint Protection\Rtvscan.exe (Symantec Corporation)

SafeBootNet: Symantec Antvirus - Service

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll
(Microsoft Corporation)

SafeBootNet: WudfPf - Driver

SafeBootNet: WudfUsbccidDriver - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus
controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk
controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers

SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy

SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host
controllers

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface
Devices

SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices

SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices



ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM

ActiveX: {1FC6FFBA-EB76-5749-4C4A-E9B277AD73A9} - Microsoft Windows Media
Player 11.0

ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media
Player 11.0

ActiveX: {29E8F4CB-4D59-2392-87AB-A9A631D0CB6C} - Microsoft Windows Media
Player 11.0

ActiveX: {2C17E5FC-F1D5-7EDB-2A8E-7819F7F0081F} - Java (Sun)

ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} -
%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall
%SystemRoot%\system32\themeui.dll

ActiveX: {33DAE3F0-6A76-61A7-4382-57F82C736CFB} - Internet Explorer

ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack

ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows
Mail\WinMail.exe" OCInstallUserConfigOE

ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -

ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx

ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help

ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script
5.6

ActiveX: {50F645EA-9A39-6A5E-2960-07DC083D5ABB} - Internet Explorer

ActiveX: {5275DAE8-D005-CC60-DE0C-43BA6653DB34} - Java (Sun)

ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup
Tools

ActiveX: {60EDEDCA-3876-CABC-5C9C-A4C17F417253} - Themes Setup

ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements

ActiveX: {6A114CBA-5023-FD59-B031-F092C283272D} - Microsoft Windows Media
Player 11.0

ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media
Player

ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access

ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7

ActiveX: {78310121-036D-427A-9FAA-A9D8135E5F8F} - .NET Framework

ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework

ActiveX: {883FEF17-C12B-E562-3430-62D1DF839D1B} - Java (Sun)

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U
shell32.dll

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
C:\Windows\system32\ie4uinit.exe -BaseSettings

ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} -
C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install

ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding

ActiveX: {A76C07CA-4482-874A-4B1C-DE6CDE0DE565} - Java (Sun)

ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core
Fonts

ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1

ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Reg Error: Value error.

ActiveX: {D58C229C-E2AB-232B-635F-BF10C5938F87} -

ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help

ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service
Interface

ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} -
C:\Windows\system32\unregmp2.exe /ShowWMP

ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} -
C:\Windows\system32\ie4uinit.exe -UserIconConfig

ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} -
"C:\Windows\System32\rundll32.exe"
"C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP



CREATERESTOREPOINT

Error creating restore point.



========== Files/Folders - Created Within 90 Days
==========




[2010-10-03 22:11:37 | 000,575,488 | ---- | C] (OldTimer Tools) --
E:\Bureaublad\OTL.exe

[2010-10-01 11:23:12 | 000,000,000 | -HSD | C] -- C:\Config.Msi

[2010-10-01 07:43:16 | 000,000,000 | R--D | C] -- C:\Users\Frank
Beurskens\Documents

[2010-09-30 21:56:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common
Files\Adobe AIR

[2010-09-30 18:56:36 | 000,000,000 | ---D | C] -- E:\Bureaublad\CS4design

[2010-09-28 17:34:27 | 000,000,000 | ---D | C] -- E:\Bureaublad\Website

[2010-09-23 23:27:46 | 000,000,000 | ---D | C] -- e:\Documenten\OneNote
Notebooks

[2010-09-23 22:56:23 | 000,000,000 | ---D | C] -- E:\Bureaublad\BoekjeEsther

[2010-09-23 19:19:25 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Roaming\ArcSoft

[2010-09-09 01:49:26 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Roaming\InstallShield

[2010-09-09 00:22:50 | 000,000,000 | ---D | C] --
C:\ProgramData\InstallShield

[2010-09-09 00:22:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common
Files\InstallShield Shared

[2010-09-09 00:18:34 | 000,000,000 | ---D | C] -- C:\Program Files\ASGvis

[2010-09-07 08:50:02 | 000,000,000 | ---D | C] --
C:\ProgramData\WindowsSearch

[2010-09-02 21:26:34 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Roaming\OpenOffice.org

[2010-09-02 21:20:13 | 000,000,000 | ---D | C] -- C:\Program
Files\OpenOffice.org 3

[2010-09-02 21:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun

[2010-09-02 21:17:17 | 000,000,000 | ---D | C] -- C:\Program
Files\OpenOffice

[2010-09-01 18:20:35 | 000,000,000 | ---D | C] -- e:\Documenten\Google

[2010-08-31 12:12:25 | 000,000,000 | ---D | C] -- e:\Documenten\Mijn
scanafbeeldingen

[2010-08-27 15:37:15 | 000,167,936 | ---- | C] (Symantec Corporation) --
C:\Windows\System32\drivers\wpshelper.sys

[2010-08-27 15:35:26 | 000,092,488 | ---- | C] (Symantec Corporation) --
C:\Windows\System32\drivers\SysPlant.sys

[2010-08-27 15:34:39 | 000,124,976 | ---- | C] (Symantec Corporation) --
C:\Windows\System32\drivers\SYMEVENT.SYS

[2010-08-24 23:16:54 | 000,000,000 | ---D | C] -- E:\Bureaublad\VROM

[2010-08-24 22:30:33 | 000,000,000 | ---D | C] -- C:\Program Files\LinkedIn

[2010-08-22 15:12:40 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Local\P5

[2010-08-22 15:12:37 | 000,000,000 | ---D | C] -- C:\Program Files\RedKings

[2010-08-22 14:43:11 | 000,000,000 | ---D | C] -- C:\Windows\Java

[2010-08-22 14:41:23 | 000,464,128 | ---- | C] (Catalyst Development
Corporation) -- C:\Windows\System32\csimxctl.ocx

[2010-08-22 14:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Poker
Tracker V2

[2010-08-01 15:34:21 | 000,000,000 | ---D | C] -- C:\Program Files\Guitar
Pro 5

[2010-08-01 15:07:46 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Local\Apple Computer

[2010-07-16 11:14:19 | 000,000,000 | R--D | C] -- e:\Documenten\My Dropbox

[2010-07-16 11:07:12 | 000,000,000 | ---D | C] -- C:\Users\Frank
Beurskens\AppData\Roaming\Dropbox

[2010-07-14 21:49:24 | 000,000,000 | ---D | C] -- e:\Documenten\Werk

[2010-07-07 10:37:31 | 000,099,656 | ---- | C] (KYOCERA MITA Corporation) --
C:\Windows\System32\KMPJLMN.DLL

[2010-07-07 10:37:31 | 000,046,877 | ---- | C] (KYOCERA MITA) --
C:\Windows\System32\KM-PMKN.DLL

[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]



========== Files - Modified Within 90 Days ==========



[2010-10-03 22:13:18 | 005,767,168 | -HS- | M] () -- C:\Users\Frank
Beurskens\ntuser.dat

[2010-10-03 22:11:50 | 000,575,488 | ---- | M] (OldTimer Tools) --
E:\Bureaublad\OTL.exe

[2010-10-03 22:07:16 | 000,002,651 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick
Launch\Microsoft Office Word 2007.lnk

[2010-10-03 21:40:32 | 000,003,568 | -H-- | M] () --
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-
439d-8115-601632D005A0

[2010-10-03 21:40:32 | 000,003,568 | -H-- | M] () --
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-
439d-8115-601632D005A0

[2010-10-03 13:48:33 | 001,479,398 | ---- | M] () --
C:\Windows\System32\PerfStringBackup.INI

[2010-10-03 13:48:33 | 000,670,256 | ---- | M] () --
C:\Windows\System32\perfh013.dat

[2010-10-03 13:48:33 | 000,590,082 | ---- | M] () --
C:\Windows\System32\perfh009.dat

[2010-10-03 13:48:33 | 000,127,698 | ---- | M] () --
C:\Windows\System32\perfc013.dat

[2010-10-03 13:48:33 | 000,102,094 | ---- | M] () --
C:\Windows\System32\perfc009.dat

[2010-10-03 13:41:14 | 000,524,288 | -HS- | M] () -- C:\Users\Frank
Beurskens\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer000000
00000000000001.regtrans-ms

[2010-10-03 13:41:14 | 000,065,536 | -HS- | M] () -- C:\Users\Frank
Beurskens\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf

[2010-10-03 13:40:36 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010-10-03 13:40:17 | 002,623,864 | ---- | M] () --
C:\Windows\System32\FNTCACHE.DAT

[2010-10-03 13:39:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010-10-03 13:39:29 | 3219,578,880 | -HS- | M] () -- C:\hiberfil.sys

[2010-10-02 12:12:21 | 002,808,833 | -H-- | M] () -- C:\Users\Frank
Beurskens\AppData\Local\IconCache.db

[2010-10-02 12:07:59 | 000,001,037 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Dreamweaver CS4.lnk

[2010-10-02 12:07:57 | 000,001,013 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Photoshop CS4.lnk

[2010-10-02 12:07:55 | 000,001,444 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Illustrator CS4.lnk

[2010-10-02 12:07:54 | 000,001,001 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
InDesign CS4.lnk

[2010-10-01 15:53:34 | 000,157,184 | ---- | M] () -- C:\Users\Frank
Beurskens\AppData\Local\GDIPFONTCACHEV1.DAT

[2010-10-01 10:18:51 | 000,001,167 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\HP
Solution Center.lnk

[2010-10-01 10:16:39 | 000,158,404 | ---- | M] () -- C:\Windows\hpoins19.dat

[2010-10-01 10:15:27 | 000,000,254 | ---- | M] () -- C:\Windows\win.ini

[2010-09-23 23:27:46 | 000,001,116 | ---- | M] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk

[2010-09-23 20:30:09 | 000,037,376 | ---- | M] () -- C:\Users\Frank
Beurskens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010-09-14 14:37:22 | 000,008,207 | ---- | M] () --
C:\Windows\System32\8.skb

[2010-09-10 22:32:20 | 000,167,936 | ---- | M] (Symantec Corporation) --
C:\Windows\System32\drivers\wpshelper.sys

[2010-09-09 00:46:53 | 000,000,646 | ---- | M] () --
E:\Bureaublad\VRayMaterials.lnk

[2010-09-09 00:37:18 | 000,000,793 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch
MaterialStudio.exe.lnk

[2010-09-09 00:07:57 | 359,594,727 | ---- | M] () -- C:\Windows\MEMORY.DMP

[2010-09-08 16:09:57 | 000,000,704 | ---- | M] () --
C:\Windows\MaxwellRender.ini

[2010-09-08 15:13:16 | 002,188,106 | ---- | M] () --
C:\Windows\System32\7.skb

[2010-09-08 14:58:14 | 002,161,536 | ---- | M] () --
C:\Windows\System32\6.skb

[2010-09-08 14:43:10 | 002,140,086 | ---- | M] () --
C:\Windows\System32\5.skb

[2010-09-08 14:28:06 | 002,137,607 | ---- | M] () --
C:\Windows\System32\4.skb

[2010-09-08 13:58:56 | 002,133,098 | ---- | M] () --
C:\Windows\System32\3.skb

[2010-09-08 13:43:54 | 002,120,336 | ---- | M] () --
C:\Windows\System32\2.skb

[2010-09-08 13:28:53 | 002,114,992 | ---- | M] () --
C:\Windows\System32\1.skb

[2010-09-07 10:40:14 | 000,001,950 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows
Photo Gallery.lnk

[2010-09-02 21:27:07 | 000,001,033 | ---- | M] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OpenOffice.org 3.2 .lnk

[2010-08-27 15:35:11 | 000,007,456 | ---- | M] () --
C:\Windows\System32\drivers\SYMEVENT.CAT

[2010-08-27 15:35:11 | 000,000,806 | ---- | M] () --
C:\Windows\System32\drivers\SYMEVENT.INF

[2010-08-27 15:34:40 | 000,124,976 | ---- | M] (Symantec Corporation) --
C:\Windows\System32\drivers\SYMEVENT.SYS

[2010-08-27 14:30:16 | 000,000,112 | ---- | M] () --
C:\ProgramData\2daP0cNV.dat

[2010-08-01 19:21:10 | 000,000,830 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\GP5.exe
- Snelkoppeling.lnk

[2010-07-16 11:14:19 | 000,000,936 | ---- | M] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\Dropbox.lnk

[2010-07-16 11:14:18 | 000,000,870 | ---- | M] () --
E:\Bureaublad\Dropbox.lnk

[2010-07-16 00:04:46 | 000,000,300 | ---- | M] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Muis -
Snelkoppeling.lnk

[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]



========== Files Created - No Company Name ==========



[2010-10-03 22:09:47 | 000,293,376 | ---- | C] () -- E:\Bureaublad\gmer.exe

[2010-10-02 12:07:59 | 000,001,037 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Dreamweaver CS4.lnk

[2010-10-02 12:07:57 | 000,001,013 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Photoshop CS4.lnk

[2010-10-02 12:07:55 | 000,001,444 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
Illustrator CS4.lnk

[2010-10-02 12:07:54 | 000,001,001 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe
InDesign CS4.lnk

[2010-10-01 10:18:51 | 000,001,167 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\HP
Solution Center.lnk

[2010-09-23 23:27:46 | 000,001,116 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk

[2010-09-14 14:37:22 | 000,008,207 | ---- | C] () --
C:\Windows\System32\8.skb

[2010-09-09 00:46:32 | 000,000,646 | ---- | C] () --
E:\Bureaublad\VRayMaterials.lnk

[2010-09-09 00:37:18 | 000,000,793 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch
MaterialStudio.exe.lnk

[2010-09-08 15:13:16 | 002,188,106 | ---- | C] () --
C:\Windows\System32\7.skb

[2010-09-08 14:58:14 | 002,161,536 | ---- | C] () --
C:\Windows\System32\6.skb

[2010-09-08 14:43:10 | 002,140,086 | ---- | C] () --
C:\Windows\System32\5.skb

[2010-09-08 14:28:06 | 002,137,607 | ---- | C] () --
C:\Windows\System32\4.skb

[2010-09-08 13:58:56 | 002,133,098 | ---- | C] () --
C:\Windows\System32\3.skb

[2010-09-08 13:43:54 | 002,120,336 | ---- | C] () --
C:\Windows\System32\2.skb

[2010-09-08 13:28:53 | 002,114,992 | ---- | C] () --
C:\Windows\System32\1.skb

[2010-09-07 10:40:14 | 000,001,950 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows
Photo Gallery.lnk

