Thanks, my computer appears to be running normally. Had a small problem with the internet connection at the start but a reboot fixed it (as told by Combofix). Here are the logs:
OTL logfile created on: 9/10/2011 20:04:07 - Run 2
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Batmobiel\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy
2,00 Gb Total Physical Memory | 0,96 Gb Available Physical Memory | 47,97% Memory free
4,22 Gb Paging File | 3,14 Gb Available in Paging File | 74,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136,44 Gb Total Space | 3,14 Gb Free Space | 2,30% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 1,26 Gb Free Space | 12,60% Space Free | Partition Type: NTFS
Computer Name: PC_BATMOBIEL | User Name: Batmobiel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/10/09 17:02:58 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Batmobiel\Desktop\OTL.exe
PRC - [2011/09/29 09:28:21 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/07/18 20:43:00 | 000,243,360 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10u_Plugin.exe
PRC - [2011/01/07 22:09:32 | 000,585,728 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2010/09/16 14:06:22 | 000,080,896 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2009/11/13 13:31:14 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/11/13 13:31:12 | 000,247,144 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2009/03/12 18:36:24 | 000,086,016 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
PRC - [2009/01/26 16:31:16 | 002,144,088 | -HS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 16:31:12 | 005,365,592 | -HS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PRC - [2009/01/26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/10/29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/01/19 09:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 09:33:35 | 001,143,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wercon.exe
PRC - [2008/01/19 09:33:04 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2007/11/21 01:24:10 | 000,054,784 | ---- | M] (Macrovision) -- C:\Windows\System32\drivers\CDAC11BA.EXE
PRC - [2007/10/21 18:25:16 | 000,079,360 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
PRC - [2007/04/18 06:48:18 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/04/18 05:31:58 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/04/16 17:10:26 | 000,184,320 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2007/03/15 13:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/03/06 22:38:28 | 000,090,112 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/03/06 22:37:30 | 000,303,104 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\sttray.exe
PRC - [2007/02/20 14:01:12 | 001,125,088 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/02/13 17:28:14 | 000,032,768 | ---- | M] (Autodesk) -- C:\Program Files\Autodesk\Data Management Server 2008\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
PRC - [2007/02/13 17:26:46 | 000,049,152 | ---- | M] (Autodesk) -- C:\Program Files\Autodesk\Data Management Server 2008\Server\Webserver\Connectivity.EDMWS.Server.exe
PRC - [2006/11/05 12:22:16 | 000,221,184 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
PRC - [2006/11/05 11:55:48 | 000,010,752 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
PRC - [2006/11/03 18:55:50 | 000,703,280 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2006/11/03 18:55:48 | 001,583,920 | ---- | M] (Broadcom Corporation.) -- c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2006/09/09 01:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2006/09/09 01:06:08 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2005/01/18 17:47:30 | 000,458,752 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Video\ISStart.exe
PRC - [2005/01/18 17:37:30 | 000,217,088 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Video\LogiTray.exe
PRC - [2005/01/18 17:07:54 | 000,196,608 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Video\ManifestEngine.exe
========== Modules (No Company Name) ========== MOD - [2011/09/29 09:28:21 | 001,833,944 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/01/07 22:09:34 | 000,516,599 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll
MOD - [2011/01/07 22:09:32 | 000,585,728 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
MOD - [2011/01/07 22:09:32 | 000,352,256 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll
MOD - [2011/01/07 22:09:32 | 000,139,264 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll
MOD - [2011/01/07 22:09:32 | 000,139,264 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll
MOD - [2011/01/07 22:09:32 | 000,094,208 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll
MOD - [2008/06/19 18:35:36 | 000,333,288 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy\sqlite3.dll
MOD - [2007/02/20 14:01:18 | 000,105,184 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2006/11/05 11:58:44 | 000,516,096 | ---- | M] () -- C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll
MOD - [2006/11/05 11:28:18 | 004,587,520 | ---- | M] () -- C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll
MOD - [2006/11/03 18:46:24 | 000,126,976 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2006/11/03 18:25:56 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (McSysmon)
SRV - File not found [Unknown | Stopped] -- -- (McShield)
SRV - [2011/09/22 19:53:45 | 003,542,616 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_b31de1e.dll -- (Akamai)
SRV - [2011/09/02 15:29:30 | 002,152,152 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/09/16 14:06:22 | 000,080,896 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/12/04 03:27:28 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/11/13 13:31:14 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/03/12 18:36:24 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe -- (mi-raysat_3dsmax2010_32)
SRV - [2009/01/26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/01/19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/21 01:24:10 | 000,054,784 | ---- | M] (Macrovision) [Auto | Running] -- C:\Windows\System32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2007/10/21 18:25:16 | 000,079,360 | ---- | M] (Autodesk) [Auto | Running] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2007/03/19 13:44:44 | 000,070,656 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2007/03/06 22:38:28 | 000,090,112 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/02/13 17:28:14 | 000,032,768 | ---- | M] (Autodesk) [Auto | Running] -- C:\Program Files\Autodesk\Data Management Server 2008\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe -- (Autodesk Data Management Job Dispatch)
SRV - [2007/02/13 17:26:46 | 000,049,152 | ---- | M] (Autodesk) [Auto | Running] -- C:\Program Files\Autodesk\Data Management Server 2008\Server\Webserver\Connectivity.EDMWS.Server.exe -- (Autodesk EDM Server)
========== Driver Services (SafeList) ========== DRV - [2011/05/25 02:00:36 | 000,064,512 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2011/05/25 02:00:36 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2010/06/23 10:23:44 | 000,023,040 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2009/06/16 15:59:00 | 009,768,640 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/06/10 00:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2007/11/21 01:24:11 | 000,012,464 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2007/09/26 09:12:00 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Stuurprogramma voor Intel®
DRV - [2007/04/13 02:02:56 | 000,157,184 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/03/06 22:38:52 | 000,323,584 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/02/25 13:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/11/27 09:48:46 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/27 09:48:44 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/27 09:48:44 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/21 14:25:44 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/02 09:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/11/02 09:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Stuurprogramma voor Intel®
DRV - [2006/10/05 18:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2006/08/05 02:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2005/01/31 12:20:03 | 000,211,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2005/01/31 12:12:46 | 000,022,016 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.be...=be&ibd=2070926IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Van Dale Woordenboek"
FF - prefs.js..browser.startup.homepage: "
https://www.facebook....com/login.php"FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:2.0.1
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 56646
FF - prefs.js..network.proxy.no_proxies_on: "*.telenet.be, *.pandora.be, 127.0.0.1"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Batmobiel\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/08 19:57:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/08 19:57:46 | 000,000,000 | ---D | M]
[2009/07/09 17:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Extensions
[2009/07/09 17:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Extensions\
[email protected][2011/10/08 23:55:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Firefox\Profiles\qct6qbvs.default\extensions
[2010/08/06 10:43:51 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Firefox\Profiles\qct6qbvs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/08 23:55:29 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Firefox\Profiles\qct6qbvs.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011/10/08 23:55:35 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Batmobiel\AppData\Roaming\mozilla\Firefox\Profiles\qct6qbvs.default\extensions\
[email protected][2011/10/08 19:57:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/21 23:12:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/09/29 09:28:21 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/07/21 23:11:18 | 000,423,656 | ---- | M] (Oracle) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/03/29 11:56:22 | 000,151,552 | ---- | M] (PopCap Games) -- C:\Program Files\mozilla firefox\plugins\nppopcaploader.dll
[2011/09/29 02:35:39 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/29 03:16:03 | 000,001,892 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bolcom-nl.xml
[2011/09/29 03:16:03 | 000,004,558 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\marktplaats-nl.xml
[2011/09/29 03:16:03 | 000,001,049 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-nl.xml
O1 HOSTS File: ([2011/10/09 19:36:48 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [dscactivate] c:\dell\dsca.exe ( )
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\RunOnce: [*autoadmdns.exe] C:\ProgramData\autoadmdns.exe (©if systems)
O4 - Startup: C:\Users\Batmobiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk = C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
O4 - Startup: C:\Users\Batmobiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Spybot - Search & Destroy.lnk = C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - %SystemRoot%\System32\winrnr.dll File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10}
http://cdn.scan.onec...l/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.130.130.4 195.130.131.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC71365-4E92-4D5F-AFFB-1E1A12183C2F}: DhcpNameServer = 195.130.130.4 195.130.131.4
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Batmobiel\AppData\Roaming\Microsoft\Windows Photo Gallery\Bureaubladachtergrond van Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Batmobiel\AppData\Roaming\Microsoft\Windows Photo Gallery\Bureaubladachtergrond van Windows Fotogalerie.jpg
O32 - Unable to open key or key not present!
O32 - AutoRun File - [2010/12/27 23:06:50 | 000,000,000 | ---D | M] - C:\autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/10/09 19:36:36 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/10/09 17:40:46 | 000,209,408 | ---- | C] (©if systems) -- C:\ProgramData\autoadmdns.exe
[2011/10/09 17:02:53 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Batmobiel\Desktop\OTL.exe
[2011/10/09 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Batmobiel\Desktop\Roguekiller
[2011/10/09 08:40:53 | 000,000,000 | ---D | C] -- C:\Users\Batmobiel\Desktop\RK_Quarantine
[2011/10/08 23:49:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\MpEngineStore
[2011/09/14 22:46:13 | 000,000,000 | ---D | C] -- C:\Users\Batmobiel\Desktop\Werk
[2011/09/13 23:00:58 | 000,000,000 | ---D | C] -- C:\Users\Batmobiel\Desktop\Waterski
[2005/01/01 21:05:00 | 000,456,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\DAO3032.DLL
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/10/09 20:02:32 | 000,032,251 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/10/09 20:02:00 | 000,000,440 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2011/10/09 20:01:12 | 000,032,251 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/10/09 20:01:10 | 000,001,042 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/09 20:01:04 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/09 20:01:04 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/09 20:00:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/10/09 20:00:50 | 2143,510,528 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/09 19:48:38 | 000,000,430 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{58BD6466-5970-429D-873B-F54947271CCC}.job
[2011/10/09 19:40:59 | 000,000,970 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/10/09 19:36:48 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2011/10/09 19:23:01 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/09 17:40:46 | 000,209,408 | ---- | M] (©if systems) -- C:\ProgramData\autoadmdns.exe
[2011/10/09 17:02:58 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Batmobiel\Desktop\OTL.exe
[2011/10/09 14:30:38 | 000,001,660 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/10/09 08:39:07 | 000,337,457 | ---- | M] () -- C:\Users\Batmobiel\Desktop\PC infected with Win32_Fakeyak - Geeks to Go Forums.pdf
[2011/10/08 19:57:54 | 000,000,872 | ---- | M] () -- C:\Users\Batmobiel\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/08 19:57:54 | 000,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/07 19:23:05 | 000,000,386 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/10/03 21:25:57 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2011/10/03 21:25:57 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2011/09/25 23:31:10 | 000,722,486 | ---- | M] () -- C:\Windows\System32\perfh013.dat
[2011/09/25 23:31:10 | 000,641,850 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/09/25 23:31:10 | 000,148,962 | ---- | M] () -- C:\Windows\System32\perfc013.dat
[2011/09/25 23:31:10 | 000,122,778 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/09/24 10:10:20 | 000,007,808 | ---- | M] () -- C:\Users\Batmobiel\AppData\Local\d3d9caps.dat
[2011/09/18 11:40:17 | 001,184,791 | ---- | M] () -- C:\Users\Batmobiel\Desktop\wolfsven_2010.pdf
[2011/09/17 12:20:12 | 000,000,940 | ---- | M] () -- C:\Users\Batmobiel\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook starten.lnk
[2011/09/14 22:12:47 | 002,270,973 | ---- | M] () -- C:\Users\Batmobiel\Documents\vlarem_ii_versie_20111404.pdf
[2011/09/13 23:05:05 | 000,000,743 | ---- | M] () -- C:\Users\Batmobiel\Application Data\Microsoft\Internet Explorer\Quick Launch\FSCapture - Snelkoppeling (2).lnk
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/10/09 08:39:22 | 000,337,457 | ---- | C] () -- C:\Users\Batmobiel\Desktop\PC infected with Win32_Fakeyak - Geeks to Go Forums.pdf
[2011/10/09 08:14:58 | 000,032,251 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011/10/09 08:14:41 | 000,032,251 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011/10/08 19:57:54 | 000,000,860 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/08 19:57:54 | 000,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/06 02:42:41 | 000,000,386 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/18 11:40:17 | 001,184,791 | ---- | C] () -- C:\Users\Batmobiel\Desktop\wolfsven_2010.pdf
[2011/09/14 22:12:47 | 002,270,973 | ---- | C] () -- C:\Users\Batmobiel\Documents\vlarem_ii_versie_20111404.pdf
[2011/09/13 23:04:59 | 000,000,743 | ---- | C] () -- C:\Users\Batmobiel\Application Data\Microsoft\Internet Explorer\Quick Launch\FSCapture - Snelkoppeling (2).lnk
[2011/08/13 09:31:09 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/05/30 19:24:12 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/05/30 19:24:12 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/05/27 21:00:07 | 000,016,432 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2009/12/26 15:25:30 | 000,000,008 | ---- | C] () -- C:\ProgramData\sysReserve.ini
[2009/11/26 04:01:34 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/26 04:01:34 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/11/06 18:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/11/06 18:33:02 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008/09/22 18:34:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008/09/10 23:57:03 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/09/10 14:30:18 | 000,081,920 | R--- | C] () -- C:\Windows\bwUnin-6.1.4.68-8876480L.exe
[2008/08/07 00:24:27 | 000,016,103 | ---- | C] () -- C:\Users\Batmobiel\AppData\Roaming\UserTile.png
[2008/03/22 10:24:46 | 000,007,808 | ---- | C] () -- C:\Users\Batmobiel\AppData\Local\d3d9caps.dat
[2008/03/22 00:53:07 | 000,008,192 | -HS- | C] () -- C:\Windows\o2cLicStore.bin
[2007/11/26 22:26:08 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2007/10/19 23:00:09 | 000,000,392 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/10/16 22:12:21 | 000,069,577 | ---- | C] () -- C:\Users\Batmobiel\AppData\Roaming\nvModes.001
[2007/10/16 22:12:20 | 000,069,577 | ---- | C] () -- C:\Users\Batmobiel\AppData\Roaming\nvModes.dat
[2007/10/16 09:53:43 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007/10/16 00:35:11 | 000,248,320 | ---- | C] () -- C:\Users\Batmobiel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/26 19:53:37 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007/09/26 12:07:41 | 000,006,656 | ---- | C] () -- C:\Windows\System32\stacutil.dll
[2007/09/26 11:59:13 | 000,001,660 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2006/11/29 10:44:34 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2006/11/07 21:25:58 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006/11/03 18:25:56 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006/11/02 18:11:51 | 000,722,486 | ---- | C] () -- C:\Windows\System32\perfh013.dat
[2006/11/02 18:11:51 | 000,336,440 | ---- | C] () -- C:\Windows\System32\perfi013.dat
[2006/11/02 18:11:51 | 000,148,962 | ---- | C] () -- C:\Windows\System32\perfc013.dat
[2006/11/02 18:11:51 | 000,041,976 | ---- | C] () -- C:\Windows\System32\perfd013.dat
[2006/11/02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 14:47:37 | 003,991,592 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 12:33:01 | 000,641,850 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 12:33:01 | 000,122,778 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 12:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/09/17 00:36:50 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/01/01 21:05:00 | 000,126,976 | ---- | C] () -- C:\Windows\System32\mbUtil.dll
[2005/01/01 21:05:00 | 000,000,662 | ---- | C] () -- C:\Windows\Contact.INI
[2003/04/07 13:10:22 | 000,005,443 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll
========== LOP Check ========== [2008/02/18 12:33:19 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Alias
[2007/10/21 23:02:28 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Ansys
[2010/12/28 00:48:21 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Autodesk
[2011/10/09 00:01:58 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Azureus
[2010/06/14 18:43:00 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Facebook
[2011/04/17 20:57:39 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\HTC
[2011/04/16 22:39:58 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2007/10/24 23:51:34 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\iScreensaver
[2011/04/17 20:57:40 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Outlook
[2010/12/18 00:26:30 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\Power MP3 Cutter
[2010/11/11 23:02:10 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2009/07/09 17:33:40 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\TomTom
[2010/02/20 23:54:52 | 000,000,000 | ---D | M] -- C:\Users\Batmobiel\AppData\Roaming\VOWSoft
[2011/10/07 19:23:05 | 000,000,386 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/10/09 14:30:36 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/10/09 19:48:38 | 000,000,430 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{58BD6466-5970-429D-873B-F54947271CCC}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Viper Suisse:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Torrents:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Ski_Tag:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Ski Tag + Els:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Sabrina dag 4:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Sabrina dag 3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Sabrina dag 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Sabrina dag 1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Liberation:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Kodak januari:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\hydrofoilb.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\hydrofoil.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\harde 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\V-shape:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Verslagen zwitserland:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\tracklists trancefm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\TomTom:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\StudioTools:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Solar Boat Reportage.mov:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\RVA:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\OldVersions:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\MP3voornovember:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Mijn ontvangen bestanden:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Kreativ Squareheads 1.0:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Inventor:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Inventor renders:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\hulls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\GTA Vice City User Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Boot - nietkdg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Bluetooth-uitwisselingsmap:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Documents\Azureus Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\waterklok parijs.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\usb ski:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Sollicitaties:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Scannen0002.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Scannen0001.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Sabrina 2-2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Sabrina 2-1:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Italie en passen:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\DSC03399.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Dirk en bergrennen:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\Bodensee rond:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\7230_144463934260_600109260_2679915_8107794_ngsm.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Batmobiel\Desktop\7230_144463934260_600109260_2679915_8107794_n.jpg:Roxio EMC Stream
< End of report >
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 11-10-09.01 - Batmobiel 09/10/2011 20:31:37.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.32.1043.18.2045.927 [GMT 2:00]
Gestart vanuit: c:\users\Batmobiel\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\$recycle$
c:\$recycle$\B8DEA5BB0E0.exe
c:\programdata\sysReserve.ini
C:\sy5tw21.bin
C:\syte821.bin
c:\syte821.bin\B3E7876E059C093
c:\windows\$NtUninstallKB58676$
c:\windows\$NtUninstallKB58676$\1025785193
c:\windows\$NtUninstallKB58676$\2637596669\@
c:\windows\$NtUninstallKB58676$\2637596669\bckfg.tmp
c:\windows\$NtUninstallKB58676$\2637596669\cfg.ini
c:\windows\$NtUninstallKB58676$\2637596669\Desktop.ini
c:\windows\$NtUninstallKB58676$\2637596669\kwrd.dll
c:\windows\$NtUninstallKB58676$\2637596669\L\qnbwvoto
c:\windows\$NtUninstallKB58676$\2637596669\U\00000001.@
c:\windows\$NtUninstallKB58676$\2637596669\U\00000002.@
c:\windows\$NtUninstallKB58676$\2637596669\U\80000000.@
c:\windows\$NtUninstallKB58676$\2637596669\U\80000032.@
c:\windows\bwUnin-6.1.4.68-8876480L.exe
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\IsUn0413.exe
c:\windows\system32\comct332.ocx
.
c:\windows\system32\drivers\cdrom.sys was verdwenen
Hersteld exemplaar van - c:\windows\SoftwareDistribution\Download\15d05090e6f876555f2419af621dda9f\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_9d3687fd
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-09-09 to 2011-10-09 ))))))))))))))))))))))))))))))
.
.
2011-10-09 18:52 . 2011-10-09 18:52 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC4A5BDA-DE40-499E-8297-A0A6B7E40BAA}\offreg.dll
2011-10-09 17:36 . 2011-10-09 17:36 -------- d-----w- C:\_OTL
2011-10-08 17:57 . 2011-09-29 07:28 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-10-08 17:57 . 2011-09-29 07:28 773080 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-10-08 17:57 . 2011-09-29 07:28 1833944 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-10-08 17:57 . 2011-09-29 07:28 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-10-08 17:57 . 2011-09-29 07:28 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-10-08 17:57 . 2011-09-29 07:28 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-10-08 17:57 . 2011-09-29 00:26 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-10-08 17:57 . 2011-09-29 00:26 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-10-07 18:28 . 2011-09-12 23:14 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC4A5BDA-DE40-499E-8297-A0A6B7E40BAA}\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-09 18:20 . 2011-10-09 18:20 209408 ----a-w- c:\users\Batmobiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hostaclaudit.exe
2011-07-18 18:43 . 2011-07-18 18:43 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2005-01-01 19:05 . 2005-01-01 19:05 456976 ----a-w- c:\program files\Common Files\DAO3032.DLL
2011-09-29 07:28 . 2011-10-08 17:57 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-07-28 18:03 . 2008-09-24 19:10 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-04-15 10:33 2515552 ----a-w- c:\program files\Vuze_Remote\tbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2010-04-16 3872080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-28 30192]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-16 13793824]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-16 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
.
c:\users\Batmobiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Mozilla Firefox.lnk - c:\program files\Mozilla Firefox\firefox.exe [2007-10-16 924632]
Spybot - Search & Destroy.lnk - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2011-1-19 5365592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-9-26 45056]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R1 acyhgdzr;acyhgdzr;c:\windows\system32\drivers\acyhgdzr.sys [x]
R1 aeyrzqpe;aeyrzqpe;c:\windows\system32\drivers\aeyrzqpe.sys [x]
R1 arbnqyyk;arbnqyyk;c:\windows\system32\drivers\arbnqyyk.sys [x]
R1 aynfxaug;aynfxaug;c:\windows\system32\drivers\aynfxaug.sys [x]
R1 beawmqdf;beawmqdf;c:\windows\system32\drivers\beawmqdf.sys [x]
R1 bhzvzemn;bhzvzemn;c:\windows\system32\drivers\bhzvzemn.sys [x]
R1 bjkmcaoq;bjkmcaoq;c:\windows\system32\drivers\bjkmcaoq.sys [x]
R1 buerknqf;buerknqf;c:\windows\system32\drivers\buerknqf.sys [x]
R1 bzzbvkqn;bzzbvkqn;c:\windows\system32\drivers\bzzbvkqn.sys [x]
R1 ckzucvbv;ckzucvbv;c:\windows\system32\drivers\ckzucvbv.sys [x]
R1 clypxioj;clypxioj;c:\windows\system32\drivers\clypxioj.sys [x]
R1 ctgdiqhj;ctgdiqhj;c:\windows\system32\drivers\ctgdiqhj.sys [x]
R1 cybyfxvg;cybyfxvg;c:\windows\system32\drivers\cybyfxvg.sys [x]
R1 dlhnqwbd;dlhnqwbd;c:\windows\system32\drivers\dlhnqwbd.sys [x]
R1 dnlrabxp;dnlrabxp;c:\windows\system32\drivers\dnlrabxp.sys [x]
R1 dnmtgwuy;dnmtgwuy;c:\windows\system32\drivers\dnmtgwuy.sys [x]
R1 dnqodjyt;dnqodjyt;c:\windows\system32\drivers\dnqodjyt.sys [x]
R1 ebolgrrd;ebolgrrd;c:\windows\system32\drivers\ebolgrrd.sys [x]
R1 egvzgryl;egvzgryl;c:\windows\system32\drivers\egvzgryl.sys [x]
R1 eiqlcvxc;eiqlcvxc;c:\windows\system32\drivers\eiqlcvxc.sys [x]
R1 ejnfzbry;ejnfzbry;c:\windows\system32\drivers\ejnfzbry.sys [x]
R1 eowzpclo;eowzpclo;c:\windows\system32\drivers\eowzpclo.sys [x]
R1 eqxjauag;eqxjauag;c:\windows\system32\drivers\eqxjauag.sys [x]
R1 errxwwlk;errxwwlk;c:\windows\system32\drivers\errxwwlk.sys [x]
R1 faxwoaua;faxwoaua;c:\windows\system32\drivers\faxwoaua.sys [x]
R1 fekkezfi;fekkezfi;c:\windows\system32\drivers\fekkezfi.sys [x]
R1 gdimdynh;gdimdynh;c:\windows\system32\drivers\gdimdynh.sys [x]
R1 gdzyexfi;gdzyexfi;c:\windows\system32\drivers\gdzyexfi.sys [x]
R1 gmptnqqq;gmptnqqq;c:\windows\system32\drivers\gmptnqqq.sys [x]
R1 gnzoiwud;gnzoiwud;c:\windows\system32\drivers\gnzoiwud.sys [x]
R1 gunhcbel;gunhcbel;c:\windows\system32\drivers\gunhcbel.sys [x]
R1 gyrauhqb;gyrauhqb;c:\windows\system32\drivers\gyrauhqb.sys [x]
R1 heyjuozl;heyjuozl;c:\windows\system32\drivers\heyjuozl.sys [x]
R1 hiqqgoqw;hiqqgoqw;c:\windows\system32\drivers\hiqqgoqw.sys [x]
R1 htmofnmi;htmofnmi;c:\windows\system32\drivers\htmofnmi.sys [x]
R1 htrnsddf;htrnsddf;c:\windows\system32\drivers\htrnsddf.sys [x]
R1 hvpilqng;hvpilqng;c:\windows\system32\drivers\hvpilqng.sys [x]
R1 ieveupwr;ieveupwr;c:\windows\system32\drivers\ieveupwr.sys [x]
R1 indgzcbj;indgzcbj;c:\windows\system32\drivers\indgzcbj.sys [x]
R1 ivpnsofq;ivpnsofq;c:\windows\system32\drivers\ivpnsofq.sys [x]
R1 jilzdbru;jilzdbru;c:\windows\system32\drivers\jilzdbru.sys [x]
R1 jivtexqz;jivtexqz;c:\windows\system32\drivers\jivtexqz.sys [x]
R1 jjaagjuk;jjaagjuk;c:\windows\system32\drivers\jjaagjuk.sys [x]
R1 jmnririd;jmnririd;c:\windows\system32\drivers\jmnririd.sys [x]
R1 joabcvvm;joabcvvm;c:\windows\system32\drivers\joabcvvm.sys [x]
R1 jqcidtjw;jqcidtjw;c:\windows\system32\drivers\jqcidtjw.sys [x]
R1 jubglpct;jubglpct;c:\windows\system32\drivers\jubglpct.sys [x]
R1 jxfiiqye;jxfiiqye;c:\windows\system32\drivers\jxfiiqye.sys [x]
R1 jxyyvact;jxyyvact;c:\windows\system32\drivers\jxyyvact.sys [x]
R1 kbnbkheb;kbnbkheb;c:\windows\system32\drivers\kbnbkheb.sys [x]
R1 kbppxrrg;kbppxrrg;c:\windows\system32\drivers\kbppxrrg.sys [x]
R1 kjbkpoyz;kjbkpoyz;c:\windows\system32\drivers\kjbkpoyz.sys [x]
R1 kwogkchx;kwogkchx;c:\windows\system32\drivers\kwogkchx.sys [x]
R1 lbfghepe;lbfghepe;c:\windows\system32\drivers\lbfghepe.sys [x]
R1 lfahbwql;lfahbwql;c:\windows\system32\drivers\lfahbwql.sys [x]
R1 lfwjtynb;lfwjtynb;c:\windows\system32\drivers\lfwjtynb.sys [x]
R1 liaqwger;liaqwger;c:\windows\system32\drivers\liaqwger.sys [x]
R1 ltiexlqz;ltiexlqz;c:\windows\system32\drivers\ltiexlqz.sys [x]
R1 lvatelbw;lvatelbw;c:\windows\system32\drivers\lvatelbw.sys [x]
R1 lxwepnwv;lxwepnwv;c:\windows\system32\drivers\lxwepnwv.sys [x]
R1 moauyqik;moauyqik;c:\windows\system32\drivers\moauyqik.sys [x]
R1 mrsamdly;mrsamdly;c:\windows\system32\drivers\mrsamdly.sys [x]
R1 mtqljnro;mtqljnro;c:\windows\system32\drivers\mtqljnro.sys [x]
R1 muxtwnuc;muxtwnuc;c:\windows\system32\drivers\muxtwnuc.sys [x]
R1 nbnvxnsu;nbnvxnsu;c:\windows\system32\drivers\nbnvxnsu.sys [x]
R1 nsbvxuhg;nsbvxuhg;c:\windows\system32\drivers\nsbvxuhg.sys [x]
R1 obmkocvy;obmkocvy;c:\windows\system32\drivers\obmkocvy.sys [x]
R1 okijqpkh;okijqpkh;c:\windows\system32\drivers\okijqpkh.sys [x]
R1 omanaiar;omanaiar;c:\windows\system32\drivers\omanaiar.sys [x]
R1 orfavfsp;orfavfsp;c:\windows\system32\drivers\orfavfsp.sys [x]
R1 pilqaevr;pilqaevr;c:\windows\system32\drivers\pilqaevr.sys [x]
R1 ploewios;ploewios;c:\windows\system32\drivers\ploewios.sys [x]
R1 pmqnhtyo;pmqnhtyo;c:\windows\system32\drivers\pmqnhtyo.sys [x]
R1 pnsjopnt;pnsjopnt;c:\windows\system32\drivers\pnsjopnt.sys [x]
R1 poxxxipo;poxxxipo;c:\windows\system32\drivers\poxxxipo.sys [x]
R1 ppniqvia;ppniqvia;c:\windows\system32\drivers\ppniqvia.sys [x]
R1 qmeqeraj;qmeqeraj;c:\windows\system32\drivers\qmeqeraj.sys [x]
R1 qocmwalu;qocmwalu;c:\windows\system32\drivers\qocmwalu.sys [x]
R1 qsdksqbk;qsdksqbk;c:\windows\system32\drivers\qsdksqbk.sys [x]
R1 rkzzazjk;rkzzazjk;c:\windows\system32\drivers\rkzzazjk.sys [x]
R1 rncqngws;rncqngws;c:\windows\system32\drivers\rncqngws.sys [x]
R1 rqkprqei;rqkprqei;c:\windows\system32\drivers\rqkprqei.sys [x]
R1 rvlcltil;rvlcltil;c:\windows\system32\drivers\rvlcltil.sys [x]
R1 sgmqlwac;sgmqlwac;c:\windows\system32\drivers\sgmqlwac.sys [x]
R1 slfpdgka;slfpdgka;c:\windows\system32\drivers\slfpdgka.sys [x]
R1 sqijyaue;sqijyaue;c:\windows\system32\drivers\sqijyaue.sys [x]
R1 srsdgegm;srsdgegm;c:\windows\system32\drivers\srsdgegm.sys [x]
R1 tchantzu;tchantzu;c:\windows\system32\drivers\tchantzu.sys [x]
R1 temynwwl;temynwwl;c:\windows\system32\drivers\temynwwl.sys [x]
R1 thtsaipj;thtsaipj;c:\windows\system32\drivers\thtsaipj.sys [x]
R1 tpplbiju;tpplbiju;c:\windows\system32\drivers\tpplbiju.sys [x]
R1 uqpbzwdl;uqpbzwdl;c:\windows\system32\drivers\uqpbzwdl.sys [x]
R1 utdlepuh;utdlepuh;c:\windows\system32\drivers\utdlepuh.sys [x]
R1 uzwgmhjc;uzwgmhjc;c:\windows\system32\drivers\uzwgmhjc.sys [x]
R1 vfwexkvp;vfwexkvp;c:\windows\system32\drivers\vfwexkvp.sys [x]
R1 vhylezxq;vhylezxq;c:\windows\system32\drivers\vhylezxq.sys [x]
R1 vlbvkgud;vlbvkgud;c:\windows\system32\drivers\vlbvkgud.sys [x]
R1 vmsupaqb;vmsupaqb;c:\windows\system32\drivers\vmsupaqb.sys [x]
R1 vpsjmasb;vpsjmasb;c:\windows\system32\drivers\vpsjmasb.sys [x]
R1 vrpgthve;vrpgthve;c:\windows\system32\drivers\vrpgthve.sys [x]
R1 wvjbecqx;wvjbecqx;c:\windows\system32\drivers\wvjbecqx.sys [x]
R1 wzhxqejy;wzhxqejy;c:\windows\system32\drivers\wzhxqejy.sys [x]
R1 xurllzee;xurllzee;c:\windows\system32\drivers\xurllzee.sys [x]
R1 yevjgwqq;yevjgwqq;c:\windows\system32\drivers\yevjgwqq.sys [x]
R2 gupdate1ca03336c81a5f0;Google Updateservice (gupdate1ca03336c81a5f0);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-12 133104]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-09-02 2152152]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-03-12 86016]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192]
R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-12 133104]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-09 24576]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-05-25 15232]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-05-25 64512]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
Akamai REG_MULTI_SZ Akamai
.
Inhoud van de 'Gedeelde Taken' map
.
2011-10-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-05-25 07:40]
.
2011-10-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-12 21:40]
.
2011-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-12 20:57]
.
2011-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-12 20:57]
.
2011-10-09 c:\windows\Tasks\User_Feed_Synchronization-{58BD6466-5970-429D-873B-F54947271CCC}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.be/
TCP: DhcpNameServer = 195.130.130.4 195.130.131.4
FF - ProfilePath - c:\users\Batmobiel\AppData\Roaming\Mozilla\Firefox\Profiles\qct6qbvs.default\
FF - prefs.js: browser.search.selectedEngine - Van Dale Woordenboek
FF - prefs.js: browser.startup.homepage - hxxps://www.facebook.com/login.php
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56646
FF - prefs.js: network.proxy.type - 4
.
.
------- Bestandsassociaties -------
.
.scr=DWGTrueViewScriptFile
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-10-09 20:58
Windows 6.0.6001 Service Pack 1 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
.
- - - - - - - > 'Explorer.exe'(4408)
c:\windows\system32\btncopy.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Autodesk\Data Management Server 2008\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
c:\program files\Autodesk\Data Management Server 2008\Server\Webserver\Connectivity.EDMWS.Server.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\sttray.exe
c:\windows\System32\rundll32.exe
c:\program files\Dell\QuickSet\quickset.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
.
**************************************************************************
.
Voltooingstijd: 2011-10-09 21:10:45 - machine werd herstart
ComboFix-quarantined-files.txt 2011-10-09 19:10
.
Pre-Run: 2.438.455.296 bytes beschikbaar
Post-Run: 2.439.532.544 bytes beschikbaar
.
- - End Of File - - CF56ED4D05879BD5E6D72FEAC9CBAF3B
--------------------------------------------------------------------------------------------------------------------------------------------------
Couldn't help my autorun programs to start up while Combofix was writing its log, but it appears not to have infected its function. Although I get messages again from Spybot S&D about the deleted register entries. Example:
Category: System startup global entry
Edit: Deleted Value
Entry: Windows Defender
Old data: %Program Files%\Windows Defender\MSASCui.exe
New data: (none)
Is it ok to accept these? I suppose it is but I haven't so far ...
Thanks already!