MalwareCrypt
May 24, 2013, 11:05:06 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News:
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: trojan (thinkpoint?) installed on my pc  (Read 1409 times)
w.schrier
Newbie
*
Posts: 5


« on: November 14, 2010, 04:58:30 PM »

Hi guys,

a Trojan got past my Microsoft Security essentials, I hope you can help! My log file is:




DDS (Ver_10-11-10.01) - NTFS_AMD64 
Run by Wouter Schrier at 23:51:37,02 on zo 14-11-2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.31.1033.18.4095.2678 [GMT 1:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Tunngle\TnglCtrl.exe
C:\Windows\explorer.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Wouter Schrier\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

mWinlogon: Userinit=userinit.exe
uWinlogon: Shell=C:\Users\Wouter Schrier\AppData\Roaming\hotfix.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Aanmelden - Help: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [HKCU] C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe
mRun: [<NO NAME>]
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
StartupFolder: C:\Users\WOUTER~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RAINME~1.LNK - C:\Program Files\Rainmeter\Rainmeter.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Verzenden naar OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: {98EE14C6-E263-4207-A5E6-6C85DF0B7778} = 8.8.4.4
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
AppInit_DLLs: acaptuser32.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64:     URLRedirectionBHO - No File
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
mRun-x64: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
AppInit_DLLs-X64: acaptuser64.dll

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-3-25 173984]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-8-4 203264]
R2 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2010-9-8 704760]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-8-4 7451648]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-8-4 268288]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\Windows\System32\drivers\l160x64.sys [2009-10-13 61440]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\System32\drivers\tap0901t.sys [2010-9-8 31232]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-3-25 40832]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-9-8 1255736]

=============== Created Last 30 ================

2010-11-14 21:27:53   194   ----a-w-   C:\Users\WOUTER~1\AppData\Roaming\sdghzxfg.bat
2010-11-14 21:27:52   564736   ----a-w-   C:\Users\WOUTER~1\AppData\Roaming\hotfix.exe
2010-11-13 22:27:24   8006480   ----a-w-   C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{31AF2623-BAB1-4124-8B34-0C933E707360}\mpengine.dll
2010-11-04 15:47:26   --------   d-----w-   C:\Program Files (x86)\Image Resizer
2010-10-31 20:55:36   21840   ----atw-   C:\Windows\SysWow64\SIntfNT.dll
2010-10-31 20:55:36   17212   ----atw-   C:\Windows\SysWow64\SIntf32.dll
2010-10-31 20:55:36   12067   ----atw-   C:\Windows\SysWow64\SIntf16.dll
2010-10-31 20:17:17   2829   ----a-w-   C:\Windows\DIIUnin.pif
2010-10-31 20:17:16   94208   ----a-w-   C:\Windows\DIIUnin.exe
2010-10-31 20:09:38   --------   d-----w-   C:\Program Files (x86)\Diablo II
2010-10-27 14:58:17   --------   d-----w-   C:\Users\WOUTER~1\AppData\Roaming\Hothead Games
2010-10-27 14:58:17   --------   d-----w-   C:\Users\WOUTER~1\AppData\Roaming\Hive Cluster
2010-10-27 14:55:04   --------   d-----w-   C:\Program Files (x86)\Deathspank
2010-10-27 14:52:22   961024   ----a-w-   C:\Windows\System32\CPFilters.dll
2010-10-27 14:52:22   641536   ----a-w-   C:\Windows\SysWow64\CPFilters.dll
2010-10-27 14:52:22   552960   ----a-w-   C:\Windows\System32\msdri.dll
2010-10-27 14:52:22   288256   ----a-w-   C:\Windows\System32\MSNP.ax
2010-10-27 14:52:22   258560   ----a-w-   C:\Windows\System32\mpg2splt.ax
2010-10-27 14:52:22   204288   ----a-w-   C:\Windows\SysWow64\MSNP.ax
2010-10-27 14:52:22   199680   ----a-w-   C:\Windows\SysWow64\mpg2splt.ax
2010-10-27 14:27:05   27008   ----a-w-   C:\Windows\System32\drivers\Diskdump.sys
2010-10-17 15:12:46   --------   d-----w-   C:\Documents
2010-10-16 21:10:47   --------   d-sh--w-   C:\PROGRA~3\DSS
2010-10-16 20:50:28   --------   d-----w-   C:\Program Files (x86)\Medal of Honor
2010-10-16 15:56:31   --------   d-----w-   C:\Users\Wouter Schrier\.spss
2010-10-16 15:55:21   --------   d-----w-   C:\PROGRA~3\SafeNet Sentinel
2010-10-16 15:54:58   --------   d-----w-   C:\Program Files (x86)\Common Files\SPSS
2010-10-16 15:54:58   --------   d-----w-   C:\PROGRA~3\SPSS
2010-10-16 15:53:28   --------   d-----w-   C:\Program Files (x86)\SPSSInc

