This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Downloader:Win32/Renos.IO New log

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I've posted a thread before with a hijackthis log, but yesterday, I did a scan with the online service of Onecare.live. It found 4 Trojan downloaders as described in the title.
I scannned my computer before with windows defender and avast, but they found nothing.
I deleted the Trojans with onecare, but now I want to know if everything is allright, and the Trojan didn't left negative traces on my computer.
Sorry for the duplicated post, but I was panicking and thought the worst for my computer.
I hope somebody could take a look if everything is allright.

Thank you for the patience, and thank you for all the good help I see on this forum.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:04, on 19/07/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Itunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Windows\system32\conime.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.be/ig/dell?hl=nl&cli…amp;ibd=3081203
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ig?hl=nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer aangeboden door Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\Itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; Tablet PC 2.0; .NET CLR 3.5.21022; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.habbo.nl/shockwave_client"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote-inhoudsopgave.onetoc2
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…e/wlscctrl2.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/51.28/uploader2.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.euro.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUpldnl-be.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.21.0.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updateservice (gupdate1c98e038bad370b) (gupdate1c98e038bad370b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe

–
End of file - 11976 bytes
Welcome to What The Tech! My name is Adam and I will be assisting you with getting the malware off of your computer. Please observe the following points before we start:
  • If at any point you don't understand something, please let me know and I will be glad to explain or go more into depth for you. :)
  • Please remember, I am a volunteer and I have a personal life. I go to school full time, have a part time job, and I do sports. A lot of this takes a lot of time.
  • Please keep all of your replies in this topic/thread and do not make a new topic/thread, thanks!
  • Please stick with this, don't stop responding because the symptoms are gone, the infection could still be there. Keep replying to my posts until I give you the All Clean message. ;)
  • If you don't reply within five days after my last instructions this topic will be closed. If you will not be able to reply within five days please tell me so the topic will not be closed.
  • Please do not run other tools to remove the malware unless I ask you to until I give you the all clean. They will just mess up my fixes and make things more complicated, not fix the problem.

RSIT
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

Regards,
Adam
Hi Adam, thank you for your time to check my computer.

4.Please stick with this, don't stop responding because the symptoms are gone, the infection could still be there. Keep replying to my posts until I give you the All Clean message.


It's actually for this rule I need you most. Cause I deleted the Trojan as sed in my first post.

So here are the logs:

Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-07-21 08:49:20
Microsoft® Windows Vista™ Ultimate Service Pack 2
System drive C: has 401 GB (87%) free of 462 GB
Total RAM: 3326 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:23, on 21/07/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Itunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\conime.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Hans\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Hans.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.be/ig/dell?hl=nl&cli…amp;ibd=3081203
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ig?hl=nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer aangeboden door Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\Itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; Tablet PC 2.0; .NET CLR 3.5.21022; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.habbo.nl/shockwave_client"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote-inhoudsopgave.onetoc2
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/51.28/uploader2.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.euro.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUpldnl-be.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.21.0.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updateservice (gupdate1c98e038bad370b) (gupdate1c98e038bad370b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe

–
End of file - 12038 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\OGADaily.job
C:\Windows\tasks\OGALogon.job
C:\Windows\tasks\RtlNICDiagVistaStart.job
C:\Windows\tasks\User_Feed_Synchronization-{AD43C8BF-DAF2-4ACF-95C5-D59A28F6690A}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Aanmelden - Help - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-10 259696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-07-15 669168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-26 470512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-10 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"dellsupportcenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-10-04 206064]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-01-23 101136]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-01-12 488984]
"LVCOMSX"=C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe [2007-01-12 244512]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"iTunesHelper"=C:\Program Files\Itunes\iTunesHelper.exe [2009-04-02 342312]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-03 39408]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"PlayNC Launcher"= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"=C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE [2009-01-16 460216]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe
OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
OneNote-inhoudsopgave.onetoc2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-12-03 10536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2007-07-20 233888]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1256283-c0d6-11dd-a7f9-806e6f6e6963}]
shell\AutoRun\command - F:\zs2009.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-07-21 08:49:20 —-D—- C:\rsit
2009-07-19 14:31:42 —-D—- C:\Windows\system32\NCLauncher.exe=
2009-07-18 14:19:23 —-D—- C:\Program Files\Windows Live Safety Center
2009-07-18 14:10:04 —-D—- C:\Windows\system32\vi-VN
2009-07-18 14:10:04 —-D—- C:\Windows\system32\eu-ES
2009-07-18 14:10:04 —-D—- C:\Windows\system32\ca-ES
2009-07-18 13:58:43 —-D—- C:\Windows\system32\EventProviders
2009-07-18 13:51:51 —-A—- C:\Windows\system32\NlsLexicons0007.dll
2009-07-18 13:51:48 —-A—- C:\Windows\system32\SLCExt.dll
2009-07-18 13:51:47 —-A—- C:\Windows\system32\SLsvc.exe
2009-07-18 13:51:46 —-A—- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-07-18 13:51:46 —-A—- C:\Windows\system32\DevicePairingWizard.exe
2009-07-18 13:51:45 —-A—- C:\Windows\system32\NlsLexicons0009.dll
2009-07-18 13:51:44 —-A—- C:\Windows\system32\mssrch.dll
2009-07-18 13:51:42 —-A—- C:\Windows\system32\tquery.dll
2009-07-18 13:51:41 —-A—- C:\Windows\system32\PresentationNative_v0300.dll
2009-07-18 13:51:41 —-A—- C:\Windows\system32\lsasrv.dll
2009-07-18 13:51:40 —-A—- C:\Windows\system32\scavenge.dll
2009-07-18 13:51:40 —-A—- C:\Windows\system32\RMActivate_isv.exe
2009-07-18 13:51:40 —-A—- C:\Windows\system32\RMActivate.exe
2009-07-18 13:51:39 —-A—- C:\Windows\system32\msi.dll
2009-07-18 13:51:38 —-A—- C:\Windows\system32\WscEapPr.dll
2009-07-18 13:51:38 —-A—- C:\Windows\system32\secproc_isv.dll
2009-07-18 13:51:38 —-A—- C:\Windows\system32\imapi2fs.dll
2009-07-18 13:51:37 —-A—- C:\Windows\system32\wcnwiz2.dll
2009-07-18 13:51:37 —-A—- C:\Windows\system32\sysmain.dll
2009-07-18 13:51:35 —-A—- C:\Windows\system32\mf.dll
2009-07-18 13:51:35 —-A—- C:\Windows\system32\icardagt.exe
2009-07-18 13:51:35 —-A—- C:\Windows\system32\EhStorShell.dll
2009-07-18 13:51:35 —-A—- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-07-18 13:51:34 —-A—- C:\Windows\system32\spreview.exe
2009-07-18 13:51:34 —-A—- C:\Windows\system32\spinstall.exe
2009-07-18 13:51:33 —-A—- C:\Windows\system32\drmv2clt.dll
2009-07-18 13:51:32 —-A—- C:\Windows\system32\spwizui.dll
2009-07-18 13:51:32 —-A—- C:\Windows\system32\shell32.dll
2009-07-18 13:51:32 —-A—- C:\Windows\system32\secproc.dll
2009-07-18 13:51:32 —-A—- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-07-18 13:51:30 —-A—- C:\Windows\system32\p2psvc.dll
2009-07-18 13:51:29 —-A—- C:\Windows\system32\SearchIndexer.exe
2009-07-18 13:51:29 —-A—- C:\Windows\system32\mssvp.dll
2009-07-18 13:51:28 —-A—- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-07-18 13:51:28 —-A—- C:\Windows\system32\mscoree.dll
2009-07-18 13:51:27 —-A—- C:\Windows\system32\sdohlp.dll
2009-07-18 13:51:27 —-A—- C:\Windows\system32\mssphtb.dll
2009-07-18 13:51:27 —-A—- C:\Windows\system32\mssph.dll
2009-07-18 13:51:27 —-A—- C:\Windows\system32\imapi2.dll
2009-07-18 13:51:26 —-A—- C:\Windows\system32\ntkrnlpa.exe
2009-07-18 13:51:26 —-A—- C:\Windows\system32\IMJP10K.DLL
2009-07-18 13:51:26 —-A—- C:\Windows\system32\esent.dll
2009-07-18 13:51:26 —-A—- C:\Windows\system32\DevicePairing.dll
2009-07-18 13:51:25 —-A—- C:\Windows\system32\wevtsvc.dll
2009-07-18 13:51:25 —-A—- C:\Windows\system32\sperror.dll
2009-07-18 13:51:25 —-A—- C:\Windows\system32\RMActivate_ssp.exe
2009-07-18 13:51:25 —-A—- C:\Windows\system32\PresentationHostProxy.dll
2009-07-18 13:51:25 —-A—- C:\Windows\system32\korwbrkr.dll
2009-07-18 13:51:24 —-A—- C:\Windows\system32\wmp.dll
2009-07-18 13:51:24 —-A—- C:\Windows\system32\SLC.dll
2009-07-18 13:51:24 —-A—- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-07-18 13:51:24 —-A—- C:\Windows\system32\msshsq.dll
2009-07-18 13:51:23 —-A—- C:\Windows\system32\WMVCORE.DLL
2009-07-18 13:51:23 —-A—- C:\Windows\system32\pmcsnap.dll
2009-07-18 13:51:23 —-A—- C:\Windows\system32\msjet40.dll
2009-07-18 13:51:23 —-A—- C:\Windows\system32\MPSSVC.dll
2009-07-18 13:51:22 —-A—- C:\Windows\system32\Query.dll
2009-07-18 13:51:22 —-A—- C:\Windows\system32\ntoskrnl.exe
2009-07-18 13:51:22 —-A—- C:\Windows\system32\msxml6.dll
2009-07-18 13:51:21 —-A—- C:\Windows\system32\qmgr.dll
2009-07-18 13:51:21 —-A—- C:\Windows\system32\P2PGraph.dll
2009-07-18 13:51:21 —-A—- C:\Windows\system32\msexch40.dll
2009-07-18 13:51:21 —-A—- C:\Windows\system32\diagperf.dll
2009-07-18 13:51:20 —-A—- C:\Windows\system32\srchadmin.dll
2009-07-18 13:51:20 —-A—- C:\Windows\system32\ole32.dll
2009-07-18 13:51:20 —-A—- C:\Windows\system32\ntdll.dll
2009-07-18 13:51:20 —-A—- C:\Windows\system32\msxml3.dll
2009-07-18 13:51:20 —-A—- C:\Windows\system32\IasMigReader.exe
2009-07-18 13:51:19 —-A—- C:\Windows\system32\winload.exe
2009-07-18 13:51:19 —-A—- C:\Windows\system32\uDWM.dll
2009-07-18 13:51:19 —-A—- C:\Windows\system32\mmc.exe
2009-07-18 13:51:19 —-A—- C:\Windows\system32\mblctr.exe
2009-07-18 13:51:19 —-A—- C:\Windows\system32\EncDec.dll
2009-07-18 13:51:18 —-A—- C:\Windows\system32\IasMigPlugin.dll
2009-07-18 13:51:18 —-A—- C:\Windows\system32\dfsr.exe
2009-07-18 13:51:17 —-A—- C:\Windows\system32\riched20.dll
2009-07-18 13:51:17 —-A—- C:\Windows\system32\fdBth.dll
2009-07-18 13:51:16 —-A—- C:\Windows\system32\RacEngn.dll
2009-07-18 13:51:15 —-A—- C:\Windows\system32\kernel32.dll
2009-07-18 13:51:14 —-A—- C:\Windows\system32\SearchProtocolHost.exe
2009-07-18 13:51:14 —-A—- C:\Windows\system32\SearchFilterHost.exe
2009-07-18 13:51:14 —-A—- C:\Windows\system32\milcore.dll
2009-07-18 13:51:14 —-A—- C:\Windows\system32\EhStorAPI.dll
2009-07-18 13:51:14 —-A—- C:\Windows\system32\CertEnroll.dll
2009-07-18 13:51:13 —-A—- C:\Windows\system32\spoolss.dll
2009-07-18 13:51:13 —-A—- C:\Windows\system32\schedsvc.dll
2009-07-18 13:51:13 —-A—- C:\Windows\system32\NaturalLanguage6.dll
2009-07-18 13:51:12 —-A—- C:\Windows\system32\msvcp60.dll
2009-07-18 13:51:12 —-A—- C:\Windows\system32\msjtes40.dll
2009-07-18 13:51:12 —-A—- C:\Windows\system32\infocardapi.dll
2009-07-18 13:51:12 —-A—- C:\Windows\system32\gpedit.dll
2009-07-18 13:51:12 —-A—- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-07-18 13:51:11 —-A—- C:\Windows\system32\WinSAT.exe
2009-07-18 13:51:11 —-A—- C:\Windows\system32\PresentationSettings.exe
2009-07-18 13:51:11 —-A—- C:\Windows\system32\fveapi.dll
2009-07-18 13:51:11 —-A—- C:\Windows\system32\es.dll
2009-07-18 13:51:11 —-A—- C:\Windows\system32\cscsvc.dll
2009-07-18 13:51:10 —-A—- C:\Windows\system32\mstext40.dll
2009-07-18 13:51:10 —-A—- C:\Windows\system32\Magnify.exe
2009-07-18 13:51:10 —-A—- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-07-18 13:51:10 —-A—- C:\Windows\system32\advapi32.dll
2009-07-18 13:51:09 —-A—- C:\Windows\system32\WMPhoto.dll
2009-07-18 13:51:09 —-A—- C:\Windows\system32\WebClnt.dll
2009-07-18 13:51:09 —-A—- C:\Windows\system32\slwmi.dll
2009-07-18 13:51:09 —-A—- C:\Windows\system32\msexcl40.dll
2009-07-18 13:51:09 —-A—- C:\Windows\system32\comsvcs.dll
2009-07-18 13:51:08 —-A—- C:\Windows\system32\vssapi.dll
2009-07-18 13:51:08 —-A—- C:\Windows\system32\msxbde40.dll
2009-07-18 13:51:08 —-A—- C:\Windows\system32\authui.dll
2009-07-18 13:51:07 —-A—- C:\Windows\system32\NetProjW.dll
2009-07-18 13:51:07 —-A—- C:\Windows\system32\mstscax.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\propsys.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\PresentationHost.exe
2009-07-18 13:51:06 —-A—- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\newdev.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\msrepl40.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\iasrecst.dll
2009-07-18 13:51:06 —-A—- C:\Windows\system32\gpsvc.dll
2009-07-18 13:51:05 —-A—- C:\Windows\system32\rpcss.dll
2009-07-18 13:51:05 —-A—- C:\Windows\system32\eudcedit.exe
2009-07-18 13:51:05 —-A—- C:\Windows\system32\crypt32.dll
2009-07-18 13:51:05 —-A—- C:\Windows\explorer.exe
2009-07-18 13:51:04 —-A—- C:\Windows\system32\setupapi.dll
2009-07-18 13:51:04 —-A—- C:\Windows\system32\mspbde40.dll
2009-07-18 13:51:04 —-A—- C:\Windows\system32\msltus40.dll
2009-07-18 13:51:04 —-A—- C:\Windows\system32\davclnt.dll
2009-07-18 13:51:04 —-A—- C:\Windows\system32\d3d9.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\shlwapi.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\msrd3x40.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\msdtctm.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\mfc42.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\EhStorPwdMgr.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\EhStorAuthn.dll
2009-07-18 13:51:03 —-A—- C:\Windows\system32\browseui.dll
2009-07-18 13:51:02 —-A—- C:\Windows\system32\wevtapi.dll
2009-07-18 13:51:02 —-A—- C:\Windows\system32\user32.dll
2009-07-18 13:51:02 —-A—- C:\Windows\system32\photowiz.dll
2009-07-18 13:51:02 —-A—- C:\Windows\system32\nlhtml.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\win32spl.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\WcnNetsh.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\SLCommDlg.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\samsrv.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\quartz.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\oleaut32.dll
2009-07-18 13:51:01 —-A—- C:\Windows\system32\ci.dll
2009-07-18 13:51:00 —-A—- C:\Windows\system32\winhttp.dll
2009-07-18 13:51:00 —-A—- C:\Windows\system32\printfilterpipelinesvc.exe
2009-07-18 13:51:00 —-A—- C:\Windows\system32\netshell.dll
2009-07-18 13:51:00 —-A—- C:\Windows\system32\msv1_0.dll
2009-07-18 13:51:00 —-A—- C:\Windows\system32\kerberos.dll
2009-07-18 13:51:00 —-A—- C:\Windows\system32\IKEEXT.DLL
2009-07-18 13:51:00 —-A—- C:\Windows\system32\compcln.exe
2009-07-18 13:51:00 —-A—- C:\Windows\system32\apds.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\xmlfilter.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\mswstr10.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\msvcrt.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\msctf.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\gdi32.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\emdmgmt.dll
2009-07-18 13:50:59 —-A—- C:\Windows\system32\audiosrv.dll
2009-07-18 13:50:58 —-A—- C:\Windows\system32\VSSVC.exe
2009-07-18 13:50:58 —-A—- C:\Windows\system32\SLUI.exe
2009-07-18 13:50:58 —-A—- C:\Windows\system32\QAGENTRT.DLL
2009-07-18 13:50:58 —-A—- C:\Windows\system32\msrd2x40.dll
2009-07-18 13:50:58 —-A—- C:\Windows\system32\mfc42u.dll
2009-07-18 13:50:58 —-A—- C:\Windows\system32\iphlpsvc.dll
2009-07-18 13:50:58 —-A—- C:\Windows\system32\eapphost.dll
2009-07-18 13:50:57 —-A—- C:\Windows\system32\winresume.exe
2009-07-18 13:50:57 —-A—- C:\Windows\system32\wbengine.exe
2009-07-18 13:50:57 —-A—- C:\Windows\system32\sqlsrv32.dll
2009-07-18 13:50:57 —-A—- C:\Windows\system32\propdefs.dll
2009-07-18 13:50:57 —-A—- C:\Windows\system32\odbc32.dll
2009-07-18 13:50:56 —-A—- C:\Windows\system32\wevtutil.exe
2009-07-18 13:50:56 —-A—- C:\Windows\system32\shdocvw.dll
2009-07-18 13:50:56 —-A—- C:\Windows\system32\dbgeng.dll
2009-07-18 13:50:55 —-A—- C:\Windows\system32\WsmSvc.dll
2009-07-18 13:50:55 —-A—- C:\Windows\system32\swprv.dll
2009-07-18 13:50:55 —-A—- C:\Windows\system32\mssitlb.dll
2009-07-18 13:50:54 —-A—- C:\Windows\system32\usp10.dll
2009-07-18 13:50:54 —-A—- C:\Windows\system32\mmcndmgr.dll
2009-07-18 13:50:53 —-A—- C:\Windows\system32\vds.exe
2009-07-18 13:50:52 —-A—- C:\Windows\system32\drvinst.exe
2009-07-18 13:50:52 —-A—- C:\Windows\system32\devmgr.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\WFS.exe
