with avast i guess you mean the other program as avast is the one i deinstalled?
i just tried to disable it, it had no disable function but a snooze function so i used that. Scanning went further then svchost, but froze at Dnscache...
And a little black screen just popped up, its the catchme.exe, not sure to let it run or not so i let it run. what do you think about this?
ok forget what i said. for some reason i suddenly got myself a log, im posting it through
[code=auto:0]OTScanIt2 logfile created on: 5/12/2008 22:57:57 - Run 3
OTScanIt2 by OldTimer - Version 1.0.2.1 Folder = C:\Documents and Settings\XP\Bureaublad\OTScanIt2
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy
319,48 Mb Total Physical Memory | 92,11 Mb Available Physical Memory | 28,83% Memory free
773,63 Mb Paging File | 381,13 Mb Available in Paging File | 49,26% Paging File free
Paging file location(s): C:\pagefile.sys 480 960;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38,17 Gb Total Space | 21,12 Gb Free Space | 55,34% Space Free | Partition Type: NTFS
Drive D: | 38,16 Gb Total Space | 37,83 Gb Free Space | 99,14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: THUIS-6BAA17DAD
Current User Name: XP
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 90 Days
[Processes - Safe List]
adeck.exe -> %ProgramFiles%\VIA\VIAudioi\SBADeck\ADeck.exe -> [2007/06/27 10:52:00 | 00,540,672 | R--- | M] (VIA Technologies, Inc.)
cavrid.exe -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe -> [2007/07/19 17:46:40 | 00,185,456 | ---- | M] (Computer Associates International, Inc.)
cavtray.exe -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe -> [2007/07/19 17:46:40 | 00,230,512 | ---- | M] (Computer Associates International, Inc.)
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> [2008/11/14 20:50:47 | 00,307,712 | ---- | M] (Mozilla Corporation)
hpi_monitor.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe -> [2000/08/14 15:48:06 | 00,032,768 | ---- | M] (Hewlett-Packard Company)
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe -> [2007/05/08 15:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard)
isafe.exe -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\iSafe.exe -> [2007/07/19 17:46:40 | 00,259,184 | ---- | M] (Computer Associates International, Inc.)
mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
msmsgs.exe -> %ProgramFiles%\Messenger\msmsgs.exe -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
msnmsgr.exe -> %ProgramFiles%\MSN Messenger\msnmsgr.exe -> [2007/01/19 12:54:42 | 05,674,352 | ---- | M] (Microsoft Corporation)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2005/10/10 20:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation)
otscanit2.exe -> %UserProfile%\Bureaublad\OTScanIt2\OTScanIt2.exe -> [2008/12/01 10:28:50 | 00,477,184 | ---- | M] (OldTimer Tools)
pdvdserv.exe -> %ProgramFiles%\CyberLink\PowerDVD\PDVDServ.exe -> [2003/11/30 01:04:56 | 00,032,768 | ---- | M] (Cyberlink Corp.)
vetmsg.exe -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe -> [2007/07/19 17:46:40 | 00,201,840 | ---- | M] (Computer Associates International, Inc.)
[Win32 Services - Safe List]
(aspnet_state) ASP.NET-statusservice [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/04/13 02:20:52 | 00,033,632 | ---- | M] (Microsoft Corporation)
(CAISafe) CAISafe [Win32_Own | Auto | Running] -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\iSafe.exe -> [2007/07/19 17:46:40 | 00,259,184 | ---- | M] (Computer Associates International, Inc.)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/04/13 02:21:18 | 00,068,952 | ---- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2006/10/20 20:21:24 | 00,036,864 | ---- | M] (Microsoft Corporation)
(helpsvc) Help en ondersteuning [Win32_Shared | Auto | Running] -> %SystemRoot%\pchealth\helpctr\binaries\pchsvc.dll -> [2004/08/04 13:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2006/10/30 02:33:58 | 00,741,376 | ---- | M] (Microsoft Corporation)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2006/10/30 02:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2005/10/10 20:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation)
(usnjsvc) Messenger USN Journal Reader service voor Gedeelde mappen [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\MSN Messenger\usnsvc.exe -> [2007/01/19 11:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation)
(VETMSGNT) VET Message Service [Win32_Own | Auto | Running] -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe -> [2007/07/19 17:46:40 | 00,201,840 | ---- | M] (Computer Associates International, Inc.)
(WMPNetworkSvc) Windows Media Player Network Sharing-service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/11/02 21:53:32 | 00,917,504 | ---- | M] (Microsoft Corporation)
(WudfSvc) Windows Driver Foundation - User-mode Driver Framework [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\WudfSvc.dll -> [2006/09/28 17:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(Dot4) IEEE-1284.4 Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hphid407.sys -> [2000/08/04 17:40:08 | 00,050,320 | R--- | M] (HP)
(Dot4Print) Print Class Driver for IEEE-1284.4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hphipr07.sys -> [2000/08/04 17:40:10 | 00,015,824 | R--- | M] (HP)
(Dot4Usb) USB to IEEE-1284.4 Translation Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\hphius07.sys -> [2000/08/04 17:40:10 | 00,017,904 | R--- | M] (HP)
(FET5X86V) VIA Rhine-Family Fast-Ethernet Adapter Driver Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\fetnd5bv.sys -> [2007/04/17 02:58:56 | 00,042,496 | ---- | M] (VIA Technologies, Inc. )
(FETNDIS) VIA PCI 10/100Mb Fast Ethernet-adapter - NT-stuurprogramma [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fetnd5.sys -> [2001/08/17 21:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. )
(gameenum) Spelpoort-enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\gameenum.sys -> [2004/08/04 00:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation)
(ms_mpu401) Microsoft MPU-401 MIDI UART-stuurprogramma [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\msmpu401.sys -> [2001/08/17 23:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2005/10/10 20:49:00 | 03,530,432 | ---- | M] (NVIDIA Corporation)
(Ptilink) Stuurprogramma voor Directe parallelle verbinding [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2004/08/04 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 11:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(VET-FILT) VET File System Filter [Kernel | System | Running] -> %SystemRoot%\System32\drivers\Vet-Filt.sys -> [2007/07/19 17:46:39 | 00,021,031 | ---- | M] (Computer Associates International, Inc.)
(VET-REC) VET File System Recognizer [Kernel | System | Running] -> %SystemRoot%\System32\drivers\Vet-Rec.sys -> [2007/07/19 17:46:39 | 00,015,478 | ---- | M] (Computer Associates International, Inc.)
(VETEBOOT) VET Boot Scan Engine [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\VetEBoot.sys -> [2007/07/23 17:03:45 | 00,108,360 | ---- | M] (Computer Associates International, Inc.)
(VETEFILE) VET File Scan Engine [Kernel | System | Running] -> %SystemRoot%\System32\drivers\VetEFile.sys -> [2007/07/23 17:03:45 | 00,879,832 | ---- | M] (Computer Associates International, Inc.)
(VETFDDNT) VET Floppy Boot Sector Monitor [Kernel | System | Running] -> %SystemRoot%\System32\drivers\VetFDDNT.sys -> [2007/07/19 17:46:39 | 00,015,735 | ---- | M] (Computer Associates International, Inc.)
(VETMONNT) VET File Monitor [Kernel | System | Running] -> %SystemRoot%\System32\drivers\vetmonnt.sys -> [2007/07/19 17:47:00 | 00,026,787 | ---- | M] (Computer Associates International, Inc.)
(VIAudio) Vinyl AC'97 Audio Controller (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\vinyl97.sys -> [2006/10/10 03:58:48 | 00,203,648 | R--- | M] (VIA Technologies, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?linkid=677 ->
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?linkid=677 ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\: "ProxyEnable" -> 0 ->
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\XP\Application Data\Mozilla\FireFox\Profiles\aua4qmfv.default\prefs.js ->
browser.search.defaultenginename -> "Ask" ->
browser.search.selectedEngine -> "Google" ->
browser.startup.homepage_override.mstone -> "rv:1.9.0.4" ->
extensions.enabledItems -> {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.0.3 ->
extensions.enabledItems -> {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.4 ->
extensions.enabledItems -> {463F6CA5-EE3C-4be1-B7E6-7FEE11953374}:3.0.4 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 ->
extensions.enabledItems -> {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20081111 ->
extensions.enabledItems -> {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.3 ->
extensions.enabledItems -> {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.0.2 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.4 ->
< HOSTS File > (776 bytes and 18 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Help bij koppelingen] -> [2006/10/22 22:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> [2008/06/10 03:27:02 | 00,509,328 | ---- | M] (Sun Microsystems, Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2006/08/31 19:33:06 | 00,322,368 | ---- | M] (Microsoft Corporation)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2007/05/11 02:06:32 | 00,040,048 | ---- | M] (Adobe Systems Incorporated)
"AudioDeck" -> %ProgramFiles%\VIA\VIAudioi\SBADeck\ADeck.exe [C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1] -> [2007/06/27 10:52:00 | 00,540,672 | R--- | M] (VIA Technologies, Inc.)
"CaAvTray" -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe ["C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"] -> [2007/07/19 17:46:40 | 00,230,512 | ---- | M] (Computer Associates International, Inc.)
"CAVRID" -> %ProgramFiles%\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe ["C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"] -> [2007/07/19 17:46:40 | 00,185,456 | ---- | M] (Computer Associates International, Inc.)
"CXMon" -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe ["C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"] -> [2000/08/14 15:48:06 | 00,032,768 | ---- | M] (Hewlett-Packard Company)
"HP Software Update" -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe [C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe] -> [2007/05/08 15:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard)
"MalwareDestructor" -> [C:\Program Files\MalwareDestructor\MalwareDestructor.exe /s] -> File not found
"NeroFilterCheck" -> %SystemRoot%\system32\NeroCheck.exe [C:\WINDOWS\system32\NeroCheck.exe] -> [2001/07/09 10:50:42 | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2005/10/10 20:49:00 | 07,286,784 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> %SystemRoot%\system32\nvmctray.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2005/10/10 20:49:00 | 00,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2005/10/10 20:49:00 | 01,519,616 | ---- | M] ()
"RemoteControl" -> %ProgramFiles%\CyberLink\PowerDVD\PDVDServ.exe [C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe] -> [2003/11/30 01:04:56 | 00,032,768 | ---- | M] (Cyberlink Corp.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"] -> File not found
"Windows SysNotify" -> %SystemRoot%\system32\mssecc.exe [C:\WINDOWS\system32\mssecc.exe] -> File not found
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AWMON" -> %ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe ["C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"] -> [2005/05/25 11:12:36 | 00,517,632 | ---- | M] (Lavasoft Sweden)
"MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
"MsnMsgr" -> %ProgramFiles%\MSN Messenger\msnmsgr.exe ["C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background] -> [2007/01/19 12:54:42 | 05,674,352 | ---- | M] (Microsoft Corporation)
"Nick LaunchPad" -> %ProgramFiles%\Nick LaunchPad\Nick LaunchPad.exe ["C:\Program Files\Nick LaunchPad\Nick LaunchPad.exe" -r] -> File not found
< RunOnce [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"Shockwave Updater" -> %SystemRoot%\system32\Macromed\Shockwave 10\SwHelper_1020022.exe [C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~1.EXE -Update -1020022 -iexplore.exe7.0] -> [2007/05/02 11:31:46 | 00,383,216 | ---- | M] (Adobe Systems, Inc.)
< Run [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AWMON" -> %ProgramFiles%\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe ["C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"] -> [2005/05/25 11:12:36 | 00,517,632 | ---- | M] (Lavasoft Sweden)
"MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
"MsnMsgr" -> %ProgramFiles%\MSN Messenger\msnmsgr.exe ["C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background] -> [2007/01/19 12:54:42 | 05,674,352 | ---- | M] (Microsoft Corporation)
"Nick LaunchPad" -> %ProgramFiles%\Nick LaunchPad\Nick LaunchPad.exe ["C:\Program Files\Nick LaunchPad\Nick LaunchPad.exe" -r] -> File not found
< RunOnce [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"Shockwave Updater" -> %SystemRoot%\system32\Macromed\Shockwave 10\SwHelper_1020022.exe [C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~1.EXE -Update -1020022 -iexplore.exe7.0] -> [2007/05/02 11:31:46 | 00,383,216 | ---- | M] (Adobe Systems, Inc.)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten ->
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Menu Start\Programma's\Opstarten ->
< toni Startup Folder > -> C:\Documents and Settings\toni\Menu Start\Programma's\Opstarten ->
< XP Startup Folder > -> C:\Documents and Settings\XP\Menu Start\Programma's\Opstarten ->
%UserProfile%\Menu Start\Programma's\Opstarten\IMVU.lnk -> %ProgramFiles%\IMVU\IMVUClient.exe -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xporteren naar Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2005/05/27 00:06:54 | 10,095,808 | ---- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xporteren naar Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2005/05/27 00:06:54 | 10,095,808 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Menu: Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Onderzoek] -> [2003/07/15 05:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
{d9288080-1baa-4bc4-9cf8-a92d743db949}:Exec [HKLM] -> %UserProfile%\Menu Start\Programma's\IMVU\Run IMVU.lnk [Button: Run IMVU] -> File not found
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 13:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation)
{F4430FE8-2638-42e5-B849-800749B94EED}:Exec [HKLM] -> %ProgramFiles%\PartyGaming.Net\PartyPokerNet\RunPF.exe [Button: PartyPoker.net] -> File not found
{F4430FE8-2638-42e5-B849-800749B94EED}:Exec [HKLM] -> %ProgramFiles%\PartyGaming.Net\PartyPokerNet\RunPF.exe [Menu: PartyPoker.net] -> File not found
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Onderzoek] -> [2003/07/15 05:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Onderzoek] -> [2003/07/15 05:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 17:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\] > -> HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-1801674531-764733703-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] ->
{5D6F45B3-9043-443D-A792-115447494D24} [HKLM] -> http://messenger.zone.msn.com/NL-BE/a-UNO1/GAME_UNO1.cab[UnoCtrl Class] ->
{69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} [HKLM] -> http://www.acclaim.com/cabs/acclaim_v4.cab[GameLauncher Control] ->
{77E32299-629F-43C6-AB77-6A1E6D7663F6} [HKLM] -> http://www.nick.com/common/groove/gx/GrooveAX27.cab[Groove Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] ->
{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} [HKLM] -> http://game14.zylom.com/activex/zylomgamesplayer.cab[Zylom Games Player] ->
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] ->
{D4323BF2-006A-4440-A2F5-27E3E7AB25F8} [HKLM] -> http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe[Reg Error: Key does not exist or could not be opened.] ->
Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{22C1F736-9026-4CD1-B86F-A82A782210A2} -> (VIA Rhine II Fast Ethernet Adapter) ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 13:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 13:00:00 | 00,142,336 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msncall.exe" -> C:\Program Files\MSN Messenger\msncall.exe [C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)] -> File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:42 | 05,674,352 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 13:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 13:00:00 | 00,142,336 | ---- | M] (Microsoft Corporation)
"C:\Documents and Settings\XP\Local Settings\Temp\WZSE0.TMP\SymNRT.exe" -> C:\Documents and Settings\XP\Local Settings\Temp\WZSE0.TMP\SymNRT.exe [C:\Documents and Settings\XP\Local Settings\Temp\WZSE0.TMP\SymNRT.exe:*:Enabled:Norton Removal Tool] -> File not found
"C:\Program Files\Internet Explorer\iexplore.exe" -> C:\Program Files\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer] -> [2007/12/06 12:04:44 | 00,625,664 | ---- | M] (Microsoft Corporation)
"C:\Program Files\LimeWire Plus\LimeWire.exe" -> C:\Program Files\LimeWire Plus\LimeWire.exe [C:\Program Files\LimeWire Plus\LimeWire.exe:*:Enabled:LimeWire] -> [2007/09/17 15:19:14 | 00,147,456 | ---- | M] (Lime Wire, LLC)
"C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\AGE2_X1.ICD" -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\AGE2_X1.ICD [C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion] -> [2000/06/27 22:09:58 | 02,695,213 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 15:10:02 | 00,297,752 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msncall.exe" -> C:\Program Files\MSN Messenger\msncall.exe [C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)] -> File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> [2007/01/19 12:54:42 | 05,674,352 | ---- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> Cd-rom-stuurprogramma ->
"ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/04 13:00:00 | 00,049,536 | ---- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2007/07/19 17:31:08 | 00,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
[Registry - Additional Scans - Safe List]
< App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ ->
7zFM.exe -> %ProgramFiles%\7-Zip\7zFM.exe [C:\Program Files\7-Zip\7zFM.exe] -> [2007/09/05 10:02:08 | 00,378,368 | ---- | M] (Igor Pavlov)
ACDSee(HP).exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\ACD\ACDSee\ACDSee(HP).exe [C:\Program Files\Hewlett-Packard\PhotoSmart\ACD\ACDSee\ACDSee(HP).exe] -> [2000/07/24 10:08:36 | 00,661,504 | ---- | M] (ACD Systems, Ltd.)
AcroRd32.exe -> %ProgramFiles%\Adobe\Reader 8.0\Reader\AcroRd32.exe [C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe] -> [2007/05/11 02:06:38 | 00,341,616 | ---- | M] (Adobe Systems Incorporated)
BackItUp.EXE -> %ProgramFiles%\Ahead\Nero BackItUp\BackItUp.exe [C:\Program Files\Ahead\Nero BackItUp\BackItUp.exe] -> [2005/07/14 20:34:34 | 05,758,976 | ---- | M] (Ahead Software AG)
bckgzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\bckgzm.exe [C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe] -> [2004/08/04 13:00:00 | 00,042,577 | ---- | M] (Microsoft Corporation)
Cam_Gallery.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\cam_gallery.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Cam_Gallery.exe] -> [2000/08/14 15:46:24 | 00,180,224 | ---- | M] ()
chkrzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\chkrzm.exe [C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe] -> [2004/08/04 13:00:00 | 00,042,575 | ---- | M] (Microsoft Corporation)
CONF.EXE -> %ProgramFiles%\NetMeeting\conf.exe [C:\Program Files\NetMeeting\conf.exe] -> [2004/08/04 13:00:00 | 01,040,384 | ---- | M] (Microsoft Corporation)
dialer.exe -> %ProgramFiles%\Windows NT\dialer.exe [C:\Program Files\Windows NT\dialer.exe] -> [2004/08/04 13:00:00 | 00,545,792 | ---- | M] (Microsoft Corporation)
excel.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE] -> [2005/05/27 00:06:54 | 10,095,808 | ---- | M] (Microsoft Corporation)
Extension Manager.exe -> %ProgramFiles%\Macromedia\Extension Manager\Extension Manager.exe [C:\Program Files\Macromedia\Extension Manager\Extension Manager.exe] -> [2005/08/10 14:13:52 | 00,614,400 | ---- | M] (Macromedia, Inc.)
EZUnload.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\EZunload.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\EZUnload.exe] -> [2000/08/14 15:46:56 | 00,118,784 | ---- | M] ()
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe] -> [2008/11/14 20:50:47 | 00,307,712 | ---- | M] (Mozilla Corporation)
Flash.exe -> %ProgramFiles%\Macromedia\Flash 8\Flash.exe [C:\Program Files\Macromedia\Flash 8\flash.exe] -> [2005/08/31 03:10:38 | 16,879,616 | ---- | M] (Macromedia, Inc.)
HELPCTR.EXE -> %SystemRoot%\pchealth\helpctr\binaries\HelpCtr.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe] -> [2004/08/04 13:00:00 | 00,768,512 | ---- | M] (Microsoft Corporation)
HijackThis.exe -> %ProgramFiles%\Trend Micro\HijackThis\HijackThis.exe [C:\Program Files\Trend Micro\HijackThis\hijackthis.exe] -> [2008/12/01 07:23:15 | 00,396,288 | ---- | M] (Trend Micro Inc.)
Hpi_CameraShell.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_CameraShell.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_CameraShell.exe] -> [2000/08/14 15:51:28 | 00,053,248 | ---- | M] ()
Hpi_JetSend.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe] -> [2000/08/14 15:52:34 | 00,585,728 | ---- | M] ()
Hpi_Monitor.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe] -> [2000/08/14 15:48:06 | 00,032,768 | ---- | M] (Hewlett-Packard Company)
hpi_print.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Photo Printing\Hpi_Print.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Printing\hpi_print.exe] -> [2000/08/14 15:43:56 | 00,512,000 | ---- | M] ()
hpi_run.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Update\HPI_Run.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Update\hpi_run.exe] -> [2000/08/14 15:50:10 | 00,036,864 | ---- | M] ()
hpi_upvm.exe -> %ProgramFiles%\Hewlett-Packard\PhotoSmart\Update\bin\hpi_upvm.exe [C:\Program Files\Hewlett-Packard\PhotoSmart\Update\bin\hpi_upvm.exe] -> [2000/08/14 15:55:02 | 00,020,544 | ---- | M] ()
hrtzzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\hrtzzm.exe [C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe] -> [2004/08/04 13:00:00 | 00,042,573 | ---- | M] (Microsoft Corporation)
hypertrm.exe -> %ProgramFiles%\Windows NT\hypertrm.exe ["C:\Program Files\Windows NT\hypertrm.exe"] -> [2004/08/04 13:00:00 | 00,028,160 | ---- | M] (Hilgraeve, Inc.)
ICWCONN1.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE"] -> [2004/08/04 13:00:00 | 00,217,088 | ---- | M] (Microsoft Corporation)
ICWCONN2.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE"] -> [2004/08/04 13:00:00 | 00,086,016 | ---- | M] (Microsoft Corporation)
IEXPLORE.EXE -> %ProgramFiles%\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\IEXPLORE.EXE] -> [2007/12/06 12:04:44 | 00,625,664 | ---- | M] (Microsoft Corporation)
ImageDrive.exe -> %ProgramFiles%\Ahead\ImageDrive\ImageDrive.exe [C:\Program Files\Ahead\ImageDrive\ImageDrive.exe] -> [2005/03/03 19:34:30 | 00,893,016 | ---- | M] (Ahead Software AG)
INETWIZ.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe ["C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE"] -> [2004/08/04 13:00:00 | 00,020,480 | ---- | M] (Microsoft Corporation)
infopath.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\INFOPATH.EXE [C:\Program Files\Microsoft Office\OFFICE11\INFOPATH.EXE] -> [2005/07/05 11:19:18 | 07,069,896 | ---- | M] (Microsoft Corporation)
install.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
ISIGNUP.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE"] -> [2004/08/04 13:00:00 | 00,016,384 | ---- | M] (Microsoft Corporation)
javaws.exe -> %ProgramFiles%\Java\jre1.6.0_07\bin\javaws.exe [C:\Program Files\Java\jre1.6.0_07\bin\javaws.exe] -> [2008/06/10 01:32:34 | 00,139,264 | ---- | M] (Sun Microsystems, Inc.)
LimeWire.exe -> %ProgramFiles%\LimeWire Plus\LimeWire.exe [C:\Program Files\LimeWire Plus\LimeWire.exe] -> [2007/09/17 15:19:14 | 00,147,456 | ---- | M] (Lime Wire, LLC)
mbam.exe -> %ProgramFiles%\Malwarebytes' Anti-Malware\mbam.exe [C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe] -> [2008/12/03 19:52:32 | 01,265,296 | ---- | M] (Malwarebytes Corporation)
migwiz.exe -> %SystemRoot%\system32\usmt\migwiz.exe [%SystemRoot%\system32\usmt\migwiz.exe] -> [2004/08/04 13:00:00 | 00,246,272 | ---- | M] (Microsoft Corporation)
moviemk.exe -> %ProgramFiles%\Movie Maker\moviemk.exe [C:\Program Files\Movie Maker\moviemk.exe] -> [2004/08/04 13:00:00 | 03,555,328 | ---- | M] (Microsoft Corporation)
mplayer2.exe -> %ProgramFiles%\Windows Media Player\mplayer2.exe ["C:\Program Files\Windows Media Player\mplayer2.exe"] -> [2004/08/04 13:00:00 | 00,004,639 | ---- | M] ()
MSACCESS.EXE -> %ProgramFiles%\Microsoft Office\OFFICE11\MSACCESS.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\MSACCESS.EXE] -> [2005/07/07 15:58:00 | 06,657,224 | ---- | M] (Microsoft Corporation)
MSCONFIG.EXE -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe] -> [2004/08/04 13:00:00 | 00,160,256 | ---- | M] (Microsoft Corporation)
msimn.exe -> %ProgramFiles%\Outlook Express\msimn.exe [%ProgramFiles%\Outlook Express\msimn.exe] -> [2004/08/04 13:00:00 | 00,060,416 | ---- | M] (Microsoft Corporation)
msinfo32.exe -> %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe [C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe] -> [2004/08/04 13:00:00 | 00,040,960 | -