When trying to use FRST, I got message it was outdated and option to download latest version fr Bleepingcomputers. i clicked yes but got to what looked as the exact same page.
- 1st time i downloaded FRST i only got FF-message to accept being directed to another page. 2nd time i got 4 warnings of being directed to less secure pages with one message of others being able to read my info.
- 1st time i downloaded FRST it would not download immediatly and i had to use the "If download does not start within x time click here"-button. 2nd time it downloaded without that.
- 2nd download looked exactly the same as the 1st, compairing mouse-over properties as well as richtclick properties.
- FF Bookmarks for GeeksToGo, made before downloading FRST, did not show the GeeksToGo Icon buta dotted outlined square. (I think that's FF standard for an unknown icon? Hotmail-icon in YahooToolbar for FF looked like that too - don't have hotmail pinned to Yahoo toolbar in Guest-account so i can not compaire).
I used the 1st download clicking "No" to download the latest version. Logfiles given below and in attachement as requested.
FRST.txt :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-06-2013 01
Ran by Eigenaar (administrator) on 06-06-2013 19:58:35
Running from C:\Documents and Settings\Eigenaar\Bureaublad
Microsoft Windows XP Service Pack 3 (X86) OS Language: Dutch Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.2.233.0\BBSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.21.145\GoogleCrashHandler.exe
(Wireless) C:\Program Files\Wireless\WPS\jswpbapi.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
() C:\Program Files\Wireless\WPS\jswtrayutil.exe
( ) C:\Program Files\TSST Korea\FW LiveUpdate\FWManager.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.2.233.0\SeaPort.exe
(Farbar) C:\Documents and Settings\Eigenaar\Bureaublad\7aFRST.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [jswtrayutil] "C:\Program Files\Wireless\WPS\jswtrayutil.exe" [32873 2009-09-24] ()
HKLM\...\Run: [Name of App] C:\Program Files\TSST Korea\FW LiveUpdate\FWManager.exe r [708721 2013-03-08] ( )
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947152 2013-01-27] (Microsoft Corporation)
HKLM\...\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" [74752 2012-06-28] (Nullsoft, Inc.)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1505144 2009-11-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
HKCU\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-06-16] (Google Inc.)
HKU\Gast\...\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [ 2008-04-14] (Microsoft Corporation)
HKU\Gast\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
BootExecute: autocheck autochk * pgdfgsvc C 1
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com/HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...=ie&ar=iesearchBHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU -&Koppelingen - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
PDF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cabPDF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macr...director/sw.cabPDF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1271944706703PDF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE}
http://download.micr...loadManager.cabPDF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://content.syste...el_4.5.11.0.cabHandler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 195.241.77.55 195.241.77.58
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\bjvlnrw9.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/DownloadManager,version=1.1 - C:\WINDOWS\ ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2166.3772\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\bjvlnrw9.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
Chrome:
=======
========================== Services (Whitelisted) =================
R2 jswpbapi; C:\Program Files\Wireless\WPS\jswpbapi.exe [188416 2009-09-21] (Wireless)
S3 jswpsapi; C:\Program Files\Wireless\WPS\jswpsapi.exe [360529 2009-09-21] (wireless)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation)
S3 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1326176 2012-07-25] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [681056 2012-07-25] (Secunia)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
S3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1668352 2009-09-16] (Atheros Communications, Inc.)
R2 BrPar; C:\Windows\System32\drivers\BrPar.sys [19537 2000-07-24] (Brother Industries Ltd.)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R2 fssfltr; C:\Windows\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
S3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [807998 2005-06-21] (Intel Corporation)
R3 JSWSCIMD; C:\Windows\System32\DRIVERS\jswscimd.sys [57440 2009-09-21] (Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia)
R3 STAC97NA; C:\Windows\System32\drivers\stac97na.sys [296179 2002-07-07] (SigmaTel Inc.)
R3 STAC97NH; C:\Windows\System32\drivers\stac97nh.sys [231983 2002-07-07] (SigmaTel Inc.)
S3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\Windows\System32\drivers\ialmsbw.sys [108480 2002-12-30] (Intel Corporation)
S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\Windows\System32\drivers\ialmkchw.sys [78144 2002-12-30] (Intel Corporation)
S4 Abiosdsk; No ImagePath
S4 abp480n5; No ImagePath
S4 adpu160m; No ImagePath
S4 Aha154x; No ImagePath
S4 aic78u2; No ImagePath
S4 aic78xx; No ImagePath
S4 AliIde; No ImagePath
S4 amsint; No ImagePath
S4 asc; No ImagePath
S4 asc3350p; No ImagePath
S4 asc3550; No ImagePath
S4 Atdisk; No ImagePath
S3 catchme; \??\C:\DOCUME~1\Eigenaar\LOCALS~1\Temp\catchme.sys [x]
S4 cd20xrnt; No ImagePath
S1 Changer; No ImagePath
S4 CmdIde; No ImagePath
S4 Cpqarray; No ImagePath
U4 dac2w2k; No ImagePath
S4 dac960nt; No ImagePath
S4 dpti2o; No ImagePath
S4 hpn; No ImagePath
S1 i2omgmt; No ImagePath
S4 i2omp; No ImagePath
S4 ini910u; No ImagePath
S1 lbrtfdc; No ImagePath
S4 mraid35x; No ImagePath
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S4 perc2; No ImagePath
S4 perc2hib; No ImagePath
S4 ql1080; No ImagePath
S4 Ql10wnt; No ImagePath
S4 ql12160; No ImagePath
S4 ql1240; No ImagePath
S4 ql1280; No ImagePath
S4 Simbad; No ImagePath
S4 Sparrow; No ImagePath
S4 symc810; No ImagePath
S4 symc8xx; No ImagePath
S4 sym_hi; No ImagePath
S4 sym_u3; No ImagePath
U3 TlntSvr;
S4 TosIde; No ImagePath
S4 ultra; No ImagePath
S4 ViaIde; No ImagePath
S3 WDICA; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-06 19:58 - 2013-06-06 19:58 - 00000000 ___DC C:\FRST
2013-06-04 09:27 - 2013-06-04 09:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-05-26 01:05 - 2013-05-26 01:05 - 00000000 ___DC C:\_OTL
2013-05-25 12:07 - 2013-05-25 12:07 - 00012473 ___AC C:\ComboFix.txt
2013-05-25 02:35 - 2013-05-25 02:35 - 00000000 RASHDC C:\cmdcons
2013-05-25 02:35 - 2013-03-26 15:52 - 00000211 ___AC C:\Boot.bak
2013-05-25 02:35 - 2004-08-03 23:00 - 00261936 RASHC C:\cmldr
2013-05-25 02:30 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe
2013-05-25 02:30 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe
2013-05-25 02:30 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00212480 ____A (SteelWerX) C:\Windows\SWXCACLS.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe
2013-05-25 02:30 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe
2013-05-25 02:28 - 2013-05-25 12:07 - 00000000 ___DC C:\Qoobox
2013-05-25 02:28 - 2013-05-25 02:54 - 00000000 ____D C:\Windows\erdnt
2013-05-24 16:44 - 2013-05-24 16:44 - 00000000 ____D C:\Windows\ERUNT
2013-05-24 16:43 - 2013-05-24 16:43 - 00000000 ___DC C:\JRT
2013-05-24 16:24 - 2013-05-24 16:24 - 00010933 ___AC C:\AdwCleaner[S1].txt
2013-05-23 19:06 - 2013-05-23 19:06 - 00000000 ____D C:\Documents and Settings\Gast\Local Settings\Application Data\Sun
2013-05-23 19:06 - 2013-05-23 19:06 - 00000000 ____D C:\Documents and Settings\Gast\Application Data\Sun
2013-05-16 09:44 - 2013-05-22 21:37 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\vlc
2013-05-16 09:42 - 2013-05-16 09:42 - 00000000 ____D C:\Program Files\VideoLAN
2013-05-15 09:26 - 2013-05-15 09:28 - 00011968 ____A C:\Windows\KB2829530-IE8.log
2013-05-15 09:04 - 2013-05-15 09:04 - 00005340 ____A C:\Windows\KB2847204-IE8.log
2013-05-15 09:02 - 2013-05-15 09:02 - 00006403 ____A C:\Windows\KB2820197.log
2013-05-15 09:02 - 2013-05-15 09:02 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-05-15 08:58 - 2013-05-15 08:58 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-05-15 08:53 - 2013-05-15 08:58 - 00009613 ____A C:\Windows\KB2829361.log
2013-05-14 16:39 - 2013-05-14 16:39 - 00000664 ____A C:\Documents and Settings\Werkaccount\Local Settings\Application Data\d3d9caps.tmp
2013-05-14 15:26 - 2013-05-14 15:26 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Macromedia
2013-05-14 15:26 - 2013-05-14 15:26 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Adobe
2013-05-14 15:20 - 2013-05-14 15:20 - 00000000 ____D C:\Documents and Settings\Werkaccount\Local Settings\Application Data\Mozilla
2013-05-14 15:20 - 2013-05-14 15:20 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Mozilla
2013-05-14 15:09 - 2013-05-14 15:33 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Winamp
2013-05-14 15:04 - 2013-05-14 15:04 - 00000000 ___RD C:\Documents and Settings\Werkaccount\Application Data\Brother
2013-05-14 14:56 - 2013-05-14 16:39 - 00000000 ____D C:\Documents and Settings\Werkaccount\Local Settings\Application Data\Google
2013-05-14 14:50 - 2013-05-14 14:50 - 00000000 __SHD C:\Documents and Settings\Werkaccount\IECompatCache
2013-05-14 14:48 - 2013-05-14 14:48 - 00000000 __SHD C:\Documents and Settings\Werkaccount\PrivacIE
2013-05-14 14:47 - 2013-05-27 18:05 - 00000196 ____A C:\Documents and Settings\Werkaccount\Application Data\TSSTLiveUpdateConfig.ini
2013-05-14 14:47 - 2013-05-14 14:48 - 00029600 ____A C:\Documents and Settings\Werkaccount\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-05-14 14:47 - 2013-05-14 14:47 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Windows Desktop Search
2013-05-14 14:46 - 2013-05-27 18:07 - 00000188 __ASH C:\Documents and Settings\Werkaccount\ntuser.ini
2013-05-14 14:46 - 2013-05-27 18:06 - 00000000 __RHD C:\Documents and Settings\Werkaccount\Onlangs geopend
2013-05-14 14:46 - 2013-05-27 18:05 - 00000062 __ASH C:\Documents and Settings\Werkaccount\Local Settings\desktop.ini
2013-05-14 14:46 - 2013-05-16 13:13 - 00000000 ____D C:\Documents and Settings\Werkaccount\Bureaublad
2013-05-14 14:46 - 2013-05-14 14:46 - 00000000 __SHD C:\Documents and Settings\Werkaccount\IETldCache
2013-05-14 14:46 - 2010-04-22 15:33 - 00000062 __ASH C:\Documents and Settings\Werkaccount\Application Data\desktop.ini
2013-05-14 14:46 - 2010-04-22 15:33 - 00000000 __SHD C:\Documents and Settings\Werkaccount\Local Settings\Geschiedenis
2013-05-14 14:46 - 2010-04-22 15:33 - 00000000 ___RD C:\Documents and Settings\Werkaccount\Menu Start
2013-05-14 14:46 - 2010-04-22 15:33 - 00000000 ___HD C:\Documents and Settings\Werkaccount\Netwerkprinteromgeving
2013-05-12 11:25 - 2013-06-06 19:56 - 00000940 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-12 11:25 - 2013-05-16 13:56 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-12 11:25 - 2013-05-16 13:56 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-05-12 10:56 - 2013-05-12 10:56 - 00000000 ____D C:\Program Files\Common Files\Java
2013-05-12 10:55 - 2013-05-12 10:55 - 00263584 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00174496 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00174496 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00144896 ____A (Oracle Corporation) C:\Windows\System32\javacpl.cpl
2013-05-12 10:55 - 2013-05-12 10:55 - 00094112 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-05-07 12:42 - 2010-06-02 04:55 - 00527192 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_7.dll
2013-05-07 12:42 - 2010-06-02 04:55 - 00239960 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_7.dll
2013-05-07 12:42 - 2010-06-02 04:55 - 00074072 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_5.dll
2013-05-07 12:42 - 2010-05-26 11:41 - 02106216 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_43.dll
2013-05-07 12:41 - 2010-05-26 11:41 - 01998168 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_43.dll
2013-05-07 12:41 - 2010-05-26 11:41 - 01868128 ____A (Microsoft Corporation) C:\Windows\System32\d3dcsx_43.dll
2013-05-07 12:41 - 2010-05-26 11:41 - 00470880 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_43.dll
2013-05-07 12:41 - 2010-05-26 11:41 - 00248672 ____A (Microsoft Corporation) C:\Windows\System32\d3dx11_43.dll
2013-05-07 12:41 - 2010-02-04 10:01 - 00528216 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_6.dll
2013-05-07 12:41 - 2010-02-04 10:01 - 00238936 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_6.dll
2013-05-07 12:41 - 2010-02-04 10:01 - 00074072 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_4.dll
2013-05-07 12:41 - 2010-02-04 10:01 - 00022360 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_7.dll
2013-05-07 12:41 - 2009-09-04 17:44 - 00515416 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_5.dll
2013-05-07 12:41 - 2009-09-04 17:44 - 00238936 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_5.dll
2013-05-07 12:41 - 2009-09-04 17:29 - 05501792 ____A (Microsoft Corporation) C:\Windows\System32\d3dcsx_42.dll
2013-05-07 12:41 - 2009-09-04 17:29 - 01974616 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_42.dll
2013-05-07 12:41 - 2009-09-04 17:29 - 00453456 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_42.dll
2013-05-07 12:41 - 2009-09-04 17:29 - 00235344 ____A (Microsoft Corporation) C:\Windows\System32\d3dx11_42.dll
2013-05-07 12:41 - 2009-03-09 15:27 - 04178264 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_41.dll
2013-05-07 12:41 - 2009-03-09 15:27 - 01846632 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_41.dll
2013-05-07 12:41 - 2009-03-09 15:27 - 00453456 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_41.dll
2013-05-07 12:40 - 2009-09-04 17:44 - 00069464 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_3.dll
2013-05-07 12:40 - 2009-03-16 14:18 - 00517448 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_4.dll
2013-05-07 12:40 - 2009-03-16 14:18 - 00235352 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_4.dll
2013-05-07 12:40 - 2009-03-16 14:18 - 00022360 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_6.dll
2013-05-07 12:40 - 2008-10-27 10:04 - 00514384 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_3.dll
2013-05-07 12:40 - 2008-10-27 10:04 - 00235856 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_3.dll
2013-05-07 12:40 - 2008-10-27 10:04 - 00070992 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_2.dll
2013-05-07 12:40 - 2008-10-27 10:04 - 00023376 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_5.dll
2013-05-07 12:40 - 2008-10-10 04:52 - 04379984 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_40.dll
2013-05-07 12:40 - 2008-10-10 04:52 - 02036576 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_40.dll
2013-05-07 12:40 - 2008-10-10 04:52 - 00452440 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_40.dll
2013-05-07 12:40 - 2008-07-31 10:41 - 00238088 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_2.dll
2013-05-07 12:40 - 2008-07-31 10:41 - 00068616 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_1.dll
2013-05-07 12:40 - 2008-07-31 10:40 - 00509448 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_2.dll
2013-05-07 12:40 - 2008-07-10 11:01 - 00467984 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
2013-05-07 12:40 - 2008-07-10 11:00 - 03851784 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
2013-05-07 12:40 - 2008-07-10 11:00 - 01493528 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
2013-05-07 12:39 - 2008-05-30 14:19 - 00507400 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_1.dll
2013-05-07 12:39 - 2008-05-30 14:18 - 00238088 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_1.dll
2013-05-07 12:39 - 2008-05-30 14:17 - 00065032 ____A (Microsoft Corporation) C:\Windows\System32\XAPOFX1_0.dll
2013-05-07 12:39 - 2008-05-30 14:17 - 00025608 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_4.dll
2013-05-07 12:39 - 2008-05-30 14:11 - 03850760 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_38.dll
2013-05-07 12:39 - 2008-05-30 14:11 - 01491992 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_38.dll
2013-05-07 12:39 - 2008-05-30 14:11 - 00467984 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_38.dll
2013-05-07 12:39 - 2008-03-05 16:03 - 00479752 ____A (Microsoft Corporation) C:\Windows\System32\XAudio2_0.dll
2013-05-07 12:39 - 2008-03-05 16:03 - 00238088 ____A (Microsoft Corporation) C:\Windows\System32\xactengine3_0.dll
2013-05-07 12:39 - 2008-03-05 16:00 - 00025608 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_3.dll
2013-05-07 12:39 - 2008-03-05 15:56 - 03786760 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_37.dll
2013-05-07 12:39 - 2008-03-05 15:56 - 01420824 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_37.dll
2013-05-07 12:39 - 2008-02-05 23:07 - 00462864 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_37.dll
2013-05-07 12:39 - 2007-10-22 03:39 - 00267272 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_10.dll
2013-05-07 12:39 - 2007-10-12 15:14 - 03734536 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_36.dll
2013-05-07 12:39 - 2007-10-12 15:14 - 01374232 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_36.dll
2013-05-07 12:39 - 2007-10-02 09:56 - 00444776 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_36.dll
2013-05-07 12:39 - 2007-07-20 00:57 - 00267112 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_9.dll
2013-05-07 12:39 - 2007-07-19 18:14 - 03727720 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_35.dll
2013-05-07 12:39 - 2007-07-19 18:14 - 01358192 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_35.dll
2013-05-07 12:39 - 2007-07-19 18:14 - 00444776 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_35.dll
2013-05-07 12:38 - 2007-10-22 03:37 - 00017928 ____A (Microsoft Corporation) C:\Windows\System32\X3DAudio1_2.dll
2013-05-07 12:38 - 2007-06-20 20:46 - 00266088 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_8.dll
2013-05-07 12:38 - 2007-05-16 16:45 - 03497832 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_34.dll
2013-05-07 12:38 - 2007-05-16 16:45 - 01124720 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_34.dll
2013-05-07 12:38 - 2007-05-16 16:45 - 00443752 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_34.dll
2013-05-07 12:38 - 2007-04-04 18:55 - 00261480 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_7.dll
2013-05-07 12:38 - 2007-04-04 18:53 - 00081768 ____A (Microsoft Corporation) C:\Windows\System32\xinput1_3.dll
2013-05-07 12:38 - 2007-03-15 16:57 - 00443752 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_33.dll
2013-05-07 12:38 - 2007-03-12 16:42 - 03495784 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_33.dll
2013-05-07 12:38 - 2007-03-12 16:42 - 01123696 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_33.dll
2013-05-07 12:38 - 2007-03-05 12:42 - 00015128 ____A (Microsoft Corporation) C:\Windows\System32\x3daudio1_1.dll
2013-05-07 12:38 - 2007-01-24 15:27 - 00255848 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_6.dll
2013-05-07 12:38 - 2006-12-08 12:02 - 00251672 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_5.dll
2013-05-07 12:38 - 2006-09-28 16:05 - 00237848 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_4.dll
2013-05-07 12:38 - 2006-07-28 09:30 - 00236824 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_3.dll
2013-05-07 12:38 - 2006-07-28 09:30 - 00062744 ____A (Microsoft Corporation) C:\Windows\System32\xinput1_2.dll
2013-05-07 12:38 - 2006-05-31 07:24 - 00230168 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_2.dll
2013-05-07 12:38 - 2006-03-31 12:40 - 02388176 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_30.dll
2013-05-07 12:38 - 2006-03-31 12:39 - 00229584 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_1.dll
2013-05-07 12:38 - 2006-03-31 12:39 - 00062672 ____A (Microsoft Corporation) C:\Windows\System32\xinput1_1.dll
2013-05-07 12:38 - 2006-02-03 08:43 - 02332368 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_29.dll
2013-05-07 12:38 - 2006-02-03 08:42 - 00230096 ____A (Microsoft Corporation) C:\Windows\System32\xactengine2_0.dll
2013-05-07 12:38 - 2006-02-03 08:41 - 00014032 ____A (Microsoft Corporation) C:\Windows\System32\x3daudio1_0.dll
2013-05-07 12:38 - 2005-12-05 18:09 - 02323664 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_28.dll
2013-05-07 12:38 - 2005-12-05 18:07 - 00061136 ____A (Microsoft Corporation) C:\Windows\System32\xinput9_1_0.dll
2013-05-07 12:38 - 2005-07-22 19:59 - 02319568 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_27.dll
2013-05-07 12:38 - 2005-05-26 15:34 - 02297552 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_26.dll
2013-05-07 12:38 - 2005-03-18 17:19 - 02337488 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_25.dll
2013-05-07 12:38 - 2005-02-05 19:45 - 02222800 ____A (Microsoft Corporation) C:\Windows\System32\d3dx9_24.dll
2013-05-07 12:34 - 2013-05-07 12:36 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-05-07 12:13 - 2013-05-07 12:14 - 00003874 ____A C:\Windows\System32\jupdate-1.7.0_21-b11.log
2013-05-07 12:11 - 2013-05-07 12:11 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\Oracle
==================== One Month Modified Files and Folders ========
2013-06-06 19:58 - 2013-06-06 19:58 - 00000000 ___DC C:\FRST
2013-06-06 19:56 - 2013-05-12 11:25 - 00000940 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-06 19:55 - 2012-07-08 02:12 - 01624795 ____A C:\Windows\pfirewall.log
2013-06-06 19:54 - 2013-04-03 16:37 - 00000000 __RHD C:\Documents and Settings\Eigenaar\Onlangs geopend
2013-06-06 19:51 - 2010-04-22 13:46 - 00000000 ____D C:\Documents and Settings\Eigenaar\Bureaublad
2013-06-06 19:43 - 2013-04-14 12:54 - 00000159 ____A C:\Windows\wiadebug.log
2013-06-06 19:43 - 2013-04-14 12:54 - 00000048 ____A C:\Windows\wiaservc.log
2013-06-06 19:33 - 2011-06-16 12:39 - 00001048 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-06 19:29 - 2011-01-17 19:41 - 00000460 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{19634F2B-6041-4CFB-B933-71C9576E8275}.job
2013-06-06 19:28 - 2013-03-06 11:12 - 00000386 ___AH C:\Windows\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-06-06 19:26 - 2013-03-13 11:46 - 00000479 ____A C:\Documents and Settings\Eigenaar\Application Data\TSSTLiveUpdateConfig.ini
2013-06-06 19:25 - 2011-06-16 12:39 - 00001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-06 19:25 - 2010-04-22 13:46 - 00000062 __ASH C:\Documents and Settings\Eigenaar\Local Settings\desktop.ini
2013-06-06 19:19 - 2013-03-13 14:26 - 00000196 ____A C:\Documents and Settings\Gast\Application Data\TSSTLiveUpdateConfig.ini
2013-06-06 19:19 - 2012-11-24 17:00 - 01880022 ____A C:\Windows\WindowsUpdate.log
2013-06-06 19:18 - 2012-07-17 06:46 - 00000062 __ASH C:\Documents and Settings\Gast\Local Settings\desktop.ini
2013-06-06 19:18 - 2010-04-22 13:46 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-06 19:18 - 2010-04-22 13:46 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-06 19:17 - 2010-04-22 13:46 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-06-06 16:17 - 2012-11-24 17:01 - 00032600 ____A C:\Windows\SchedLgU.Txt
2013-06-06 16:16 - 2013-03-18 16:13 - 00000000 __RHD C:\Documents and Settings\Gast\Onlangs geopend
2013-06-06 16:16 - 2013-03-14 11:27 - 00000283 ____A C:\Windows\Brownie.ini
2013-06-05 19:54 - 2010-04-22 13:46 - 00000288 ___SH C:\Documents and Settings\Eigenaar\ntuser.ini
2013-06-05 19:50 - 2010-04-22 15:26 - 00013646 ____A C:\Windows\System32\wpa.dbl
2013-06-05 09:44 - 2012-07-08 11:33 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-06-04 09:31 - 2013-06-04 09:27 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-05-27 18:07 - 2013-05-14 14:46 - 00000188 __ASH C:\Documents and Settings\Werkaccount\ntuser.ini
2013-05-27 18:06 - 2013-05-14 14:46 - 00000000 __RHD C:\Documents and Settings\Werkaccount\Onlangs geopend
2013-05-27 18:05 - 2013-05-14 14:47 - 00000196 ____A C:\Documents and Settings\Werkaccount\Application Data\TSSTLiveUpdateConfig.ini
2013-05-27 18:05 - 2013-05-14 14:46 - 00000062 __ASH C:\Documents and Settings\Werkaccount\Local Settings\desktop.ini
2013-05-27 11:46 - 2010-04-22 15:33 - 00000000 ____D C:\Documents and Settings\All Users\Bureaublad
2013-05-27 11:45 - 2011-06-16 12:27 - 00000000 ____D C:\Program Files\Google
2013-05-26 23:22 - 2012-07-08 02:12 - 04086141 ____A C:\Windows\pfirewall.log.old
2013-05-26 22:12 - 2012-07-17 17:26 - 00000664 ____A C:\Documents and Settings\Gast\Local Settings\Application Data\d3d9caps.tmp
2013-05-26 01:05 - 2013-05-26 01:05 - 00000000 ___DC C:\_OTL
2013-05-25 12:07 - 2013-05-25 12:07 - 00012473 ___AC C:\ComboFix.txt
2013-05-25 12:07 - 2013-05-25 02:28 - 00000000 ___DC C:\Qoobox
2013-05-25 12:03 - 2010-04-22 15:26 - 00000227 ___AC C:\Windows\system.ini
2013-05-25 02:54 - 2013-05-25 02:28 - 00000000 ____D C:\Windows\erdnt
2013-05-25 02:35 - 2013-05-25 02:35 - 00000000 RASHDC C:\cmdcons
2013-05-25 02:35 - 2010-04-22 15:26 - 00000327 RASHC C:\boot.ini
2013-05-24 16:44 - 2013-05-24 16:44 - 00000000 ____D C:\Windows\ERUNT
2013-05-24 16:43 - 2013-05-24 16:43 - 00000000 ___DC C:\JRT
2013-05-24 16:24 - 2013-05-24 16:24 - 00010933 ___AC C:\AdwCleaner[S1].txt
2013-05-24 15:40 - 2012-07-17 06:46 - 00000000 ____D C:\Documents and Settings\Gast\Bureaublad
2013-05-24 15:13 - 2013-04-12 11:11 - 00067998 ____A C:\Windows\setupapi.log
2013-05-23 19:06 - 2013-05-23 19:06 - 00000000 ____D C:\Documents and Settings\Gast\Local Settings\Application Data\Sun
2013-05-23 19:06 - 2013-05-23 19:06 - 00000000 ____D C:\Documents and Settings\Gast\Application Data\Sun
2013-05-22 23:53 - 2011-03-30 19:18 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-05-22 21:37 - 2013-05-16 09:44 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\vlc
2013-05-16 13:56 - 2013-05-12 11:25 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-16 13:56 - 2013-05-12 11:25 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-05-16 13:13 - 2013-05-14 14:46 - 00000000 ____D C:\Documents and Settings\Werkaccount\Bureaublad
2013-05-16 09:42 - 2013-05-16 09:42 - 00000000 ____D C:\Program Files\VideoLAN
2013-05-15 09:44 - 2011-03-24 11:49 - 00000000 ____D C:\Windows\Microsoft.NET
2013-05-15 09:30 - 2013-04-03 16:39 - 00168304 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-15 09:28 - 2013-05-15 09:26 - 00011968 ____A C:\Windows\KB2829530-IE8.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00055649 ____A C:\Windows\FaxSetup.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00026604 ____A C:\Windows\ocgen.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00021231 ____A C:\Windows\tsoc.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00018579 ____A C:\Windows\comsetup.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00011264 ____A C:\Windows\ntdtcsetup.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00008842 ____A C:\Windows\iis6.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00003474 ____A C:\Windows\ocmsn.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00002781 ____A C:\Windows\msgsocm.log
2013-05-15 09:28 - 2013-04-12 11:11 - 00001374 ____A C:\Windows\imsins.log
2013-05-15 09:27 - 2013-04-12 11:22 - 00008625 ____A C:\Windows\updspapi.log
2013-05-15 09:23 - 2010-04-22 15:34 - 01279806 ___AC C:\Windows\System32\PerfStringBackup.INI
2013-05-15 09:23 - 2010-04-22 15:26 - 00598768 ____A C:\Windows\System32\perfh013.dat
2013-05-15 09:23 - 2010-04-22 15:26 - 00120562 ____A C:\Windows\System32\perfc013.dat
2013-05-15 09:04 - 2013-05-15 09:04 - 00005340 ____A C:\Windows\KB2847204-IE8.log
2013-05-15 09:04 - 2013-04-12 11:11 - 00001374 ____A C:\Windows\imsins.BAK
2013-05-15 09:04 - 2010-05-11 14:42 - 00000000 ____D C:\Windows\ie8updates
2013-05-15 09:02 - 2013-05-15 09:02 - 00006403 ____A C:\Windows\KB2820197.log
2013-05-15 09:02 - 2013-05-15 09:02 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-05-15 09:02 - 2010-04-22 16:00 - 00000000 ___HD C:\Windows\$hf_mig$
2013-05-15 08:58 - 2013-05-15 08:58 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-05-15 08:58 - 2013-05-15 08:53 - 00009613 ____A C:\Windows\KB2829361.log
2013-05-15 08:58 - 2010-05-11 14:49 - 72607752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-14 16:39 - 2013-05-14 16:39 - 00000664 ____A C:\Documents and Settings\Werkaccount\Local Settings\Application Data\d3d9caps.tmp
2013-05-14 16:39 - 2013-05-14 14:56 - 00000000 ____D C:\Documents and Settings\Werkaccount\Local Settings\Application Data\Google
2013-05-14 15:33 - 2013-05-14 15:09 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Winamp
2013-05-14 15:26 - 2013-05-14 15:26 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Macromedia
2013-05-14 15:26 - 2013-05-14 15:26 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Adobe
2013-05-14 15:20 - 2013-05-14 15:20 - 00000000 ____D C:\Documents and Settings\Werkaccount\Local Settings\Application Data\Mozilla
2013-05-14 15:20 - 2013-05-14 15:20 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Mozilla
2013-05-14 15:04 - 2013-05-14 15:04 - 00000000 ___RD C:\Documents and Settings\Werkaccount\Application Data\Brother
2013-05-14 14:50 - 2013-05-14 14:50 - 00000000 __SHD C:\Documents and Settings\Werkaccount\IECompatCache
2013-05-14 14:48 - 2013-05-14 14:48 - 00000000 __SHD C:\Documents and Settings\Werkaccount\PrivacIE
2013-05-14 14:48 - 2013-05-14 14:47 - 00029600 ____A C:\Documents and Settings\Werkaccount\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2013-05-14 14:47 - 2013-05-14 14:47 - 00000000 ____D C:\Documents and Settings\Werkaccount\Application Data\Windows Desktop Search
2013-05-14 14:46 - 2013-05-14 14:46 - 00000000 __SHD C:\Documents and Settings\Werkaccount\IETldCache
2013-05-12 15:44 - 2010-05-11 15:16 - 00000000 ____D C:\Program Files\Windows Live
2013-05-12 15:40 - 2011-06-16 12:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Google
2013-05-12 15:40 - 2011-06-16 12:31 - 00000000 ____D C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google
2013-05-12 15:39 - 2011-01-12 13:41 - 00000000 ____D C:\Program Files\Uniblue
2013-05-12 15:39 - 2011-01-12 13:41 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\Uniblue
2013-05-12 12:04 - 2010-05-11 14:22 - 00000000 ____D C:\Windows\System32\Adobe
2013-05-12 11:47 - 2011-03-14 15:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2013-05-12 10:56 - 2013-05-12 10:56 - 00000000 ____D C:\Program Files\Common Files\Java
2013-05-12 10:55 - 2013-05-12 10:55 - 00263584 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00174496 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00174496 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-05-12 10:55 - 2013-05-12 10:55 - 00144896 ____A (Oracle Corporation) C:\Windows\System32\javacpl.cpl
2013-05-12 10:55 - 2013-05-12 10:55 - 00094112 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll
2013-05-12 10:55 - 2013-03-14 11:07 - 00866720 ____A (Oracle Corporation) C:\Windows\System32\npdeployJava1.dll
2013-05-12 10:55 - 2013-03-14 11:07 - 00000000 ____D C:\Program Files\Java
2013-05-12 10:55 - 2010-05-11 14:21 - 00788896 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-05-12 10:33 - 2010-05-11 14:25 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\Adobe
2013-05-07 12:42 - 2010-04-22 13:40 - 00000000 ____D C:\Windows\System32\DirectX
2013-05-07 12:36 - 2013-05-07 12:34 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-05-07 12:14 - 2013-05-07 12:13 - 00003874 ____A C:\Windows\System32\jupdate-1.7.0_21-b11.log
2013-05-07 12:11 - 2013-05-07 12:11 - 00000000 ____D C:\Documents and Settings\Eigenaar\Application Data\Oracle
2013-05-07 06:22 - 2010-04-22 15:25 - 06015488 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll
2013-05-07 06:22 - 2010-04-22 15:25 - 06015488 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2010-04-22 15:25] - [2008-04-15 02:33] - 1037312 ____A (Microsoft Corporation) aa04f042a820bf1868e643575887e1a6
C:\Windows\System32\winlogon.exe
[2010-04-22 15:26] - [2008-04-15 02:33] - 0510464 ____A (Microsoft Corporation) 1247d4d5444e28519bbe31be8ab4c029
C:\Windows\System32\svchost.exe
[2010-04-22 15:26] - [2008-04-15 02:33] - 0014336 ____A (Microsoft Corporation) e410ec73e2be2a41d923b006f51c8427
C:\Windows\System32\services.exe
[2010-04-22 15:26] - [2009-02-09 13:27] - 0111104 ____A (Microsoft Corporation) 657b69389b893f440b07590c9e963f23
C:\Windows\System32\User32.dll
[2010-04-22 15:26] - [2008-04-15 02:32] - 0580096 ____A (Microsoft Corporation) 4cf588d2f2363b73eb4af57967d46dff
C:\Windows\System32\userinit.exe
[2010-04-22 15:26] - [2008-04-15 02:33] - 0026112 ____A (Microsoft Corporation) 6818a533ed3b2fa9936df3daf45352df
C:\Windows\System32\Drivers\volsnap.sys
[2010-04-22 15:26] - [2008-04-15 02:03] - 0053504 ____A (Microsoft Corporation) 8ab662b3c4691e6ddf61c96bb5b7d103
==================== End Of Log ============================