==================== Find3M  ====================

2010-10-19 20:51:33   270720   ------w-   C:\Windows\System32\MpSigStub.exe
2010-09-24 08:27:05   65028   ----a-w-   C:\Users\WOUTER~1\AppData\Roaming\Wouter Schrier3SQLite3.dll
2010-09-10 05:35:44   135168   ----a-w-   C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43   347648   ----a-w-   C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 14:59:27   99384   ----a-w-   C:\Users\WOUTER~1\AppData\Roaming\inst.exe
2010-09-08 14:59:27   82816   ----a-w-   C:\Windows\System32\drivers\pcouffin.sys
2010-09-08 14:59:27   82816   ----a-w-   C:\Users\WOUTER~1\AppData\Roaming\pcouffin.sys
2010-09-08 12:43:03   18960   ----a-w-   C:\Windows\System32\drivers\LNonPnP.sys
2010-09-08 11:45:03   0   ----a-w-   C:\Windows\ativpsrm.bin
2010-09-08 05:36:17   1192960   ----a-w-   C:\Windows\System32\wininet.dll
2010-09-08 05:34:34   57856   ----a-w-   C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04   978432   ----a-w-   C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15   44544   ----a-w-   C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38   482816   ----a-w-   C:\Windows\System32\html.iec
2010-09-08 03:35:30   1638912   ----a-w-   C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31   386048   ----a-w-   C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16   1638912   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2010-09-01 05:12:09   12625920   ----a-w-   C:\Windows\System32\wmploc.DLL
2010-09-01 04:23:49   12625408   ----a-w-   C:\Windows\SysWow64\wmploc.DLL
2010-09-01 02:58:34   3123712   ----a-w-   C:\Windows\System32\win32k.sys
2010-08-31 04:32:30   954752   ----a-w-   C:\Windows\SysWow64\mfc40.dll
2010-08-31 04:32:30   954288   ----a-w-   C:\Windows\SysWow64\mfc40u.dll
2010-08-27 06:14:02   236032   ----a-w-   C:\Windows\System32\srvsvc.dll
2010-08-27 05:46:48   9728   ----a-w-   C:\Windows\SysWow64\sscore.dll
2010-08-27 03:38:04   463360   ----a-w-   C:\Windows\System32\drivers\srv.sys
2010-08-27 03:37:48   402944   ----a-w-   C:\Windows\System32\drivers\srv2.sys
2010-08-27 03:37:26   161792   ----a-w-   C:\Windows\System32\drivers\srvnet.sys
2010-08-26 05:27:28   148992   ----a-w-   C:\Windows\System32\t2embed.dll
2010-08-26 04:39:58   109056   ----a-w-   C:\Windows\SysWow64\t2embed.dll
2010-08-21 06:38:47   1024512   ----a-w-   C:\Windows\System32\wmpmde.dll
2010-08-21 06:36:49   340992   ----a-w-   C:\Windows\System32\schannel.dll
2010-08-21 06:31:06   633856   ----a-w-   C:\Windows\System32\comctl32.dll
2010-08-21 06:29:47   558592   ----a-w-   C:\Windows\System32\spoolsv.exe
2010-08-21 05:36:33   738816   ----a-w-   C:\Windows\SysWow64\wmpmde.dll
2010-08-21 05:36:24   224256   ----a-w-   C:\Windows\SysWow64\schannel.dll
2010-08-21 05:33:24   530432   ----a-w-   C:\Windows\SysWow64\comctl32.dll

============= FINISH: 23:51:57,25 ===============
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3879



WWW
« Reply #1 on: November 14, 2010, 06:50:24 PM »

Welcome to Malware Crypt w.schrier,

No outright infection so far, though there are some unfamiliar startups we do need to check them.

Many of the specialty tools we use in these repairs are not all updated for Windows 7, and/or 64 bit systems, which does limit some repairs. Also with 7, be sure to right click/run as administrator any scan files we use.


Open Task Manager (Ctrl-alt-delete then select that from the menu), and under the Processes tab locate and click on this file, then click End Process, and close Task manager:

C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe

-------------

For locating the unknown files, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"


Then just go here, press new topic, fill in the needed details and just give a link to your post back here (see the "Instructions for uploading files" there for help, if needed). Then press the browse button and then navigate to & select the following file on your computer.

C:\Users\Wouter Schrier\AppData\Roaming\hotfix.exe
C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe

You DO NOT need to be a member to upload, anybody can upload the files. You will not be able to see the file once uploaded.

Just click the "(more attachments)" next to the Browse button to upload more than one file.

--------------------

Download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup-1.46.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform quick scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    * The log is automatically saved by Malwarebytes and can be viewed by clicking the Logs tab in Malwarebytes.
    * Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.

--------------------

Click here and download OldTimer's OTL to your desktop, then click that to open the scan display. At the top check "Scan All Users", then click "Complete Scan". Make no other changes at this time.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are also saved in the same location as OTL.exe. Post the contents of those back here please.

Also the Malwarebytes log please.
Logged
w.schrier
Newbie
*
Posts: 5


« Reply #2 on: November 15, 2010, 03:27:11 AM »

Hello Jintan,

thank you for your welcome and fast reply!

I performed the actions you asked for, the only thing I couldn't do was upload the file C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe, since for some reason I was not able to find it!

Here are my logs:

OTL.txt


OTL logfile created on: 15-11-2010 10:22:23 - Run 1
OTL by OldTimer - Version 3.2.17.3     Folder = C:\Users\Wouter Schrier\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
 
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 71,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): s:\pagefile.sys 2048 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,66 Gb Total Space | 72,53 Gb Free Space | 43,78% Space Free | Partition Type: NTFS
Drive D: | 61,21 Gb Total Space | 37,40 Gb Free Space | 61,09% Space Free | Partition Type: NTFS
Drive E: | 300,10 Gb Total Space | 86,07 Gb Free Space | 28,68% Space Free | Partition Type: NTFS
Drive F: | 100,00 Gb Total Space | 40,13 Gb Free Space | 40,13% Space Free | Partition Type: NTFS
Drive G: | 300,54 Gb Total Space | 97,12 Gb Free Space | 32,32% Space Free | Partition Type: NTFS
Drive S: | 4,00 Gb Total Space | 1,95 Gb Free Space | 48,82% Space Free | Partition Type: NTFS
 
Computer Name: WOUTERSCHRIER | User Name: Wouter Schrier | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2010-11-15 10:21:22 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wouter Schrier\Downloads\OTL.exe
PRC - [2010-11-01 22:36:03 | 000,974,904 | ---- | M] (Google Inc.) -- C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010-04-01 10:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010-03-23 15:15:58 | 000,704,760 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe
PRC - [2010-02-26 06:10:20 | 021,979,992 | ---- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010-11-15 10:21:22 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wouter Schrier\Downloads\OTL.exe
MOD - [2010-08-21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010-08-04 00:51:22 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010-05-06 10:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2010-03-25 22:48:42 | 000,017,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009-12-15 21:07:16 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010-09-08 22:12:34 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010-03-23 15:15:58 | 000,704,760 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2010-02-19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2010-09-08 15:59:27 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
DRV:64bit: - [2010-09-08 15:46:11 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010-08-04 01:22:38 | 007,451,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010-08-04 00:15:46 | 000,268,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010-03-18 10:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2010-03-18 10:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010-03-18 10:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009-10-13 01:15:52 | 000,061,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\l160x64.sys -- (AtcL001)
DRV:64bit: - [2009-09-16 06:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV:64bit: - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2005-03-29 00:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 B1 9B 02 2F 80 CB 01  [binary data]
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
O1 HOSTS File: ([2010-09-08 22:10:11 | 000,000,859 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts:    127.0.0.1    activate.adobe.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\Wouter Schrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\SysWow64\acaptuser32.dll (Adobe Systems Incorporated)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010-11-15 10:06:29 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Malwarebytes
[2010-11-15 10:06:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-11-15 10:06:19 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010-11-15 10:06:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010-11-15 10:06:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010-11-04 16:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image Resizer
[2010-10-31 21:17:16 | 000,094,208 | ---- | C] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010-10-31 21:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo II
[2010-10-27 15:58:17 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Hothead Games
[2010-10-27 15:58:17 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Hive Cluster
[2010-10-27 15:55:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Deathspank
[2010-10-27 15:52:22 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010-10-27 15:52:22 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010-10-27 15:52:22 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010-10-27 15:52:22 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010-10-27 15:52:22 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2010-10-27 15:52:22 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010-10-27 15:52:22 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2010-10-27 15:27:05 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2010-10-17 16:12:46 | 000,000,000 | ---D | C] -- C:\Documents
[2010-10-16 22:10:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2010-10-16 22:10:46 | 000,000,000 | ---D | C] -- D:\Documents\EA Games
[2010-10-16 21:50:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Medal of Honor
[2010-10-16 16:56:31 | 000,000,000 | ---D | C] -- D:\Documents\SafeNet Sentinel
[2010-10-16 16:56:31 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\.spss
[2010-10-16 16:55:21 | 000,000,000 | ---D | C] -- C:\ProgramData\SafeNet Sentinel
[2010-10-16 16:54:58 | 000,000,000 | ---D | C] -- C:\ProgramData\SPSS
[2010-10-16 16:54:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SPSS
[2010-10-16 16:53:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SPSSInc
[2010-10-16 16:51:12 | 000,000,000 | ---D | C] -- D:\Documents\Kring Amsterdam
[2010-09-08 15:59:27 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010-11-15 10:20:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-11-15 10:20:04 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys
[2010-11-15 10:19:28 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\Access.dat
[2010-11-15 10:18:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1307191677-1467720726-2620043386-1000UA.job
[2010-11-15 10:06:23 | 000,001,019 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-11-15 09:58:09 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-11-15 09:58:09 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-11-15 09:56:30 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010-11-15 09:56:30 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010-11-15 09:56:30 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010-11-15 09:54:51 | 003,970,918 | -H-- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrierlog.dat
[2010-11-14 23:57:07 | 000,003,489 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\attach.zip
[2010-11-14 23:51:07 | 000,630,272 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\dds.scr
[2010-11-14 22:32:24 | 000,000,854 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\ThinkPoint.lnk
[2010-11-14 22:27:53 | 000,000,194 | ---- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\sdghzxfg.bat
[2010-11-13 23:18:00 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1307191677-1467720726-2620043386-1000Core.job
[2010-11-07 17:32:18 | 000,002,408 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Google Chrome.lnk
[2010-11-04 09:13:26 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-10-31 22:12:06 | 000,001,470 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Diablo II.exe - Shortcut.lnk
[2010-10-31 22:00:28 | 000,039,913 | ---- | M] () -- C:\Windows\DIIUnin.dat
[2010-10-31 21:59:10 | 000,021,840 | ---- | M] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010-10-31 21:59:10 | 000,017,212 | ---- | M] () -- C:\Windows\SysWow64\SIntf32.dll
[2010-10-31 21:59:10 | 000,012,067 | ---- | M] () -- C:\Windows\SysWow64\SIntf16.dll
[2010-10-31 21:23:23 | 000,001,911 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Diablo II - Lord of Destruction.lnk
[2010-10-31 21:17:17 | 000,002,829 | ---- | M] () -- C:\Windows\DIIUnin.pif
[2010-10-31 21:17:17 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\Diablo II.lnk
[2010-10-31 21:17:16 | 000,094,208 | ---- | M] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010-10-27 15:57:56 | 000,001,041 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\DeathSpank.lnk
[2010-10-17 23:41:43 | 000,001,626 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Medal of Honor.lnk
[2010-10-17 11:58:45 | 004,910,048 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010-11-15 10:06:23 | 000,001,019 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-11-14 23:57:07 | 000,003,489 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\attach.zip
[2010-11-14 23:51:03 | 000,630,272 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\dds.scr
[2010-11-14 22:29:33 | 000,000,854 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\ThinkPoint.lnk
[2010-11-14 22:27:53 | 000,000,194 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\sdghzxfg.bat
[2010-11-04 09:13:26 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-10-31 22:12:00 | 000,001,470 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\Diablo II.exe - Shortcut.lnk
[2010-10-31 21:55:36 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010-10-31 21:55:36 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2010-10-31 21:55:36 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2010-10-31 21:23:23 | 000,001,911 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\Diablo II - Lord of Destruction.lnk
[2010-10-31 21:17:18 | 000,039,913 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2010-10-31 21:17:17 | 000,002,829 | ---- | C] () -- C:\Windows\DIIUnin.pif
[2010-10-31 21:17:17 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\Diablo II.lnk
[2010-10-27 15:52:07 | 000,001,041 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\DeathSpank.lnk
[2010-10-17 23:41:43 | 000,001,626 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\Medal of Honor.lnk
[2010-09-24 09:27:05 | 000,065,028 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrier3SQLite3.dll
[2010-09-08 16:04:29 | 000,001,044 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\vso_ts_preview.xml
[2010-09-08 16:01:52 | 000,000,034 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.log
[2010-09-08 15:59:27 | 000,099,384 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\inst.exe
[2010-09-08 15:59:27 | 000,007,859 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.cat
[2010-09-08 15:59:27 | 000,001,167 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.inf
[2010-09-08 15:35:25 | 000,003,584 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2005-04-08 03:16:43 | 003,970,918 | -H-- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrierlog.dat

< End of report >


Logged
w.schrier
Newbie
*
Posts: 5


« Reply #3 on: November 15, 2010, 03:27:26 AM »

*****************************************************************

Extras.txt

OTL Extras logfile created on: 15-11-2010 10:22:23 - Run 1
OTL by OldTimer - Version 3.2.17.3     Folder = C:\Users\Wouter Schrier\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
 
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 71,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): s:\pagefile.sys 2048 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,66 Gb Total Space | 72,53 Gb Free Space | 43,78% Space Free | Partition Type: NTFS
Drive D: | 61,21 Gb Total Space | 37,40 Gb Free Space | 61,09% Space Free | Partition Type: NTFS
Drive E: | 300,10 Gb Total Space | 86,07 Gb Free Space | 28,68% Space Free | Partition Type: NTFS
Drive F: | 100,00 Gb Total Space | 40,13 Gb Free Space | 40,13% Space Free | Partition Type: NTFS
Drive G: | 300,54 Gb Total Space | 97,12 Gb Free Space | 32,32% Space Free | Partition Type: NTFS
Drive S: | 4,00 Gb Total Space | 1,95 Gb Free Space | 48,82% Space Free | Partition Type: NTFS
 
Computer Name: WOUTERSCHRIER | User Name: Wouter Schrier | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1387BA33-3FAC-49E9-B545-0E8D3BBC550B}" = Adobe Photoshop Lightroom 3 64-bit
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0413-1000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2010
"{90140000-0016-0413-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2010
"{90140000-0018-0413-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2010
"{90140000-0019-0413-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2010
"{90140000-001A-0413-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2010
"{90140000-001B-0413-1000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0413-1000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2010
"{90140000-002C-0413-1000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0413-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Dutch) 2010
"{90140000-0044-0413-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Dutch) 2010
"{90140000-006E-0413-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2010
"{90140000-00A1-0413-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2010
"{90140000-00BA-0413-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Dutch) 2010
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{A39FD4D2-002C-49F9-A13D-C15BC435D92E}" = Microsoft Antimalware Service NL-NL Language Pack
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AC76BA86-1033-0000-0064-0003D0000004}" = Adobe Acrobat 9 Pro Extended 64-bit Add-On
"{C862EC05-1C15-4327-B15D-C7788D6CFF73}" = Image Resizer Powertoy Clone for Windows (64 bit)
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"Microsoft Security Essentials" = Microsoft Security Essentials
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"SP6" = Logitech SetPoint 6.15
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{12ED438C-3908-43CD-8E35-0EB75C4F5B9F}_is1" = Sygic Assistant
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1BD6AE96-4742-4498-9D03-9451C7E5A214}" = Windows Live aanmeldhulp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live - Hulpprogramma voor uploaden
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{415030B8-3E8B-462A-8C03-41D95AA3AB3B}" = Medal of Honor (TM)
"{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}" = SPSS Statistics 17.0
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.8.0.193c
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = De Sims™ 3 Ambities
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}_932" = Adobe Acrobat 9.3.2 - CPSID_53951
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{ADE91A13-434D-4229-00BC-182BAD607303}" = Need for Speed™ Most Wanted
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = De Sims™ 3 Wereldavonturen
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C20C2630-B3A7-44BA-BDD0-31E256AE490E}" = Windows Live Call
"{CC38A00D-7EED-46CE-9281-D1D97B81F22A}" = Windows Live Messenger
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EB5A3E9D-91CF-4C97-B816-72DE0625ACA3}" = Windows Live Essentials
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1B1BB41-2494-4FC2-BEF7-9C282B6815A8}" = Image Resizer Powertoy Clone for Windows
"Adobe AIR" = Adobe AIR
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Diablo II" = Diablo II
"EVEREST Ultimate + Corporate Edition_is1" = EVEREST Ultimate v4.20.1257 + Corporate Edition Beta Registered
"FreeFileSync" = FreeFileSync v3.9
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"Lara Croft and the Guardian of Light_is1" = Lara Croft and the Guardian of Light
"Mafia II DLC Jimmy's Vendetta_is1" = Mafia II DLC Jimmy's Vendetta
"Mafia II Update 1_is1" = Mafia II Update 1
"Mafia II_is1" = Mafia II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NewsLeecher_is1" = NewsLeecher v4.0 Beta 18 ( using new supersearch engine )
"Rainmeter" = Rainmeter (remove only)
"SABnzbd" = SABnzbd (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 9-11-2010 12:56:06 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
Error - 9-11-2010 15:50:53 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
 Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3.  The value
 "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
 "version" in element "assemblyIdentity" is invalid.
 
Error - 9-11-2010 15:51:53 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\Adobe\acrobat
 9.0\designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
Error - 10-11-2010 16:27:38 | Computer Name = WouterSchrier | Source = Application Error | ID = 1000
Description = Faulting application name: speed.exe, version: 0.0.0.0, time stamp:
 0x438e4c8c  Faulting module name: speed.exe, version: 0.0.0.0, time stamp: 0x438e4c8c
Exception
 code: 0xc0000005  Fault offset: 0x00064f20  Faulting process id: 0xa14  Faulting application
 start time: 0x01cb811472f7b096  Faulting application path: C:\Program Files (x86)\Need
 for Speed Most Wanted\speed.exe  Faulting module path: C:\Program Files (x86)\Need
 for Speed Most Wanted\speed.exe  Report Id: f52af52d-ed08-11df-81f0-001e8c56b477
 
Error - 11-11-2010 17:47:33 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
 Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3.  The value
 "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
 "version" in element "assemblyIdentity" is invalid.
 
Error - 11-11-2010 17:48:31 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\Adobe\acrobat
 9.0\designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
Error - 14-11-2010 14:54:00 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
 Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
 Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3.  The value
 "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
 "version" in element "assemblyIdentity" is invalid.
 
Error - 14-11-2010 14:54:48 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\Adobe\acrobat
 9.0\designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
Error - 14-11-2010 17:38:11 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
Error - 14-11-2010 17:38:11 | Computer Name = WouterSchrier | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
 9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
.  A component version required by the application conflicts with another component
 version already active.  Conflicting components are:.  Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.
 
[ System Events ]
Error - 14-11-2010 17:38:05 | Computer Name = WouterSchrier | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 14-11-2010 17:38:05 | Computer Name = WouterSchrier | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 14-11-2010 17:54:00 | Computer Name = WouterSchrier | Source = DCOM | ID = 10005
Description =
 
Error - 14-11-2010 18:00:34 | Computer Name = WouterSchrier | Source = DCOM | ID = 10005
Description =
 
Error - 14-11-2010 18:00:35 | Computer Name = WouterSchrier | Source = DCOM | ID = 10005
Description =
 
Error - 14-11-2010 18:00:34 | Computer Name = WouterSchrier | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 14-11-2010 18:25:01 | Computer Name = WouterSchrier | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 14-11-2010 18:42:33 | Computer Name = WouterSchrier | Source = Microsoft Antimalware | ID = 3002
Description = %%861 Real-Time Protection feature has encountered an error and failed.

   Feature:
 %%835     Error Code: 0x80004005     Error description: Unspecified error      Reason: %%842
 
Error - 15-11-2010 4:50:59 | Computer Name = WouterSchrier | Source = Microsoft Antimalware | ID = 3002
Description = %%861 Real-Time Protection feature has encountered an error and failed.

   Feature:
 %%835     Error Code: 0x80004005     Error description: Unspecified error      Reason: %%842
 
Error - 15-11-2010 5:20:16 | Computer Name = WouterSchrier | Source = Microsoft Antimalware | ID = 3002
Description = %%861 Real-Time Protection feature has encountered an error and failed.

   Feature:
 %%835     Error Code: 0x80004005     Error description: Unspecified error      Reason: %%842
 
 
< End of report >


**********************************************************************

Malwarebytes' Anti-Malware 1.46


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5118

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

15-11-2010 10:18:50
mbam-log-2010-11-15 (10-18-50).txt

Scan type: Quick scan
Objects scanned: 138017
Time elapsed: 3 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hkcu (Backdoor.Bot.M) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Wouter Schrier\AppData\Roaming\hotfix.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\3.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\3029.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\302A.tmp.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\dwqw.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\IXP000.TMP\ppi.exe (PWS.Fignotok) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Roaming\install\server.exe (Backdoor.Bot.M) -> Quarantined and deleted successfully.
C:\Users\Wouter Schrier\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> Quarantined and deleted successfully.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3879



WWW
« Reply #4 on: November 15, 2010, 06:26:55 PM »

Since many, and very likely most, of these malware help requests are tied to the downloading and/or use of illegal software, we tend to see the same very expensive softwares in scan logs. Lately most often one of the Adobe CS versions. One fairly common method for illegally using CS installs is to block the program from contacting Adobe, which shows here in your last logs.

 Many of the other help sites end all assistance if anything showing illegal software use becomes known. Their help, and also mine and others, can be viewed as aiding those who are using their computer to quite literally/legally steal from others. I am surely not here to judge the deeds of others, but before we can go any further, I will need you to uninstall/delete all illegal programs and files that are on your system. Reboot after, then run and post a new OTL log please.
Logged
w.schrier
Newbie
*
Posts: 5


« Reply #5 on: November 16, 2010, 02:20:43 PM »

done.

This time; the OTL did not create an 'extra.txt' file; is it supposed to not do that?

PS: I couldn't find how to disable the blocking of the contacting of Adobe; so that may be still showing in the logs?

Here is the OTL.txt file:

OTL logfile created on: 16-11-2010 21:13:42 - Run 2
OTL by OldTimer - Version 3.2.17.3     Folder = C:\Users\Wouter Schrier\Downloads
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
 
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 67,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): s:\pagefile.sys 2048 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,66 Gb Total Space | 89,85 Gb Free Space | 54,24% Space Free | Partition Type: NTFS
Drive D: | 61,21 Gb Total Space | 37,39 Gb Free Space | 61,08% Space Free | Partition Type: NTFS
Drive E: | 300,10 Gb Total Space | 86,07 Gb Free Space | 28,68% Space Free | Partition Type: NTFS
Drive F: | 100,00 Gb Total Space | 40,27 Gb Free Space | 40,27% Space Free | Partition Type: NTFS
Drive G: | 300,54 Gb Total Space | 104,13 Gb Free Space | 34,65% Space Free | Partition Type: NTFS
Drive S: | 4,00 Gb Total Space | 1,95 Gb Free Space | 48,82% Space Free | Partition Type: NTFS
 
Computer Name: WOUTERSCHRIER | User Name: Wouter Schrier | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2010-11-15 10:21:22 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wouter Schrier\Downloads\OTL.exe
PRC - [2010-11-01 22:36:03 | 000,974,904 | ---- | M] (Google Inc.) -- C:\Users\Wouter Schrier\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010-04-01 10:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010-03-23 15:15:58 | 000,704,760 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe
PRC - [2010-02-26 06:10:20 | 021,979,992 | ---- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010-11-15 10:21:22 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Wouter Schrier\Downloads\OTL.exe
MOD - [2010-08-21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010-08-04 00:51:22 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010-05-06 10:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2010-03-25 22:48:42 | 000,017,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009-12-15 21:07:16 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010-03-23 15:15:58 | 000,704,760 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2010-09-08 15:59:27 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
DRV:64bit: - [2010-09-08 15:46:11 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010-08-04 01:22:38 | 007,451,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010-08-04 00:15:46 | 000,268,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010-03-18 10:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2010-03-18 10:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010-03-18 10:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009-10-13 01:15:52 | 000,061,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\l160x64.sys -- (AtcL001)
DRV:64bit: - [2009-09-16 06:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV:64bit: - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2005-03-29 00:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 B1 9B 02 2F 80 CB 01  [binary data]
IE - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
O1 HOSTS File: ([2010-09-08 22:10:11 | 000,000,859 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts:    127.0.0.1    activate.adobe.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1307191677-1467720726-2620043386-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\Wouter Schrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Wouter Schrier\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - AppInit_DLLs: (acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010-11-16 20:54:44 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010-11-16 20:52:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2010-11-15 10:06:29 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Malwarebytes
[2010-11-15 10:06:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-11-15 10:06:19 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010-11-15 10:06:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010-11-15 10:06:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010-11-04 16:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image Resizer
[2010-10-31 21:17:16 | 000,094,208 | ---- | C] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010-10-31 21:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo II
[2010-10-27 15:58:17 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Hothead Games
[2010-10-27 15:58:17 | 000,000,000 | ---D | C] -- C:\Users\Wouter Schrier\AppData\Roaming\Hive Cluster
[2010-10-27 15:55:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Deathspank
[2010-10-27 15:52:22 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010-10-27 15:52:22 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010-10-27 15:52:22 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010-10-27 15:52:22 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010-10-27 15:52:22 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2010-10-27 15:52:22 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010-10-27 15:52:22 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2010-10-27 15:27:05 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2010-09-08 15:59:27 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010-11-16 21:13:58 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-11-16 21:13:58 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-11-16 21:10:59 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010-11-16 21:10:59 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010-11-16 21:10:59 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010-11-16 21:06:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-11-16 21:06:31 | 004,896,080 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010-11-16 21:06:10 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys
[2010-11-16 21:05:35 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\Access.dat
[2010-11-16 08:18:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1307191677-1467720726-2620043386-1000UA.job
[2010-11-15 23:18:14 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1307191677-1467720726-2620043386-1000Core.job
[2010-11-15 10:06:23 | 000,001,019 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-11-15 09:54:51 | 003,970,918 | -H-- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrierlog.dat
[2010-11-14 23:51:07 | 000,630,272 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\dds.scr
[2010-11-14 22:27:53 | 000,000,194 | ---- | M] () -- C:\Users\Wouter Schrier\AppData\Roaming\sdghzxfg.bat
[2010-11-07 17:32:18 | 000,002,408 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Google Chrome.lnk
[2010-11-04 09:13:26 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-10-31 22:12:06 | 000,001,470 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Diablo II.exe - Shortcut.lnk
[2010-10-31 22:00:28 | 000,039,913 | ---- | M] () -- C:\Windows\DIIUnin.dat
[2010-10-31 21:59:10 | 000,021,840 | ---- | M] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010-10-31 21:59:10 | 000,017,212 | ---- | M] () -- C:\Windows\SysWow64\SIntf32.dll
[2010-10-31 21:59:10 | 000,012,067 | ---- | M] () -- C:\Windows\SysWow64\SIntf16.dll
[2010-10-31 21:23:23 | 000,001,911 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\Diablo II - Lord of Destruction.lnk
[2010-10-31 21:17:17 | 000,002,829 | ---- | M] () -- C:\Windows\DIIUnin.pif
[2010-10-31 21:17:17 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\Diablo II.lnk
[2010-10-31 21:17:16 | 000,094,208 | ---- | M] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010-10-27 15:57:56 | 000,001,041 | ---- | M] () -- C:\Users\Wouter Schrier\Desktop\DeathSpank.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010-11-15 10:06:23 | 000,001,019 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-11-14 23:51:03 | 000,630,272 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\dds.scr
[2010-11-14 22:27:53 | 000,000,194 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\sdghzxfg.bat
[2010-11-04 09:13:26 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-10-31 22:12:00 | 000,001,470 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\Diablo II.exe - Shortcut.lnk
[2010-10-31 21:55:36 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010-10-31 21:55:36 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2010-10-31 21:55:36 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2010-10-31 21:23:23 | 000,001,911 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\Diablo II - Lord of Destruction.lnk
[2010-10-31 21:17:18 | 000,039,913 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2010-10-31 21:17:17 | 000,002,829 | ---- | C] () -- C:\Windows\DIIUnin.pif
[2010-10-31 21:17:17 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\Diablo II.lnk
[2010-10-27 15:52:07 | 000,001,041 | ---- | C] () -- C:\Users\Wouter Schrier\Desktop\DeathSpank.lnk
[2010-09-24 09:27:05 | 000,065,028 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrier3SQLite3.dll
[2010-09-08 16:04:29 | 000,001,044 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\vso_ts_preview.xml
[2010-09-08 16:01:52 | 000,000,034 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.log
[2010-09-08 15:59:27 | 000,099,384 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\inst.exe
[2010-09-08 15:59:27 | 000,007,859 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.cat
[2010-09-08 15:59:27 | 000,001,167 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\pcouffin.inf
[2010-09-08 15:35:25 | 000,003,584 | ---- | C] () -- C:\Users\Wouter Schrier\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2005-04-08 03:16:43 | 003,970,918 | -H-- | C] () -- C:\Users\Wouter Schrier\AppData\Roaming\Wouter Schrierlog.dat

< End of report >



Logged
Jintan
Administrator
Hero Member
*****
Posts: 3879



WWW
« Reply #6 on: November 16, 2010, 07:53:48 PM »

The Adobe block is located in the Hosts. We can see if HijackThis will help in removing it. Not seeing any active infection, so let's run an additional scan to see what might remain.


Open HijackThis (right click/run as administrator) and click Config - Misc Tools - Open hosts file manager, and click "Open in Notepad", which will open a Notepad textbox. Just locate and delete this entry:

127.0.0.1    activate.adobe.com

Then go to File - Save, and allow it to save the new Hosts file. To check the changes were made still in HijackThis click Back, then click Open hosts file manager again and make sure your new text is there (then close HijackThis).

------------------

Disable your antivirus program and go here and run an online scan using ESET Online Scanner (you will need to use Internet Explorer for this scan, or download the installer to run it in a different browser). If you accept the Terms of Use, check the box and click Start. After the ActiveX Control has loaded, it will take a couple minutes for the scanner to get ready.  Next, check the following boxes:

Remove found threats
Scan unwanted applications


Next to "Current scan targets: Operating memory, Local drives", click the "Change" word. Make sure you place a check next to all disk drives, including any external drives that are attached (no need to check off the floppy or DVD/CD-Rom drives).

Click Start.  This scan may take a while, so please be patient.  A log may open when the scan is complete (if not, go to C:\Program Files\EsetOnlineScanner\ and open the file log.txt). Click Edit - Select All then copy/paste that log back here please.


If you have any problems getting Eset started, one work-around is to have an open Internet connection, and then click here and download the esetsmartinstaller_enu.exe Eset installer. Then click that file, and follow the same previous steps to run the scan.
Logged
w.schrier
Newbie
*
Posts: 5


« Reply #7 on: November 17, 2010, 01:58:10 AM »

Done: The Log-file didn't open by itself, so here is the content of the Log.txt file:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

------------------------------

In the end, ESET found and removed another 11 "threats" (see below), of which 1 was the executable of programs I use (newsleecher), which now I, sadly, cannot anymore.

C:\Program Files (x86)\Deathspank\Uninstall.exe   probably a variant of Win32/Agent.FFNCJSV trojan   cleaned by deleting - quarantined
C:\Program Files (x86)\NewsLeecher\newsLeecher.exe   probably a variant of Win32/Packed.Themida application   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WNM732P\1[1].exe   a variant of Win32/Kryptik.IDX trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WNM732P\lpgbiq[1].htm   a variant of Win32/Kryptik.IEZ trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2WNM732P\yctbwh[1].htm   a variant of Win32/Adware.FakeAntiSpy.S application   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2HO973A\mmuyj[1].htm   Win32/TrojanDownloader.FakeAlert.BBT trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QO943SYS\2[1].exe   a variant of Win32/Kryptik.IDK trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QO943SYS\3[1].exe   a variant of Win32/Olmarik.AHQ trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QO943SYS\otjrzgb[1].htm   Win32/Votwup.K trojan   cleaned by deleting - quarantined
C:\Users\Wouter Schrier\AppData\Local\Temp\muifnds.exe   Win32/Votwup.K trojan   cleaned by deleting - quarantined
G:\Uitzoeken\HUD.Vision_by_Jiri_Mahel-v1.81.exe   probably a variant of Win32/Agent.FRRLICC trojan   deleted - quarantined

------------------------------------------------

Seeing as there have been 10 more threats on my computer: do you recon that my Microsoft Security essentials is not good enough as a virus-scanner and I should look for a better alternative?
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3879



WWW
« Reply #8 on: November 17, 2010, 05:51:39 PM »

In general, no antivirus software blocks or catches every malware action. If you look through the other threads in this forum, you will see that almost all of them have a reputable antivirus program, and all have infected systems. Downloading and installing illegal softwares, all of which have at least 50% likelihood of containing malware code, bypasses any security anyway, since the user who clicks to run the installer file can also pass to the infection that user's permissions level. The AV program guards the front door, while the user opens the back door, and invites the infection in. Attending to ideas like these however will help with security issues.

The Eset log shows mostly installer-type infection files, and none that suggest active malware still exists. The rootkit references in the log do suggest we do at least one "stealth" scan.


Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Click here and download the installer for Gmer to your desktop, then click that file to run Gmer (right click - run as administrator).


Once the opening scan finishes, click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan). 

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document.  Once the file is created, open it and rightclick again and choose Paste.  Copy the information and post it here please.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
SMFAds for Free Forums
Valid XHTML 1.0! Valid CSS!