[2010-09-02 21:27:07 | 000,001,033 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\OpenOffice.org 3.2 .lnk

[2010-08-27 15:34:39 | 000,007,456 | ---- | C] () --
C:\Windows\System32\drivers\SYMEVENT.CAT

[2010-08-27 15:34:39 | 000,000,806 | ---- | C] () --
C:\Windows\System32\drivers\SYMEVENT.INF

[2010-08-27 14:15:08 | 3219,578,880 | -HS- | C] () -- C:\hiberfil.sys

[2010-08-01 19:21:10 | 000,000,830 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\GP5.exe
- Snelkoppeling.lnk

[2010-07-16 11:14:19 | 000,000,936 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\Dropbox.lnk

[2010-07-16 11:14:18 | 000,000,870 | ---- | C] () --
E:\Bureaublad\Dropbox.lnk

[2010-07-16 00:04:46 | 000,000,300 | ---- | C] () -- C:\Users\Frank
Beurskens\Application Data\Microsoft\Internet Explorer\Quick Launch\Muis -
Snelkoppeling.lnk

[2010-06-25 01:01:39 | 000,000,680 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Local\d3d9caps.dat

[2010-06-14 20:57:43 | 000,691,696 | ---- | C] () --
C:\Windows\System32\drivers\sptd.sys

[2010-06-06 20:19:31 | 000,000,112 | ---- | C] () --
C:\ProgramData\2daP0cNV.dat

[2010-04-21 14:31:49 | 000,000,124 | ---- | C] () -- C:\Windows\ccolwiz.ini

[2010-04-09 00:52:54 | 000,000,000 | ---- | C] () -- C:\Windows\ToDisc.INI

[2010-04-01 21:51:37 | 000,002,133 | ---- | C] () --
C:\ProgramData\hpzinstall.log

[2010-03-26 03:25:55 | 000,000,704 | ---- | C] () --
C:\Windows\MaxwellRender.ini

[2010-03-26 02:58:00 | 000,000,050 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Roaming\MXMCheckerPaths.pref

[2010-03-21 11:15:54 | 000,117,248 | ---- | C] () --
C:\Windows\System32\EhStorAuthn.dll

[2010-03-21 11:15:34 | 000,053,224 | ---- | C] () --
C:\Windows\System32\drivers\termdd.sys

[2010-03-17 03:15:07 | 000,037,376 | ---- | C] () -- C:\Users\Frank
Beurskens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010-03-14 20:36:15 | 002,463,976 | ---- | C] () --
C:\Windows\System32\NPSWF32.dll

[2010-03-14 14:25:58 | 000,087,552 | ---- | C] () --
C:\Windows\System32\cpwmon2k.dll

[2009-08-03 16:07:42 | 000,403,816 | ---- | C] () --
C:\Windows\System32\OGACheckControl.dll

[2008-11-05 13:42:45 | 000,062,400 | ---- | C] () --
C:\Windows\System32\IFC.dll

[2008-11-05 13:41:56 | 000,422,848 | ---- | C] () --
C:\Windows\System32\PPL.dll

[2008-01-08 16:30:04 | 000,159,744 | ---- | C] () --
C:\Windows\System32\atitmmxx.dll

[2007-10-16 12:00:39 | 001,060,424 | ---- | C] () --
C:\Windows\System32\WdfCoInstaller01000.dll

[2007-10-16 11:59:41 | 000,128,113 | ---- | C] () --
C:\Windows\System32\csellang.ini

[2007-10-16 11:59:41 | 000,045,056 | ---- | C] () --
C:\Windows\System32\csellang.dll

[2007-10-16 11:59:41 | 000,010,149 | ---- | C] () --
C:\Windows\System32\tosmreg.ini

[2007-10-16 11:59:41 | 000,007,671 | ---- | C] () --
C:\Windows\System32\cseltbl.ini

[2007-07-15 15:52:43 | 000,036,864 | ---- | C] () --
C:\Windows\System32\HWS_Ctrl.dll

[2007-04-26 09:41:20 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI

[2006-12-05 13:05:06 | 000,114,688 | ---- | C] () --
C:\Windows\System32\TosBtAcc.dll

[2006-11-02 14:35:32 | 000,005,632 | ---- | C] () --
C:\Windows\System32\sysprepMCE.dll

[2006-11-02 09:40:29 | 000,013,750 | ---- | C] () --
C:\Windows\System32\pacerprf.ini

[2005-11-23 14:55:42 | 000,024,576 | ---- | C] () --
C:\Windows\System32\SPCtl.dll

[2005-07-22 21:30:20 | 000,065,536 | ---- | C] () --
C:\Windows\System32\TosCommAPI.dll



========== LOP Check ==========



[2010-06-21 15:54:25 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\.algor

[2010-06-10 19:22:10 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Absolute Poker

[2010-08-19 12:17:20 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Autodesk

[2010-08-27 12:35:12 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\B6A98F94978EA990DC26A8BA87631964

[2010-06-07 14:00:38 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\DAEMON Tools Lite

[2010-06-07 13:53:13 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\DAEMON Tools Pro

[2010-10-03 13:44:09 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Dropbox

[2010-08-01 19:20:15 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Guitar Pro 6

[2010-09-09 15:02:10 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Image Zone Express

[2010-06-10 01:13:06 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\IrfanView

[2010-06-07 14:39:00 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\MaxwellDotNET

[2010-04-22 08:54:29 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\NeatImage PS

[2010-04-21 21:05:07 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\NeatImage SL

[2010-09-02 21:26:34 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\OpenOffice.org

[2010-04-01 23:08:04 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Printer Info Cache

[2010-06-28 11:06:31 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Robert McNeel & Associates

[2010-04-02 15:16:01 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Texture Maker

[2006-05-29 17:10:18 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Toshiba

[2010-10-01 12:23:20 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\uTorrent

[2010-06-10 01:13:07 | 000,000,000 | ---D | M] -- C:\Users\Frank
Beurskens\AppData\Roaming\Xerox

[2010-10-02 12:13:00 | 000,032,518 | ---- | M] () --
C:\Windows\Tasks\SCHEDLGU.TXT



========== Purity Check ==========







========== Custom Scans ==========





< %SYSTEMDRIVE%\*.* >

[2006-09-18 23:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat

[2009-04-11 08:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr

[2007-04-26 08:02:34 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK

[2006-09-18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys

[2010-06-17 10:55:35 | 000,000,000 | ---- | M] () -- C:\ctapi_out_gr.txt

[2010-10-03 13:39:29 | 3219,578,880 | -HS- | M] () -- C:\hiberfil.sys

[2010-10-03 13:39:26 | 3533,180,928 | -HS- | M] () -- C:\pagefile.sys

[2010-06-21 12:35:32 | 000,000,063 | ---- | M] () -- C:\product.id

[2007-04-26 09:00:41 | 000,000,420 | ---- | M] () -- C:\RHDSetup.log

[2010-08-27 13:13:12 | 000,000,557 | ---- | M] () -- C:\rkill.log

[2008-01-08 16:30:59 | 000,000,335 | -H-- | M] () -- C:\SWSTAMP.TXT

[2006-05-26 21:57:06 | 000,023,548 | ---- | M] () -- C:\_wdsuef.dmp



< %systemroot%\Fonts\*.com >

[2006-11-02 14:37:12 | 000,026,040 | ---- | M] () --
C:\Windows\Fonts\GlobalMonospace.CompositeFont

[2006-11-02 14:37:12 | 000,026,489 | ---- | M] () --
C:\Windows\Fonts\GlobalSansSerif.CompositeFont

[2006-11-02 14:37:12 | 000,029,779 | ---- | M] () --
C:\Windows\Fonts\GlobalSerif.CompositeFont

[2010-03-23 04:14:40 | 000,037,665 | ---- | M] () --
C:\Windows\Fonts\GlobalUserInterface.CompositeFont



< %systemroot%\Fonts\*.dll >



< %systemroot%\Fonts\*.ini >

[2006-09-18 23:37:34 | 000,000,065 | ---- | M] () --
C:\Windows\Fonts\desktop.ini



< %systemroot%\Fonts\*.ini2 >



< %systemroot%\Fonts\*.exe >



< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

[2008-01-19 09:34:28 | 000,089,600 | ---- | M] (Hewlett-Packard Corporation)
-- C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL

[2006-11-02 14:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) --
C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

[2006-10-26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) --
C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll



< %systemroot%\REPAIR\*.bak1 >



< %systemroot%\REPAIR\*.ini >



< %systemroot%\system32\*.jpg >



< %systemroot%\*.jpg >



< %systemroot%\*.png >



< %systemroot%\*.scr >



< %systemroot%\*._sy >



< %APPDATA%\Adobe\Update\*.* >



< %ALLUSERSPROFILE%\Favorites\*.* >



< %APPDATA%\Microsoft\*.* >



< %PROGRAMFILES%\*.* >

[2010-03-20 22:11:33 | 000,000,174 | -HS- | M] () -- C:\Program
Files\desktop.ini



< %APPDATA%\Update\*.* >



< %systemroot%\*. /mp /s >



< %systemroot%\System32\config\*.sav >

[2007-04-26 08:02:25 | 006,660,096 | ---- | M] () --
C:\Windows\System32\config\COMPONENTS.SAV

[2007-04-26 08:02:23 | 000,102,400 | ---- | M] () --
C:\Windows\System32\config\DEFAULT.SAV

[2007-04-26 08:02:25 | 000,020,480 | ---- | M] () --
C:\Windows\System32\config\SECURITY.SAV

[2007-04-26 08:02:31 | 015,712,256 | ---- | M] () --
C:\Windows\System32\config\SOFTWARE.SAV

[2007-04-26 08:02:32 | 006,008,832 | ---- | M] () --
C:\Windows\System32\config\SYSTEM.SAV



< %PROGRAMFILES%\bak. /s >



< %systemroot%\system32\bak. /s >



< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >



< %systemroot%\system32\config\systemprofile\*.dat /x
>




< %systemroot%\*.config >



< %systemroot%\system32\*.db >



< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
>


[2010-09-07 10:40:14 | 000,000,441 | -HS- | M] () -- C:\Users\Frank
Beurskens\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\desktop.ini



< %USERPROFILE%\Desktop\*.exe >



< %PROGRAMFILES%\Common Files\*.* >



< %systemroot%\*.src >



< %systemroot%\install\*.* >



< %systemroot%\system32\DLL\*.* >



< %systemroot%\system32\HelpFiles\*.* >



< %systemroot%\system32\rundll\*.* >



< %systemroot%\winn32\*.* >



< %systemroot%\Java\*.* >



< %systemroot%\system32\test\*.* >



< %systemroot%\system32\Rundll32\*.* >



< %systemroot%\AppPatch\Custom\*.* >



< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
>




< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >



< %PROGRAMFILES%\Internet Explorer\*.tmp >



< %PROGRAMFILES%\Internet Explorer\*.dat >



< %USERPROFILE%\My Documents\*.exe >



< %USERPROFILE%\*.exe >



< %systemroot%\ADDINS\*.* >



< %systemroot%\assembly\*.bak2 >



< %systemroot%\Config\*.* >



< %systemroot%\REPAIR\*.bak2 >



< %systemroot%\SECURITY\Database\*.sdb /x >



< %systemroot%\SYSTEM\*.bak2 >



< %systemroot%\Web\*.bak2 >



< %systemroot%\Driver Cache\*.* >



< %PROGRAMFILES%\Mozilla Firefox\0*.exe >



< %ProgramFiles%\Microsoft Common\*.* >



< %ProgramFiles%\TinyProxy. >



< %USERPROFILE%\Favorites\*.url /x >



< %systemroot%\system32\*.bk >



< %systemroot%\*.te >



< %systemroot%\system32\system32\*.* >



< %ALLUSERSPROFILE%\*.dat /x >

[2010-10-01 10:16:39 | 000,002,133 | ---- | M] () --
C:\ProgramData\hpzinstall.log



< %systemroot%\system32\drivers\*.rmv >



< dir /b "%systemroot%\system32\*.exe" | find /i " " /c
>




< dir /b "%systemroot%\*.exe" | find /i " " /c >



< %PROGRAMFILES%\Microsoft\*.* >



< %systemroot%\System32\Wbem\proquota.exe >



< %PROGRAMFILES%\Mozilla Firefox\*.dat >



< %USERPROFILE%\Cookies\*.txt /x >



< %SystemRoot%\system32\fonts\*.* >



< %systemroot%\system32\winlog\*.* >



< %systemroot%\system32\Language\*.* >



< %systemroot%\system32\Settings\*.* >



< %systemroot%\system32\*.quo >



< %SYSTEMROOT%\AppPatch\*.exe >



< %SYSTEMROOT%\inf\*.exe >



< %SYSTEMROOT%\Installer\*.exe >



< %systemroot%\system32\config\*.bak2 >



< %systemroot%\system32\Computers\*.* >



< %SystemRoot%\system32\Sound\*.* >



< %SystemRoot%\system32\SpecialImg\*.* >



< %SystemRoot%\system32\code\*.* >



< %SystemRoot%\system32\draft\*.* >



< %SystemRoot%\system32\MSSSys\*.* >



< %ProgramFiles%\Javascript\*.* >



< %systemroot%\pchealth\helpctr\System\*.exe /s >



< %systemroot%\Web\*.exe >



< %systemroot%\system32\msn\*.* >



< %systemroot%\system32\*.tro >



< %AppData%\Microsoft\Installer\msupdates\*.* >



< %ProgramFiles%\Messenger\*.exe >



< %systemroot%\system32\systhem32\*.* >



< %systemroot%\system\*.exe >



< %USERPROFILE%\Templates\*.tmp >



< %SYSTEMDRIVE%\explorexxx.exe\*.* >



< %Windir%\Installer\*.tmp >

[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]



< %systemroot%\System32\*.xco >



< %ProgramFiles%\system32\*.* >



< %systemroot%\System32\windos\*.* >



< %SystemRoot%\system32\sandbox\*.* >



< %SystemRoot%\system32\*.amo >



< %SystemRoot%\system32\Windows Live\*.* >



< %ProgramFiles%\logs\*.* >



< %ProgramFiles%\Bifrost\*.* >



< %SystemRoot%\system32\*.goo >



< %systemroot%\system32\IME\*.* >



< %systemroot%\BackUp\*.* >



< %systemroot%\system32\*.ico >

[2006-09-18 23:31:55 | 000,107,620 | ---- | M] () --
C:\Windows\System32\acwizard.ico



< %systemroot%\system\*.dat >



< %systemroot%\system\*.exe >



< %AppData%\Macromedia\Common\*.* >



< %SYSTEMDRIVE%\dir\*.* /s >



< %systemroot%\system32\ras\*.exe >



< %SYSTEMDRIVE%\MFILES\*.* >



< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >



< %systemroot%\system32\services\*.* >



< %systemroot%\Spooler\*.* >



< %ProgramFiles%\system32\*.* >



< %systemroot%\system32\Setup\*.dll /x >



< %systemroot%\system32\*.mine >



< %SYSTEMDRIVE%\cleansweep.exe\*.* >



< %systemroot%\system32\ras\*.dll >



< %systemroot%\system32\ras\*.drv >



< %systemroot%\*.iq >



< %systemroot%\system32\XP\*.* >



< %SYSTEMDRIVE%\Extracted\*.* >



< %systemroot%\system32\windows\*.* >



< %systemroot%\logs\*.* >

[2010-08-19 11:27:57 | 000,135,812 | ---- | M] () --
C:\Windows\Logs\DirectX.log



< %SYSTEMDRIVE%\Win.Msi\*.* >



< %systemroot%\regedit\*.* >



< %systemroot%\system32\skype\*.* >



< %AppData%\Adobe\dlluplwin25\*.* >



< %UserProfile%\*.dat >

[2010-10-03 22:23:09 | 005,767,168 | -HS- | M] () -- C:\Users\Frank
Beurskens\ntuser.dat



< %UserProfile%\*.dll >



< %systemroot%\system32\*.sxo >



< %SYSTEMDRIVE%\Gazma\*.* /s >



< %systemroot%\system32\spynet\*.* >



< %systemroot%\system32\System\*.* >



< %appdata%\Microsoft\Windows\*.* >



< %systemroot%\system32\WinDir\*.* >



< %systemroot%\_\*.* >



< %systemroot%\system32\windows32\*.* >



< %ProgramFiles%\win\*.* >



< %AppData%\Microsoft\CD Burning\*.* >



< %systemroot%\*.cab >



< %systemroot%\K.Backup\*.* >



< %ProgramFiles%\Massenger\*.* >



< %systemroot%\System32\*.doc >



< %systemroot%\Office12\*.* >



< %systemroot%\System32\Rundl32.exe\*.* >



< %ProgramFiles%\yahoo.net\*.* >



< %systemroot%\system32\*.igo >



< %systemroot%\*.rew >



< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe
>


[2007-03-08 16:03:52 | 000,167,988 | ---- | M] (Hewlett-Packard Corporation,
Microsoft Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\HPLTCOL1.EXE

[2007-03-08 15:54:24 | 000,038,400 | ---- | M] (Hewlett-Packard Corporation,
Microsoft Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\HPLTLNK.EXE

[2008-01-23 10:18:36 | 000,090,112 | ---- | M] (Hewlett-Packard Corporation,
Microsoft Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\HPLTLNK2.EXE

[2008-01-23 09:46:50 | 001,429,504 | ---- | M] (Hewlett-Packard Corporation)
-- C:\Windows\System32\spool\drivers\w32x86\3\hpltren7.exe

[2008-01-23 10:18:12 | 000,086,016 | ---- | M] (Hewlett-Packard Corporation,
Microsoft Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\HPLTSRE6.EXE

[2006-10-31 13:49:24 | 000,061,440 | ---- | M] (Hewlett-Packard) --
C:\Windows\System32\spool\drivers\w32x86\3\HPNRA.EXE

[2009-03-02 13:07:08 | 000,258,560 | ---- | M] (Xerox Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\x2fpb02.exe

[2008-10-02 10:00:54 | 000,453,120 | ---- | M] (Xerox Corporation) --
C:\Windows\System32\spool\drivers\w32x86\3\x2jobtC6.exe



< %USERPROFILE%\.COMMgr\*.* >



< %USERPROFILE%\Desktop\*.bat >



< %PROGRAMFILES%\Common Files\Real\visualizations\*.*
>




< %PROGRAMFILES%\Internet Explorer\*.Jmp >



< %PROGRAMFILES%\Windows NT\system\*.dll >



< %systemroot%\system32\*.ext >



< %systemroot%\system32\Com\*.cfg >



< %systemroot%\system32\btz\*.* >



< %systemroot%\system32\EMP\*.* >



< %systemroot%\system32\expo\*.* >



< %systemroot%\system32\inet2\*.* >



< %systemroot%\system32\xrem\*.* >



< %ProgramFiles%\Microsoft\*.* >



< %systemroot%\usgwmt\*.* >



< %ProgramFiles%\B\*.* >



< %SYSTEMDRIVE%\lspp\*.* >



< %systemroot%\Kral\*.* >



< %SYSTEMDRIVE%\windowsdvd.exe\*.* >



< %systemroot%\system32\*.ipo >



< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >



< %systemroot%\system32\*.mof >



< %systemroot%\*.atm >



< %systemroot%\system32\svhost\*.* >



< %ProgramFiles%\system32\*.* >



< %ProgramFiles%\Docmentt\*.* >



< %systemroot%\Help\*.vbs >



< %ProgramFiles%\Windows WinSxs\*.* /s >



< %ProgramFiles%\Outlook Express\IDT\*.* /s >



< %ProgramFiles%\Microsoft Office\365\*.* /s >



< %ProgramFiles%\Windows Live\*.* >



< %systemroot%\system32\win32\*.* >



< %SYSTEMDRIVE%\RECYCLER\*.* >



< %systemroot%\Fresh1\*.* >



< %ProgramFiles%\Kekj\*.* /s >



< %systemroot%\GDU\*.* >



< %systemroot%\KA\*.* >



< %systemroot%\R\*.* >



< %systemroot%\system32\*.fyo >



< %USERPROFILE%\System\*.* >



< %systemroot%\Source\*.* >



< %systemroot%\system32\ac\*.* >



< %ProgramFiles%\MSDN\*.* >



< %AppData%\AdobeUM\winvcldll54\*.* /s >



< %ProgramFiles%\Internet Explorer\*.ico >



< %systemroot%\system32\*.ojo >



< %systemroot%\system32\d323s\*.* >



< %systemroot%\system32\re\*.* >



< %UserProfile%\Microsoft\*.dll >



< %UserProfile%\Microsoft\*.log >



< %systemroot%\Bios\*.* >



< %ProgramFiles%\Spool\*.* >



<
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
>




<
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\A
uto Update\Results\Install|LastSuccessTime /rs >


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\A
uto Update\Results\Install\\LastSuccessTime: 2010-08-27 14:12:06

< End of report >



OTL Extras logfile created on: 3-10-2010 22:13:32 - Run 1

OTL by OldTimer - Version 3.2.14.1 Folder = E:\Bureaublad

Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) -
Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18943)

Locale: 00000413 | Country: Nederland | Language: NLD | Date Format:
d-M-yyyy



3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 56,00%
Memory free

6,00 Gb Paging File | 5,00 Gb Available in Paging File | 76,00% Paging File
free

Paging file location(s): ?:\pagefile.sys [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program
Files

Drive C: | 116,21 Gb Total Space | 43,57 Gb Free Space | 37,49% Space Free |
Partition Type: NTFS

Drive D: | 1,46 Gb Total Space | 1,27 Gb Free Space | 86,59% Space Free |
Partition Type: NTFS

Drive E: | 115,21 Gb Total Space | 29,97 Gb Free Space | 26,01% Space Free |
Partition Type: NTFS

F: Drive not present or media not loaded

Drive G: | 931,51 Gb Total Space | 871,58 Gb Free Space | 93,57% Space Free
| Partition Type: NTFS

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Drive K: | 3,79 Gb Total Space | 3,79 Gb Free Space | 100,00% Space Free |
Partition Type: FAT32



Computer Name: S030518T

Current User Name: Frank Beurskens

Logged in as Administrator.



Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 90 Days

Output = Minimal

Quick Scan



========== Extra Registry (SafeList) ==========





========== File Associations ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft
Corporation)

.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)



[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found



========== Shell Spawning ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft
Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe"
%1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft
Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1"
(Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft
Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe
%SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [Browse with &IrfanView] -- "C:\Program
Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L"
(Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
(Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L
(Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)



========== Security Center Settings ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

"DisableMonitoring" = 1



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecAntiVirus]

"DisableMonitoring" = 1



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecFirewall]

"DisableMonitoring" = 1



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = Reg Error: Unknown registry data type -- File not found

"VistaSp2" = Reg Error: Unknown registry data type -- File not found



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Svc\S-1-5-21-746755872-990099436-3570819603-1000]

"EnableNotifications" = 1

"EnableNotificationsRef" = 1



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]



========== Firewall Settings ==========



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter
s\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter
s\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter
s\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0



========== Authorized Applications List ==========





========== Vista Active Open Ports Exception List
==========




[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter
s\FirewallPolicy\FirewallRules]

"{1AB2BAD7-0766-4208-ACD6-108EA773A876}" = lport=51000 | protocol=6 | dir=in
| name=adobe version cue cs4 server |

"{25A86783-9858-4C18-98BC-E13C248F5E58}" = lport=49159 | protocol=6 | dir=in
| name=akamai netsession interface |

"{32287E52-8247-4310-9654-66FB544B3558}" = lport=56463 | protocol=6 | dir=in
| name=akamai netsession interface |

"{34ED8CDA-D8D4-480B-BF0C-B91AC9235FC3}" = lport=3703 | protocol=6 | dir=in
| name=adobe version cue cs4 server |

"{3C21C0FF-B3AB-46A4-A65F-4A736C9919BF}" = lport=5000 | protocol=17 | dir=in
| name=akamai netsession interface |

"{48B65929-B057-4D14-8245-8FE862227E4B}" = lport=3704 | protocol=6 | dir=in
| name=adobe version cue cs4 server |

"{65B66069-2C75-4476-84FA-B00CF3A5C9C9}" = lport=6004 | protocol=17 | dir=in
| app=c:\program files\microsoft office\office12\outlook.exe |

"{6A5FB9C8-BD31-4AC5-9834-76357A848D51}" = lport=5353 | protocol=6 | dir=in
| name=adobe csi cs4 |

"{713ADC1F-78C1-48CA-AC77-900CDB3CE5DF}" = lport=51001 | protocol=6 | dir=in
| name=adobe version cue cs4 server |

"{B4EB06BA-2F1F-4987-B48C-EA7E46925B45}" = lport=5000 | protocol=17 | dir=in
| name=akamai netsession interface |



========== Vista Active Application Exception List
==========




[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter
s\FirewallPolicy\FirewallRules]

"{06ED416A-5A21-46BE-AD08-D22E7DD43E0E}" = protocol=6 | dir=in |
app=c:\program files\common
files\adobe\cs4servicemanager\cs4servicemanager.exe |

"{0F8DE268-7495-4E1B-B689-735B35793259}" = protocol=6 | dir=in |
app=c:\program files\microsoft office\office12\groove.exe |

"{1C880C87-4127-4B16-9C37-5F030FE094BA}" = protocol=6 | dir=in |
app=c:\users\frank beurskens\appdata\roaming\dropbox\bin\dropbox.exe |

"{33073539-BF04-4E16-A0D9-492A8AAEC862}" = protocol=17 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\smc.exe |

"{62BABCBC-A316-4C9F-9413-788B9BBF7C1A}" = protocol=6 | dir=in |
app=c:\program files\common files\symantec shared\ccapp.exe |

"{76263E52-A8FA-4AD2-852C-531EE6FEC93A}" = protocol=6 | dir=in |
app=c:\program files\mcafee\common framework\frameworkservice.exe |

"{85493E59-10B0-4652-BE6A-6F29455DC6C5}" = protocol=17 | dir=in |
app=c:\program files\utorrent\utorrent.exe |

"{87A3CB6B-A079-49E0-BD1B-0A6767E842FB}" = protocol=17 | dir=in |
app=c:\program files\mcafee\common framework\frameworkservice.exe |

"{96A50B88-CFD4-4509-B0CA-1B8BA4DC5DE0}" = protocol=6 | dir=in |
app=c:\program files\utorrent\utorrent.exe |

"{9EA3A561-C3E0-4386-859C-16613BF741DB}" = protocol=17 | dir=in |
app=c:\program files\common files\adobe\adobe version cue
cs4\server\bin\versioncuecs4.exe |

"{A3558ACC-83D8-4688-BFAB-385A2B3BAC23}" = protocol=17 | dir=in |
app=c:\users\frank beurskens\appdata\roaming\dropbox\bin\dropbox.exe |

"{A48DF5CB-29E9-433C-878A-727CFD6ED42A}" = protocol=6 | dir=in |
app=c:\program files\microsoft office\office12\onenote.exe |

"{A5D32F9D-5BEA-4ECD-A3B3-8BBA5470CD39}" = protocol=6 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\snac.exe |

"{A6FD502D-C598-4397-A8BF-D04305F9D0FB}" = protocol=17 | dir=in |
app=c:\program files\microsoft office\office12\onenote.exe |

"{B07A3846-68AE-4E60-A676-5E23615E20D4}" = protocol=17 | dir=in |
app=c:\program files\common files\symantec shared\ccapp.exe |

"{B7DA5145-F579-44F4-889E-A4B26F61037E}" = protocol=17 | dir=in |
app=c:\program files\common files\symantec shared\ccapp.exe |

"{C222D2BC-08E3-4AD8-9309-46B4945ADDB3}" = protocol=17 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\smc.exe |

"{CE30E5DC-8B5F-4944-BF95-927B409C10AE}" = protocol=6 | dir=in |
app=c:\program files\common files\adobe\adobe version cue
cs4\server\bin\versioncuecs4.exe |

"{D580A100-B3B3-4CD3-8D29-326B56C41CF8}" = protocol=17 | dir=in |
app=c:\program files\common
files\adobe\cs4servicemanager\cs4servicemanager.exe |

"{DC749331-9A7E-400D-B433-749861F95D96}" = protocol=6 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\smc.exe |

"{DD31BF03-84BE-45AE-AEE2-2D83D7CC08A9}" = protocol=17 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\snac.exe |

"{E3F32DB4-5C58-429F-A4F0-9352BF4A0CC6}" = protocol=6 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\snac.exe |

"{E6C1EDB3-1403-4499-A2B5-A9C4FF6CCAB7}" = protocol=17 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\snac.exe |

"{EEE5302B-0968-4DC3-9F45-76B231F0978F}" = protocol=6 | dir=in |
app=c:\program files\symantec\symantec endpoint protection\smc.exe |

"{F45F2EF6-5CF7-4BAD-A161-A77CF5668D7D}" = protocol=17 | dir=in |
app=c:\program files\microsoft office\office12\groove.exe |

"{F63324DF-92F6-45C2-A69A-4F7AA888D277}" = protocol=6 | dir=in |
app=c:\program files\common files\symantec shared\ccapp.exe |

"TCP Query User{985DDA17-02DB-47EE-B2EC-DCA45579214C}C:\program
files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program
files\internet explorer\iexplore.exe |

"TCP Query User{DAC9117B-53F6-43C2-838E-369C3B3685AB}C:\program files\next
limit\maxwell 2\maxwell.exe" = protocol=6 | dir=in | app=c:\program
files\next limit\maxwell 2\maxwell.exe |

"TCP Query User{E194760B-0C7E-48FB-B229-4E8F5C0EBCA8}C:\program files\next
limit\maxwell 2\maxwell.exe" = protocol=6 | dir=in | app=c:\program
files\next limit\maxwell 2\maxwell.exe |

"UDP Query User{064A62C3-901B-4FCA-82AA-0B8304848C2D}C:\program files\next
limit\maxwell 2\maxwell.exe" = protocol=17 | dir=in | app=c:\program
files\next limit\maxwell 2\maxwell.exe |

"UDP Query User{43D54271-1506-40AD-8B59-A514058118EC}C:\program
files\internet explorer\iexplore.exe" = protocol=17 | dir=in |
app=c:\program files\internet explorer\iexplore.exe |

"UDP Query User{D80A9550-FF56-4AD9-8C82-66B249012297}C:\program files\next
limit\maxwell 2\maxwell.exe" = protocol=17 | dir=in | app=c:\program
files\next limit\maxwell 2\maxwell.exe |



========== HKEY_LOCAL_MACHINE Uninstall List
==========




[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL
Update kb973924 - x86 9.0.30729.4148

"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended
Settings CS4

"{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin

"{04CB6099-90D2-896A-8E01-8F1228499D93}" = Catalyst Control Center
Localization Dutch

"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4

"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4

"{068138BE-11F5-8F56-8D88-13837314558E}" = CCC Help German

"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler

"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4

"{0A2F0BB6-D45B-AF3C-C19A-6950342AF6B1}" = Catalyst Control Center
Localization Turkish

"{0BAA36F4-8138-AD8A-3791-44A7F0DD63E7}" = CCC Help Japanese

"{0C2B0B35-CF80-1384-D2F0-14F119F1784E}" = Catalyst Control Center
Localization Chinese Standard

"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan

"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4

"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended
Settings CS4

"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4

"{101738D7-D805-37A9-BB91-1F2C351782BF}" = Microsoft .NET Framework 3.5
Language Pack SP1 - nld

"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver

"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist

"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise

"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4

"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4

"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4

"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB

"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan

"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg

"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR

"{1A998953-E64F-CE34-4517-C58EF5092157}" = CCC Help Turkish

"{1AED74D3-4C54-3CAA-65DE-4EAB7B589AE1}" = Catalyst Control Center
Localization Greek

"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server

"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4

"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.4148

"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en

"{228A2F09-4557-92B9-44A9-E13D41FFAD02}" = Catalyst Control Center
Localization Hungarian

"{228D6BCB-7B30-39F5-5442-A99CD76A9762}" = Catalyst Control Center
Localization Danish

"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product
Information

"{2672817F-EB60-5FA1-9691-FE03D3E674F9}" = CCC Help French

"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 21

"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application
Feature Set Files (Roman)

"{2CC25320-CD83-B987-4B0A-B53B8413CC87}" = CCC Help Italian

"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection

"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4

"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6

"{33A0D18A-019E-8F30-6EDA-776CDC319771}" = CCC Help Norwegian

"{342F5437-C87D-4BB5-89B9-B23E16C6A395}" = Microsoft VC80 Support DLLs

"{34537704-7E4C-F552-AFC7-E3FDB0A4FDC1}" = Catalyst Control Center
Localization Italian

"{357D2DAA-1743-AC07-D88B-0077FC725DF6}" = Catalyst Control Center Graphics
Full Existing

"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4

"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for
Toshiba

"{3899B709-95BD-752E-B320-1686DACA370E}" = CCC Help Portuguese

"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4

"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX

"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific
CS4

"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin

"{3E84E56E-FC81-4E08-AA90-E8B2FDC02557}" = Catalyst Control Center
Localization Norwegian

"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4

"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit

"{469DFB95-185F-CA9E-3D5E-0036754B5033}" = Catalyst Control Center
Localization German

"{475BF3D4-E418-18CF-34FC-1D8DD3E67F46}" = Catalyst Control Center
Localization Chinese Traditional

"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension

"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4

"{4D881F9F-90B1-6992-BA30-72333A6BC669}" = CCC Help Danish

"{51035563-B7F5-01AF-0BE4-47533DEE5B51}" = Catalyst Control Center
Localization Russian

"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password

"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup

"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)

"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4

"{5783F2D7-6004-0409-0002-0060B0CE6BBA}" = AutoCAD Architecture 2008

"{5AC66835-7850-401E-AC93-65AD4D6A7E2E}" = Catalyst Control Center
Localization Portuguese

"{5C2CBFFD-FC3B-4AA9-993B-CE2B8DA25B87}" = Rhinoceros 4.0

"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator

"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help

"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053

"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support

"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for
Windows Mobility Center

"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support
Utility

"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4

"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support

"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder

"{6789E743-FF41-3E96-8C59-0F43ADE6D9E6}" = Catalyst Control Center
Localization French

"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant

"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4

"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK

"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update

"{698CEC51-8E29-5B7C-2C88-20CDE9DC3DFF}" = ccc-core-static

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox
Plugin

"{6BFA4644-7864-4A21-9EE1-5B7DCAF8373A}" = Maxwell for Rhino x86

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005
Redistributable

"{74E2F60E-5C4D-3200-3AB5-6A5C1806A64F}" = CCC Help Hungarian

"{759D7567-3027-5605-BF42-9363090FAF71}" = CCC Help Czech

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL
Update kb973923 - x86 8.0.50727.4053

"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree

"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash
Lite STI en

"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax

"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base
Files

"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer

"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005
Redistributable

"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4

"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4

"{85737D46-5FDE-7798-02BA-68AC06CD0B17}" = CCC Help Spanish

"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4

"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder

"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E
PCIe Ethernet Network Card Driver for Windows Vista

"{892DB0A0-CF31-DA46-8142-2B3953CA7B38}" = CCC Help English

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8D7BD6EE-C597-4375-B07F-A91FC78991C7}" = V-Ray for SketchUp 6

"{8F2E8ADC-871F-7B91-708D-BC2899C7D986}" = Catalyst Control Center
Localization Swedish

"{8FC9A62D-90DB-7122-09F3-587C42EE9FAC}" = Catalyst Control Center
Localization Czech

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI
(English) 2007

"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI
(English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI
(English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI
(English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI
(English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI
(English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic)
2007

"{90120000-001F-0401-0000-0000000FF1CE}_PROOFKIT_{14809F99-C601-4D4A-9391-F1
E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0402-0000-0000000FF1CE}" = Microsoft Office Proof
(Bulgarian) 2007

"{90120000-001F-0402-0000-0000000FF1CE}_PROOFKIT_{FB4EE5BD-7C0B-4B5C-ACEC-D1
F160BE9B47}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan)
2007

"{90120000-001F-0403-0000-0000000FF1CE}_PROOFKIT_{4B47C31E-46B0-462B-BEE4-DC
383B6A1F2A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0404-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese
(Traditional)) 2007

"{90120000-001F-0404-0000-0000000FF1CE}_PROOFKIT_{33FA7680-10ED-444E-BC72-21
4064317283}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech)
2007

"{90120000-001F-0405-0000-0000000FF1CE}_PROOFKIT_{294B4278-CF7B-40B9-86A1-2D
3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0406-0000-0000000FF1CE}" = Microsoft Office Proof (Danish)
2007

"{90120000-001F-0406-0000-0000000FF1CE}_PROOFKIT_{25E093C2-374E-44A9-9BCE-38
81BD442F3F}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German)
2007

"{90120000-001F-0407-0000-0000000FF1CE}_PROOFKIT_{A0516415-ED61-419A-981D-93
596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0408-0000-0000000FF1CE}" = Microsoft Office Proof (Greek)
2007

"{90120000-001F-0408-0000-0000000FF1CE}_PROOFKIT_{3C7DCB2F-8EA1-4558-B8F5-11
07C4055A0B}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English)
2007

"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-
DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish)
2007

"{90120000-001F-040B-0000-0000000FF1CE}_PROOFKIT_{8C00DF3E-E8BD-4C6A-B86F-01
35E11DAF1C}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French)
2007

"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-
EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-040D-0000-0000000FF1CE}" = Microsoft Office Proof (Hebrew)
2007

"{90120000-001F-040D-0000-0000000FF1CE}_PROOFKIT_{D51DB996-6D46-4195-B495-5E
96F61A3CB9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof
(Hungarian) 2007

"{90120000-001F-040E-0000-0000000FF1CE}_PROOFKIT_{573CA1BB-C8A3-46C4-993E-DB
4043D9BFCD}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian)
2007

"{90120000-001F-0410-0000-0000000FF1CE}_PROOFKIT_{322296D4-1EAE-4030-9FBC-D2
787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese)
2007

"{90120000-001F-0411-0000-0000000FF1CE}_PROOFKIT_{09FD8ECF-B585-47FD-8E53-68
BB8741DA65}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0412-0000-0000000FF1CE}" = Microsoft Office Proof (Korean)
2007

"{90120000-001F-0412-0000-0000000FF1CE}_PROOFKIT_{B017C4D5-E774-4A94-A8E3-38
0489B86F47}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch)
2007

"{90120000-001F-0413-0000-0000000FF1CE}_PROOFKIT_{D66D5A44-E480-4BA4-B4F2-C5
54F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0414-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian
(Bokmål)) 2007

"{90120000-001F-0414-0000-0000000FF1CE}_PROOFKIT_{D3413506-02DD-4918-AB8B-A9
939A14C2E8}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish)
2007

"{90120000-001F-0415-0000-0000000FF1CE}_PROOFKIT_{E9EA2604-8AC9-47D2-8F4B-6B
F60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof
(Portuguese (Brazil)) 2007

"{90120000-001F-0416-0000-0000000FF1CE}_PROOFKIT_{75EBE365-7FC5-4720-A7D3-80
4BF550D1BC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0418-0000-0000000FF1CE}" = Microsoft Office Proof (Romanian)
2007

"{90120000-001F-0418-0000-0000000FF1CE}_PROOFKIT_{6E3398C5-9A81-4054-B474-8B
23A60F5048}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0419-0000-0000000FF1CE}" = Microsoft Office Proof (Russian)
2007

"{90120000-001F-0419-0000-0000000FF1CE}_PROOFKIT_{57A92C5E-E76A-49CC-9EC2-A7
B6CE1255EA}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-041A-0000-0000000FF1CE}" = Microsoft Office Proof (Croatian)
2007

"{90120000-001F-041A-0000-0000000FF1CE}_PROOFKIT_{C9CC66D9-D7D3-46C1-A485-96
01E4DE8D28}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak)
2007

"{90120000-001F-041B-0000-0000000FF1CE}_PROOFKIT_{10EC59E5-9BCE-4884-BB1A-E2
8627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish)
2007

"{90120000-001F-041D-0000-0000000FF1CE}_PROOFKIT_{43722AA8-ACEA-4F54-9B83-24
67D376EF8A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-041E-0000-0000000FF1CE}" = Microsoft Office Proof (Thai)
2007

"{90120000-001F-041E-0000-0000000FF1CE}_PROOFKIT_{0ED7C31A-FB21-4F8E-BD16-92
1A5E69B2C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-041F-0000-0000000FF1CE}" = Microsoft Office Proof (Turkish)
2007

"{90120000-001F-041F-0000-0000000FF1CE}_PROOFKIT_{CB71F1CB-4CC3-47DE-B003-40
413E64FE10}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0420-0000-0000000FF1CE}" = Microsoft Office Proof (Urdu)
2007

"{90120000-001F-0420-0000-0000000FF1CE}_PROOFKIT_{65201326-4FD3-43C6-9B2F-77
E507E76709}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0422-0000-0000000FF1CE}" = Microsoft Office Proof
(Ukrainian) 2007

"{90120000-001F-0422-0000-0000000FF1CE}_PROOFKIT_{6F177D09-F21D-4F50-9436-35
3972D1D232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0424-0000-0000000FF1CE}" = Microsoft Office Proof
(Slovenian) 2007

"{90120000-001F-0424-0000-0000000FF1CE}_PROOFKIT_{6E8DFF8D-F7D1-4451-952A-61
CAB73A59E2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0425-0000-0000000FF1CE}" = Microsoft Office Proof (Estonian)
2007

"{90120000-001F-0425-0000-0000000FF1CE}_PROOFKIT_{198E4A56-E02D-4594-AA6A-B2
5D83F50A81}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0426-0000-0000000FF1CE}" = Microsoft Office Proof (Latvian)
2007

"{90120000-001F-0426-0000-0000000FF1CE}_PROOFKIT_{1B3EDDDA-158A-4AFB-A493-57
446AC5964D}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0427-0000-0000000FF1CE}" = Microsoft Office Proof
(Lithuanian) 2007

"{90120000-001F-0427-0000-0000000FF1CE}_PROOFKIT_{15B60D1E-FBD2-4659-A159-AD
B32FA4105D}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque)
2007

"{90120000-001F-042D-0000-0000000FF1CE}_PROOFKIT_{E62E1AA9-F2F1-4230-8EC7-5D
90ECCDFE1A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0439-0000-0000000FF1CE}" = Microsoft Office Proof (Hindi)
2007

"{90120000-001F-0439-0000-0000000FF1CE}_PROOFKIT_{B0126B90-3F42-404B-8435-DE
45FBC3BE45}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0446-0000-0000000FF1CE}" = Microsoft Office Proof (Punjabi)
2007

"{90120000-001F-0446-0000-0000000FF1CE}_PROOFKIT_{9B293D98-7E05-4D34-BDB0-2B
851192EE25}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0447-0000-0000000FF1CE}" = Microsoft Office Proof (Gujarati)
2007

