I've been having problems with Firefox opening new windows by itself. Each window has four tabs with the following addresses:
hxxp://www.xn--&-8ga.com/
hxxp://www.xn--pda.com/
file:///C:/Program%20Files/Mozilla%20Firefox/
file:///C:/Program%20Files/Mozilla%20Firefox/T%E2%80%98%C3%91%C3%A5%C2%AD%C2%
I looked around for a guide on how to delete the virus but came up empty. If someone would be so kind as to help me out I'd really appreciate it!
Here is the OTL Report:
OTL logfile created on: 21-7-2011 22:21:46 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Ingrid\Bureaublad
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
894,42 Mb Total Physical Memory | 48,40 Mb Available Physical Memory | 5,41% Memory free
2,12 Gb Paging File | 1,34 Gb Available in Paging File | 63,26% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69,40 Gb Total Space | 2,82 Gb Free Space | 4,07% Space Free | Partition Type: NTFS
Drive D: | 69,89 Gb Total Space | 2,06 Gb Free Space | 2,94% Space Free | Partition Type: NTFS
Drive H: | 960,00 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: STANLEY | User Name: Ingrid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-07-21 22:20:44 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ingrid\Bureaublad\OTL.exe
PRC - [2011-06-23 18:12:18 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011-04-17 02:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
PRC - [2010-10-25 11:07:48 | 000,095,568 | ---- | M] (Devguru Co., Ltd.) -- C:\WINDOWS\system32\dgdersvc.exe
PRC - [2010-10-25 11:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2009-07-13 23:18:12 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2008-09-05 11:52:32 | 003,220,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
PRC - [2008-08-28 11:19:34 | 001,630,208 | ---- | M] (Sitecom Europe BV) -- C:\Program Files\Sitecom\Common\RaUI.exe
PRC - [2008-05-13 16:12:54 | 000,069,632 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\Sitecom\Common\RegistryWriter.exe
PRC - [2008-04-15 14:00:00 | 001,037,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-02-20 16:02:00 | 000,308,600 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
PRC - [2008-02-20 16:02:00 | 000,238,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007-12-10 20:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2007-01-30 00:39:34 | 001,432,064 | ---- | M] (Phoenix Labs) -- C:\Program Files\uTorrent\PeerGuardian2\pg2.exe
PRC - [2006-11-03 19:20:12 | 000,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006-11-03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
========== Modules (SafeList) ==========
MOD - [2011-07-21 22:20:44 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ingrid\Bureaublad\OTL.exe
MOD - [2011-04-29 02:29:01 | 000,413,112 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\18.6.0.29\asoehook.dll
MOD - [2009-07-12 01:02:02 | 000,653,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
MOD - [2009-07-12 01:02:00 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
MOD - [2008-04-15 14:00:00 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011-04-17 02:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe -- (NIS)
SRV - [2010-10-25 11:07:48 | 000,095,568 | ---- | M] (Devguru Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\dgdersvc.exe -- (dgdersvc)
SRV - [2010-10-25 11:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2009-07-13 23:18:12 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2008-09-05 11:52:32 | 003,220,856 | ---- | M] (Symantec Corporation) [On_Demand | Running] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)
SRV - [2008-05-13 16:12:54 | 000,069,632 | ---- | M] (Ralink Technology, Corp.) [Auto | Running] -- C:\Program Files\Sitecom\Common\RegistryWriter.exe -- (RalinkRegistryWriter)
SRV - [2008-05-06 00:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008-02-20 16:02:00 | 000,238,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2007-12-10 20:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006-11-03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011-07-07 17:01:40 | 000,355,256 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110720.031\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011-06-16 20:20:31 | 001,542,392 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110721.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2011-06-16 20:20:31 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011-06-16 20:20:31 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110721.003\NAVENG.SYS -- (NAVENG)
DRV - [2011-05-19 21:37:06 | 000,810,616 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110701.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011-05-11 15:55:52 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011-05-10 10:38:48 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011-03-31 05:00:09 | 000,516,216 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SRTSP.SYS -- (SRTSP)