2009-07-18 13:50:51 —-A—- C:\Windows\system32\schannel.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\netlogon.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\msscb.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\msctfp.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\fdBthProxy.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\DevicePairingProxy.dll
2009-07-18 13:50:51 —-A—- C:\Windows\system32\BFE.DLL
2009-07-18 13:50:51 —-A—- C:\Windows\system32\adsldpc.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\WSDApi.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\WMVSDECD.DLL
2009-07-18 13:50:50 —-A—- C:\Windows\system32\Wldap32.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\WindowsCodecs.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\wcnwiz.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\PhotoMetadataHandler.dll
2009-07-18 13:50:50 —-A—- C:\Windows\system32\evr.dll
2009-07-18 13:50:49 —-A—- C:\Windows\system32\wercon.exe
2009-07-18 13:50:49 —-A—- C:\Windows\system32\wcncsvc.dll
2009-07-18 13:50:49 —-A—- C:\Windows\system32\services.exe
2009-07-18 13:50:49 —-A—- C:\Windows\system32\mimefilt.dll
2009-07-18 13:50:49 —-A—- C:\Windows\system32\comdlg32.dll
2009-07-18 13:50:49 —-A—- C:\Windows\system32\adtschema.dll
2009-07-18 13:50:47 —-A—- C:\Windows\system32\PortableDeviceApi.dll
2009-07-18 13:50:47 —-A—- C:\Windows\system32\msdrm.dll
2009-07-18 13:50:47 —-A—- C:\Windows\system32\certcli.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\umpnpmgr.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\taskeng.exe
2009-07-18 13:50:46 —-A—- C:\Windows\system32\rtffilt.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\reg.exe
2009-07-18 13:50:46 —-A—- C:\Windows\system32\mswdat10.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\msjter40.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\msdtcprx.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\ipsmsnap.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\dnsapi.dll
2009-07-18 13:50:46 —-A—- C:\Windows\system32\certutil.exe
2009-07-18 13:50:45 —-A—- C:\Windows\system32\WMNetMgr.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\w32time.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\rsaenh.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\msshooks.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\msscntrs.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\IPSECSVC.DLL
2009-07-18 13:50:45 —-A—- C:\Windows\system32\bthserv.dll
2009-07-18 13:50:45 —-A—- C:\Windows\system32\bcrypt.dll
2009-07-18 13:50:44 —-A—- C:\Windows\system32\TsWpfWrp.exe
2009-07-18 13:50:44 —-A—- C:\Windows\system32\msstrc.dll
2009-07-18 13:50:44 —-A—- C:\Windows\system32\msihnd.dll
2009-07-18 13:50:44 —-A—- C:\Windows\system32\MMDevAPI.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\scrptadm.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\netapi32.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\mtxclu.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\inetpp.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\inetcomm.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\hidserv.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\fundisc.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\dfshim.dll
2009-07-18 13:50:43 —-A—- C:\Windows\system32\cryptsvc.dll
2009-07-18 13:50:42 —-A—- C:\Windows\system32\wmicmiplugin.dll
2009-07-18 13:50:42 —-A—- C:\Windows\system32\termsrv.dll
2009-07-18 13:50:42 —-A—- C:\Windows\system32\profsvc.dll
2009-07-18 13:50:42 —-A—- C:\Windows\system32\mscories.dll
2009-07-18 13:50:42 —-A—- C:\Windows\system32\dhcpcsvc6.dll
2009-07-18 13:50:41 —-A—- C:\Windows\system32\wdc.dll
2009-07-18 13:50:41 —-A—- C:\Windows\system32\shsvcs.dll
2009-07-18 13:50:41 —-A—- C:\Windows\system32\msiexec.exe
2009-07-18 13:50:41 —-A—- C:\Windows\system32\imapi.dll
2009-07-18 13:50:41 —-A—- C:\Windows\system32\gameux.dll
2009-07-18 13:50:41 —-A—- C:\Windows\system32\chsbrkr.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\spoolsv.exe
2009-07-18 13:50:40 —-A—- C:\Windows\system32\scrrun.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\rasmans.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\pnidui.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\icardres.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\iassdo.dll
2009-07-18 13:50:40 —-A—- C:\Windows\system32\autofmt.exe
2009-07-18 13:50:39 —-A—- C:\Windows\system32\wersvc.dll
2009-07-18 13:50:39 —-A—- C:\Windows\system32\slmgr.vbs
2009-07-18 13:50:39 —-A—- C:\Windows\system32\PSHED.DLL
2009-07-18 13:50:39 —-A—- C:\Windows\system32\pidgenx.dll
2009-07-18 13:50:39 —-A—- C:\Windows\system32\pdh.dll
2009-07-18 13:50:39 —-A—- C:\Windows\system32\dhcpcsvc.dll
2009-07-18 13:50:39 —-A—- C:\Windows\system32\CertEnrollUI.dll
2009-07-18 13:50:39 —-A—- C:\Windows\system32\azroles.dll
2009-07-18 13:50:38 —-A—- C:\Windows\system32\wmpmde.dll
2009-07-18 13:50:38 —-A—- C:\Windows\system32\winlogon.exe
2009-07-18 13:50:38 —-A—- C:\Windows\system32\SyncCenter.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\SLUINotify.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\sethc.exe
2009-07-18 13:50:37 —-A—- C:\Windows\system32\ncrypt.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\msjetoledb40.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\kd1394.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\comuid.dll
2009-07-18 13:50:37 —-A—- C:\Windows\system32\certmgr.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\wisptis.exe
2009-07-18 13:50:36 —-A—- C:\Windows\system32\WindowsCodecsExt.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\untfs.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\taskcomp.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\spp.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\scrobj.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\rtutils.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\iassam.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\dwm.exe
2009-07-18 13:50:36 —-A—- C:\Windows\system32\cscui.dll
2009-07-18 13:50:36 —-A—- C:\Windows\system32\autochk.exe
2009-07-18 13:50:35 —-A—- C:\Windows\system32\winsrv.dll
2009-07-18 13:50:35 —-A—- C:\Windows\system32\printui.dll
2009-07-18 13:50:35 —-A—- C:\Windows\system32\iasnap.dll
2009-07-18 13:50:35 —-A—- C:\Windows\system32\cscript.exe
2009-07-18 13:50:35 —-A—- C:\Windows\system32\autoconv.exe
2009-07-18 13:50:34 —-A—- C:\Windows\system32\wow32.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\userenv.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\osk.exe
2009-07-18 13:50:34 —-A—- C:\Windows\system32\onex.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\mswsock.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\kdcom.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\basecsp.dll
2009-07-18 13:50:34 —-A—- C:\Windows\system32\audiodg.exe
2009-07-18 13:50:33 —-A—- C:\Windows\system32\winmm.dll
2009-07-18 13:50:33 —-A—- C:\Windows\system32\RelMon.dll
2009-07-18 13:50:33 —-A—- C:\Windows\system32\rdpencom.dll
2009-07-18 13:50:33 —-A—- C:\Windows\system32\kdusb.dll
2009-07-18 13:50:32 —-A—- C:\Windows\system32\WinSCard.dll
2009-07-18 13:50:32 —-A—- C:\Windows\system32\WerFaultSecure.exe
2009-07-18 13:50:32 —-A—- C:\Windows\system32\spcmsg.dll
2009-07-18 13:50:32 —-A—- C:\Windows\system32\offfilt.dll
2009-07-18 13:50:32 —-A—- C:\Windows\system32\msftedit.dll
2009-07-18 13:50:32 —-A—- C:\Windows\system32\dnsrslvr.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\wsepno.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\WerFault.exe
2009-07-18 13:50:31 —-A—- C:\Windows\system32\Utilman.exe
2009-07-18 13:50:31 —-A—- C:\Windows\system32\stobject.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\SndVol.exe
2009-07-18 13:50:31 —-A—- C:\Windows\system32\secproc_ssp_isv.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\secproc_ssp.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\msnetobj.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\mscms.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\mfplat.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\mcmde.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\diskraid.exe
2009-07-18 13:50:31 —-A—- C:\Windows\system32\apphelp.dll
2009-07-18 13:50:31 —-A—- C:\Windows\system32\adsmsext.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\wscript.exe
2009-07-18 13:50:30 —-A—- C:\Windows\system32\wiaservc.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\ulib.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\sysclass.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\secur32.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\prnntfy.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\odbccp32.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\IPHLPAPI.DLL
2009-07-18 13:50:30 —-A—- C:\Windows\system32\iasdatastore.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\dsound.dll
2009-07-18 13:50:30 —-A—- C:\Windows\system32\cryptui.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\wscntfy.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\wlansvc.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\wlangpui.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\vdsdyn.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\rastls.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\rastapi.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\pnpsetup.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\ipsecsnp.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\iashlpr.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\gpapi.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\fdProxy.dll
2009-07-18 13:50:29 —-A—- C:\Windows\system32\diskpart.exe
2009-07-18 13:50:29 —-A—- C:\Windows\system32\brcpl.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\zipfldr.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\wusa.exe
2009-07-18 13:50:28 —-A—- C:\Windows\system32\wscsvc.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\WMVENCOD.DLL
2009-07-18 13:50:28 —-A—- C:\Windows\system32\regsvc.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\rasapi32.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\ntprint.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\netiohlp.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\mscorier.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\logman.exe
2009-07-18 13:50:28 —-A—- C:\Windows\system32\iasrad.dll
2009-07-18 13:50:28 —-A—- C:\Windows\system32\findstr.exe
2009-07-18 13:50:27 —-A—- C:\Windows\system32\wshext.dll
2009-07-18 13:50:27 —-A—- C:\Windows\system32\wpccpl.dll
2009-07-18 13:50:27 —-A—- C:\Windows\system32\netcenter.dll
2009-07-18 13:50:26 —-A—- C:\Windows\system32\wer.dll
2009-07-18 13:50:26 —-A—- C:\Windows\system32\rasdlg.dll
2009-07-18 13:50:26 —-A—- C:\Windows\system32\iassvcs.dll
2009-07-18 13:50:25 —-A—- C:\Windows\system32\wsnmp32.dll
2009-07-18 13:50:25 —-A—- C:\Windows\system32\themecpl.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\uxsms.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\tsbyuv.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\srvsvc.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\scansetting.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\ntmarta.dll
2009-07-18 13:50:24 —-A—- C:\Windows\system32\mssprxy.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\slcc.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\powrprof.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\powercpl.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\networkmap.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\msutb.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\mstsc.exe
2009-07-18 13:50:23 —-A—- C:\Windows\system32\mstlsapi.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\iasads.dll
2009-07-18 13:50:23 —-A—- C:\Windows\system32\iasacct.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\wlanhlp.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\umrdp.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\systemcpl.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\sud.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\PerfCenterCPL.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\newdev.exe
2009-07-18 13:50:22 —-A—- C:\Windows\system32\fveui.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\dot3svc.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\connect.dll
2009-07-18 13:50:22 —-A—- C:\Windows\system32\authz.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\wlanpref.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\usercpl.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\themeui.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\samlib.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\qdvd.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\pcaui.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\mmci.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\brcplsiw.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\autoplay.dll
2009-07-18 13:50:21 —-A—- C:\Windows\system32\accessibilitycpl.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\wpcao.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\vdsutil.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\rpchttp.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\regapi.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\msinfo32.exe