"{90120000-001F-0447-0000-0000000FF1CE}_PROOFKIT_{6163604F-6E24-40DF-A223-8E
98916CA437}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0449-0000-0000000FF1CE}" = Microsoft Office Proof (Tamil)
2007

"{90120000-001F-0449-0000-0000000FF1CE}_PROOFKIT_{ECADA80E-BB52-41D1-9CD6-EE
C0EB9B580E}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-044A-0000-0000000FF1CE}" = Microsoft Office Proof (Telugu)
2007

"{90120000-001F-044A-0000-0000000FF1CE}_PROOFKIT_{35747EC2-9A65-41BB-8180-0E
37E4D50E2B}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-044B-0000-0000000FF1CE}" = Microsoft Office Proof (Kannada)
2007

"{90120000-001F-044B-0000-0000000FF1CE}_PROOFKIT_{B5565948-16E8-4FFD-AFD4-57
E449601113}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-044E-0000-0000000FF1CE}" = Microsoft Office Proof (Marathi)
2007

"{90120000-001F-044E-0000-0000000FF1CE}_PROOFKIT_{E1FA82EE-699A-477F-8B11-13
2116F2B717}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician)
2007

"{90120000-001F-0456-0000-0000000FF1CE}_PROOFKIT_{D93B4372-B042-4AB2-A657-C5
C5C25F8BAC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0804-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese
(Simplified)) 2007

"{90120000-001F-0804-0000-0000000FF1CE}_PROOFKIT_{82E853AD-6911-4EA9-9EB0-2F
9BE7747878}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0814-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian
(Nynorsk)) 2007

"{90120000-001F-0814-0000-0000000FF1CE}_PROOFKIT_{1B70EF07-15AB-483B-B7DE-C6
0584A3F518}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0816-0000-0000000FF1CE}" = Microsoft Office Proof
(Portuguese (Portugal)) 2007

"{90120000-001F-0816-0000-0000000FF1CE}_PROOFKIT_{C312E1CD-EC19-4270-A072-F3
6F634DFF79}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-081A-0000-0000000FF1CE}" = Microsoft Office Proof (Serbian
(Latin)) 2007

"{90120000-001F-081A-0000-0000000FF1CE}_PROOFKIT_{5D31A216-8A77-4993-AAF4-A7
47E3E81B35}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish)
2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-
D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0028-0404-0000-0000000FF1CE}" = Microsoft Office IME (Chinese
(Traditional)) 2007

"{90120000-0028-0404-0000-0000000FF1CE}_PROOFKIT_{5E6C6E79-40BE-491B-9ABF-C6
65667E1B07}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese)
2007

"{90120000-0028-0411-0000-0000000FF1CE}_PROOFKIT_{85644C8B-569F-4998-9A4F-08
45AA579E9E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0028-0412-0000-0000000FF1CE}" = Microsoft Office IME (Korean)
2007

"{90120000-0028-0412-0000-0000000FF1CE}_PROOFKIT_{15281683-B481-47B8-A981-70
43F35441FF}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0028-0804-0000-0000000FF1CE}" = Microsoft Office IME (Chinese
(Simplified)) 2007

"{90120000-0028-0804-0000-0000000FF1CE}_PROOFKIT_{4029CB10-E410-41AD-BB3F-05
2C95243407}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing
(English) 2007

"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-
4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-
815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI
(English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0048-0409-0000-0000000FF1CE}" = Microsoft Office ProofMUI
(English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI
(English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-
3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI
(English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI
(English) 2007

"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup
Metadata MUI (English) 2007

"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup
Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-
3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup
Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-
FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{91120000-0103-0000-0000-0000000FF1CE}" = Microsoft Office Proofing Kit
2007

"{9128A108-FE27-997F-A118-E6C65FAE2256}" = CCC Help Korean

"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4

"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4

"{95140000-004E-0409-0000-0000000FF1CE}" = Microsoft Outlook Social
Connector 32-bit

"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook
Connector

"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58

"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status

"{9809A7E4-3B3B-4547-3B80-0073E0115EB4}" = Catalyst Control Center Graphics
Previews Vista

"{9842DEA7-806B-08CA-608C-9717F5F5D7F3}" = Catalyst Control Center Graphics
Light

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.17

"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7

"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations

"{9C6ABCF3-A9BF-2A09-0974-777B6C421E28}" = CCC Help Swedish

"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components
Installer

"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = Geluiddemper v. cd/dvd-station

"{A128921B-D03F-4BFB-8141-C365AA48D660}" = Adobe Setup

"{A2881E09-38DB-4F79-9135-00FDA01768A7}" = Adobe Creative Suite 4 Design
Premium

"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter

"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy

"{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver

"{A6F2C0CD-E0A2-BCC1-5BEF-600AC4D9AE62}" = Catalyst Control Center
Localization Spanish

"{AA951B10-7089-4D60-B288-516E641F48E6}" = McAfee Agent

"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder

"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.03.10

"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English,
Français, Deutsch

"{AC76BA86-7AD7-1043-7B44-A70900000002}" = Adobe Reader 7.0.9 - Nederlands

"{AED8FA19-763C-BA3F-A243-3136EEF255E8}" = CCC Help Russian

"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0

"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect

"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser

"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4

"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4

"{BA98E840-DCB3-10B7-D016-8890E4F8F4CC}" = Catalyst Control Center Graphics
Full New

"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module

"{BC1ADEAD-99F1-4707-B31B-CDB222D5BB68}" = Catalyst Control Center -
Branding

"{BE2DB46C-EA1A-434E-AABD-50EAF626EBEE}" = ASGvis Material Studio

"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm

"{C1F4123D-6C93-D087-F50F-8D7AC51AFE76}" = ATI Catalyst Install Manager

"{C3E7A3AD-142E-2433-0107-D2CA4D85F19F}" = CCC Help Greek

"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4

"{C5A5F901-08F3-7E96-3049-A950A80ACCF4}" = Catalyst Control Center Graphics
Previews Common

"{C716522C-3731-4667-8579-40B098294500}" = Toolbox

"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime

"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and
Deskjet All-In-One Driver Software 8.0.B

"{CA9483A2-742A-4A72-881D-B81C6B1ACB3E}" = Google SketchUp Pro 7

"{CB082B01-F65B-05DA-3048-8979BF7B5BD2}" = CCC Help Dutch

"{CC0E0442-B3BA-6FB5-3E94-C5F96B9B8915}" = Skins

"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by
Toshiba

"{D281F20C-FA11-D09A-8A20-B78D771222F8}" = Catalyst Control Center
Localization Japanese

"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI

"{DD766B16-BE10-F87C-73A7-A6FC09148633}" = CCC Help Polish

"{DDF91F62-6CBF-2932-93BA-D487B60635B5}" = Catalyst Control Center Core
Implementation

"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4

"{DEC00B1F-5E63-D40F-6291-A2A531414613}" = CCC Help Chinese Traditional

"{DF066D23-C0C8-8755-8244-A8A78B8798A5}" = CCC Help Thai

"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport

"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software

"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series

"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext

"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential

"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities

"{EC2F2081-6B46-810C-8408-EC04D29EDFF0}" = Catalyst Control Center
Localization Thai

"{ECC0CADD-0491-4FB0-AAB8-5DC6C371890E}" = Rhinoceros 4.0 SR7

"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help

"{F0EF93AE-6B13-DB6A-3C03-8CB5A51D0A7A}" = CCC Help Finnish

"{F0FFE43C-7FCC-55F3-6BDE-11F6E9F9FB4A}" = CCC Help Chinese Standard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio
Driver

"{F1568757-E564-4cb5-8980-9333119A4384}" = F300

"{F1E1E2E3-2F93-E548-7675-10A78CDD04A6}" = Catalyst Control Center
Localization Finnish

"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components
Installer

"{F20B6876-0F18-1A47-D858-D0D9F6888B99}" = Catalyst Control Center
Localization Polish

"{F400ED9E-848C-DB0B-CED5-F69DAA2CE8AD}" = ccc-utility

"{F5EFBB2D-2CD6-FD3D-FA53-DFB962BFD14C}" = Catalyst Control Center
Localization Korean

"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb

"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4

"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4

"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4

"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All

"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package

"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe_55230b0b70661df0f212e88f0b655f7" = Adobe Creative Suite 4 Design
Premium

"Akamai" = Akamai NetSession Interface

"AutoCAD Architecture 2008" = AutoCAD Architecture 2008

"CutePDF Writer Installation" = CutePDF Writer 2.8

"DivX Setup.divx.com" = DivX Setup

"ENTERPRISE" = Microsoft Office Enterprise 2007

"Grasshopper" = Grasshopper

"Guitar Pro 5_is1" = Guitar Pro 5.2

"HP Imaging Device Functions" = HP Imaging Device Functions 8.0

"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0

"HPOCR" = HP OCR Software 8.0

"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA
Supervisorwachtwoord

"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware
Setup

"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended
Tiles for Windows Mobility Center

"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards
Support Utility

"InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A}" = Emdedded IR Driver

"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments
PCIxx21/x515/xx12 drivers.

"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added
Package

"IrfanView" = IrfanView (remove only)

"LinkedIn Outlook Connector" = LinkedIn Outlook Connector

"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)

"Maxwell 2" = Maxwell 2

"MaxwellExport_is1" = MaxwellExport (Version 2.4)

"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise
Module

"Microsoft .NET Framework 3.5 Language Pack SP1 - nld" = Taalpakket voor
Microsoft .NET Framework 3.5 SP1 - NL

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"PROOFKIT" = Microsoft Office Proofing Tools Kit 2007

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"TOSHIBA Software Modem" = TOSHIBA Software Modem

"uTorrent" = µTorrent

"Windows Media Encoder 9" = Windows Media Encoder 9 Series

"WinRAR archiver" = WinRAR



========== HKEY_CURRENT_USER Uninstall List
==========




[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Absolute Poker" = Absolute Poker

"Dropbox" = Dropbox



========== Last 10 Event Log Errors ==========



[ Application Events ]

Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



Error - 22-4-2010 8:01:22 | Computer Name = S030518T | Source = Adobe
Version Cue CS3 | ID = 3

Description =



[ OSession Events ]

Error - 7-6-2010 17:40:45 | Computer Name = S030518T | Source = Microsoft
Office 12 Sessions | ID = 7001

Description = ID: 1, Application Name: Microsoft Office Excel, Application
Version:

12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session
lasted 3053

seconds with 1080 seconds of active time. This session ended with a crash.



Error - 5-7-2010 13:05:05 | Computer Name = S030518T | Source = Microsoft
Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application
Version:

12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 1362

seconds with 180 seconds of active time. This session ended with a crash.



Error - 15-8-2010 19:17:31 | Computer Name = S030518T | Source = Microsoft
Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application
Version:

12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session
lasted 220

seconds with 120 seconds of active time. This session ended with a crash.



[ System Events ]

Error - 1-10-2010 5:41:21 | Computer Name = S030518T | Source = Server | ID
= 2505

Description = De server kan geen binding tot stand brengen met transport
\Device\NetBT_Tcpip_{769A91AB-8C5D-4B8E-B674-52903BFB0677}

omdat een andere computer op het netwerk dezelfde naam heeft. De server kan
niet

worden gestart.



Error - 1-10-2010 6:31:35 | Computer Name = S030518T | Source = Server | ID
= 2505

Description = De server kan geen binding tot stand brengen met transport
\Device\NetBT_Tcpip_{769A91AB-8C5D-4B8E-B674-52903BFB0677}

omdat een andere computer op het netwerk dezelfde naam heeft. De server kan
niet

worden gestart.



Error - 1-10-2010 6:31:39 | Computer Name = S030518T | Source = Server | ID
= 2505

Description = De server kan geen binding tot stand brengen met transport
\Device\NetBT_Tcpip_{769A91AB-8C5D-4B8E-B674-52903BFB0677}

omdat een andere computer op het netwerk dezelfde naam heeft. De server kan
niet

worden gestart.



Error - 1-10-2010 11:50:35 | Computer Name = S030518T | Source = Service
Control Manager | ID = 7034

Description =



Error - 1-10-2010 14:03:48 | Computer Name = S030518T | Source = Service
Control Manager | ID = 7034

Description =



Error - 1-10-2010 16:54:09 | Computer Name = S030518T | Source = Service
Control Manager | ID = 7034

Description =



Error - 1-10-2010 17:26:09 | Computer Name = S030518T | Source = Server | ID
= 2505

Description = De server kan geen binding tot stand brengen met transport
\Device\NetBT_Tcpip_{769A91AB-8C5D-4B8E-B674-52903BFB0677}

omdat een andere computer op het netwerk dezelfde naam heeft. De server kan
niet

worden gestart.



Error - 2-10-2010 6:12:41 | Computer Name = S030518T | Source = DCOM | ID =
10010

Description =



Error - 3-10-2010 7:40:53 | Computer Name = S030518T | Source = Service
Control Manager | ID = 7000

Description =



Error - 3-10-2010 7:40:53 | Computer Name = S030518T | Source = Service
Control Manager | ID = 7000

Description =





< End of report >
  • 0

#4
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
:D

Don't worry about the GMER scan crashing. Lets go ahead and run a couple of programs now that should help in getting rid of this Rootkit ;)

Please follow the steps below, in order....



1)
Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    Posted Image

  • If an infected file is detected, the default action will be Cure, click on Continue.


    Posted Image

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    Posted Image

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    Posted Image

  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.




2)
Quick Scan using MBAM
Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.




3)
You have two Anti Virus programs running on your PC at the moment, Symantec Endpoint and McAfee Virus Scan Enterprise. It is highly recommended to only have one Anti Virus program installed at any one time as they could potentially clash and cause problems.



In your next reply
Please post the contents of...
TDSSKiller log
MBAM log

  • 0

#5
Vladice

Vladice

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Once again, thanks for your help!

1.The Symantec notification disappeared after running TDSS.

2.After running MBAM I got a notification which said that MBAM couldn't remove all possible threads (out of 2).

3.Which anti virus program is best to keep, Symantec or McAfee? What are the differences?

Here are the requested logs:



2010/10/04 23:36:00.0182 TDSS rootkit removing tool 2.4.4.0 Oct 4 2010 09:06:59
2010/10/04 23:36:00.0182 ================================================================================
2010/10/04 23:36:00.0182 SystemInfo:
2010/10/04 23:36:00.0182
2010/10/04 23:36:00.0182 OS Version: 6.0.6002 ServicePack: 2.0
2010/10/04 23:36:00.0182 Product type: Workstation
2010/10/04 23:36:00.0182 ComputerName: S030518T
2010/10/04 23:36:00.0182 UserName: Frank Beurskens
2010/10/04 23:36:00.0182 Windows directory: C:\Windows
2010/10/04 23:36:00.0182 System windows directory: C:\Windows
2010/10/04 23:36:00.0182 Processor architecture: Intel x86
2010/10/04 23:36:00.0182 Number of processors: 2
2010/10/04 23:36:00.0182 Page size: 0x1000
2010/10/04 23:36:00.0182 Boot type: Normal boot
2010/10/04 23:36:00.0182 ================================================================================
2010/10/04 23:36:10.0462 Initialize success
2010/10/04 23:36:15.0329 ================================================================================
2010/10/04 23:36:15.0329 Scan started
2010/10/04 23:36:15.0329 Mode: Manual;
2010/10/04 23:36:15.0329 ================================================================================
2010/10/04 23:36:15.0735 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2010/10/04 23:36:15.0829 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys
2010/10/04 23:36:16.0016 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2010/10/04 23:36:16.0141 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2010/10/04 23:36:16.0219 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2010/10/04 23:36:16.0312 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2010/10/04 23:36:16.0437 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2010/10/04 23:36:16.0562 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
2010/10/04 23:36:16.0702 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
2010/10/04 23:36:16.0827 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2010/10/04 23:36:16.0952 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2010/10/04 23:36:17.0045 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2010/10/04 23:36:17.0170 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2010/10/04 23:36:17.0233 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2010/10/04 23:36:17.0295 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2010/10/04 23:36:17.0560 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2010/10/04 23:36:17.0685 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2010/10/04 23:36:17.0825 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/10/04 23:36:17.0935 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2010/10/04 23:36:18.0044 athr (6046a55f79de9c581b8d5e9c1366cc81) C:\Windows\system32\DRIVERS\athr.sys
2010/10/04 23:36:18.0231 atikmdag (d9527f4bde7e18077a33623f0bc8eb86) C:\Windows\system32\DRIVERS\atikmdag.sys
2010/10/04 23:36:18.0527 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2010/10/04 23:36:18.0637 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2010/10/04 23:36:18.0699 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2010/10/04 23:36:18.0824 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2010/10/04 23:36:18.0917 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2010/10/04 23:36:18.0980 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2010/10/04 23:36:19.0058 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2010/10/04 23:36:19.0136 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2010/10/04 23:36:19.0229 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2010/10/04 23:36:19.0385 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/10/04 23:36:19.0463 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2010/10/04 23:36:19.0604 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
2010/10/04 23:36:19.0682 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2010/10/04 23:36:19.0822 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/10/04 23:36:20.0041 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2010/10/04 23:36:20.0119 COH_Mon (c586875ece5318c6309ed1ab79d0e55f) C:\Windows\system32\Drivers\COH_Mon.sys
2010/10/04 23:36:20.0306 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2010/10/04 23:36:20.0462 CplIR (c3156b712e3873aad354f1696b2b2925) C:\Windows\system32\DRIVERS\CplIR.SYS
2010/10/04 23:36:20.0540 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2010/10/04 23:36:20.0602 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2010/10/04 23:36:20.0711 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2010/10/04 23:36:20.0867 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2010/10/04 23:36:20.0930 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2010/10/04 23:36:21.0008 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2010/10/04 23:36:21.0055 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2010/10/04 23:36:21.0195 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2010/10/04 23:36:21.0304 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
2010/10/04 23:36:21.0382 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2010/10/04 23:36:21.0538 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2010/10/04 23:36:21.0679 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2010/10/04 23:36:21.0959 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2010/10/04 23:36:22.0037 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2010/10/04 23:36:22.0162 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2010/10/04 23:36:22.0240 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2010/10/04 23:36:22.0349 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2010/10/04 23:36:22.0505 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2010/10/04 23:36:22.0646 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2010/10/04 23:36:22.0755 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/10/04 23:36:22.0880 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2010/10/04 23:36:22.0973 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2010/10/04 23:36:23.0051 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2010/10/04 23:36:23.0192 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
2010/10/04 23:36:23.0270 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/10/04 23:36:23.0348 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2010/10/04 23:36:23.0426 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\DRIVERS\hidir.sys
2010/10/04 23:36:23.0644 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2010/10/04 23:36:23.0894 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2010/10/04 23:36:24.0034 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2010/10/04 23:36:24.0097 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2010/10/04 23:36:24.0206 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/10/04 23:36:24.0331 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2010/10/04 23:36:24.0487 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2010/10/04 23:36:24.0721 IntcAzAudAddService (0f16d98c3af2138fabfa20adde4e01fe) C:\Windows\system32\drivers\RTKVHDA.sys
2010/10/04 23:36:24.0970 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2010/10/04 23:36:25.0048 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2010/10/04 23:36:25.0157 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/10/04 23:36:25.0360 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2010/10/04 23:36:25.0438 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2010/10/04 23:36:25.0516 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2010/10/04 23:36:25.0672 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2010/10/04 23:36:26.0015 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/10/04 23:36:26.0265 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2010/10/04 23:36:26.0343 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2010/10/04 23:36:26.0468 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/10/04 23:36:26.0546 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/10/04 23:36:26.0655 KR10I (a383f2cea0a8f4e76e71abc869bd5748) C:\Windows\system32\drivers\kr10i.sys
2010/10/04 23:36:26.0749 KR10N (6e9922332386c2a49936b30b2b6fd298) C:\Windows\system32\drivers\kr10n.sys
2010/10/04 23:36:26.0873 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2010/10/04 23:36:27.0029 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/10/04 23:36:27.0107 LPCFilter (515fc18cabee0158a324b08b1c2667cf) C:\Windows\system32\DRIVERS\LPCFilter.sys
2010/10/04 23:36:27.0201 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2010/10/04 23:36:27.0310 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2010/10/04 23:36:27.0373 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2010/10/04 23:36:27.0653 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2010/10/04 23:36:27.0794 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2010/10/04 23:36:27.0903 mfeapfk (4d81c0e4ed846e9a70b881891a5598ab) C:\Windows\system32\drivers\mfeapfk.sys
2010/10/04 23:36:28.0075 mfeavfk (ff75f47ec2a9ea3e780a9d08daba1276) C:\Windows\system32\drivers\mfeavfk.sys
2010/10/04 23:36:28.0199 mfebopk (5a3b000fdccf826ffb74e76b0474c856) C:\Windows\system32\drivers\mfebopk.sys
2010/10/04 23:36:28.0574 mfehidk (8e6b4e55d3a33b92693f7081ec018c39) C:\Windows\system32\drivers\mfehidk.sys
2010/10/04 23:36:29.0057 mferkdet (fa097d72a439c3a387fe38a654df44c5) C:\Windows\system32\drivers\mferkdet.sys
2010/10/04 23:36:29.0260 mfetdik (a45d0c099a478de5cbd0d6e8466becd5) C:\Windows\system32\drivers\mfetdik.sys
2010/10/04 23:36:29.0557 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2010/10/04 23:36:29.0650 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2010/10/04 23:36:29.0775 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2010/10/04 23:36:29.0900 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2010/10/04 23:36:29.0993 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2010/10/04 23:36:30.0087 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2010/10/04 23:36:30.0259 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2010/10/04 23:36:30.0368 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2010/10/04 23:36:30.0508 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2010/10/04 23:36:30.0602 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/10/04 23:36:30.0649 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/10/04 23:36:30.0711 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/10/04 23:36:30.0836 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
2010/10/04 23:36:30.0961 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2010/10/04 23:36:31.0039 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2010/10/04 23:36:31.0148 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2010/10/04 23:36:31.0397 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2010/10/04 23:36:31.0553 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/10/04 23:36:31.0585 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2010/10/04 23:36:31.0647 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2010/10/04 23:36:31.0741 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/10/04 23:36:31.0850 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2010/10/04 23:36:31.0990 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2010/10/04 23:36:32.0099 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2010/10/04 23:36:32.0224 NAVENG (49d802531e5984cf1fe028c6c129b9d8) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20101002.003\NAVENG.SYS
2010/10/04 23:36:32.0365 NAVEX15 (158676a5758c1fa519563b3e72fbf256) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20101002.003\NAVEX15.SYS
2010/10/04 23:36:32.0630 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2010/10/04 23:36:32.0973 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/10/04 23:36:33.0098 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/10/04 23:36:33.0238 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/10/04 23:36:33.0410 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2010/10/04 23:36:33.0581 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2010/10/04 23:36:33.0893 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2010/10/04 23:36:34.0096 NETw4v32 (c4f27ba95327b6441ca44ddcfb47562a) C:\Windows\system32\DRIVERS\NETw4v32.sys
2010/10/04 23:36:34.0330 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2010/10/04 23:36:34.0471 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2010/10/04 23:36:34.0595 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2010/10/04 23:36:34.0985 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2010/10/04 23:36:35.0141 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2010/10/04 23:36:35.0266 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2010/10/04 23:36:35.0375 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2010/10/04 23:36:35.0500 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2010/10/04 23:36:35.0641 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2010/10/04 23:36:36.0187 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/10/04 23:36:36.0327 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2010/10/04 23:36:36.0467 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2010/10/04 23:36:36.0779 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2010/10/04 23:36:36.0998 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2010/10/04 23:36:37.0107 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2010/10/04 23:36:37.0201 pcmcia (3bb2244f343b610c29c98035504c9b75) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/10/04 23:36:37.0294 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2010/10/04 23:36:37.0544 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2010/10/04 23:36:37.0622 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2010/10/04 23:36:37.0715 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2010/10/04 23:36:37.0809 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2010/10/04 23:36:38.0137 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2010/10/04 23:36:38.0246 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2010/10/04 23:36:38.0355 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2010/10/04 23:36:38.0433 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/10/04 23:36:38.0542 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/10/04 23:36:38.0651 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2010/10/04 23:36:38.0776 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2010/10/04 23:36:38.0823 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/10/04 23:36:38.0932 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2010/10/04 23:36:39.0151 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2010/10/04 23:36:39.0260 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2010/10/04 23:36:39.0369 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2010/10/04 23:36:39.0494 RTL8169 (b8b159fa669c6386a458fcd468ebb1e6) C:\Windows\system32\DRIVERS\Rtlh86.sys
2010/10/04 23:36:39.0634 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2010/10/04 23:36:39.0712 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
2010/10/04 23:36:39.0806 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/10/04 23:36:39.0899 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2010/10/04 23:36:40.0243 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2010/10/04 23:36:40.0367 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2010/10/04 23:36:40.0445 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/10/04 23:36:40.0523 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
2010/10/04 23:36:41.0194 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/10/04 23:36:41.0428 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2010/10/04 23:36:41.0553 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
2010/10/04 23:36:41.0631 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2010/10/04 23:36:41.0881 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2010/10/04 23:36:42.0239 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2010/10/04 23:36:42.0411 SPBBCDrv (e621bb5839cf45fa477f48092edd2b40) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
2010/10/04 23:36:42.0692 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2010/10/04 23:36:42.0785 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2010/10/04 23:36:42.0785 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2010/10/04 23:36:42.0801 sptd - detected Locked file (1)
2010/10/04 23:36:42.0879 SRTSP (2abf82c8452ab0b9ffc74a2d5da91989) C:\Windows\system32\Drivers\SRTSP.SYS
2010/10/04 23:36:43.0285 SRTSPL (e2f9e5887bea5bd8784d337e06eda31b) C:\Windows\system32\Drivers\SRTSPL.SYS
2010/10/04 23:36:43.0487 SRTSPX (3b974c158fabd910186f98df8d3e23f3) C:\Windows\system32\Drivers\SRTSPX.SYS
2010/10/04 23:36:43.0643 srv (96a5e2c642af8f591a7366429809506b) C:\Windows\system32\DRIVERS\srv.sys
2010/10/04 23:36:43.0784 srv2 (71da2d64880c97e5ffc3c81761632751) C:\Windows\system32\DRIVERS\srv2.sys
2010/10/04 23:36:43.0893 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
2010/10/04 23:36:44.0033 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2010/10/04 23:36:44.0252 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2010/10/04 23:36:44.0361 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS
2010/10/04 23:36:44.0470 SYMREDRV (394b2368212114d538316812af60fddd) C:\Windows\System32\Drivers\SYMREDRV.SYS
2010/10/04 23:36:44.0626 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\Windows\System32\Drivers\SYMTDI.SYS
2010/10/04 23:36:44.0923 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2010/10/04 23:36:45.0016 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2010/10/04 23:36:45.0515 SynTP (ac4459d34f22b52feb6e619746ff6bd4) C:\Windows\system32\DRIVERS\SynTP.sys
2010/10/04 23:36:45.0671 SysPlant (1295b1da3e2a2c24c7d176f6e97afbd1) C:\Windows\SYSTEM32\Drivers\SysPlant.sys
2010/10/04 23:36:45.0890 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2010/10/04 23:36:46.0061 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2010/10/04 23:36:46.0358 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2010/10/04 23:36:46.0467 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys
2010/10/04 23:36:46.0592 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2010/10/04 23:36:46.0685 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2010/10/04 23:36:46.0826 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2010/10/04 23:36:46.0919 Teefer2 (1de2e1357552a79f39bff003a11c533e) C:\Windows\system32\DRIVERS\teefer2.sys
2010/10/04 23:36:47.0029 TermDD (60995be8152fcbe6561722ce8a888e23) C:\Windows\system32\DRIVERS\termdd.sys
2010/10/04 23:36:47.0029 Suspicious file (Forged): C:\Windows\system32\DRIVERS\termdd.sys. Real md5: 60995be8152fcbe6561722ce8a888e23, Fake md5: fe4edcb804966ebe77361151bb960add
2010/10/04 23:36:47.0029 TermDD - detected Rootkit.Win32.TDSS.tdl3 (0)
2010/10/04 23:36:47.0387 tifm21 (e4c85c291ddb3dc5e4a2f227ca465ba6) C:\Windows\system32\drivers\tifm21.sys
2010/10/04 23:36:47.0621 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys
2010/10/04 23:36:47.0840 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/10/04 23:36:47.0918 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2010/10/04 23:36:47.0996 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2010/10/04 23:36:48.0043 TVALZ (521c5f39829875adf5466dd94c6282c7) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
2010/10/04 23:36:48.0355 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
2010/10/04 23:36:48.0448 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2010/10/04 23:36:48.0542 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2010/10/04 23:36:48.0651 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2010/10/04 23:36:48.0760 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2010/10/04 23:36:48.0854 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2010/10/04 23:36:48.0932 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2010/10/04 23:36:49.0072 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/10/04 23:36:49.0150 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2010/10/04 23:36:49.0369 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2010/10/04 23:36:49.0478 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2010/10/04 23:36:49.0540 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2010/10/04 23:36:49.0634 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2010/10/04 23:36:49.0696 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2010/10/04 23:36:49.0774 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/10/04 23:36:49.0837 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/10/04 23:36:49.0946 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2010/10/04 23:36:50.0055 UVCFTR (3b929a72aaea96dc0150d3a6da268c89) C:\Windows\system32\Drivers\UVCFTR_S.SYS
2010/10/04 23:36:50.0539 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/10/04 23:36:50.0679 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2010/10/04 23:36:50.0788 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2010/10/04 23:36:50.0866 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2010/10/04 23:36:50.0944 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
2010/10/04 23:36:51.0085 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2010/10/04 23:36:51.0163 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2010/10/04 23:36:51.0256 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2010/10/04 23:36:51.0334 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2010/10/04 23:36:51.0475 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2010/10/04 23:36:51.0553 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/04 23:36:51.0584 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2010/10/04 23:36:51.0646 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2010/10/04 23:36:51.0771 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2010/10/04 23:36:51.0989 WmiAcpi (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
2010/10/04 23:36:52.0083 WPS (c1620ebb375d3b02e31fd311c44fedeb) C:\Windows\system32\drivers\wpsdrvnt.sys
2010/10/04 23:36:52.0192 WpsHelper (ff983a25ae6f7d3f87f26bf51f02a201) C:\Windows\system32\drivers\WpsHelper.sys
2010/10/04 23:36:52.0411 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/10/04 23:36:52.0676 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/10/04 23:36:52.0769 ================================================================================
2010/10/04 23:36:52.0769 Scan finished
2010/10/04 23:36:52.0769 ================================================================================
2010/10/04 23:36:52.0785 Detected object count: 2
2010/10/04 23:37:20.0943 Locked file(sptd) - User select action: Skip
2010/10/04 23:37:21.0052 TermDD (60995be8152fcbe6561722ce8a888e23) C:\Windows\system32\DRIVERS\termdd.sys
2010/10/04 23:37:21.0052 Suspicious file (Forged): C:\Windows\system32\DRIVERS\termdd.sys. Real md5: 60995be8152fcbe6561722ce8a888e23, Fake md5: fe4edcb804966ebe77361151bb960add
2010/10/04 23:37:21.0271 Backup copy found, using it..
2010/10/04 23:37:21.0395 C:\Windows\system32\DRIVERS\termdd.sys - will be cured after reboot
2010/10/04 23:37:21.0395 Rootkit.Win32.TDSS.tdl3(TermDD) - User select action: Cure
2010/10/04 23:37:38.0197 Deinitialize success

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4742

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

5-10-2010 0:04:43
mbam-log-2010-10-05 (00-04-43).txt

Scan type: Quick scan
Objects scanned: 159240
Time elapsed: 18 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Frank Beurskens\AppData\Local\Temp\~DFBD8A.tmp (Trojan.Downloader) -> Delete on reboot.
C:\Windows\Temp\rptssn.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
  • 0

#6
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
No probs, your PC is looking better now but I just want a couple of other programs running to see if any nasties are still lurking :D

As for the Anti Virus programs you have installed, I would probably slightly edge on keeping Symantec as it did detect the evidence of this rootkit with the Tidserv warnings, but there's probably not an awful lot to choose between the two though. My personal favourite paid Anti Virus programs are Kaspersky and Eset Nod32, so when you next think about buying one it's worth taking a look at those ;)

You can also go down the free AV route in the future if you wanted, as Microsoft Security Essentials and Avast are both good in my opinion, but for now if you want to just uninstall one of the two you've got at the moment and leave the other on, that's fine ;)


Ok, lets get a couple of other scans done, please follow the steps below, in order...



1)
Uninstall one of the Anti Virus programs, leaving just one installed.



2)
Download ComboFix from one of these locations:

Link 1
Link 2


IMPORTANT !!! You need to Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you are still unsure on how to do this, see here
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click Yes, to continue scanning for malware. Please be patient and don't use the PC whilst it is scanning.

When finished, it shall produce a log for you. Please copy & paste the contents of this log (also found at C:\ComboFix.txt) in your next reply.




3)
Get a second look using an online Anti Virus scan
Kaspersky Online Scan

Java updates
  • Click the Start button
  • Click Control Panel
  • Double Click Java
  • Click the Update tab
  • Click Update Now
  • Allow any updates to be downloaded and installed

If the Java icon is not visible in Control Panel, please go to here and click "Free Java Download" to get the latest version.


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report... at the bottom.
  • Click the Save report... button.

    Posted Image

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply




In your next reply
Please post the contents of...
ComboFix log
Kaspersky Online Scan log

  • 0

#7
Vladice

Vladice

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hey BlackOxide,

I did the last tests and it seems that my laptop is a lot cleaner now! And I uninstalled Mcafee btw.

Here are the logs:

ComboFix 10-10-06.02 - Frank Beurskens 07-10-2010 9:01.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3070.2112 [GMT 2:00]
Gestart vanuit: e:\bureaublad\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\Frank Beurskens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk

.
(((((((((((((((((((( Bestanden Gemaakt van 2010-09-07 to 2010-10-07 ))))))))))))))))))))))))))))))
.

2010-10-07 07:10 . 2010-10-07 07:11 -------- d-----w- c:\users\Frank Beurskens\AppData\Local\temp
2010-10-07 07:10 . 2010-10-07 07:10 -------- d-----w- c:\users\Ralf\AppData\Local\temp
2010-10-07 07:10 . 2010-10-07 07:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-04 22:39 . 2010-10-04 22:39 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-10-04 22:26 . 2010-06-22 13:30 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-04 22:22 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-10-04 22:12 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-10-04 22:12 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-10-04 22:11 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-04 21:45 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-04 21:44 . 2010-10-04 21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-04 21:44 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-01 06:07 . 2008-04-07 03:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2010-10-01 06:07 . 2008-04-07 03:38 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2010-09-30 19:56 . 2010-09-30 19:56 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-09-23 17:19 . 2010-09-23 17:19 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\ArcSoft
2010-09-08 23:49 . 2010-09-08 23:49 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\InstallShield
2010-09-08 22:24 . 2010-08-14 12:20 614400 ----a-w- c:\windows\system32\msvcr80.dll
2010-09-08 22:24 . 2010-08-14 12:16 540672 ----a-w- c:\windows\system32\msvcp80.dll
2010-09-08 22:22 . 2010-09-08 22:36 -------- d-----w- c:\programdata\InstallShield
2010-09-08 22:22 . 2010-09-08 22:22 -------- d-----w- c:\program files\Common Files\InstallShield Shared
2010-09-08 22:18 . 2010-09-08 23:13 -------- d-----w- c:\program files\ASGvis

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-07 07:04 . 2006-11-02 16:11 670256 ----a-w- c:\windows\system32\perfh013.dat
2010-10-07 07:04 . 2006-11-02 16:11 127698 ----a-w- c:\windows\system32\perfc013.dat
2010-10-07 06:57 . 2010-06-21 09:42 -------- d-----w- c:\program files\Common Files\Akamai
2010-10-07 06:47 . 2010-03-14 12:04 -------- d-----w- c:\program files\McAfee
2010-10-06 16:05 . 2010-06-24 23:01 680 ----a-w- c:\users\Frank Beurskens\AppData\Local\d3d9caps.dat
2010-10-05 08:05 . 2010-07-16 09:07 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox
2010-10-05 07:56 . 2010-03-14 19:48 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-04 22:39 . 2010-03-14 12:26 -------- d-----w- c:\programdata\Microsoft Help
2010-10-04 22:35 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-10-04 21:38 . 2010-03-21 09:15 53224 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-10-01 15:13 . 2007-04-26 08:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-10-01 13:53 . 2006-05-28 21:54 157184 ----a-w- c:\users\Frank Beurskens\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-01 10:43 . 2010-03-14 20:17 -------- d-----w- c:\programdata\FLEXnet
2010-10-01 10:23 . 2010-04-29 08:50 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\uTorrent
2010-10-01 08:45 . 2010-03-14 20:26 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-10-01 08:30 . 2007-04-26 06:48 -------- d-----w- c:\program files\Common Files\Java
2010-10-01 08:29 . 2007-04-26 06:48 -------- d-----w- c:\program files\Java
2010-10-01 08:26 . 2010-09-02 19:20 -------- d-----w- c:\program files\OpenOffice.org 3
2010-10-01 08:17 . 2010-08-22 12:41 -------- d-----w- c:\program files\Poker Tracker V2
2010-10-01 08:16 . 2010-04-01 20:21 158404 ----a-w- c:\windows\hpoins19.dat
2010-10-01 08:16 . 2010-08-22 13:12 -------- d-----w- c:\program files\RedKings
2010-10-01 08:08 . 2010-04-29 08:51 -------- d-----w- c:\program files\uTorrent
2010-10-01 06:08 . 2006-11-02 10:25 51200 ----a-w- c:\windows\Inf\infpub.dat
2010-10-01 06:08 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstrng.dat
2010-10-01 06:08 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstor.dat
2010-09-23 17:19 . 2007-04-26 06:59 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-10 20:32 . 2010-08-27 13:37 167936 ----a-w- c:\windows\system32\drivers\wpshelper.sys
2010-09-10 12:58 . 2010-09-02 19:26 1 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-09-09 13:02 . 2010-04-01 21:08 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Image Zone Express
2010-09-08 23:48 . 2007-04-26 06:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-07 06:50 . 2010-09-07 06:50 -------- d-----w- c:\programdata\WindowsSearch
2010-09-06 07:52 . 2010-06-23 08:03 151720 ----a-w- c:\users\Ralf\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-02 19:26 . 2010-09-02 19:26 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\OpenOffice.org
2010-09-02 19:17 . 2010-09-02 19:17 -------- d-----w- c:\program files\OpenOffice
2010-08-27 13:37 . 2007-04-26 07:59 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-08-27 13:37 . 2007-04-26 07:59 -------- d-----w- c:\programdata\Symantec
2010-08-27 13:35 . 2010-06-09 15:02 -------- d-----w- c:\program files\Symantec
2010-08-27 13:35 . 2010-08-27 13:34 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-08-27 13:35 . 2010-08-27 13:34 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-08-27 13:34 . 2010-08-27 13:34 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-08-27 12:49 . 2010-04-20 07:44 -------- d-----w- c:\program files\QuickTime
2010-08-27 12:30 . 2010-06-06 18:19 112 ----a-w- c:\programdata\2daP0cNV.dat
2010-08-27 10:35 . 2010-06-01 21:26 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\B6A98F94978EA990DC26A8BA87631964
2010-08-24 20:31 . 2010-06-14 18:25 -------- d-----w- c:\program files\MSECache
2010-08-24 20:30 . 2010-08-24 20:30 -------- d-----w- c:\program files\LinkedIn
2010-08-19 10:30 . 2010-03-14 20:28 -------- d-----w- c:\programdata\Autodesk
2010-08-19 10:17 . 2010-03-14 20:29 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Autodesk
2010-08-19 10:13 . 2010-08-19 10:13 57344 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Autodesk\ACA 2011\enu\ContextualTabSelectorRules.dll
2010-08-19 09:31 . 2010-03-14 20:26 -------- d-----w- c:\program files\Autodesk
2010-07-17 03:00 . 2010-09-02 19:19 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 09:12 . 2010-07-16 09:07 89831 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\Uninstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe" [2010-08-19 232912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-04-03 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"NDSTray.exe"="NDSTray.exe" [BU]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IME JPN 2007 Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE" [2009-02-14 63856]
"Korean IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 26400]
"Microsoft Pinyin IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE" [2008-11-04 33128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-08 115560]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\Ralf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Frank Beurskens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2007-04-10 14:40 413696 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-746755872-990099436-3570819603-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001

R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2009-07-14 23888]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-14 691696]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-08-19 102448]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.archdaily.com/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch...cker_url2.pl?NL
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co...nk-21&site=home
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch...acker_url.pl?NL
.
.
------- Bestandsassociaties -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS VERWIJDERD - - - -

HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
SafeBoot-klmdb.sys
SafeBoot-Symantec Antvirus
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\uninstall_plugin.exe


.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_USERS\S-1-5-21-746755872-990099436-3570819603-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D1A24D24-A61A-AC57-39BE-B7D63877EDEB}*]
"iapfccnpkedakkdemd"=hex:63,61,6d,6a,66,69,00,61
"hadhgmjfdlcnjabh"=hex:67,61,61,6b,65,69,6d,6a,6b,65,66,61,62,61,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Voltooingstijd: 2010-10-07 09:15:05
ComboFix-quarantined-files.txt 2010-10-07 07:15

Pre-Run: 47.566.204.928 bytes beschikbaar
Post-Run: 48.640.880.640 bytes beschikbaar

- - End Of File - - DF54EEC81C5E00E99EEDA4CE236BC61A

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, October 7, 2010
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, October 06, 2010 11:54:00
Records in database: 4280474
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan statistics:
Objects scanned: 391985
Threats found: 4
Infected objects found: 66
Suspicious objects found: 0
Scan duration: 07:53:48


File name / Threat / Threats count
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180000\4E1FB168.VBN Infected: Trojan-Downloader.Win32.Agent.dwej 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180003\4E1FB855.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180004\4E1FBAAE.VBN Infected: Trojan-Downloader.Win32.Agent.dxut 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180005\4E1FBD0B.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180006\4E1FBF62.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180007\4E1FC1BC.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180008\4E1FC416.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180009\4E1FC670.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000A\4E1FC8C9.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000B\4E1FCB29.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000C\4E1FCD82.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000D\4E1FCFDC.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000E\4E1FD236.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0218000F\4E1FD492.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180010\4E1FD6EA.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180011\4E1FD947.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180012\4E1FDBC2.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\02180013\4E1FDE1A.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80000\4DAFE12D.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80001\4DAFE32E.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80002\4DAFE59E.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80003\4DAFE7FA.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80004\4DAFEA3B.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80005\4DAFEFA5.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80006\4DAFF655.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80007\4DAFF668.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80008\4DAFF67F.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A80009\4DAFF692.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A8000A\4DAFF862.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A8000B\4DAFFAD5.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\05A8000C\4DAFFD48.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\0F5C0000\4F7D14A3.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\ProgramData\Symantec\Symantec Endpoint Protection\Quarantine\15440000\5D568FF8.VBN Infected: Trojan-Downloader.Win32.Agent.dwej 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180000\4E1FB168.VBN Infected: Trojan-Downloader.Win32.Agent.dwej 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180003\4E1FB855.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180004\4E1FBAAE.VBN Infected: Trojan-Downloader.Win32.Agent.dxut 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180005\4E1FBD0B.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180006\4E1FBF62.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180007\4E1FC1BC.VBN Infected: Trojan-Downloader.Win32.Agent.dvup 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180008\4E1FC416.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180009\4E1FC670.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000A\4E1FC8C9.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000B\4E1FCB29.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000C\4E1FCD82.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000D\4E1FCFDC.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000E\4E1FD236.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0218000F\4E1FD492.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180010\4E1FD6EA.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180011\4E1FD947.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180012\4E1FDBC2.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\02180013\4E1FDE1A.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80000\4DAFE12D.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80001\4DAFE32E.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80002\4DAFE59E.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80003\4DAFE7FA.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80004\4DAFEA3B.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80005\4DAFEFA5.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80006\4DAFF655.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80007\4DAFF668.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80008\4DAFF67F.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A80009\4DAFF692.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A8000A\4DAFF862.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A8000B\4DAFFAD5.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\05A8000C\4DAFFD48.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\0F5C0000\4F7D14A3.VBN Infected: Trojan-Downloader.Win32.Agent.dtfw 1
C:\Users\All Users\Symantec\Symantec Endpoint Protection\Quarantine\15440000\5D568FF8.VBN Infected: Trojan-Downloader.Win32.Agent.dwej 1

Selected area has been scanned.
  • 0

#8
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts

I did the last tests and it seems that my laptop is a lot cleaner now! And I uninstalled Mcafee btw.