DRV - [2011-03-31 05:00:09 | 000,050,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1206000.01D\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011-03-22 02:39:49 | 000,369,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\NIS\1206000.01D\SYMTDI.SYS -- (SYMTDI)
DRV - [2011-03-15 04:31:23 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMEFA.SYS -- (SymEFA)
DRV - [2011-01-27 08:47:10 | 000,340,088 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1206000.01D\SYMDS.SYS -- (SymDS)
DRV - [2011-01-27 07:07:05 | 000,136,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1206000.01D\Ironx86.SYS -- (SymIRON)
DRV - [2010-10-25 11:07:48 | 000,018,120 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010-10-25 11:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010-08-27 06:32:08 | 000,121,576 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2010-08-27 06:32:08 | 000,096,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2010-08-27 06:32:08 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2009-02-10 17:23:02 | 000,082,320 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive)
DRV - [2008-10-29 15:34:40 | 000,644,096 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
DRV - [2008-05-20 02:53:00 | 004,800,000 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-04-15 14:00:00 | 000,053,504 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\volsnap.sys -- (VolSnap)
DRV - [2008-01-28 21:37:48 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008-01-28 21:37:46 | 000,054,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008-01-07 01:54:50 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2007-01-30 00:16:42 | 000,006,144 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\uTorrent\PeerGuardian2\pgfilter.sys -- (pgfilter)
DRV - [2005-01-13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2002-11-28 16:18:04 | 000,015,360 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [1999-09-10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emac...d=0409&m=el1200
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ig?hl=nl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.9.2
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.51
FF - prefs.js..extensions.enabledItems: [email protected]:0.2.7
FF - prefs.js..extensions.enabledItems: [email protected]:5.0.1
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.0.8
FF - prefs.js..network.proxy.no_proxies_on: "local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\WINDOWS\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Ingrid\Local Settings\Application Data\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Ingrid\Local Settings\Application Data\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011-07-08 17:36:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_0_8 [2011-07-21 22:04:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-07-06 20:16:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-07-06 20:16:00 | 000,000,000 | ---D | M]
[2010-01-19 20:26:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Extensions
[2011-07-21 22:15:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions
[2010-04-27 21:33:18 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-07-02 17:13:36 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011-05-27 10:27:21 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2011-06-23 22:03:56 | 000,000,000 | ---D | M] (Adblock Plus Pop-up Addon) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\[email protected]
[2011-05-22 20:57:28 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\[email protected]
[2010-10-02 11:41:13 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\[email protected]
[2011-06-23 22:03:59 | 000,000,000 | ---D | M] (Form History Control) -- C:\Documents and Settings\Ingrid\Application Data\Mozilla\Firefox\Profiles\a62rnhkd.default\extensions\[email protected]
[2011-03-16 23:38:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011-07-21 22:04:11 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\COFFPLGN_2011_7_0_8
[2011-07-08 17:36:56 | 000,000,000 | ---D | M] (Symantec IPS) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPLGN
[2010-01-15 20:34:02 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011-03-03 19:14:40 | 000,001,892 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bolcom-nl.xml
[2011-03-03 19:14:40 | 000,004,558 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\marktplaats-nl.xml
[2011-03-03 19:14:40 | 000,001,111 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\vandale-nl.xml
[2011-03-03 19:14:40 | 000,001,049 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-nl.xml
[2011-03-03 19:14:40 | 000,001,106 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-nl.xml
O1 HOSTS File: ([2010-07-21 08:08:19 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (QuickNet BHO) - {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - File not found
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CloneCDElbyCDFL] C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe (Elaborate Bytes AG)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [KiesTrayAgent] File not found
O4 - HKCU..\Run: [oheOiUJvGfNI] File not found
O4 - HKCU..\Run: [PeerGuardian] C:\Program Files\uTorrent\PeerGuardian2\pg2.exe (Phoenix Labs)
O4 - HKCU..\Run: [Power2GoExpress] File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Common\RaUI.exe (Sitecom Europe BV)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.54.40.25 212.54.35.25
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mijn huidige introductiepagina) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-05 09:35:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006-11-13 15:24:41 | 000,000,175 | R--- | M] () - H:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{9cfc8c08-fc6d-11de-98f9-000cf654952e}\Shell\AutoRun\command - "" = I:\setupSNK.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\setup.exe -- [2006-11-13 15:24:41 | 000,463,152 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\H\Shell\configure\command - "" = H:\setup.exe -- [2006-11-13 15:24:41 | 000,463,152 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\H\Shell\install\command - "" = H:\setup.exe -- [2006-11-13 15:24:41 | 000,463,152 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-07-21 22:20:29 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ingrid\Bureaublad\OTL.exe
[2011-07-06 20:18:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\iTunes
[2011-07-06 20:16:45 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011-07-06 20:16:39 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011-07-06 20:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011-07-06 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\QuickTime
[2011-07-06 20:15:00 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011-07-06 20:14:27 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011-07-06 20:13:44 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011-07-06 20:12:19 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011-06-26 21:11:52 | 000,000,000 | ---D | C] -- C:\Warren Zevon
[2009-07-10 12:47:08 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Ingrid\Application Data\pcouffin.sys
[2009-04-10 16:23:29 | 000,016,384 | ---- | C] ( ) -- C:\WINDOWS\System32\ClearEvent.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-07-21 22:20:44 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ingrid\Bureaublad\OTL.exe
[2011-07-21 22:20:05 | 000,001,044 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-07-21 22:20:04 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-07-21 22:08:18 | 000,513,384 | ---- | M] () -- C:\WINDOWS\System32\perfh013.dat
[2011-07-21 22:08:18 | 000,092,564 | ---- | M] () -- C:\WINDOWS\System32\perfc013.dat
[2011-07-21 22:08:17 | 000,445,370 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-07-21 22:08:17 | 000,072,576 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-07-21 22:07:05 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011-07-21 22:03:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-07-21 22:03:38 | 937,938,944 | -HS- | M] () -- C:\hiberfil.sys
[2011-07-21 19:33:05 | 000,001,140 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1489460643-2323725418-3324827107-1006UA.job
[2011-07-17 14:46:18 | 000,001,044 | ---- | M] () -- C:\Documents and Settings\Ingrid\Application Data\vso_ts_preview.xml
[2011-07-17 12:33:02 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1489460643-2323725418-3324827107-1006Core.job
[2011-07-16 17:19:59 | 000,226,304 | ---- | M] () -- C:\Documents and Settings\Ingrid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-07-15 18:36:47 | 000,002,273 | ---- | M] () -- C:\Documents and Settings\Ingrid\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011-07-15 18:36:45 | 000,002,295 | ---- | M] () -- C:\Documents and Settings\Ingrid\Bureaublad\Google Chrome.lnk
[2011-07-13 17:50:53 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-07-12 20:12:57 | 006,896,215 | ---- | M] () -- C:\Documents and Settings\Ingrid\Bureaublad\LdR portfolio 2011.pdf
[2011-07-06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011-07-06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011-07-03 18:01:27 | 000,006,992 | ---- | M] () -- C:\{1D20E4E2-7D1E-4A61-B9AE-A0621B0CEA31}
[2011-07-02 20:34:40 | 000,374,250 | ---- | M] () -- C:\Documents and Settings\Ingrid\Bureaublad\CV_SPIROS GOGAS.pdf
[2011-07-02 17:27:11 | 000,114,445 | ---- | M] () -- C:\Documents and Settings\Ingrid\Bureaublad\Groupon-9952EDBE51.pdf
[2011-06-26 21:54:33 | 000,081,467 | ---- | M] () -- C:\Documents and Settings\Ingrid\Mijn documenten\Uchi Deshi 1.2.fdx
[2011-06-23 19:46:33 | 000,001,690 | ---- | M] () -- C:\Documents and Settings\Ingrid\Bureaublad\CyberLink PowerDirector.lnk
[2011-06-22 22:02:12 | 028,783,088 | ---- | M] () -- C:\Documents and Settings\Ingrid\Mijn documenten\Produce.avi
[2011-06-22 21:40:03 | 001,228,854 | ---- | M] () -- C:\Documents and Settings\Ingrid\Mijn documenten\Snapshot(1).bmp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-07-21 22:03:38 | 937,938,944 | -HS- | C] () -- C:\hiberfil.sys
[2011-07-12 20:12:40 | 006,896,215 | ---- | C] () -- C:\Documents and Settings\Ingrid\Bureaublad\LdR portfolio 2011.pdf
[2011-07-03 18:01:27 | 000,006,992 | ---- | C] () -- C:\{1D20E4E2-7D1E-4A61-B9AE-A0621B0CEA31}
[2011-07-02 20:32:45 | 000,374,250 | ---- | C] () -- C:\Documents and Settings\Ingrid\Bureaublad\CV_SPIROS GOGAS.pdf
[2011-07-02 17:27:06 | 000,114,445 | ---- | C] () -- C:\Documents and Settings\Ingrid\Bureaublad\Groupon-9952EDBE51.pdf
[2011-06-22 21:59:55 | 028,783,088 | ---- | C] () -- C:\Documents and Settings\Ingrid\Mijn documenten\Produce.avi
[2011-06-22 21:39:55 | 001,228,854 | ---- | C] () -- C:\Documents and Settings\Ingrid\Mijn documenten\Snapshot(1).bmp
[2011-04-18 10:13:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\null0.722122206150118.exe
[2011-04-15 22:32:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\null0.7659450352661257.exe
[2011-03-18 13:13:40 | 000,007,143 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\N360BUOptions.ini
[2011-03-16 19:11:22 | 000,000,062 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\17293108.lic
[2011-03-16 18:30:09 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~17293108r
[2011-03-16 18:30:09 | 000,000,096 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~17293108
[2011-03-16 18:29:32 | 000,000,472 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\17293108
[2011-03-11 20:03:07 | 000,075,480 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-01-21 23:58:32 | 000,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2010-12-04 01:02:33 | 000,667,768 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-11-29 00:03:11 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010-11-29 00:03:11 | 000,036,640 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010-10-25 23:10:21 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\rt2870.bin
[2010-10-25 11:09:56 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2010-10-25 11:09:56 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2010-10-25 11:09:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2010-10-25 11:09:56 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010-08-04 09:08:41 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010-01-19 20:25:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010-01-18 20:59:52 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\.811261211181235583101118113995
[2010-01-09 12:19:55 | 000,015,312 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2009-11-22 16:13:57 | 002,067,140 | R--- | C] () -- C:\WINDOWS\System32\avcodec.dll
[2009-07-20 18:22:53 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-07-12 11:59:43 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-07-12 11:59:41 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-07-10 12:48:07 | 000,001,044 | ---- | C] () -- C:\Documents and Settings\Ingrid\Application Data\vso_ts_preview.xml
[2009-07-10 12:47:08 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Ingrid\Application Data\inst.exe
[2009-07-10 12:47:08 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Ingrid\Application Data\pcouffin.cat
[2009-07-10 12:47:08 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Ingrid\Application Data\pcouffin.inf
[2009-05-14 04:18:04 | 000,279,629 | ---- | C] () -- C:\WINDOWS\esubmit.exe
[2009-05-09 22:40:39 | 000,226,304 | ---- | C] () -- C:\Documents and Settings\Ingrid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-05-09 21:58:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhotoNow.INI
[2009-04-11 01:08:11 | 000,009,728 | ---- | C] () -- C:\WINDOWS\HWID_detect.exe
[2009-04-10 16:21:24 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Ingrid\Local Settings\Application Data\fusioncache.dat
[2008-09-05 11:11:18 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008-09-05 11:11:02 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008-09-05 10:47:12 | 000,513,384 | ---- | C] () -- C:\WINDOWS\System32\perfh013.dat
[2008-09-05 10:47:12 | 000,445,370 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008-09-05 10:47:12 | 000,092,564 | ---- | C] () -- C:\WINDOWS\System32\perfc013.dat
[2008-09-05 10:47:12 | 000,072,576 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008-09-05 10:07:16 | 000,358,544 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008-09-05 09:48:42 | 000,001,024 | R--- | C] () -- C:\WINDOWS\System32\NTIOFM4.dll
[2008-09-05 09:48:42 | 000,001,024 | R--- | C] () -- C:\WINDOWS\System32\NTIBUN5.dll
[2008-09-05 09:47:54 | 000,001,024 | R--- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll
[2008-09-05 09:47:54 | 000,001,024 | R--- | C] () -- C:\WINDOWS\System32\NTIMP3.dll
[2008-09-05 09:35:04 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008-09-05 09:34:00 | 000,021,748 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-08-25 10:17:58 | 000,023,634 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008-07-10 08:06:32 | 000,524,288 | ---- | C] () -- C:\WINDOWS\Alaunch.exe
[2008-04-15 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008-04-15 14:00:00 | 000,318,670 | ---- | C] () -- C:\WINDOWS\System32\perfi013.dat
[2008-04-15 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008-04-15 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008-04-15 14:00:00 | 000,053,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\volsnap.sys
[2008-04-15 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008-04-15 14:00:00 | 000,039,178 | ---- | C] () -- C:\WINDOWS\System32\perfd013.dat
[2008-04-15 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008-04-15 14:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008-04-15 14:00:00 | 000,003,717 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008-04-15 14:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008-04-15 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008-02-24 21:29:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-02-24 21:29:00 | 001,626,112 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008-02-24 21:29:00 | 001,482,752 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-02-24 21:29:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008-02-24 21:29:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-02-24 21:29:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-02-24 21:29:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008-02-24 21:29:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008-02-24 21:29:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008-01-16 15:17:56 | 000,003,948 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2006-08-01 00:02:32 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2005-03-28 09:45:26 | 000,000,097 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
[2004-04-09 16:06:30 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\AudioLevel.dll
[2002-05-24 10:34:46 | 000,032,768 | ---- | C] () -- C:\WINDOWS\AMove.exe
[2001-12-26 16:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001-09-03 23:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001-08-26 11:04:08 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-26 11:02:42 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-07-30 16:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001-07-23 22:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
========== LOP Check ==========
[2010-12-29 14:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\A-PDF
[2011-02-13 23:38:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2009-07-11 10:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010-01-18 20:58:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2009-06-20 14:58:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
[2011-03-18 13:13:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2010-12-29 15:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlotSoft
[2010-11-28 23:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010-01-09 12:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sitecom Driver
[2011-03-16 23:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2009-07-10 18:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2009-04-11 15:59:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2009-04-11 00:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2009-04-10 18:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2011-07-06 20:17:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010-07-19 19:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\BD44EE4CCDFCB6D39F4628C5045063A4
[2010-03-30 21:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Belastingdienst
[2009-07-27 20:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Canneverbe_Limited
[2010-09-26 21:37:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\FileZilla
[2010-01-18 21:00:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Final Draft
[2011-01-21 23:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\FreeAudioPack
[2011-03-16 23:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Igsare
[2010-11-28 23:52:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Samsung
[2011-01-22 14:06:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Search Settings
[2010-09-26 21:21:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Spot Software
[2011-02-13 23:46:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\The Learning Company
[2011-07-20 23:05:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\uTorrent
[2011-07-17 14:46:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Vso
[2011-03-16 23:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ingrid\Application Data\Ymfiz
[2011-07-21 22:07:05 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:6971CCC5
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:CB0AACC9
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:A8ADE5D8
< End of report >