2009-07-18 13:50:20 —-A—- C:\Windows\system32\fvecpl.dll
2009-07-18 13:50:20 —-A—- C:\Windows\system32\cscobj.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\tapisrv.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\scksp.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\scesrv.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\rekeywiz.exe
2009-07-18 13:50:19 —-A—- C:\Windows\system32\psisdecd.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\oleprn.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\mpr.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\imm32.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\feclient.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\Faultrep.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\dot3msm.dll
2009-07-18 13:50:19 —-A—- C:\Windows\system32\AudioSes.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\wscisvif.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\WindowsUltimateExtrasCPL.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\sdclt.exe
2009-07-18 13:50:18 —-A—- C:\Windows\system32\qedit.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\pnpui.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\perfdisk.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\ncryptui.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\iaspolcy.dll
2009-07-18 13:50:18 —-A—- C:\Windows\system32\dpapimig.exe
2009-07-18 13:50:18 —-A—- C:\Windows\system32\DeviceEject.exe
2009-07-18 13:50:18 —-A—- C:\Windows\system32\certreq.exe
2009-07-18 13:50:17 —-A—- C:\Windows\system32\TSTheme.exe
2009-07-18 13:50:17 —-A—- C:\Windows\system32\tcpipcfg.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\spwinsat.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\scecli.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\rasplap.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\rasgcw.dll
2009-07-18 13:50:17 —-A—- C:\Windows\system32\PnPUnattend.exe
2009-07-18 13:50:17 —-A—- C:\Windows\system32\hdwwiz.exe
2009-07-18 13:50:17 —-A—- C:\Windows\system32\FWPUCLNT.DLL
2009-07-18 13:50:17 —-A—- C:\Windows\system32\cmmon32.exe
2009-07-18 13:50:16 —-A—- C:\Windows\system32\whealogr.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\tcpmon.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\srcore.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\SnippingTool.exe
2009-07-18 13:50:16 —-A—- C:\Windows\system32\SCardSvr.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\raschap.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\fontext.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\fdWSD.dll
2009-07-18 13:50:16 —-A—- C:\Windows\system32\conime.exe
2009-07-18 13:50:16 —-A—- C:\Windows\system32\cmdial32.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\WMVXENCD.DLL
2009-07-18 13:50:15 —-A—- C:\Windows\system32\wlanui.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\wiaaut.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\shwebsvc.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\rasppp.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\PnPutil.exe
2009-07-18 13:50:15 —-A—- C:\Windows\system32\MSVidCtl.dll
2009-07-18 13:50:15 —-A—- C:\Windows\system32\dsprop.dll
2009-07-18 13:50:14 —-A—- C:\Windows\system32\wlanmsm.dll
2009-07-18 13:50:14 —-A—- C:\Windows\system32\oobefldr.dll
2009-07-18 13:50:14 —-A—- C:\Windows\system32\dimsroam.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\wmdrmsdk.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\shsetup.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\rasmontr.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\mscandui.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\modemui.dll
2009-07-18 13:50:13 —-A—- C:\Windows\system32\chtbrkr.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\WSDMon.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\wlgpclnt.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\tscfgwmi.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\smss.exe
2009-07-18 13:50:12 —-A—- C:\Windows\system32\rdpwsx.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\netplwiz.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\dataclen.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\credui.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\blackbox.dll
2009-07-18 13:50:12 —-A—- C:\Windows\system32\appmgmts.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\wscapi.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\wpcsvc.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\wmpeffects.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\networkexplorer.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\msscp.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\msimtf.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\logagent.exe
2009-07-18 13:50:11 —-A—- C:\Windows\system32\InkEd.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\ifmon.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\gpresult.exe
2009-07-18 13:50:11 —-A—- C:\Windows\system32\CscMig.dll
2009-07-18 13:50:11 —-A—- C:\Windows\system32\cipher.exe
2009-07-18 13:50:11 —-A—- C:\Windows\system32\certprop.dll
2009-07-18 13:50:10 —-A—- C:\Windows\system32\thawbrkr.dll
2009-07-18 13:50:10 —-A—- C:\Windows\system32\softkbd.dll
2009-07-18 13:50:10 —-A—- C:\Windows\system32\sendmail.dll
2009-07-18 13:50:10 —-A—- C:\Windows\system32\MediaMetadataHandler.dll
2009-07-18 13:50:09 —-A—- C:\Windows\system32\rdpclip.exe
2009-07-18 13:50:09 —-A—- C:\Windows\system32\olepro32.dll
2009-07-18 13:50:09 —-A—- C:\Windows\system32\msctfui.dll
2009-07-18 13:50:09 —-A—- C:\Windows\system32\drmmgrtn.dll
2009-07-18 13:50:09 —-A—- C:\Windows\system32\dmsynth.dll
2009-07-18 13:50:09 —-A—- C:\Windows\system32\Apphlpdm.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\wshbth.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\version.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\SLLUA.exe
2009-07-18 13:50:08 —-A—- C:\Windows\system32\puiapi.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\msisip.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\mprapi.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\input.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\gpprnext.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\fc.exe
2009-07-18 13:50:08 —-A—- C:\Windows\system32\ExplorerFrame.dll
2009-07-18 13:50:08 —-A—- C:\Windows\system32\cdd.dll
2009-07-18 13:50:07 —-A—- C:\Windows\system32\fdSSDP.dll
2009-07-18 13:50:07 —-A—- C:\Windows\system32\dmusic.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\rdpendp.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\printfilterpipelineprxy.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\msjint40.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\MsCtfMonitor.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\l2nacp.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\ftp.exe
2009-07-18 13:50:06 —-A—- C:\Windows\system32\eapp3hst.dll
2009-07-18 13:50:06 —-A—- C:\Windows\system32\cscapi.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\wsdchngr.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\Storprop.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\SMBHelperClass.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\rrinstaller.exe
2009-07-18 13:50:05 —-A—- C:\Windows\system32\rasdial.exe
2009-07-18 13:50:05 —-A—- C:\Windows\system32\rasdiag.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\PortableDeviceTypes.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\gpscript.exe
2009-07-18 13:50:05 —-A—- C:\Windows\system32\fdWCN.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\dot3cfg.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\cscdll.dll
2009-07-18 13:50:05 —-A—- C:\Windows\system32\bthudtask.exe
2009-07-18 13:50:05 —-A—- C:\Windows\system32\bthci.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\tscupgrd.exe
2009-07-18 13:50:04 —-A—- C:\Windows\system32\slcinst.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\PrintBrmUi.exe
2009-07-18 13:50:04 —-A—- C:\Windows\system32\nslookup.exe
2009-07-18 13:50:04 —-A—- C:\Windows\system32\networkitemfactory.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\mfps.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\ipconfig.exe
2009-07-18 13:50:04 —-A—- C:\Windows\system32\eappcfg.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\CHxReadingStringIME.dll
2009-07-18 13:50:04 —-A—- C:\Windows\system32\aaclient.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\qprocess.exe
2009-07-18 13:50:03 —-A—- C:\Windows\system32\ocsetup.exe
2009-07-18 13:50:03 —-A—- C:\Windows\system32\mmcico.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\mfpmp.exe
2009-07-18 13:50:03 —-A—- C:\Windows\system32\hbaapi.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\gpscript.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\FwRemoteSvr.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\fdeploy.dll
2009-07-18 13:50:03 —-A—- C:\Windows\system32\eappgnui.dll
2009-07-18 13:50:02 —-A—- C:\Windows\system32\tsgqec.dll
2009-07-18 13:50:02 —-A—- C:\Windows\system32\tscon.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\shadow.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\PNPXAssoc.dll
2009-07-18 13:50:02 —-A—- C:\Windows\system32\logoff.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\gpupdate.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\csrstub.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\chgusr.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\chgport.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\cbsra.exe
2009-07-18 13:50:02 —-A—- C:\Windows\system32\bitsigd.dll
2009-07-18 13:50:01 —-A—- C:\Windows\system32\vdmdbg.dll
2009-07-18 13:50:01 —-A—- C:\Windows\system32\tskill.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\tsdiscon.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\rwinsta.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\reset.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\query.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\qappsrv.exe
2009-07-18 13:50:01 —-A—- C:\Windows\system32\odbcconf.dll
2009-07-18 13:50:01 —-A—- C:\Windows\system32\NcdProp.dll
2009-07-18 13:50:01 —-A—- C:\Windows\system32\iscsilog.dll
2009-07-18 13:50:01 —-A—- C:\Windows\system32\chglogon.exe
2009-07-18 13:50:00 —-A—- C:\Windows\system32\winrnr.dll
2009-07-18 13:50:00 —-A—- C:\Windows\system32\slwga.dll
2009-07-18 13:50:00 —-A—- C:\Windows\system32\midimap.dll
2009-07-18 13:50:00 —-A—- C:\Windows\system32\inetppui.dll
2009-07-18 13:50:00 —-A—- C:\Windows\system32\change.exe
2009-07-18 13:49:59 —-A—- C:\Windows\system32\spwmp.dll
2009-07-18 13:49:59 —-A—- C:\Windows\system32\dxmasf.dll
2009-07-18 13:49:58 —-A—- C:\Windows\system32\wmploc.DLL
2009-07-18 13:49:58 —-A—- C:\Windows\system32\msimsg.dll
2009-07-18 13:49:58 —-A—- C:\Windows\system32\mferror.dll
2009-07-18 13:49:58 —-A—- C:\Windows\system32\f3ahvoas.dll
2009-07-18 13:49:31 —-A—- C:\Windows\system32\SmiEngine.dll
2009-07-18 13:49:13 —-A—- C:\Windows\system32\wdscore.dll
2009-07-18 13:49:13 —-A—- C:\Windows\system32\PkgMgr.exe
2009-07-18 13:48:16 —-A—- C:\Windows\system32\drvstore.dll
2009-07-17 15:58:18 —-D—- C:\Program Files\Trend Micro
2009-07-15 09:30:53 —-A—- C:\Windows\system32\t2embed.dll
2009-07-15 09:30:53 —-A—- C:\Windows\system32\lpk.dll
2009-07-15 09:30:53 —-A—- C:\Windows\system32\fontsub.dll
2009-07-15 09:30:53 —-A—- C:\Windows\system32\atmfd.dll
2009-07-15 09:30:52 —-A—- C:\Windows\system32\dciman32.dll
2009-07-15 09:30:52 —-A—- C:\Windows\system32\atmlib.dll
2009-07-14 13:11:35 —-D—- C:\Program Files\Enterbrain
2009-07-14 13:11:16 —-D—- C:\Program Files\Common Files\Enterbrain
2009-07-08 01:55:12 —-A—- C:\Windows\system32\xfcodec.dll
2009-07-04 14:12:45 —-D—- C:\Program Files\Microsoft Games for Windows - LIVE
2009-07-03 17:14:15 —-A—- C:\Windows\system32\CmdLineExt.dll
2009-07-03 16:58:12 —-D—- C:\Windows\system32\xlive
2009-07-02 16:25:36 —-D—- C:\ProgramData\ATI
2009-07-02 15:09:00 —-A—- C:\Windows\system32\Oemdspif.dll
2009-07-02 15:08:59 —-A—- C:\Windows\system32\atioglxx.dll
2009-07-02 15:08:59 —-A—- C:\Windows\system32\ATIODE.exe
2009-07-02 15:08:59 —-A—- C:\Windows\system32\ATIODCLI.exe
2009-07-02 15:08:59 —-A—- C:\Windows\system32\atidxx32.dll
2009-07-02 15:08:59 —-A—- C:\Windows\system32\ATIDEMGX.dll
2009-07-02 15:08:59 —-A—- C:\Windows\system32\atibrtmon.exe
2009-07-02 15:08:59 —-A—- C:\Windows\system32\atiadlxx.dll
2009-07-02 15:08:59 —-A—- C:\Windows\system32\amdpcom32.dll
2009-07-01 17:23:36 —-D—- C:\Program Files\ATI
2009-06-30 15:12:24 —-D—- C:\Downloads
2009-06-30 15:12:06 —-D—- C:\Program Files\BitComet
2009-06-27 17:03:37 —-D—- C:\Users\Hans\AppData\Roaming\Turbine
2009-06-26 18:47:10 —-A—- C:\Windows\system32\PnkBstrB.exe
2009-06-26 18:47:09 —-A—- C:\Windows\system32\PnkBstrA.exe
2009-06-26 18:47:09 —-A—- C:\Windows\system32\pbsvc.exe
2009-06-26 18:46:20 —-D—- C:\Users\Hans\AppData\Roaming\Xfire
2009-06-26 18:46:18 —-D—- C:\ProgramData\Xfire
2009-06-26 18:46:18 —-D—- C:\Program Files\Xfire
2009-06-26 15:50:52 —-D—- C:\Users\Hans\AppData\Roaming\Mozilla
2009-06-26 15:50:47 —-D—- C:\Program Files\Mozilla Firefox
2009-06-26 12:31:22 —-D—- C:\Program Files\Zbrush