:D


Looking better now, I just want you to run one more CF scan for me using the instructions below then we'll do one more Quick Scan with MBAM to see if those two that it detected earlier are now gone ;)

Please follow the steps below carefully...


1)
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

RegNull::
[HKEY_USERS\S-1-5-21-746755872-990099436-3570819603-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D1A24D24-A61A-AC57-39BE-B7D63877EDEB}*]


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




2)
Run a Quick Scan with Malwarebytes Anti-Malware (MBAM) after updating...
  • Open MBAM
  • Click the Update tab, then click Check for Updates and let it install any updates if they are available
  • Click the Scanner tab, then make sure Quick Scan is selected and click Scan
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • Post the log that it produces in your next reply



In your next reply
Please post the contents of...
ComboFix log
MBAM log

  • 0

#9
Vladice

Vladice

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Here are the ComboFix and MBAM logs:

ComboFix 10-10-06.02 - Frank Beurskens 10-10-2010 21:03:25.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3070.1937 [GMT 2:00]
Gestart vanuit: e:\bureaublad\ComboFix.exe
gebruikte Opdracht switches :: e:\bureaublad\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((( Bestanden Gemaakt van 2010-09-10 to 2010-10-10 ))))))))))))))))))))))))))))))
.

2010-10-10 19:11 . 2010-10-10 19:11 -------- d-----w- c:\users\Ralf\AppData\Local\temp
2010-10-10 19:11 . 2010-10-10 19:11 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-10-10 19:11 . 2010-10-10 19:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-07 07:15 . 2010-10-10 19:11 -------- d-----w- c:\users\Frank Beurskens\AppData\Local\temp
2010-10-04 22:39 . 2010-10-04 22:39 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-10-04 22:26 . 2010-06-22 13:30 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-04 22:22 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-10-04 22:12 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-10-04 22:12 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-10-04 22:11 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-04 21:45 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-04 21:44 . 2010-10-04 21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-04 21:44 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-01 06:07 . 2008-04-07 03:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2010-10-01 06:07 . 2008-04-07 03:38 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2010-09-30 19:56 . 2010-09-30 19:56 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-09-23 17:19 . 2010-09-23 17:19 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\ArcSoft

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-10 18:50 . 2006-11-02 16:11 670256 ----a-w- c:\windows\system32\perfh013.dat
2010-10-10 18:50 . 2006-11-02 16:11 127698 ----a-w- c:\windows\system32\perfc013.dat
2010-10-10 18:44 . 2010-07-16 09:07 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox
2010-10-10 18:43 . 2010-06-21 09:42 -------- d-----w- c:\program files\Common Files\Akamai
2010-10-07 10:50 . 2010-04-01 20:21 158404 ----a-w- c:\windows\hpoins19.dat
2010-10-07 06:47 . 2010-03-14 12:04 -------- d-----w- c:\program files\McAfee
2010-10-06 16:05 . 2010-06-24 23:01 680 ----a-w- c:\users\Frank Beurskens\AppData\Local\d3d9caps.dat
2010-10-05 07:56 . 2010-03-14 19:48 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-04 22:39 . 2010-03-14 12:26 -------- d-----w- c:\programdata\Microsoft Help
2010-10-04 22:35 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-10-04 21:38 . 2010-03-21 09:15 53224 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-10-01 15:13 . 2007-04-26 08:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-10-01 13:53 . 2006-05-28 21:54 157184 ----a-w- c:\users\Frank Beurskens\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-01 10:43 . 2010-03-14 20:17 -------- d-----w- c:\programdata\FLEXnet
2010-10-01 10:23 . 2010-04-29 08:50 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\uTorrent
2010-10-01 08:45 . 2010-03-14 20:26 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-10-01 08:30 . 2007-04-26 06:48 -------- d-----w- c:\program files\Common Files\Java
2010-10-01 08:29 . 2007-04-26 06:48 -------- d-----w- c:\program files\Java
2010-10-01 08:26 . 2010-09-02 19:20 -------- d-----w- c:\program files\OpenOffice.org 3
2010-10-01 08:17 . 2010-08-22 12:41 -------- d-----w- c:\program files\Poker Tracker V2
2010-10-01 08:16 . 2010-08-22 13:12 -------- d-----w- c:\program files\RedKings
2010-10-01 08:08 . 2010-04-29 08:51 -------- d-----w- c:\program files\uTorrent
2010-10-01 06:08 . 2006-11-02 10:25 51200 ----a-w- c:\windows\Inf\infpub.dat
2010-10-01 06:08 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstrng.dat
2010-10-01 06:08 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstor.dat
2010-09-23 17:19 . 2007-04-26 06:59 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-10 20:32 . 2010-08-27 13:37 167936 ----a-w- c:\windows\system32\drivers\wpshelper.sys
2010-09-10 12:58 . 2010-09-02 19:26 1 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-09-09 13:02 . 2010-04-01 21:08 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Image Zone Express
2010-09-08 23:49 . 2010-09-08 23:49 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\InstallShield
2010-09-08 23:48 . 2007-04-26 06:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-08 23:13 . 2010-09-08 22:18 -------- d-----w- c:\program files\ASGvis
2010-09-08 22:36 . 2010-09-08 22:22 -------- d-----w- c:\programdata\InstallShield
2010-09-08 22:22 . 2010-09-08 22:22 -------- d-----w- c:\program files\Common Files\InstallShield Shared
2010-09-07 06:50 . 2010-09-07 06:50 -------- d-----w- c:\programdata\WindowsSearch
2010-09-06 07:52 . 2010-06-23 08:03 151720 ----a-w- c:\users\Ralf\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-02 19:26 . 2010-09-02 19:26 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\OpenOffice.org
2010-09-02 19:17 . 2010-09-02 19:17 -------- d-----w- c:\program files\OpenOffice
2010-08-27 13:37 . 2007-04-26 07:59 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-08-27 13:37 . 2007-04-26 07:59 -------- d-----w- c:\programdata\Symantec
2010-08-27 13:35 . 2010-06-09 15:02 -------- d-----w- c:\program files\Symantec
2010-08-27 13:35 . 2010-08-27 13:34 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-08-27 13:35 . 2010-08-27 13:34 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-08-27 13:34 . 2010-08-27 13:34 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-08-27 12:49 . 2010-04-20 07:44 -------- d-----w- c:\program files\QuickTime
2010-08-27 12:30 . 2010-06-06 18:19 112 ----a-w- c:\programdata\2daP0cNV.dat
2010-08-27 10:35 . 2010-06-01 21:26 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\B6A98F94978EA990DC26A8BA87631964
2010-08-24 20:31 . 2010-06-14 18:25 -------- d-----w- c:\program files\MSECache
2010-08-24 20:30 . 2010-08-24 20:30 -------- d-----w- c:\program files\LinkedIn
2010-08-19 10:30 . 2010-03-14 20:28 -------- d-----w- c:\programdata\Autodesk
2010-08-19 10:17 . 2010-03-14 20:29 -------- d-----w- c:\users\Frank Beurskens\AppData\Roaming\Autodesk
2010-08-19 10:13 . 2010-08-19 10:13 57344 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Autodesk\ACA 2011\enu\ContextualTabSelectorRules.dll
2010-08-19 09:31 . 2010-03-14 20:26 -------- d-----w- c:\program files\Autodesk
2010-08-14 12:20 . 2010-09-08 22:24 614400 ----a-w- c:\windows\system32\msvcr80.dll
2010-08-14 12:16 . 2010-09-08 22:24 540672 ----a-w- c:\windows\system32\msvcp80.dll
2010-07-17 03:00 . 2010-09-02 19:19 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 09:12 . 2010-07-16 09:07 89831 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\Uninstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-04-03 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"NDSTray.exe"="NDSTray.exe" [BU]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IME JPN 2007 Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE" [2009-02-14 63856]
"Korean IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 26400]
"Microsoft Pinyin IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE" [2008-11-04 33128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-08 115560]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\Ralf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Frank Beurskens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2007-04-10 14:40 413696 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-746755872-990099436-3570819603-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001

R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2009-07-14 23888]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-14 691696]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-08-19 102448]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.archdaily.com/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch...cker_url2.pl?NL
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co...nk-21&site=home
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch...acker_url.pl?NL
.
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------

- - - - - - - > 'Explorer.exe'(3296)
c:\users\Frank Beurskens\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Voltooingstijd: 2010-10-10 21:13:49
ComboFix-quarantined-files.txt 2010-10-10 19:13
ComboFix2.txt 2010-10-07 07:15

Pre-Run: 55.531.724.800 bytes beschikbaar
Post-Run: 55.495.630.848 bytes beschikbaar

- - End Of File - - BF251918857993F9AB9E0F2424EA3A3D

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4791

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

10-10-2010 21:42:21
mbam-log-2010-10-10 (21-42-21).txt

Scan type: Quick scan
Objects scanned: 157669
Time elapsed: 6 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#10
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Good stuff, your logs now appear clean :D

Please go through the Cleanup section below and have a read of the other information which will help keep your PC protected ;)

Just let me know if you have any other queries or problems ;)


Thank you for following the procedures, your system now appears free from Malware. Below is a list of steps that are well worth following, they help finalize the fixes we have been doing and will help minimize the risk of a smilar situation happening again by protecting your PC and helping secure it.

Please make sure you follow the Cleanup stage just below.


========== CLEANUP ==========

Remove the Tools used in this cleanup

1)
Tools on the Desktop:
You can now safely remove GMER and TDSSKiller from the Desktop (if present)

2)
Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK
    Posted Image
  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled

3)
Clear Old Restore Points
  • Run OTL, copy and paste the following into the Custom Scans/Fixes area at the bottom
    :Commands
    [CLEARALLRESTOREPOINTS]
  • Then Click Run Fix

4)
OTL Cleanup
  • Open OTL
  • Click the CleanUp button at the top, it will ask to reboot your PC, please allow it to do so


========== Anti Malware Protection ==========

Spyware Blaster
Spyware Blaster is an excellent program that creates a huge list of known suspect/dangerous sites and blocks any attempts to visit those sites by embedding the list into Internet Explorer and Firefox. Very useful to have!

MalwareBytes Anti-Malware
This is an excellent Anti-Malware product. It is recommended to periodically run a Quick Scan to keep your PC as clean as possible.

Free Anti-Virus protection...
If you haven't got an AntiVirus or are thinking of changing, my personal recommendations are Microsoft Security Essentials and Avast, both are free to use. Remember though, you can only have one AntiVirus installed at any one given time.
Microsoft Security Essentials
Avast

========== Updates ==========

Keeping your PC updated is vital in the battle against infections and exploits. There are many infections which will exploit loopholes within Windows itself, Java and Adobe Reader. Keeping these updated is a very good habit to get into.

Automatic Updates

Updates to your Operating System are vital in closing loopholes and fixing bugs which some infections exploit.
To keep your Windows updated, ensure that 'Automatic Updates' is enabled on your PC. To do this...
  • In XP,
  • Click the Start button
  • Click Run
  • Type sysdm.cpl into the run dialogue box and click OK
  • Click the Automatic Updates tab
  • Make sure Automatic (Recommended) is selected and click OK

    In Vista,
  • Click the Start button
  • Click All Programs, then click Windows Update
  • In the left pane, click Change Settings
  • Choose Install updates autmatically (recommended), then click OK
Java updates
  • Click the Start button
  • Click Control Panel
  • Double Click Java
  • Click the Update tab
  • Click Update Now
  • Allow any updates to be downloaded and installed
Adobe Reader updates
  • Open Adobe Reader
  • Click Help on the menu at the top
  • Click Check for Updates
  • Allow any updates to be downloaded and installed
========== Alternate Browsers ==========

Using an alternative web browser can help protect your PC from infections which exploit security holes within Internet Explorer. They can also be quicker to load pages and offer more tools and features such as Firefox's huge addon list.

Firefox - My personal choice, easy to use, safer to use than Internet Explorer and a large number of excellent addons that can be installed such as AdBlockPlus and WOT.

Opera - Another efficient browser that works well. Quick and easy to use.


Have fun and stay safe online ;)
BlackOxide

  • 0

#11
Vladice

Vladice

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thanks for your help once more!
I really appreciate it.

Cheers!

Edited by Vladice, 13 October 2010 - 06:11 AM.

  • 0

#12
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
No problem, you're welcome ;)

Glad we could help you out here :D
  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :D

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP