barbapapa5800
7 August 2008, 16:44
ik heb recent een nieuwe format gedaan en vind dat de pc traag is, trager dan XP.
uit een vorig topic heb ik gelezen over dss.exe, hier dan al een logje:
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-08-07 16:38:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-08-07 14:38:58 UTC - RP1 - Controlepunt van systeem
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-07 16:41:55
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Desktop Tray Clock\DTClock.exe
D:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\RTHDCPL.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\oodtray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\DynDNS Updater\DynUpPs.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\VoipBusterMate\VoipBusterMate.exe
D:\Program Files\DynDNS Updater\DynTray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\ccxgui\ccXservice.exe
C:\WINDOWS\ehome\ehRecvr.exe
C:\WINDOWS\ehome\ehSched.exe
D:\Program Files\ESET\ESET Smart Security\ekrn.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
D:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Administrator\Bureaublad\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.nl/
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SkinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl] "d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LanguageShortcut] "d:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [VoipBuster] "D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'Default user')
O4 - Startup: VoipBusterMate.lnk = D:\Program Files\VoipBusterMate\VoipBusterMate.exe
O4 - Global Startup: DynDNS Updater.lnk = D:\Program Files\DynDNS Updater\DynUpPs.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)
O9 - Extra 'Tools' menuitem: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O15 - ProtocolDefaults: Unknown 'about' protocol is in Restricted Zone (HKLM)
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{25902A38-06CB-4049-857C-F2F5BD26B813}: NameServer = 193.109.184.72,193.109.184.75
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ccXgui - [XC]D-Ice - D:\Program Files\ccxgui\ccXservice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\HCWTVServer.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
--
End of file - 9710 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 vaxscsi - c:\windows\system32\drivers\vaxscsi.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ccXgui - d:\program files\ccxgui\ccxservice.exe <Not Verified; [XC]D-Ice; >
R2 UPHClean (User Profile Hive Cleanup) - c:\program files\uphclean\uphclean.exe <Not Verified; Microsoft Corporation; User Profile Hive Cleanup Service>
S3 HauppaugeTVServer - c:\progra~1\wintv\hcwtvs~1.exe <Not Verified; Hauppauge Computer Works; Hauppauge TV Server>
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-07-07 and 2008-08-07 -----------------------------
2008-08-07 16:08:32 0 d-------- C:\WINDOWS\nview
2008-08-07 14:13:57 53248 --a------ C:\WINDOWS\system32\CSVer.dll <Not Verified; Windows XP Bundled build C-Centric Single User; Windows XP Bundled build C-Centric Single User CSVer>
2008-08-07 06:25:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-07 06:25:22 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-04 16:12:19 0 d-------- C:\Documents and Settings\All Users\Application Data\DynDNS
2008-07-31 15:28:58 0 d-------- C:\WINDOWS\system32\oodag
2008-07-31 15:14:44 1236992 --a------ C:\WINDOWS\system32\cpuz142.exe <Not Verified; CPUID; CPU-Z Application>
2008-07-31 14:14:19 0 d-------- C:\WINDOWS\CSC
2008-07-29 16:02:02 0 d-------- C:\WINDOWS\pss
2008-07-27 09:26:30 215144 -ra------ C:\WINDOWS\patchw32.dll
2008-07-27 09:25:53 215144 -ra------ C:\WINDOWS\pw32a.dll
2008-07-27 09:16:32 0 d-------- C:\Program Files\Symantec
2008-07-27 09:14:37 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-27 09:14:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-27 08:35:23 294912 --a------ C:\WINDOWS\system32\hcwzblast.dll <Not Verified; Zilog; IRblaster>
2008-07-27 08:35:23 65603 --a------ C:\WINDOWS\system32\hcwIRblast.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:35:01 0 d-------- C:\Program Files\Common Files\IviSDK
2008-07-27 08:34:47 28672 --a------ C:\WINDOWS\system32\hcwsched.dll <Not Verified; Hauppauge Computer Works; HCW Scheduler>
2008-07-27 08:34:47 69632 --a------ C:\WINDOWS\system32\3DES.dll <Not Verified; Hauppauge Computer Works; 3DES>
2008-07-27 08:34:34 0 d-------- C:\MyVideos
2008-07-27 08:34:33 30720 --a------ C:\WINDOWS\system32\hcwWinTVCI.dll <Not Verified; Hauppauge Computer Works; WinTVCI Dynamic Link Library>
2008-07-27 08:34:33 36921 --a------ C:\WINDOWS\system32\hcwutl32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:33 806985 -----n--- C:\WINDOWS\system32\hcwtvwnd.dll <Not Verified; Hauppauge Computer Works; HCWTVWND>
2008-07-27 08:34:33 163840 --a------ C:\WINDOWS\system32\hcwChDB.dll <Not Verified; ; HcwChDB Dynamic Link Library>
2008-07-27 08:34:33 65536 --a------ C:\WINDOWS\system32\dmcrypto.dll
2008-07-27 08:34:33 90190 --a------ C:\WINDOWS\system32\Bt848WST.DLL <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:30 106559 --a------ C:\WINDOWS\system32\hcwTVDlg.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 393216 --a------ C:\WINDOWS\system32\hcwsnbd9.dll <Not Verified; Snowbound Software Corporation (www.Snowbnd.com); SnowBound RasterMaster for NT/W2000>
2008-07-27 08:34:26 294968 -----n--- C:\WINDOWS\system32\hcwpnp32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 106552 --a------ C:\WINDOWS\system32\hcwi2c32.dll <Not Verified; Hauppauge Computer Works, Inc.; WinTV>
2008-07-27 08:34:26 11264 --a------ C:\WINDOWS\system32\hcwhook.dll <Not Verified; Hauppauge Computer Works; HCW hcwhook>
2008-07-27 08:34:26 213050 --a------ C:\WINDOWS\system32\hcwChan.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 0 d-------- C:\Program Files\WinTV
2008-07-26 23:33:22 0 d-------- C:\Program Files\MSXML 4.0
2008-07-26 14:02:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-26 13:43:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-07-26 11:37:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Dr. DivX 2.0 OSS
2008-07-25 07:19:57 0 d-------- C:\Program Files\DIKO
2008-07-24 21:30:48 0 d-------- C:\Documents and Settings\Administrator\Contacts
2008-07-24 21:30:04 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-07-24 21:23:50 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-24 21:23:30 0 d-------- C:\Program Files\Windows Live
2008-07-24 21:23:26 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-24 16:20:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-07-24 16:20:27 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-12 12:25:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\URSoft
2008-07-12 12:24:59 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-12 08:53:57 116736 --a------ C:\WINDOWS\system32\libsndfile-1.dll
2008-07-12 08:49:13 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-07-12 08:49:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-12 08:48:22 0 d-------- C:\Program Files\Nero
2008-07-12 08:48:22 0 d-------- C:\Program Files\Common Files\Ahead
2008-07-12 08:48:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-11 14:39:29 0 d-------- C:\WINDOWS\Downloaded Installations
2008-07-11 14:36:58 0 d-------- C:\WINDOWS\Sun
2008-07-11 14:36:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-07-10 16:53:39 35365 --a------ C:\WINDOWS\system32\uninstHelixYUV.exe
2008-07-09 13:24:07 28 --a------ C:\WINDOWS\system32\'
2008-07-09 13:23:57 5760 --a------ C:\WINDOWS\system32\vnchelp.dll <Not Verified; RDV Soft; UltraVnc Kernel>
2008-07-09 06:49:41 43602 --a------ C:\WINDOWS\system32\xvid-uninstall.exe
2008-07-09 06:42:46 0 d-------- C:\Documents and Settings\Administrator\Application Data\VoipBusterMate
2008-07-08 20:14:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\VoipBuster
2008-07-08 20:13:36 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-08 20:13:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-07-08 20:12:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-07-08 20:12:52 0 d-------- C:\Program Files\Skype
2008-07-08 20:12:51 0 d-------- C:\Program Files\Common Files\Skype
2008-07-08 20:12:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-08 19:10:55 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-08 19:10:55 47360 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-08 19:10:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Vso
2008-07-08 18:38:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-07-08 18:38:37 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-08 18:36:52 0 d-------- C:\Program Files\Cyberlink
2008-07-08 17:38:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-07-08 17:32:41 414272 --a------ C:\WINDOWS\system32\DivXc32f.dll <Not Verified; Hacked with Joy !; DivX ;-) MPEG-4 Video Codec>
2008-07-08 17:32:41 414272 --a------ C:\WINDOWS\system32\DivXc32.dll <Not Verified; Hacked with Joy !; DivX ;-) MPEG-4 Video Codec>
2008-07-08 16:55:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-07-08 14:46:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-07-08 14:28:59 0 d-------- C:\WINDOWS\system32\NtmsData
2008-07-08 06:33:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-07-08 06:33:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-07-08 06:30:54 0 d-------- C:\Program Files\Microsoft Works
2008-07-08 06:30:32 0 d-------- C:\Program Files\Microsoft.NET
2008-07-08 06:29:39 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-08 06:29:23 0 d-------- C:\WINDOWS\SHELLNEW
2008-07-08 06:29:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-08 06:29:05 0 dr-h----- C:\MSOCache
2008-07-07 21:29:22 0 d-------- C:\WINDOWS\system32\RTCOM
2008-07-07 21:25:42 0 d--hs---- C:\WINDOWS\Installer
2008-07-07 21:25:42 0 d-------- C:\Program Files\Common Files\ODBC
2008-07-07 21:25:40 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-07-07 21:25:39 0 dr------- C:\Program Files
2008-07-07 21:25:39 0 d-------- C:\Program Files\Common Files
2008-07-07 21:25:23 156160 --a------ C:\WINDOWS\NOTEPAD.EXE <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Sjablonen
2008-07-07 21:25:18 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Onlangs geopend
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Mijn documenten
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\Default User\Menu Start
2008-07-07 21:25:18 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Favorieten
2008-07-07 21:25:18 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Bureaublad
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\All Users\Sjablonen
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\All Users\Menu Start
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\All Users\Favorieten
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\All Users\Documenten
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\All Users\Bureaublad
2008-07-07 21:25:07 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-07-07 21:25:07 0 d-------- C:\WINDOWS\system32\CatRoot
2008-07-07 21:25:02 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-07-07 21:25:02 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-07-07 21:25:02 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-07-07 21:25:02 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-07-07 21:23:38 223128 --a------ C:\WINDOWS\system32\drivers\vaxscsi.sys
2008-07-07 21:23:16 4395008 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.sys <Not Verified; Realtek Semiconductor Corp.; Realtek(r) High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)>
2008-07-07 21:23:15 1822720 -r------- C:\WINDOWS\SkyTel.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Voice Manager>
2008-07-07 21:23:15 1191936 -r------- C:\WINDOWS\RtlUpd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update and remove driver Tool>
2008-07-07 21:23:14 16126464 -r------- C:\WINDOWS\RTHDCPL.exe <Not Verified; Realtek Semiconductor Corp.; Realtek HD Audio Sound Effect Manager>
2008-07-07 21:23:14 2157568 -r------- C:\WINDOWS\MicCal.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Audio Microphone Calibration>
2008-07-07 21:21:12 48128 --a------ C:\WINDOWS\system32\wnaspi32.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 23936 --a------ C:\WINDOWS\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 5600 --a------ C:\WINDOWS\system\winaspi.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 23936 --a------ C:\WINDOWS\system\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:18:31 0 d--hs---- C:\System Volume Information
2008-07-07 21:18:31 0 d-------- C:\Documents and Settings
2008-07-07 21:17:46 0 d-------- C:\WINDOWS\SFD
2008-07-07 21:14:14 0 d-------- C:\WINDOWS
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\WinSxS
2008-07-07 21:14:14 0 dr------- C:\WINDOWS\Web
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\twain_32
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\wins
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\wbem
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\usmt
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\spool
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ShellExt
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\Setup
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ras
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\oobe
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\npp
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\mui
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\inetsrv
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\IME
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\icsxml
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ias
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\export
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-07-07 21:14:14 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\dhcp
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\config
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\3076
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\2052
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1054
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1043
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1042
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1041
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1037
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1033
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1031
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1028
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1025
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\security
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Resources
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\repair
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Provisioning
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\PeerNet
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\pchealth
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\mui
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\msapps
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\msagent
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Media
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\java
2008-07-07 21:14:14 0 d--h----- C:\WINDOWS\inf
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\ime
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Help
2008-07-07 21:14:14 0 dr--s---- C:\WINDOWS\Fonts
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\ehome
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Driver Cache
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Debug
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Cursors
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Connection Wizard
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Config
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\AppPatch
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\addins
2008-07-07 20:59:33 0 d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-07-07 20:51:24 0 d-------- C:\Documents and Settings\Administrator\Downloads
2008-07-07 20:51:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\NewsLeecher
2008-07-07 20:44:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-07 20:36:18 49152 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-07-07 20:36:16 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-07 20:35:46 1953792 -r------- C:\WINDOWS\system32\JMRaidSetup.exe <Not Verified; Gigabyte Technology Corp.; Gigabyte RAID Configurer>
2008-07-07 20:35:46 143360 -r------- C:\WINDOWS\system32\JMRaidAPI.dll <Not Verified; JMicron Technology Corp.; JMB36X RAID API Dynamic Link Library>
2008-07-07 20:35:39 0 d-------- C:\WINDOWS\JM
2008-07-07 20:35:28 0 d-------- C:\WINDOWS\OPTIONS
2008-07-07 20:35:26 0 d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-07 20:35:11 0 d-------- C:\Program Files\Realtek
2008-07-07 20:35:10 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-07 20:35:08 520192 -r------- C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-07-07 20:35:08 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-07-07 20:35:05 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-07 20:34:52 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-07-07 20:33:28 0 d-------- C:\Program Files\Intel
2008-07-07 20:33:25 0 d-------- C:\Intel
2008-07-07 20:29:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-07-07 20:26:48 0 d-------- C:\WINDOWS\system32\appmgmt
2008-07-07 20:18:27 0 d-------- C:\Documents and Settings\Administrator\Application Data\ESET
2008-07-07 20:18:03 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 20:11:09 357655 --a------ C:\WINDOWS\system32\UN_windowssidebar.exe
2008-07-07 20:11:09 0 d-------- C:\Program Files\Windows Sidebar
2008-07-07 20:11:09 0 d-------- C:\Program Files\Windows Sidebar GadgetInstaller
2008-07-07 20:11:04 0 d-------- C:\WINDOWS\l2schemas
2008-07-07 20:10:53 0 d-------- C:\WINDOWS\Local Settings
2008-07-07 20:10:53 0 d-------- C:\Program Files\Desktop Tray Clock
2008-07-07 20:10:53 0 d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-07-07 20:10:53 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-07-07 20:10:47 0 d-------- C:\Program Files\Windows Journal Viewer
2008-07-07 20:10:43 0 d-------- C:\Program Files\HashTab Shell Extension
2008-07-07 20:06:00 0 d-------- C:\WINDOWS\system32\nl-nl
2008-07-07 20:01:59 0 d-------- C:\WINDOWS\system32\Lang
2008-07-07 20:01:48 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-07-07 19:45:48 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-07 19:45:45 0 d--h----- C:\WINDOWS\$hf_mig$
2008-07-07 19:43:29 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-07-07 19:43:29 0 d-------- C:\Program Files\MSBuild
2008-07-07 19:43:26 0 d-------- C:\Program Files\Reference Assemblies
2008-07-07 19:42:41 0 d-------- C:\Program Files\MSXML 6.0
2008-07-07 19:41:46 124928 -----n--- C:\WINDOWS\system32\prntvpt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:41:07 0 d-------- C:\Program Files\UPHClean
2008-07-07 19:41:03 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe <Not Verified; Sysinternals - www.sysinternals.com; Page File Defragmenter>
2008-07-07 19:40:49 0 d-------- C:\Program Files\Windows Media Connect 2
2008-07-07 19:40:24 0 d-------- C:\WINDOWS\system32\LogFiles
2008-07-07 19:40:24 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Sjablonen
2008-07-07 19:39:44 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-07 19:39:44 0 d--hs---- C:\Documents and Settings\Administrator\Onlangs geopend
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Netwerkprinteromgeving
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-07 19:39:44 0 d---s---- C:\Documents and Settings\Administrator\Mijn documenten
2008-07-07 19:39:44 0 dr------- C:\Documents and Settings\Administrator\Menu Start
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-07 19:39:44 0 d---s---- C:\Documents and Settings\Administrator\Favorieten
2008-07-07 19:39:44 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-07 19:39:44 0 d-------- C:\Documents and Settings\Administrator\Bureaublad
2008-07-07 19:39:44 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-07 19:39:43 2883584 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-07 19:39:26 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-07-07 19:39:23 0 d-------- C:\WINDOWS\Prefetch
2008-07-07 19:39:22 786432 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-07-07 19:39:22 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-07-07 19:39:22 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-07-07 19:39:22 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-07-07 19:39:22 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-07-07 19:39:17 786432 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-07-07 19:39:17 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-07-07 19:39:17 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-07-07 19:39:17 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-07-07 19:39:17 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-07-07 19:38:18 434176 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-07-07 19:37:48 55086 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-07-07 19:37:27 6120 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-07-07 19:37:24 0 d-------- C:\WINDOWS\BricoPacks
2008-07-07 19:37:08 715248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-07 19:36:32 0 d-------- C:\Program Files\Windows Plus
2008-07-07 19:36:31 3345408 --a------ C:\WINDOWS\system32\nature.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:31 1744896 --a------ C:\WINDOWS\system32\mypixdx.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:30 5070848 --a------ C:\WINDOWS\system32\davinci.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:29 7095808 --a------ C:\WINDOWS\system32\space.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:27 4397056 --a------ C:\WINDOWS\system32\wpgldfsh.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:21 85504 --a------ C:\WINDOWS\system32\mhn.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:36:21 8704 --a------ C:\WINDOWS\system32\igdetect.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:36:21 11008 --a------ C:\WINDOWS\system32\drivers\mhndrv.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:35:04 0 d-------- C:\WINDOWS\system32\URTTemp
2008-07-07 19:34:45 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-07-07 19:34:36 0 d-------- C:\Program Files\Java
2008-07-07 19:34:36 0 d-------- C:\Program Files\Common Files\Java
2008-07-07 19:34:25 0 d-------- C:\Program Files\VAIOXP
2008-07-07 19:34:04 0 -rahs---- C:\MSDOS.SYS
2008-07-07 19:34:04 0 -rahs---- C:\IO.SYS
2008-07-07 19:34:04 0 --a------ C:\CONFIG.SYS
2008-07-07 19:34:04 0 --a------ C:\AUTOEXEC.BAT
2008-07-07 19:33:35 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-07-07 19:33:30 0 dr------- C:\WINDOWS\Offline Web Pages
2008-07-07 19:33:30 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-07-07 19:33:25 0 d--h----- C:\Program Files\WindowsUpdate
2008-07-07 19:33:22 0 d-------- C:\Program Files\Online Services
2008-07-07 19:33:09 0 d-------- C:\WINDOWS\system32\DirectX
2008-07-07 19:32:37 0 d---s---- C:\WINDOWS\Tasks
2008-07-07 19:32:36 0 d-------- C:\Program Files\Common Files\MSSoap
2008-07-07 19:32:33 0 d-------- C:\WINDOWS\srchasst
2008-07-07 19:32:32 0 d-------- C:\WINDOWS\system32\Macromed
2008-07-07 19:32:28 287744 --a------ C:\WINDOWS\system32\wuauclt1.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:32:25 0 d-------- C:\Program Files\Movie Maker
2008-07-07 19:32:17 0 d-------- C:\WINDOWS\system32\Restore
2008-07-07 19:32:10 325120 --a------ C:\WINDOWS\system32\mstask.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:52 21748 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-07-07 19:31:43 0 d-------- C:\WINDOWS\Registration
2008-07-07 19:31:33 0 d-------- C:\WINDOWS\VistaDrive
2008-07-07 19:31:30 0 d-------- C:\Program Files\MSN Gaming Zone
2008-07-07 19:31:20 152576 --a------ C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:02 181760 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:01 442880 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:01 0 d-------- C:\Program Files\Windows NT
2008-07-07 19:30:59 657408 --a------ C:\WINDOWS\system32\mstscax.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:30:58 0 d-------- C:\WINDOWS\system32\MsDtc
2008-07-07 19:30:56 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2008-08-07 16:10:29 843 --a------ C:\Documents and Settings\Administrator\Application Data\DesktopTrayClock.ini
2008-08-06 21:06:10 512410 --a------ C:\WINDOWS\system32\perfh013.dat
2008-08-06 21:06:10 92052 --a------ C:\WINDOWS\system32\perfc013.dat
2008-08-06 17:49:33 494 --a------ C:\Documents and Settings\Administrator\Application Data\alarms.ini
2008-07-28 21:13:54 642 --a------ C:\Documents and Settings\Administrator\Application Data\AutoGK.ini
2008-07-09 06:59:03 34 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.log
2008-07-09 06:59:01 1144 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.inf
2008-07-09 06:59:01 7887 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.cat
2008-07-07 21:25:18 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2008-07-07 19:37:48 219136 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-06-20 06:40:46 351744 --a------ C:\WINDOWS\system32\avisynth.dll <Not Verified; The Public; Avisynth 2.5>
2008-06-11 02:07:20 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-11 02:03:26 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-06-11 02:03:26 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-06-11 02:03:20 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-06-11 02:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:20 815104 --a------ C:\WINDOWS\system32\divx_xx0a.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:18 683520 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-23 00:18:54 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-16 14:01:00 1630208 --a------ C:\WINDOWS\system32\nwiz.exe
2008-05-16 14:01:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-05-16 14:01:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-05-16 14:01:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-05-16 14:01:00 1486848 --a------ C:\WINDOWS\system32\nview.dll
2008-05-16 14:01:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-05-16 14:01:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-05-16 14:01:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SkinClock"="C:\Program Files\Desktop Tray Clock\DTClock.exe" [22/10/2007 15:49]
"egui"="D:\Program Files\ESET\ESET Smart Security\egui.exe" [21/12/2007 08:21]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [30/10/2006 14:44]
"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [06/02/2007 14:08]
"RTHDCPL"="RTHDCPL.EXE" [21/03/2007 08:49 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 12:43 C:\WINDOWS\Alcmtr.exe]
"RemoteControl"="d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [07/02/2007 16:24]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [11/05/2007 02:08]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [05/10/2006 20:56]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/03/2007 15:57]
"LanguageShortcut"="d:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [07/02/2007 16:21]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [10/08/2004 04:04]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [16/05/2008 14:01]
"nwiz"="nwiz.exe" [16/05/2008 14:01 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [16/05/2008 14:01]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [31/12/2002 10:00]
"SkinClock"="C:\Program Files\Desktop Tray Clock\DTClock.exe" [22/10/2007 15:49]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [30/05/2008 15:54]
"VoipBuster"="D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" [17/01/2008 15:54]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [27/06/2007 19:03]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"PackNoVs"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs
C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\
VoipBusterMate.lnk - D:\Program Files\VoipBusterMate\VoipBusterMate.exe [28/06/2007 4:00:52]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
DynDNS Updater.lnk - D:\Program Files\DynDNS Updater\DynUpPs.exe [23/06/2008 21:04:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyle s
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\system]
"SetVisualStyle"=C:\WINDOWS\Resources\Themes\Inspirat2\Inspirat2.m sstyles
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoRemoteRecursiveEvents"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"ForceClassicControlPanel"=1 (0x1)
"NoSaveSettings"=0 (0x0)
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^AutoStart IR.lnk]
backup=C:\WINDOWS\pss\AutoStart IR.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 14.0]
"D:\Program Files\Norton Ghost\Agent\VProTray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
C:\WINDOWS\system32\hidec /W "C:\Program Files\VAIOXP\Tools\regtlib.exe" "C:\Program Files\Windows Sidebar\sidebar.exe"
-- End of Deckard's System Scanner: finished at 2008-08-07 16:42:33 ------------
uit een vorig topic heb ik gelezen over dss.exe, hier dan al een logje:
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-08-07 16:38:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-08-07 14:38:58 UTC - RP1 - Controlepunt van systeem
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-07 16:41:55
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Desktop Tray Clock\DTClock.exe
D:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\RTHDCPL.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\oodtray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\DynDNS Updater\DynUpPs.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\VoipBusterMate\VoipBusterMate.exe
D:\Program Files\DynDNS Updater\DynTray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\ccxgui\ccXservice.exe
C:\WINDOWS\ehome\ehRecvr.exe
C:\WINDOWS\ehome\ehSched.exe
D:\Program Files\ESET\ESET Smart Security\ekrn.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
D:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Administrator\Bureaublad\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.nl/
O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SkinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl] "d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LanguageShortcut] "d:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [VoipBuster] "D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [PackNoVs] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs (User 'Default user')
O4 - Startup: VoipBusterMate.lnk = D:\Program Files\VoipBusterMate\VoipBusterMate.exe
O4 - Global Startup: DynDNS Updater.lnk = D:\Program Files\DynDNS Updater\DynUpPs.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)
O9 - Extra 'Tools' menuitem: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O15 - ProtocolDefaults: Unknown 'about' protocol is in Restricted Zone (HKLM)
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{25902A38-06CB-4049-857C-F2F5BD26B813}: NameServer = 193.109.184.72,193.109.184.75
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ccXgui - [XC]D-Ice - D:\Program Files\ccxgui\ccXservice.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\HCWTVServer.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
--
End of file - 9710 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 vaxscsi - c:\windows\system32\drivers\vaxscsi.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ccXgui - d:\program files\ccxgui\ccxservice.exe <Not Verified; [XC]D-Ice; >
R2 UPHClean (User Profile Hive Cleanup) - c:\program files\uphclean\uphclean.exe <Not Verified; Microsoft Corporation; User Profile Hive Cleanup Service>
S3 HauppaugeTVServer - c:\progra~1\wintv\hcwtvs~1.exe <Not Verified; Hauppauge Computer Works; Hauppauge TV Server>
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-07-07 and 2008-08-07 -----------------------------
2008-08-07 16:08:32 0 d-------- C:\WINDOWS\nview
2008-08-07 14:13:57 53248 --a------ C:\WINDOWS\system32\CSVer.dll <Not Verified; Windows XP Bundled build C-Centric Single User; Windows XP Bundled build C-Centric Single User CSVer>
2008-08-07 06:25:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-07 06:25:22 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-04 16:12:19 0 d-------- C:\Documents and Settings\All Users\Application Data\DynDNS
2008-07-31 15:28:58 0 d-------- C:\WINDOWS\system32\oodag
2008-07-31 15:14:44 1236992 --a------ C:\WINDOWS\system32\cpuz142.exe <Not Verified; CPUID; CPU-Z Application>
2008-07-31 14:14:19 0 d-------- C:\WINDOWS\CSC
2008-07-29 16:02:02 0 d-------- C:\WINDOWS\pss
2008-07-27 09:26:30 215144 -ra------ C:\WINDOWS\patchw32.dll
2008-07-27 09:25:53 215144 -ra------ C:\WINDOWS\pw32a.dll
2008-07-27 09:16:32 0 d-------- C:\Program Files\Symantec
2008-07-27 09:14:37 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-27 09:14:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-27 08:35:23 294912 --a------ C:\WINDOWS\system32\hcwzblast.dll <Not Verified; Zilog; IRblaster>
2008-07-27 08:35:23 65603 --a------ C:\WINDOWS\system32\hcwIRblast.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:35:01 0 d-------- C:\Program Files\Common Files\IviSDK
2008-07-27 08:34:47 28672 --a------ C:\WINDOWS\system32\hcwsched.dll <Not Verified; Hauppauge Computer Works; HCW Scheduler>
2008-07-27 08:34:47 69632 --a------ C:\WINDOWS\system32\3DES.dll <Not Verified; Hauppauge Computer Works; 3DES>
2008-07-27 08:34:34 0 d-------- C:\MyVideos
2008-07-27 08:34:33 30720 --a------ C:\WINDOWS\system32\hcwWinTVCI.dll <Not Verified; Hauppauge Computer Works; WinTVCI Dynamic Link Library>
2008-07-27 08:34:33 36921 --a------ C:\WINDOWS\system32\hcwutl32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:33 806985 -----n--- C:\WINDOWS\system32\hcwtvwnd.dll <Not Verified; Hauppauge Computer Works; HCWTVWND>
2008-07-27 08:34:33 163840 --a------ C:\WINDOWS\system32\hcwChDB.dll <Not Verified; ; HcwChDB Dynamic Link Library>
2008-07-27 08:34:33 65536 --a------ C:\WINDOWS\system32\dmcrypto.dll
2008-07-27 08:34:33 90190 --a------ C:\WINDOWS\system32\Bt848WST.DLL <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:30 106559 --a------ C:\WINDOWS\system32\hcwTVDlg.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 393216 --a------ C:\WINDOWS\system32\hcwsnbd9.dll <Not Verified; Snowbound Software Corporation (www.Snowbnd.com); SnowBound RasterMaster for NT/W2000>
2008-07-27 08:34:26 294968 -----n--- C:\WINDOWS\system32\hcwpnp32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 106552 --a------ C:\WINDOWS\system32\hcwi2c32.dll <Not Verified; Hauppauge Computer Works, Inc.; WinTV>
2008-07-27 08:34:26 11264 --a------ C:\WINDOWS\system32\hcwhook.dll <Not Verified; Hauppauge Computer Works; HCW hcwhook>
2008-07-27 08:34:26 213050 --a------ C:\WINDOWS\system32\hcwChan.dll <Not Verified; Hauppauge Computer Works; WinTV>
2008-07-27 08:34:26 0 d-------- C:\Program Files\WinTV
2008-07-26 23:33:22 0 d-------- C:\Program Files\MSXML 4.0
2008-07-26 14:02:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-26 13:43:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-07-26 11:37:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Dr. DivX 2.0 OSS
2008-07-25 07:19:57 0 d-------- C:\Program Files\DIKO
2008-07-24 21:30:48 0 d-------- C:\Documents and Settings\Administrator\Contacts
2008-07-24 21:30:04 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-07-24 21:23:50 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-24 21:23:30 0 d-------- C:\Program Files\Windows Live
2008-07-24 21:23:26 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-24 16:20:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-07-24 16:20:27 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-12 12:25:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\URSoft
2008-07-12 12:24:59 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-12 08:53:57 116736 --a------ C:\WINDOWS\system32\libsndfile-1.dll
2008-07-12 08:49:13 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-07-12 08:49:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-12 08:48:22 0 d-------- C:\Program Files\Nero
2008-07-12 08:48:22 0 d-------- C:\Program Files\Common Files\Ahead
2008-07-12 08:48:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-11 14:39:29 0 d-------- C:\WINDOWS\Downloaded Installations
2008-07-11 14:36:58 0 d-------- C:\WINDOWS\Sun
2008-07-11 14:36:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-07-10 16:53:39 35365 --a------ C:\WINDOWS\system32\uninstHelixYUV.exe
2008-07-09 13:24:07 28 --a------ C:\WINDOWS\system32\'
2008-07-09 13:23:57 5760 --a------ C:\WINDOWS\system32\vnchelp.dll <Not Verified; RDV Soft; UltraVnc Kernel>
2008-07-09 06:49:41 43602 --a------ C:\WINDOWS\system32\xvid-uninstall.exe
2008-07-09 06:42:46 0 d-------- C:\Documents and Settings\Administrator\Application Data\VoipBusterMate
2008-07-08 20:14:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\VoipBuster
2008-07-08 20:13:36 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-08 20:13:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-07-08 20:12:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-07-08 20:12:52 0 d-------- C:\Program Files\Skype
2008-07-08 20:12:51 0 d-------- C:\Program Files\Common Files\Skype
2008-07-08 20:12:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-08 19:10:55 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-08 19:10:55 47360 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-07-08 19:10:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Vso
2008-07-08 18:38:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-07-08 18:38:37 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-08 18:36:52 0 d-------- C:\Program Files\Cyberlink
2008-07-08 17:38:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-07-08 17:32:41 414272 --a------ C:\WINDOWS\system32\DivXc32f.dll <Not Verified; Hacked with Joy !; DivX ;-) MPEG-4 Video Codec>
2008-07-08 17:32:41 414272 --a------ C:\WINDOWS\system32\DivXc32.dll <Not Verified; Hacked with Joy !; DivX ;-) MPEG-4 Video Codec>
2008-07-08 16:55:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-07-08 14:46:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-07-08 14:28:59 0 d-------- C:\WINDOWS\system32\NtmsData
2008-07-08 06:33:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-07-08 06:33:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-07-08 06:30:54 0 d-------- C:\Program Files\Microsoft Works
2008-07-08 06:30:32 0 d-------- C:\Program Files\Microsoft.NET
2008-07-08 06:29:39 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-08 06:29:23 0 d-------- C:\WINDOWS\SHELLNEW
2008-07-08 06:29:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-08 06:29:05 0 dr-h----- C:\MSOCache
2008-07-07 21:29:22 0 d-------- C:\WINDOWS\system32\RTCOM
2008-07-07 21:25:42 0 d--hs---- C:\WINDOWS\Installer
2008-07-07 21:25:42 0 d-------- C:\Program Files\Common Files\ODBC
2008-07-07 21:25:40 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-07-07 21:25:39 0 dr------- C:\Program Files
2008-07-07 21:25:39 0 d-------- C:\Program Files\Common Files
2008-07-07 21:25:23 156160 --a------ C:\WINDOWS\NOTEPAD.EXE <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Sjablonen
2008-07-07 21:25:18 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Onlangs geopend
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Mijn documenten
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\Default User\Menu Start
2008-07-07 21:25:18 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Favorieten
2008-07-07 21:25:18 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\Default User\Bureaublad
2008-07-07 21:25:18 0 d--h----- C:\Documents and Settings\All Users\Sjablonen
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\All Users\Menu Start
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\All Users\Favorieten
2008-07-07 21:25:18 0 dr------- C:\Documents and Settings\All Users\Documenten
2008-07-07 21:25:18 0 d-------- C:\Documents and Settings\All Users\Bureaublad
2008-07-07 21:25:07 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-07-07 21:25:07 0 d-------- C:\WINDOWS\system32\CatRoot
2008-07-07 21:25:02 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-07-07 21:25:02 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-07-07 21:25:02 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-07-07 21:25:02 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-07-07 21:23:38 223128 --a------ C:\WINDOWS\system32\drivers\vaxscsi.sys
2008-07-07 21:23:16 4395008 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.sys <Not Verified; Realtek Semiconductor Corp.; Realtek(r) High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)>
2008-07-07 21:23:15 1822720 -r------- C:\WINDOWS\SkyTel.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Voice Manager>
2008-07-07 21:23:15 1191936 -r------- C:\WINDOWS\RtlUpd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update and remove driver Tool>
2008-07-07 21:23:14 16126464 -r------- C:\WINDOWS\RTHDCPL.exe <Not Verified; Realtek Semiconductor Corp.; Realtek HD Audio Sound Effect Manager>
2008-07-07 21:23:14 2157568 -r------- C:\WINDOWS\MicCal.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Audio Microphone Calibration>
2008-07-07 21:21:12 48128 --a------ C:\WINDOWS\system32\wnaspi32.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 23936 --a------ C:\WINDOWS\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 5600 --a------ C:\WINDOWS\system\winaspi.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:21:12 23936 --a------ C:\WINDOWS\system\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-07-07 21:18:31 0 d--hs---- C:\System Volume Information
2008-07-07 21:18:31 0 d-------- C:\Documents and Settings
2008-07-07 21:17:46 0 d-------- C:\WINDOWS\SFD
2008-07-07 21:14:14 0 d-------- C:\WINDOWS
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\WinSxS
2008-07-07 21:14:14 0 dr------- C:\WINDOWS\Web
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\twain_32
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\wins
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\wbem
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\usmt
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\spool
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ShellExt
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\Setup
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ras
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\oobe
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\npp
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\mui
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\inetsrv
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\IME
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\icsxml
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\ias
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\export
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-07-07 21:14:14 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\dhcp
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\config
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\3076
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\2052
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1054
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1043
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1042
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1041
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1037
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1033
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1031
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1028
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system32\1025
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\system
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\security
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Resources
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\repair
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Provisioning
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\PeerNet
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\pchealth
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\mui
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\msapps
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\msagent
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Media
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\java
2008-07-07 21:14:14 0 d--h----- C:\WINDOWS\inf
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\ime
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Help
2008-07-07 21:14:14 0 dr--s---- C:\WINDOWS\Fonts
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\ehome
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Driver Cache
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Debug
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Cursors
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Connection Wizard
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\Config
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\AppPatch
2008-07-07 21:14:14 0 d-------- C:\WINDOWS\addins
2008-07-07 20:59:33 0 d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-07-07 20:51:24 0 d-------- C:\Documents and Settings\Administrator\Downloads
2008-07-07 20:51:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\NewsLeecher
2008-07-07 20:44:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-07 20:36:18 49152 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-07-07 20:36:16 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-07 20:35:46 1953792 -r------- C:\WINDOWS\system32\JMRaidSetup.exe <Not Verified; Gigabyte Technology Corp.; Gigabyte RAID Configurer>
2008-07-07 20:35:46 143360 -r------- C:\WINDOWS\system32\JMRaidAPI.dll <Not Verified; JMicron Technology Corp.; JMB36X RAID API Dynamic Link Library>
2008-07-07 20:35:39 0 d-------- C:\WINDOWS\JM
2008-07-07 20:35:28 0 d-------- C:\WINDOWS\OPTIONS
2008-07-07 20:35:26 0 d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-07 20:35:11 0 d-------- C:\Program Files\Realtek
2008-07-07 20:35:10 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-07 20:35:08 520192 -r------- C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-07-07 20:35:08 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-07-07 20:35:05 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-07 20:34:52 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-07-07 20:33:28 0 d-------- C:\Program Files\Intel
2008-07-07 20:33:25 0 d-------- C:\Intel
2008-07-07 20:29:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-07-07 20:26:48 0 d-------- C:\WINDOWS\system32\appmgmt
2008-07-07 20:18:27 0 d-------- C:\Documents and Settings\Administrator\Application Data\ESET
2008-07-07 20:18:03 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 20:11:09 357655 --a------ C:\WINDOWS\system32\UN_windowssidebar.exe
2008-07-07 20:11:09 0 d-------- C:\Program Files\Windows Sidebar
2008-07-07 20:11:09 0 d-------- C:\Program Files\Windows Sidebar GadgetInstaller
2008-07-07 20:11:04 0 d-------- C:\WINDOWS\l2schemas
2008-07-07 20:10:53 0 d-------- C:\WINDOWS\Local Settings
2008-07-07 20:10:53 0 d-------- C:\Program Files\Desktop Tray Clock
2008-07-07 20:10:53 0 d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-07-07 20:10:53 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-07-07 20:10:47 0 d-------- C:\Program Files\Windows Journal Viewer
2008-07-07 20:10:43 0 d-------- C:\Program Files\HashTab Shell Extension
2008-07-07 20:06:00 0 d-------- C:\WINDOWS\system32\nl-nl
2008-07-07 20:01:59 0 d-------- C:\WINDOWS\system32\Lang
2008-07-07 20:01:48 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-07-07 19:45:48 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-07 19:45:45 0 d--h----- C:\WINDOWS\$hf_mig$
2008-07-07 19:43:29 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-07-07 19:43:29 0 d-------- C:\Program Files\MSBuild
2008-07-07 19:43:26 0 d-------- C:\Program Files\Reference Assemblies
2008-07-07 19:42:41 0 d-------- C:\Program Files\MSXML 6.0
2008-07-07 19:41:46 124928 -----n--- C:\WINDOWS\system32\prntvpt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:41:07 0 d-------- C:\Program Files\UPHClean
2008-07-07 19:41:03 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe <Not Verified; Sysinternals - www.sysinternals.com; Page File Defragmenter>
2008-07-07 19:40:49 0 d-------- C:\Program Files\Windows Media Connect 2
2008-07-07 19:40:24 0 d-------- C:\WINDOWS\system32\LogFiles
2008-07-07 19:40:24 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Sjablonen
2008-07-07 19:39:44 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-07 19:39:44 0 d--hs---- C:\Documents and Settings\Administrator\Onlangs geopend
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Netwerkprinteromgeving
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-07 19:39:44 0 d---s---- C:\Documents and Settings\Administrator\Mijn documenten
2008-07-07 19:39:44 0 dr------- C:\Documents and Settings\Administrator\Menu Start
2008-07-07 19:39:44 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-07 19:39:44 0 d---s---- C:\Documents and Settings\Administrator\Favorieten
2008-07-07 19:39:44 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-07 19:39:44 0 d-------- C:\Documents and Settings\Administrator\Bureaublad
2008-07-07 19:39:44 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-07 19:39:43 2883584 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-07 19:39:26 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-07-07 19:39:23 0 d-------- C:\WINDOWS\Prefetch
2008-07-07 19:39:22 786432 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-07-07 19:39:22 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-07-07 19:39:22 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-07-07 19:39:22 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-07-07 19:39:22 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-07-07 19:39:17 786432 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-07-07 19:39:17 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-07-07 19:39:17 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-07-07 19:39:17 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-07-07 19:39:17 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-07-07 19:38:18 434176 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-07-07 19:37:48 55086 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-07-07 19:37:27 6120 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-07-07 19:37:24 0 d-------- C:\WINDOWS\BricoPacks
2008-07-07 19:37:08 715248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-07 19:36:32 0 d-------- C:\Program Files\Windows Plus
2008-07-07 19:36:31 3345408 --a------ C:\WINDOWS\system32\nature.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:31 1744896 --a------ C:\WINDOWS\system32\mypixdx.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:30 5070848 --a------ C:\WINDOWS\system32\davinci.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:29 7095808 --a------ C:\WINDOWS\system32\space.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:27 4397056 --a------ C:\WINDOWS\system32\wpgldfsh.scr <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:36:21 85504 --a------ C:\WINDOWS\system32\mhn.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:36:21 8704 --a------ C:\WINDOWS\system32\igdetect.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:36:21 11008 --a------ C:\WINDOWS\system32\drivers\mhndrv.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:35:04 0 d-------- C:\WINDOWS\system32\URTTemp
2008-07-07 19:34:45 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-07-07 19:34:36 0 d-------- C:\Program Files\Java
2008-07-07 19:34:36 0 d-------- C:\Program Files\Common Files\Java
2008-07-07 19:34:25 0 d-------- C:\Program Files\VAIOXP
2008-07-07 19:34:04 0 -rahs---- C:\MSDOS.SYS
2008-07-07 19:34:04 0 -rahs---- C:\IO.SYS
2008-07-07 19:34:04 0 --a------ C:\CONFIG.SYS
2008-07-07 19:34:04 0 --a------ C:\AUTOEXEC.BAT
2008-07-07 19:33:35 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-07-07 19:33:30 0 dr------- C:\WINDOWS\Offline Web Pages
2008-07-07 19:33:30 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-07-07 19:33:25 0 d--h----- C:\Program Files\WindowsUpdate
2008-07-07 19:33:22 0 d-------- C:\Program Files\Online Services
2008-07-07 19:33:09 0 d-------- C:\WINDOWS\system32\DirectX
2008-07-07 19:32:37 0 d---s---- C:\WINDOWS\Tasks
2008-07-07 19:32:36 0 d-------- C:\Program Files\Common Files\MSSoap
2008-07-07 19:32:33 0 d-------- C:\WINDOWS\srchasst
2008-07-07 19:32:32 0 d-------- C:\WINDOWS\system32\Macromed
2008-07-07 19:32:28 287744 --a------ C:\WINDOWS\system32\wuauclt1.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:32:25 0 d-------- C:\Program Files\Movie Maker
2008-07-07 19:32:17 0 d-------- C:\WINDOWS\system32\Restore
2008-07-07 19:32:10 325120 --a------ C:\WINDOWS\system32\mstask.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:52 21748 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-07-07 19:31:43 0 d-------- C:\WINDOWS\Registration
2008-07-07 19:31:33 0 d-------- C:\WINDOWS\VistaDrive
2008-07-07 19:31:30 0 d-------- C:\Program Files\MSN Gaming Zone
2008-07-07 19:31:20 152576 --a------ C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:02 181760 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:01 442880 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-07-07 19:31:01 0 d-------- C:\Program Files\Windows NT
2008-07-07 19:30:59 657408 --a------ C:\WINDOWS\system32\mstscax.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-07 19:30:58 0 d-------- C:\WINDOWS\system32\MsDtc
2008-07-07 19:30:56 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2008-08-07 16:10:29 843 --a------ C:\Documents and Settings\Administrator\Application Data\DesktopTrayClock.ini
2008-08-06 21:06:10 512410 --a------ C:\WINDOWS\system32\perfh013.dat
2008-08-06 21:06:10 92052 --a------ C:\WINDOWS\system32\perfc013.dat
2008-08-06 17:49:33 494 --a------ C:\Documents and Settings\Administrator\Application Data\alarms.ini
2008-07-28 21:13:54 642 --a------ C:\Documents and Settings\Administrator\Application Data\AutoGK.ini
2008-07-09 06:59:03 34 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.log
2008-07-09 06:59:01 1144 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.inf
2008-07-09 06:59:01 7887 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.cat
2008-07-07 21:25:18 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2008-07-07 19:37:48 219136 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
2008-06-20 06:40:46 351744 --a------ C:\WINDOWS\system32\avisynth.dll <Not Verified; The Public; Avisynth 2.5>
2008-06-11 02:07:20 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-11 02:03:26 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-06-11 02:03:26 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-06-11 02:03:20 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-06-11 02:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:20 815104 --a------ C:\WINDOWS\system32\divx_xx0a.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-11 02:03:18 683520 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-23 00:18:54 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-16 14:01:00 1630208 --a------ C:\WINDOWS\system32\nwiz.exe
2008-05-16 14:01:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-05-16 14:01:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-05-16 14:01:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-05-16 14:01:00 1486848 --a------ C:\WINDOWS\system32\nview.dll
2008-05-16 14:01:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-05-16 14:01:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-05-16 14:01:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SkinClock"="C:\Program Files\Desktop Tray Clock\DTClock.exe" [22/10/2007 15:49]
"egui"="D:\Program Files\ESET\ESET Smart Security\egui.exe" [21/12/2007 08:21]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [30/10/2006 14:44]
"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [06/02/2007 14:08]
"RTHDCPL"="RTHDCPL.EXE" [21/03/2007 08:49 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 12:43 C:\WINDOWS\Alcmtr.exe]
"RemoteControl"="d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [07/02/2007 16:24]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [11/05/2007 02:08]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [05/10/2006 20:56]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/03/2007 15:57]
"LanguageShortcut"="d:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [07/02/2007 16:21]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [10/08/2004 04:04]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [16/05/2008 14:01]
"nwiz"="nwiz.exe" [16/05/2008 14:01 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [16/05/2008 14:01]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [31/12/2002 10:00]
"SkinClock"="C:\Program Files\Desktop Tray Clock\DTClock.exe" [22/10/2007 15:49]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [30/05/2008 15:54]
"VoipBuster"="D:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" [17/01/2008 15:54]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [27/06/2007 19:03]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"PackNoVs"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe" --unsetvs
C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\
VoipBusterMate.lnk - D:\Program Files\VoipBusterMate\VoipBusterMate.exe [28/06/2007 4:00:52]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
DynDNS Updater.lnk - D:\Program Files\DynDNS Updater\DynUpPs.exe [23/06/2008 21:04:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyle s
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\system]
"SetVisualStyle"=C:\WINDOWS\Resources\Themes\Inspirat2\Inspirat2.m sstyles
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoRemoteRecursiveEvents"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"ForceClassicControlPanel"=1 (0x1)
"NoSaveSettings"=0 (0x0)
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^AutoStart IR.lnk]
backup=C:\WINDOWS\pss\AutoStart IR.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 14.0]
"D:\Program Files\Norton Ghost\Agent\VProTray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
C:\WINDOWS\system32\hidec /W "C:\Program Files\VAIOXP\Tools\regtlib.exe" "C:\Program Files\Windows Sidebar\sidebar.exe"
-- End of Deckard's System Scanner: finished at 2008-08-07 16:42:33 ------------