======List of files/folders modified in the last 1 months======

2009-07-21 08:49:23 —-D—- C:\Windows\Prefetch
2009-07-21 08:49:22 —-D—- C:\Windows\Temp
2009-07-21 08:49:16 —-D—- C:\Windows\System32
2009-07-21 08:49:16 —-D—- C:\Windows\inf
2009-07-21 08:49:16 —-A—- C:\Windows\system32\PerfStringBackup.INI
2009-07-21 08:46:36 —-D—- C:\Windows\Tasks
2009-07-21 08:44:37 —-D—- C:\Users\Hans\AppData\Roaming\WTablet
2009-07-20 19:00:31 —-SHD—- C:\System Volume Information
2009-07-20 18:42:05 —-D—- C:\ProgramData\Google Updater
2009-07-19 18:12:49 —-D—- C:\Windows\system32\drivers
2009-07-19 16:00:17 —-SHD—- C:\Windows\Installer
2009-07-19 15:59:41 —-SD—- C:\Windows\Downloaded Program Files
2009-07-19 14:41:43 —-HD—- C:\Program Files\InstallShield Installation Information
2009-07-19 14:41:16 —-D—- C:\Users\Hans\AppData\Roaming\GetRightToGo
2009-07-19 14:32:04 —-HD—- C:\Windows\system32\GroupPolicy
2009-07-19 14:32:04 —-HD—- C:\ProgramData
2009-07-19 09:32:44 —-A—- C:\Windows\ntbtlog.txt
2009-07-19 09:10:16 —-D—- C:\Windows\system32\catroot2
2009-07-18 18:27:15 —-D—- C:\Windows
2009-07-18 18:27:14 —-D—- C:\Windows\system32\Tasks
2009-07-18 14:38:00 —-D—- C:\Windows\rescache
2009-07-18 14:37:20 —-D—- C:\Windows\Microsoft.NET
2009-07-18 14:37:15 —-RSD—- C:\Windows\assembly
2009-07-18 14:19:23 —-RD—- C:\Program Files
2009-07-18 14:16:27 —-D—- C:\Windows\system32\catroot
2009-07-18 14:16:26 —-SHD—- C:\Boot
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Sidebar
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Photo Gallery
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Media Player
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Mail
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Journal
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Collaboration
2009-07-18 14:10:24 —-D—- C:\Program Files\Windows Calendar
2009-07-18 14:10:24 —-D—- C:\Program Files\Movie Maker
2009-07-18 14:10:24 —-D—- C:\Program Files\Internet Explorer
2009-07-18 14:10:24 —-D—- C:\Program Files\Common Files\System
2009-07-18 14:10:23 —-D—- C:\Windows\servicing
2009-07-18 14:10:23 —-D—- C:\Windows\ehome
2009-07-18 14:10:23 —-D—- C:\Program Files\Windows Defender
2009-07-18 14:10:18 —-D—- C:\Windows\system32\XPSViewer
2009-07-18 14:10:18 —-D—- C:\Windows\system32\sk-SK
2009-07-18 14:10:18 —-D—- C:\Windows\system32\oobe
2009-07-18 14:10:18 —-D—- C:\Windows\system32\lv-LV
2009-07-18 14:10:18 —-D—- C:\Windows\system32\ko-KR
2009-07-18 14:10:18 —-D—- C:\Windows\system32\it-IT
2009-07-18 14:10:18 —-D—- C:\Windows\system32\hr-HR
2009-07-18 14:10:18 —-D—- C:\Windows\system32\et-EE
2009-07-18 14:10:18 —-D—- C:\Windows\system32\en-US
2009-07-18 14:10:18 —-D—- C:\Windows\system32\el-GR
2009-07-18 14:10:18 —-D—- C:\Windows\system32\de-DE
2009-07-18 14:10:18 —-D—- C:\Windows\system32\da-DK
2009-07-18 14:10:18 —-D—- C:\Windows\PolicyDefinitions
2009-07-18 14:10:18 —-D—- C:\Windows\IME
2009-07-18 14:10:17 —-D—- C:\Windows\system32\zh-TW
2009-07-18 14:10:17 —-D—- C:\Windows\system32\zh-CN
2009-07-18 14:10:17 —-D—- C:\Windows\system32\uk-UA
2009-07-18 14:10:17 —-D—- C:\Windows\system32\th-TH
2009-07-18 14:10:17 —-D—- C:\Windows\system32\sv-SE
2009-07-18 14:10:17 —-D—- C:\Windows\system32\sr-Latn-CS
2009-07-18 14:10:17 —-D—- C:\Windows\system32\SLUI
2009-07-18 14:10:17 —-D—- C:\Windows\system32\sl-SI
2009-07-18 14:10:17 —-D—- C:\Windows\system32\setup
2009-07-18 14:10:17 —-D—- C:\Windows\system32\ru-RU
2009-07-18 14:10:17 —-D—- C:\Windows\system32\ro-RO
2009-07-18 14:10:17 —-D—- C:\Windows\system32\pt-PT
2009-07-18 14:10:17 —-D—- C:\Windows\system32\pl-PL
2009-07-18 14:10:17 —-D—- C:\Windows\system32\migration
2009-07-18 14:10:17 —-D—- C:\Windows\system32\manifeststore
2009-07-18 14:10:17 —-D—- C:\Windows\system32\ja-JP
2009-07-18 14:10:17 —-D—- C:\Windows\system32\hu-HU
2009-07-18 14:10:17 —-D—- C:\Windows\system32\he-IL
2009-07-18 14:10:17 —-D—- C:\Windows\system32\fr-FR
2009-07-18 14:10:17 —-D—- C:\Windows\system32\fi-FI
2009-07-18 14:10:17 —-D—- C:\Windows\system32\es-ES
2009-07-18 14:10:17 —-D—- C:\Windows\system32\cs-CZ
2009-07-18 14:10:17 —-D—- C:\Windows\system32\bg-BG
2009-07-18 14:10:17 —-D—- C:\Windows\system32\AdvancedInstallers
2009-07-18 14:10:16 —-D—- C:\Windows\system32\wbem
2009-07-18 14:10:16 —-D—- C:\Windows\system32\tr-TR
2009-07-18 14:10:16 —-D—- C:\Windows\system32\pt-BR
2009-07-18 14:10:16 —-D—- C:\Windows\system32\nl-NL
2009-07-18 14:10:16 —-D—- C:\Windows\system32\nb-NO
2009-07-18 14:10:16 —-D—- C:\Windows\system32\migwiz
2009-07-18 14:10:16 —-D—- C:\Windows\system32\lt-LT
2009-07-18 14:10:16 —-D—- C:\Windows\system32\ar-SA
2009-07-18 14:10:10 —-RSD—- C:\Windows\Fonts
2009-07-18 14:10:10 —-D—- C:\Windows\AppPatch
2009-07-18 14:10:04 —-D—- C:\Windows\system32\Boot
2009-07-18 14:05:47 —-D—- C:\Windows\winsxs
2009-07-14 13:11:16 —-D—- C:\Program Files\Common Files
2009-07-07 17:10:56 —-A—- C:\Windows\system32\mrt.exe
2009-07-02 16:22:25 —-D—- C:\Program Files\ATI Technologies
2009-07-02 14:24:47 —-D—- C:\Windows\Registration
2009-06-26 18:47:09 —-D—- C:\Windows\system32\LogFiles
2009-06-26 12:30:23 —-D—- C:\Windows\Downloaded Installations
2009-06-26 12:04:25 —-D—- C:\Program Files\Google
2009-06-24 18:34:36 —-D—- C:\Windows\system32\Macromed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-02-05 23152]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2009-04-11 351744]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-02-05 51792]
R2 RtNdPt60;Realtek NDIS Protocol Driver; C:\Windows\system32\DRIVERS\RtNdPt60.sys [2008-07-21 27648]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-04-10 3591168]
R3 BCM43XX;Stuurprogramma voor Broadcom 802.11-netwerkadapter; C:\Windows\system32\DRIVERS\bcmwl6.sys [2008-01-03 1044984]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2007-11-20 1034496]
R3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2007-01-23 34576]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2007-01-23 33296]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-07-10 123904]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\Windows\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\Windows\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver; C:\Windows\system32\DRIVERS\WacomVKHid.sys [2007-02-15 11440]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 61883;61883-eenheidsapparaat; C:\Windows\system32\DRIVERS\61883.sys [2008-01-21 45696]
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 Avc;AVC-apparaat; C:\Windows\system32\DRIVERS\avc.sys [2008-01-21 40448]
S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 e1express;Stuurprogramma voor Intel® PRO/1000 PCI Express-netwerkverbinding; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys []
S3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2007-01-23 28176]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-21 52608]
S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-04-10 3591168]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2008-07-15 312344]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Windows\system32\AERTSrv.exe [2008-07-18 73728]
R2 Apple Mobile Device;Mobiel Apple apparaat; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-26 132424]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-05-21 675840]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-06-26 75064]
R2 sprtsvc_DellSupportCenter;SupportSoft Sprocket Service (DellSupportCenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-10-04 201968]
R2 TabletServicePen;TabletServicePen; C:\Windows\system32\Pen_Tablet.exe [2007-09-07 1373480]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
R3 usnjsvc;Messenger USN Journal Reader service voor Gedeelde mappen; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
S2 gupdate1c98e038bad370b;Google Updateservice (gupdate1c98e038bad370b); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-13 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-21 183280]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-21 523776]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-05-14 655624]
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2008-12-03 16680]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2009-06-12 2837916]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 usprserv;User Privilege Service; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-04-11 918528]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–





info.txt logfile of random's system information tool 1.06 2009-07-21 08:49:25

======Uninstall list======

–>D:\Programma's\DivX\DivXConverterUninstall.exe /CONVERTER
3DVIA player 4.1–>MsiExec.exe /X{4E868D3D-6EEB-4273-926C-2287236B5B79}
Adobe Anchor Service CS4–>MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
Adobe Bridge CS4–>MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
Adobe CMaps CS4–>MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific CS4–>MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Adobe Color EU Extra Settings CS4–>MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
Adobe Color JA Extra Settings CS4–>MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
Adobe Color NA Recommended Settings CS4–>MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
Adobe Color Video Profiles CS CS4–>MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
Adobe CSI CS4–>MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
Adobe Default Language CS4–>MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe ExtendScript Toolkit CS4–>MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
Adobe Flash Player 10 ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Fonts All–>MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Linguistics CS4–>MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
Adobe Output Module–>MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
Adobe PDF Library Files CS4–>MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS4 Support–>MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
Adobe Photoshop CS4–>C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe –uninstall=1
Adobe Photoshop CS4–>MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
Adobe Photoshop CS4–>MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
Adobe Reader 9 - Nederlands–>MsiExec.exe /I{AC76BA86-7AD7-1043-7B44-A90000000001}
Adobe Search for Help–>MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
Adobe Service Manager Extension–>MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
Adobe Setup–>MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
Adobe Shockwave Player 11–>C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
Adobe Type Support CS4–>MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS4–>MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
Adobe XMP Panels CS4–>MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
AdobeColorCommonSetCMYK–>MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
AdobeColorCommonSetRGB–>MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
Anime Studio 5.6–>"C:\Program Files\Smith Micro\Anime Studio\unins000.exe"
Apple Mobile Device Support–>MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Assassin's Creed–>C:\Program Files\InstallShield Installation Information\{8CFA9151-6404-409A-AF22-4632D04582FD}\setup.exe -runfromtemp -l0x0009 -removeonly
ATI Catalyst Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x13
avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Battlefield Heroes–>"D:\Games\Battlefield heroes\uninstaller.exe" "D:\Games\Battlefield heroes\Uninstall.xml"
BitComet 1.13–>C:\Program Files\BitComet\uninst.exe
Bonjour–>MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Browser Address Error Redirector–>MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
Catalyst Control Center - Branding–>MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
CDDRV_Installer–>MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
Combat Arms EU–>"C:\ProgramData\NexonEU\NGM\NGM.exe" -mode:uninstall -dll:ngm.nexoneu.com/cbangm/NGM/Bin/NGMDll.dll -game:50340359 -locale:EU
Connect–>MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
Dell Dock–>MsiExec.exe /I{F6CB42B9-F033-4152-8813-FF11DA8E6A78}
Dell Getting Started Guide–>MsiExec.exe /I{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}
Dell Resource CD–>MsiExec.exe /X{42929F0F-CE14-47AF-9FC7-FF297A603021}
Dell Support Center (Support Software)–>MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
DivX Codec–>D:\Programma's\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter–>D:\Programma's\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>D:\Programma's\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player–>D:\Programma's\DivX\DivXWebPlayerUninstall.exe /PLUGIN
EDocs–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}\setup.exe"
Evochron Legends–>"D:\Games\EvochronLegends\unins000.exe"
Fallout 3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x9 -removeonly
Fraps–>"C:\Program Files\Fraps\uninstall.exe"
Freez FLV to AVI/MPEG/WMV Converter–>"C:\Program Files\Freez FLV to AVI MPEG WMV Converter\unins000.exe"
Geluidsschema's voor Windows–>RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\UltSound.inf,Uninstall
Google Chrome–>"C:\Program Files\Google\Chrome\Application\2.0.172.37\Installer\setup.exe" –uninstall –system-level
Google Earth–>MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
Google Toolbar for Internet Explorer–>"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
Google Toolbar for Internet Explorer–>MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper–>MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
GoToAssist 8.0.0.514–>C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
Guild Wars–>"D:\Games\Guild Wars\Gw.exe" -uninstall
Hauppauge MCE XP/Vista Software Encoder (2.0.25296)–>C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
Hauppauge TV Tuner Driver–>MsiExec.exe /I{AF094932-91E6-4EF8-8AB8-1C7226DFEECB}
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
iTunes–>MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KhalSetup–>MsiExec.exe /I{C89C8D86-4423-4A58-AA40-DD259ACE07C1}
kuler–>MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
Logitech Communications Manager–>MsiExec.exe /I{BD202930-5F70-4B35-B875-1E28604F328D}
Logitech Desktop Messenger–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x9 UNINSTALL
Logitech SetPoint–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe" -l0x9 -removeonly
Microsoft .NET Framework 3.5 Language Pack SP1 - nld–>MsiExec.exe /I{101738D7-D805-37A9-BB91-1F2C351782BF}
Microsoft .NET Framework 3.5 SP1–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Games for Windows - LIVE –>MsiExec.exe /X{4D243BA7-9AC4-46D1-90E5-EEB88974F501}
Microsoft Games for Windows - LIVE Redistributable–>MsiExec.exe /X{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}
Microsoft MapPoint Europe 2009–>MsiExec.exe /I{C82185E8-C27B-4EF4-2009-2222BC2C2B6D}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-0016-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-0018-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-001B-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-006E-0413-0000-0000000FF1CE} /uninstall {89C8E56A-90D8-4598-B0E6-EB28F6270E07}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-00A1-0413-0000-0000000FF1CE} /uninstall {DC387AA5-94A6-4920-B004-D59846526D81}
Microsoft Office 2007 Service Pack 2 (SP2)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access database engine 2007 (English)–>MsiExec.exe /I{90120000-00D1-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Dutch) 2007–>MsiExec.exe /X{90120000-0016-0413-0000-0000000FF1CE}
Microsoft Office Home and Student 2007–>"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007–>MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Dutch) 2007–>MsiExec.exe /X{90120000-00A1-0413-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Dutch) 2007–>MsiExec.exe /X{90120000-0018-0413-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007–>MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007–>MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proofing (Dutch) 2007–>MsiExec.exe /X{90120000-002C-0413-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)–>msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Shared MUI (Dutch) 2007–>MsiExec.exe /X{90120000-006E-0413-0000-0000000FF1CE}
Microsoft Office Word MUI (Dutch) 2007–>MsiExec.exe /X{90120000-001B-0413-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022–>MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft XNA Framework Redistributable 3.0–>MsiExec.exe /I{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}
Mozilla Firefox (3.5)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
NCsoft Launcher–>C:\Program Files\InstallShield Installation Information\{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}\setup.exe -runfromtemp -l0x0009 -removeonly
OGA Notifier 1.7.0105.35.0–>MsiExec.exe /I{ADE14C1E-AA43-45D3-88E5-00767D31B0E8}
PDF Settings CS4–>MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
Pen Tablet–>C:\Program Files\Tablet\Pen\Remove.exe /u
Photoshop Camera Raw–>MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
Picasa 3–>"C:\Program Files\Google\Picasa3\Uninstall.exe"
Prince of Persia The Sands of Time–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8C453F13-6877-4D34-8816-009ABDE306DB}\setup.exe" -l0x9
PunkBuster Services–>C:\Windows\system32\pbsvc.exe -u
QuickTime–>MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
Realtek 8169 8168 8101E 8102E Ethernet Driver–>C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0013 -removeonly
Realtek Ethernet Network Card Diagnostic tool for Windows Vista–>C:\Program Files\InstallShield Installation Information\{1FECF5F8-8E75-432C-9FF7-1C04F1956B54}\setup.exe -runfromtemp -l0x0013 -removeonly
Roxio Creator Audio–>MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
Roxio Creator Copy–>MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
Roxio Creator Data–>MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
Roxio Creator DE–>C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
Roxio Creator DE–>MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
Roxio Creator Tools–>MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
Roxio Express Labeler 3–>MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
RPG Maker VX RTP–>"C:\Program Files\Common Files\Enterbrain\RGSS2\RPGVX\unins000.exe"
RPG Maker VX–>"C:\Program Files\Enterbrain\RPGVX\unins000.exe"
Runes of Magic–>"D:\Games\runes of magic\unins000.exe"
save2pc Pro Demo 3.54–>"D:\Programma's\save2pc\unins000.exe"
Security Update for 2007 Microsoft Office System (KB969559)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office system 2007 (KB969613)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
SPORE™–>"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\SPORESetup.exe" -runfromtemp -l0x0013 -removeonly
Suite Shared Configuration CS4–>MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - nld\setup.exe
The Battle for Middle-earth™ II–>D:\Games\LOTR II\EAUninstall.exe
The Lord of the Rings Online™: Mines of Moria™ v02.01.03.4020–>"D:\Games\LOTRO\unins000.exe"
Ultimate Extras sounds from Microsoft® Tinker™–>RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\UltSound2.inf,Uninstall
Update for 2007 Microsoft Office System (KB967642)–>msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update voor Microsoft Office Excel 2007 Help (KB963678)–>msiexec /package {90120000-0016-0413-0000-0000000FF1CE} /uninstall {5CF7002F-6F49-4482-9564-5614FBE560FA}
Update voor Microsoft Office Powerpoint 2007 Help (KB963669)–>msiexec /package {90120000-0018-0413-0000-0000000FF1CE} /uninstall {15D84E79-1ED7-42C5-B2FD-745C3FBDDDC5}
Update voor Microsoft Office Word 2007 Help (KB963665)–>msiexec /package {90120000-001B-0413-0000-0000000FF1CE} /uninstall {A66AE6A1-8D8C-4102-BC18-38CBDE40F809}
Warhammer Mark of Chaos Manual Patch–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{442D5880-05B4-4DC8-A038-2EDA79FAE601}\setup.exe" -l0x9 -removeonly
Warhammer Mark of Chaos–>C:\Program Files\InstallShield Installation Information\{5F374D5D-DB43-4263-9C29-BAB2C93FEFE6}\Setup.exe -runfromtemp -l0x0009 -removeonly
Windows Live aanmeldhulp–>MsiExec.exe /I{7E1FBCB0-500C-4A0D-AC9C-B1B76E75666B}
Windows Live installer–>MsiExec.exe /X{A258173E-F308-475A-951B-F1BF76A4451B}
Windows Live Messenger–>MsiExec.exe /X{A0C978B8-B82B-4FAD-8C31-EBEE8E57468A}
Windows Live OneCare safety scanner–>%ProgramFiles%\Windows Live Safety Center\wlschost.exe -Uninstall
Windows Live OneCare safety scanner–>MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
WinRAR archiver–>D:\Programma's\Winrar\uninstall.exe
Xfire (remove only)–>"C:\Program Files\Xfire\uninst.exe"
ZBrush3–>MsiExec.exe /I{6084D038-3401-4C9D-A216-86E6EEA25AFB}

======Security center information======

AS: Windows Defender

======System event log======

Computer Name: BigDell
Event Code: 7036
Message: De avast! Antivirus-service heeft nu de status wordt uitgevoerd.
Record Number: 37141
Source Name: Service Control Manager
Time Written: 20090209160426.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 7036
Message: De Shell Hardware Detection-service heeft nu de status wordt uitgevoerd.
Record Number: 37140
Source Name: Service Control Manager
Time Written: 20090209160426.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 7036
Message: De avast! iAVS4 Control Service-service heeft nu de status wordt uitgevoerd.
Record Number: 37139
Source Name: Service Control Manager
Time Written: 20090209160426.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 7036
Message: De WLAN Auto Config-service heeft nu de status wordt uitgevoerd.
Record Number: 37138
Source Name: Service Control Manager
Time Written: 20090209160426.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 7036
Message: De Extensible Authentication Protocol-service heeft nu de status wordt uitgevoerd.
Record Number: 37137
Source Name: Service Control Manager
Time Written: 20090209160426.000000-000
Event Type: Informatie
User:

=====Application event log=====

Computer Name: BigDell
Event Code: 0
Message: Setting Delayed Startup info for Vista
Record Number: 552
Source Name: DellStart
Time Written: 20081218215722.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 0
Message: Consent #1 Handled
Record Number: 551
Source Name: DellStart
Time Written: 20081218215722.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 0
Message: Consent #2 Handled
Record Number: 550
Source Name: DellStart
Time Written: 20081218215722.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 0
Message: Provider ID: DellSupportCenter
Record Number: 549
Source Name: DellStart
Time Written: 20081218215722.000000-000
Event Type: Informatie
User:

Computer Name: BigDell
Event Code: 0
Message: Administrator verified
Record Number: 548
Source Name: DellStart
Time Written: 20081218215722.000000-000
Event Type: Informatie
User:

=====Security event log=====

Computer Name: BigDell
Event Code: 4907
Message: De controle-instellingen voor een object zijn gewijzigd.

Onderwerp:
Beveiligings-id: S-1-5-18
Accountnaam: BIGDELL$
Accountdomein: WORKGROUP
Aanmeldings-id: 0x3e7

Object:
Objectserver: Security
Objecttype: File
Objectnaam: C:\Windows\System32\mshtml.dll
Ingangs-id: 0x14

Procesgegevens:
Proces-id: 0x13d4
Procesnaam: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe

Controle-instellingen:
Oorspronkelijke security descriptor:
Nieuwe security descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 641
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081219084718.245541-000
Event Type: Controle geslaagd
User:

Computer Name: BigDell
Event Code: 4907
Message: De controle-instellingen voor een object zijn gewijzigd.

Onderwerp:
Beveiligings-id: S-1-5-18
Accountnaam: BIGDELL$
Accountdomein: WORKGROUP
Aanmeldings-id: 0x3e7

Object:
Objectserver: Security
Objecttype: File
Objectnaam: C:\Windows\System32\drivers\mrxsmb10.sys
Ingangs-id: 0x14

Procesgegevens:
Proces-id: 0x13d4
Procesnaam: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe

Controle-instellingen:
Oorspronkelijke security descriptor:
Nieuwe security descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 640
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081219084717.964741-000
Event Type: Controle geslaagd
User:

Computer Name: BigDell
Event Code: 4907
Message: De controle-instellingen voor een object zijn gewijzigd.

Onderwerp:
Beveiligings-id: S-1-5-18
Accountnaam: BIGDELL$
Accountdomein: WORKGROUP
Aanmeldings-id: 0x3e7

Object:
Objectserver: Security
Objecttype: File
Objectnaam: C:\Windows\System32\Apphlpdm.dll
Ingangs-id: 0x14

Procesgegevens:
Proces-id: 0x13d4
Procesnaam: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe

Controle-instellingen:
Oorspronkelijke security descriptor:
Nieuwe security descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 639
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081219084717.933541-000
Event Type: Controle geslaagd
User:

Computer Name: BigDell
Event Code: 4907
Message: De controle-instellingen voor een object zijn gewijzigd.

Onderwerp:
Beveiligings-id: S-1-5-18
Accountnaam: BIGDELL$
Accountdomein: WORKGROUP
Aanmeldings-id: 0x3e7

Object:
Objectserver: Security
Objecttype: File
Objectnaam: C:\Windows\System32\GameUXLegacyGDFs.dll
Ingangs-id: 0x14

Procesgegevens:
Proces-id: 0x13d4
Procesnaam: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe

Controle-instellingen:
Oorspronkelijke security descriptor:
Nieuwe security descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 638
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081219084717.886741-000
Event Type: Controle geslaagd
User:

Computer Name: BigDell
Event Code: 4907
Message: De controle-instellingen voor een object zijn gewijzigd.

Onderwerp:
Beveiligings-id: S-1-5-18
Accountnaam: BIGDELL$
Accountdomein: WORKGROUP
Aanmeldings-id: 0x3e7

Object:
Objectserver: Security
Objecttype: File
Objectnaam: C:\Windows\AppPatch\AcSpecfc.dll
Ingangs-id: 0x14

Procesgegevens:
Proces-id: 0x13d4
Procesnaam: C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6001.18000_none_095f6148c74a7a64\poqexec.exe

Controle-instellingen:
Oorspronkelijke security descriptor:
Nieuwe security descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 637
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20081219084717.683941-000
Event Type: Controle geslaagd
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=4
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

—————–EOF—————–
Hello,

So sorry about the late reply.

You have/had BitComet, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

If you wish to keep it, please do not use it until your computer is cleaned.

I would recommend that you uninstall BitComet, however that choice is up to you.

Punkbuster warning
I see you have Punkbuster installed. This is spyware. Punkbuster can take control over various aspects of your computer, and some gaming tools not unlike Punkbuster also hinder their removals. By the definition we handle here, Punkbuster is actual spyware. Therefore, I now ask you to decide the following:
  • Either we try to leave Punkbuster alone but there is no guarantee a spyware component doesn't 'accidentally' get taken out; so Punkbuster might break. This will, of course, also break your ability to play games using Punkbuster enabled servers.
  • Or we can just remove Punkbuster. You can reinstall it afterwards if you wish, but please keep in mind that it is spyware.
  • Another option is to not clean this computer at all. This ensures Punkbuster will continue to function.

If you don't want to clean the computer and leave punkbuster in tact, then please do NOT follow any more instructions and let me know that you wish to not clean it. If you want to remove it, please also let me know that. If you want me to try to fix it and leave punkbuster then please just follow the instructions.

Backup Registry
  • Please download ERUNT from here.
  • Unzip all the files into a folder of your choice.

Click Erunt.exe to backup your registry to the folder of your choice.

Note: If you ever need to restore your registry in case something breaks, go to the folder and start ERDNT.exe

Download and Run OTM.exe

Download OTM.exe by Old Timer and save it to your Desktop.
  • Double-click OTM.exe. (Vista users, please right click on OTM.exe and select "Run as an Administrator")
  • Copy the lines in the codebox below.
:Reg
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1256283-c0d6-11dd-a7f9-806e6f6e6963}]
:Files
  • Return to OTM.exe, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTM.exe

Fix HijackThis lines

  • Run HijackThis!
  • Click on Do a System Scan only
  • Place a tick next to the following lines:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
Close all open windows and click on Fix checked and when you get a popup window click on Yes.

In your next reply, please include:
  • OTM results
  • A new HijackThis log

Regards,
Adam
Hi Adam,
no problem for the late reply ^_^ ,
I deleted Bitcomet and will install it on a computer less important to me. (Actually, I know where the Trojan came from, I downloaded a keygen, that wasn't even zipped, but .exe. I will think twice next time!!)
For the punkbusters, I play Battlefield Heroes which uses punkbusters, so when we delete it will reappear, won't it? If not I agree to remove it.
Again thank you for your time :)

OMT log
========== REGISTRY ==========
========== FILES ==========

OTM by OldTimer - Version 3.0.0.5 log created on 07222009_185506

New Hijack log after fixing checked:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:05:25, on 22/07/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Itunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.be/ig/dell?hl=nl&cli…amp;ibd=3081203
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ig?hl=nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer aangeboden door Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\Itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; Tablet PC 2.0; .NET CLR 3.5.21022; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.habbo.nl/shockwave_client"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote-inhoudsopgave.onetoc2
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/51.28/uploader2.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.euro.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUpldnl-be.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.21.0.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updateservice (gupdate1c98e038bad370b) (gupdate1c98e038bad370b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe

–
End of file - 11729 bytes
Hi, my apologies. I posted a bad script to you for OTM which did absolutely nothing. Here is the correct one:

Backup Registry
  • Please download ERUNT from here.
  • Unzip all the files into a folder of your choice.

Click Erunt.exe to backup your registry to the folder of your choice.

Note: If you ever need to restore your registry in case something breaks, go to the folder and start ERDNT.exe

Download and Run OTM.exe

Download OTM.exe by Old Timer and save it to your Desktop.
  • Double-click OTM.exe. (Vista users, please right click on OTM.exe and select "Run as an Administrator")
  • Copy the lines in the codebox below.
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1256283-c0d6-11dd-a7f9-806e6f6e6963}]
:Files
  • Return to OTM.exe, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTM.exe

In your next reply, please include:
  • OTM results
  • A new HijackThis log

Regards,
Adam
Hi Adam
I deleted Bitcomet and will install it on a computer less important to me. (Actually, I know where the Trojan came from, I downloaded a keygen, that wasn't even zipped, but .exe. I will think twice next time!!)
For the punkbusters, I play Battlefield Heroes which uses punkbusters, so when we delete it will reappear, won't it? If not I agree to remove it.
Again thank you for your time.

here's the new OTM log:

========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1256283-c0d6-11dd-a7f9-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e1256283-c0d6-11dd-a7f9-806e6f6e6963}\ not found.
========== FILES ==========

OTM by OldTimer - Version 3.0.0.5 log created on 07232009_181347


And here the Hijack:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:15:58, on 23/07/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Hans\Desktop\OTM.exe
C:\Windows\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.be/ig/dell?hl=nl&cli…amp;ibd=3081203
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ig?hl=nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer aangeboden door Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; Tablet PC 2.0; .NET CLR 3.5.21022; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.habbo.nl/shockwave_client"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: OneNote-inhoudsopgave.onetoc2
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/51.28/uploader2.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.euro.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUpldnl-be.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.21.0.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updateservice (gupdate1c98e038bad370b) (gupdate1c98e038bad370b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe

–
End of file - 9539 bytes
Congratulations, you are now all clean! To help to prevent from becoming reinfected, please follow the instructions below in order. If you have any questions, please feel free to ask them. If after 48 hours you have not responded to this, then I will assume you have no questions and have the topic closed.


  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Click the CleanUp! button.
  • When it prompts you to Restart, click Yes.

Flush the system restore points

  • Right click on My Computer and select Properties.
  • Select the System Restore tab.
  • Check (tick) Turn off system restore on all drives box.
  • Click Apply.
  • Uncheck (untick) Turn off system restore on all drives box.
  • Click OK.
  • Restart your computer.
Note: Do this only ONCE, don't flush it regularly.

Keep your system updated

Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Please ensure that you visit the following websites regularly or do update your system regularly.

Install the updates immediately if they are found. Reboot your computer if necessary, revisit Windows Update and Office update sites until there are no more updates to be installed.

To update Windows and office

Go to Start > All Programs > Microsoft Update


Alternatively, you can visit the link below to update Windows and Office products.

Microsoft Update

I also recommend, if it's not already on, to enable Automatic updates. It will notify you whenever there are new updates available. Here's how:

  • Go to Start > Control Panel > Automatic Updates
  • Select Automatic (recommended) radio button if you want the updates to be downloaded and installed without prompting you.
  • Select Download updates for me, but let me chose when to install them radio button if you want the updates to be downloaded automatically but to be installed at another time.
  • Select Notify me but don't automatically download or install them radio button if you want to be notified of the updates.

Besides Windows that needs regular updating, antivirus, anti-spyware and firewall programs update regularly too.

Please make sure that you update your antivirus, firewall and anti-spyware programs at least once a week.

Surf safely

Many of the exploits are directed to users of Internet Explorer and Firefox.

Using Firefox with NoScript add-on helps to prevent most exploits from running as NoScript by default disables all scripts on all websites. If you trust the website, you can manually allow it.

If you prefer to use Internet Explorer, here are some settings to change to improve the security of Internet Explorer.

Backup regularly

You never know when your PC will become unstable or become so infected that you can't recover it. Follow this Microsoft article to learn how to backup. Follow this article by Microsoft to restore your backups.

Alternatively, you can use 3rd-party programs to back up your data. One example can be found at Bleeping Computer.

Avoid P2P

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. If you do need to use them, use them sparingly. Check this list of clean and infected P2P programs if you need to use one.

Prevent a re-infection

  • Winpatrol
    Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here.

    You can get a free copy of Winpatrol or use the Plus version for more features.

    You can read Winpatrol's FAQ if you run into problems.

  • Hosts File
    A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your PC will look up the website's IP address before you can view the website.

    Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to 127.0.0.1.

    Here are some Hosts files:

    MVPS Hosts File
    Bluetack's Hosts File
    Bluetack's Host Manager
    hpHosts

    A tutorial about Hosts File can be found at Malware Removal.

  • Spybot Search and Destroy
    Spybot Search & Destroy is another program for scanning spywares and adwares. Not only so, it has other preventive options as well. You are strongly encouraged to run a scan at least once per week.

    Spybot Search & Destroy can be downloaded from here.

    If you need help in using Spybot Search & Destroy, you can read Spybot Search and Destroy tutorial at Bleeping Computer.

    Before downloading any anti-spyware programs, always check the Rogue/Suspect list of anti-spyware programs and Malwarebytes RogueNET. This will save you from a lot of trouble. If in doubt, don't ever download it.

  • SiteHound Toolbar
    SiteHound is a toolbar that warns you if you go to a site that is known to scam people, that has potentially lots of viruses or spywares or has questionable contents. If you know the site, you can enter it; if you don't, it will bring you back to the previous page. Currently, SiteHound works for Internet Explorer and Firefox only.


Stand Up and Be Counted —> Malware Complaints <— where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Happy surfing and stay clean!

Regards,
Adam
Hi Adam, thank you for all your help ^_^. I've encountered two last problems. 1. On forums I visit daily, I check "remember me" when I log in. Next day I'm not logged in anymore. 2. On my favourite forum, when I scroll down, there are glitches, my monitor doesn't follow the speed of my scroll right. (I'm not english, I don't know how to explain). Before the Trojan, I didn't encountered this. Thank you for all the help, Xaver
Before sending you on your way, lets do a few more scans to make sure its gone.

Kaspersky Online Scanner
Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Run GMER
Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.

In your next reply, please include:
  • Kaspersky report
  • GMER log
  • A new HijackThis log

Regards,
Adam
Hi Adam, 1.Kaspersky report: No malware found 2. When GMER was scanning, suddenly there came a blue screen with some white text and message bumping memory. Then computer restarted and everything looks normal. Should I try GMER again? Thanks, Xaver
Ok, try this instead of GMER:

RootRepeal
Please download RootRepeal to your desktop
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Files, Processes and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop. Post that log here in your reply
Hi Adam, I've closed all my virus programs and windows firewall. When I start RootRepeal, I get an error, and the log is saved to it's own folder. ROOTREPEAL CRASH REPORT ————————- Windows Version: Windows Vista SP2 Exception Code: 0xc0000005 Exception Address: 0x004298a0 Attempt to write to address: 0x01686000 My computer doesn't want to cooperate ^_^ Xaver
Run Blacklight
  • Please download F-Secure Blacklight and save it to C drive.
  • Click on Start > Run and copy and paste in the following: C:\fsbl.exe /expert. Click OK.
  • You will be shown a license agreement. Read through it and select I accept the agreement. Click Next.
  • Click on Scan.
  • Once the scan is done, close F-Secure Blacklight. Don't rename anything found!
  • A log will be produced on your C drive. It's named fsbl-XXXXXXXXXXXXXX.log, where the XXXXXXXXXXXXXX are numbers. Please post this log in your next reply.
Hi Adam Here's the log: 07/31/09 09:27:32 [Info]: BlackLight Engine 2.2.1092 initialized 07/31/09 09:27:32 [Info]: OS: 6.0 build 6002 (Service Pack 2) 07/31/09 09:27:32 [Note]: 7019 4 07/31/09 09:27:32 [Note]: 7005 0 07/31/09 09:27:45 [Note]: 7006 0 07/31/09 09:27:45 [Note]: 7027 0 07/31/09 09:27:46 [Note]: 7035 0 07/31/09 09:27:46 [Note]: 7026 0 07/31/09 09:27:46 [Note]: 7026 0 07/31/09 09:27:47 [Note]: FSRAW library version 1.7.1024 07/31/09 09:27:53 [Note]: 4015 66990 07/31/09 09:27:53 [Note]: 4027 66990 6029312 07/31/09 09:27:53 [Note]: 4020 56057 3866624 07/31/09 09:27:53 [Note]: 4018 56057 3866624 07/31/09 09:28:15 [Note]: 4015 49820 07/31/09 09:28:15 [Note]: 4027 49820 655360 07/31/09 09:28:15 [Note]: 4020 49819 393216 07/31/09 09:28:15 [Note]: 4018 49819 393216 07/31/09 09:31:11 [Note]: 4015 1382 07/31/09 09:31:11 [Note]: 4027 1382 65536 07/31/09 09:31:11 [Note]: 4020 1378 65536 07/31/09 09:31:11 [Note]: 4018 1378 65536 07/31/09 09:31:22 [Note]: 4015 1564 07/31/09 09:31:22 [Note]: 4027 1564 65536 07/31/09 09:31:22 [Note]: 4020 513 65536 07/31/09 09:31:22 [Note]: 4018 513 65536 07/31/09 09:37:22 [Note]: 7007 0 Xaver

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI