Mededeling

Collapse
No announcement yet.

Onberekenbare trage pc..

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Onberekenbare trage pc..

    Wie kan mij helpen met het nakijken van mijn pc ?
    Ongeveer twee weken geleden viel de pc op een middag uit.
    Het was me al opgevallen dat hij traag was.

    Dit is het logje.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:53:05, on 8-1-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\Rundll32.exe
    D:\HP Software Update\HPWuSchd2.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    D:\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Eset\nod32krn.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\WINDOWS\system32\PSIService.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
    D:\Digital Imaging\bin\hpqimzone.exe
    D:\Digital Imaging\bin\hpqSTE08.exe
    D:\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.msn.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {F5938714-BD46-408A-9842-4058206D37E3} - (no file)
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\nl\msntb.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [HP Software Update] D:\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Video ActiveX Object\isamntr.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Snelstart HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sterre-luna.spaces.live.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160813015843
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183295552062
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab
    O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader4.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6FA806C5-0DA5-4C88-9F31-7680E47AE032}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7318A03F-5C73-4FD4-BDED-B95F3A1298D8}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DC36004B-E332-499D-80E7-0F72E7E124DC}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O20 - AppInit_DLLs:
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Program Files\Spyware Doctor\sdhelp.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: SPYWAREfighterRP - Unknown owner - C:\Program Files\SPYWAREfighter\spfprc.exe (file missing)

    --
    End of file - 9461 bytes

  • #2
    Download reglooks.exe
    Plaats het op je bureaublad.
    Dubbelklik op reglooks.exe. Doe verder niets en wacht tot er een logfile opent. Post de inhoud van deze logfile.

    Comment


    • #3
      REGLOOKS logfile

      version 0.977
      Wed 09-01-2008 18:16:53,32
      running from: "C:\Documents and Settings\Patricia Dam Cotino\Bureaublad"

      --- SSODL regkeys ---

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
      only standard or legit regkeys found


      --- STS regkeys ---

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
      only standard or legit regkeys found


      --- USERINIT regkey ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"


      --- SHELL regkey ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
      "Shell"="Explorer.exe"


      --- SYSTEM regkey ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
      "System"="kdyqg.exe"


      --- APPINIT_DLLS regkey ---

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
      "AppInit_DLLs"=" "


      --- NOTIFY regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
      "WRNotifier" "DllName"="WRLogonNTF.dll"


      --- RUN / LOAD regkeys ---

      HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
      "load"=""


      --- BOOTEXECUTE regkey ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
      BootExecute= autocheck autochk *\0SsiEfr.e\0lsdelete\0\0


      --- SHELLEXECUTEHOOKS regkey ---

      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
      "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""


      --- AUTORUN regkeys ---

      HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
      "AutoRun"=""


      --- HKLM\Run regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
      "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
      "P17Helper"="Rundll32 P17.dll,P17Helper"
      "HP Software Update"="D:\\HP Software Update\\HPWuSchd2.exe"
      "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
      "NWEReboot"=""
      "HotKey"="C:\\WINDOWS\\Twain_32\\SlimU2\\HotKey.exe"
      "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
      "PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
      "NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""
      "NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
      [Run\OptionalComponents]
      @=""
      [Run\OptionalComponents\IMAIL]
      "Installed"="1"
      @=""
      [Run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"
      @=""
      [Run\OptionalComponents\MSFS]
      "Installed"="1"
      @=""


      --- HKLM\RunOnce regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
      no HKLM RunOnce keys found


      --- HKLM\RunOnceEx regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
      no HKLM RunOnceEx keys found


      --- HKLM\RunServices regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
      no HKLM RunServices keys found


      --- HKLM\RunServicesOnce regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
      regkey does not exist


      --- HKCU\Run regkeys ---

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
      "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""


      --- HKCU\RunOnce regkeys ---

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
      no HKCU RunOnce keys found


      --- HKCU\RunOnceEx regkeys ---

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
      no HKCU RunOnceEx keys found


      --- HKCU\RunServices regkeys ---

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
      no HKCU RunServices keys found


      --- HKCU\RunServicesOnce regkeys ---

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
      regkey does not exist


      --- HKU\.DEFAULT\Run regkeys - Default user ---

      HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
      "Spyware Doctor"=""
      "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"


      --- HKU\S-1-5-18\Run regkeys - user SYSTEM ---

      HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
      "Spyware Doctor"=""
      "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"


      --- HKU\S-1-5-19\Run regkeys - User Lokale service ---

      HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
      "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"


      --- HKU\S-1-5-20\Run regkeys - User Netwerkservice ---

      HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
      "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
      "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"


      --- HKLM\Explorer\Run regkeys ---

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
      "user32.dll"="C:\\Program Files\\Video ActiveX Object\\isamntr.exe"


      --- HKCU\Explorer\Run regkeys ---

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
      regkey does not exist


      --- Image File Execution regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
      no debuggers found


      --- BROWSER HELPER OBJECTS regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
      "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" regkey not found (ERROR)
      "{1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A}" FILE ="C:\\PROGRA~1\\MACROG~1\\SWEETI~1\\toolbar.dll"
      "{53707962-6F74-2D53-2644-206D7942484F}" FILE ="C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll"
      "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" FILE ="C:\\Program Files\\Java\\jre1.6.0_03\\bin\\ssv.dll"
      "{7E853D72-626A-48EC-A868-BA8D5E23E045}" regkey not found (ERROR)
      "{9030D464-4C02-4ABF-8ECC-5164760863C6}" FILE ="C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll"


      --- TOOLBAR regkeys ---

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
      "{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}" FILE ="C:\\Program Files\\Macrogaming\\SweetIMBarForIE\\toolbar.dll"
      "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" FILE ="C:\\Program Files\\MSN Toolbar\\01.01.2607.0\\nl\\msntb.dll"


      --- URLSEARCHHOOKS regkeys ---

      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
      Default URLSearchHook is missing
      "{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}"="" FILE ="C:\\Program Files\\Macrogaming\\SweetIMBarForIE\\toolbar.dll"


      --- SRCEENSAVER regkey ---

      HKEY_CURRENT_USER\Control Panel\Desktop
      "SCRNSAVE.EXE"="C:\\WINDOWS\\System32\\logon.scr"


      --- CONTEXTMENUHANDLERS regkeys ---

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
      "AVG7 Shell Extension" CLSID ={9F97547E-4609-42C5-AE0C-81C61FFAEBC3} FILE ="C:\\Program Files\\Grisoft\\AVG Free\\avgse.dll"
      "MagicISO" CLSID ={DB85C504-C730-49DD-BEC1-7B39C6103B7A} FILE ="C:\\Program Files\\MagicISO\\misosh.dll"
      "Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
      "Open With" CLSID ={09799AFB-AD67-11d1-ABCD-00C04FC30936} FILE =%SystemRoot%\system32\SHELL32.dll
      "Open With EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
      "PowerISO" CLSID ={967B2D40-8B7D-4127-9049-61EA0C2C6DCE} FILE ="C:\\Program Files\\PowerISO\\PWRISOSH.DLL"
      "WinRAR" CLSID ={B41DB860-8EE4-11D2-9906-E49FADC173CA} FILE ="C:\\Program Files\\WinRAR\\rarext.dll"
      "{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}" Start Menu Pin FILE =%SystemRoot%\system32\SHELL32.dll

      HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers
      "EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
      "MagicISO" CLSID ={DB85C504-C730-49DD-BEC1-7B39C6103B7A} FILE ="C:\\Program Files\\MagicISO\\misosh.dll"
      "Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
      "PowerISO" CLSID ={967B2D40-8B7D-4127-9049-61EA0C2C6DCE} FILE ="C:\\Program Files\\PowerISO\\PWRISOSH.DLL"
      "Sharing" CLSID ={f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} FILE ="ntshrui.dll"
      "WinRAR" CLSID ={B41DB860-8EE4-11D2-9906-E49FADC173CA} FILE ="C:\\Program Files\\WinRAR\\rarext.dll"

      HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers
      "AVG7 Shell Extension" CLSID ={9F97547E-4609-42C5-AE0C-81C61FFAEBC3} FILE ="C:\\Program Files\\Grisoft\\AVG Free\\avgse.dll"
      "MagicISO" CLSID ={DB85C504-C730-49DD-BEC1-7B39C6103B7A} FILE ="C:\\Program Files\\MagicISO\\misosh.dll"
      "PowerISO" CLSID ={967B2D40-8B7D-4127-9049-61EA0C2C6DCE} FILE ="C:\\Program Files\\PowerISO\\PWRISOSH.DLL"
      "WinRAR" CLSID ={B41DB860-8EE4-11D2-9906-E49FADC173CA} FILE ="C:\\Program Files\\WinRAR\\rarext.dll"


      --- ALTERNATESHELL regkey ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
      "AlternateShell"="cmd.exe"


      --- SAFEBOOT MINIMAL SERVICES ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
      no unknown services found


      --- SAFEBOOT NETWORK SERVICES ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
      no unknown services found


      --- SERVICES ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CCALib8
      "DisplayName"="Canon Camera Access Library 8"
      C:\Program Files\Canon\CAL\CALMAIN.exe

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ctsfm2k
      "DisplayName"="Creative SoundFont Management Device Driver"
      system32\DRIVERS\ctsfm2k.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ikhfile
      "DisplayName"="File Security Kernel Anti-Spyware Driver"
      system32\drivers\ikhfile.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ikhlayer
      "DisplayName"="Kernel Anti-Spyware Driver"
      system32\drivers\ikhlayer.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MZU_RK
      "DisplayName"="MZU_RK"
      \??\C:\WINDOWS\system32\MZU_DRV.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ossrv
      "DisplayName"="Creative OS Services Driver"
      system32\DRIVERS\ctoss2k.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\P17
      "DisplayName"="Sound Blaster Audigy"
      system32\drivers\P17.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SCDEmu
      no imagepath value found

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SDhelper
      "DisplayName"="PC Tools Spyware Doctor"
      C:\Program Files\Spyware Doctor\sdhelp.exe

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SlWdmSup
      "DisplayName"="SlWdmSup"
      system32\DRIVERS\SlWdmSup.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SpyFighter
      "DisplayName"="SpyFighter Guard Device"
      \??\C:\Program Files\SPYWAREfighter\spyfighter.sys

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SPYWAREfighterRP
      "DisplayName"="SPYWAREfighterRP"
      "C:\Program Files\SPYWAREfighter\spfprc.exe"

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VXD
      no imagepath value found

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{6FA806C5-0DA5-4C88-9F31-7680E47AE032}
      no imagepath value found

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{7318A03F-5C73-4FD4-BDED-B95F3A1298D8}
      no imagepath value found

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{DC36004B-E332-499D-80E7-0F72E7E124DC}
      no imagepath value found

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{E52D9A7B-600B-475B-B970-D5829B383F44}
      no imagepath value found


      --- SECURITYPROVIDERS regkey ---

      HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


      --- SVCHOST regkey ---

      HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost
      HTTPFilter: HTTPFilter\0\0
      LocalService: Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
      NetworkService: DnsCache\0\0
      netsvcs: 6to4\0AppMgmt\0AudioSrv\0Browser\0CryptSvc\0DMServer\0DHCP\0ERSvc\0EventSystem\0FastUserSwitchingCom patibility\0HidServ\0Ias\0Iprip\0Irmon\0LanmanServer\0LanmanWorkstation\0Messenger\0Netman\0Nla\0Ntm ssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0Schedule\0Seclogon\0SENS\0Sharedacc ess\0SRService\0Tapisrv\0Themes\0TrkWks\0W32Time\0WZCSVC\0Wmi\0WmdmPmSp\0winmgmt\0wscsvc\0xmlprov\0B ITS\0wuauserv\0ShellHWDetection\0helpsvc\0\0
      DcomLaunch: DcomLaunch\0TermService\0\0
      rpcss: RpcSs\0\0
      imgsvc: StiSvc\0\0
      termsvcs: TermService\0\0


      --- WOW-CMDLINE regkeys ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW
      "cmdline" = %SystemRoot%\system32\ntvdm.exe
      "wowcmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386


      --- DNS SERVER regkeys ---

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6FA806C5-0DA5-4C88-9F31-7680E47AE032}
      "NameServer"="208.67.220.220,208.67.222.222 "

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7318A03F-5C73-4FD4-BDED-B95F3A1298D8}
      "NameServer"="208.67.220.220,208.67.222.222 "

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DC36004B-E332-499D-80E7-0F72E7E124DC}
      "NameServer"="208.67.220.220,208.67.222.222 "

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
      "NameServer"="208.67.220.220,208.67.222.222"


      --- STARTUP FOLDERS ---

      C:\Documents and Settings\Patricia Dam Cotino\Menu Start\Programma's\Opstarten\desktop.ini
      C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\desktop.ini
      C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\HP Digital Imaging Monitor.lnk
      C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\Snelstart HP Image Zone.lnk


      --- TASK SCHEDULER JOBS ---

      no .job files found


      --- File associations ---

      .BAT files: ("%1" %*)
      .COM files: ("%1" %*)
      .EXE files: ("%1" %*)
      .HLP files: (%SystemRoot%\System32\winhlp32.exe %1)
      .INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
      .INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
      .JS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
      .PIF files: ("%1" %*)
      .REG files: (regedit.exe "%1")
      .SCR files: ("%1" /S)
      .TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1)
      .VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*)


      FINISHED

      Comment


      • #4
        Open een kladblokbestand.
        Kopieer onderstaande code in dit kladblokbestand.
        Ga naar Bestand - Opslaan als.
        Bij "Opslaan in" kies je: Bureaublad
        Bij "Bestandsnaam" zet je: fix.reg
        Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).
        Klik op de knop Opslaan.
        Code:
        REGEDIT4
        
        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
        "AppInit_DLLs"=-
        "AppInit_DLLs"=""
        Dubbelklik op de fix.reg file en laat de wijzigingen aan het register toevoegen.

        Download FixWareout van één van deze locaties:


        Plaatst het op de bureaublad en start het.
        Klik op "Next", daarna op "Install".
        Zorg dat "Run Fixit" aangevinkt is en klik dan op "Finish".
        Volg de aanwijzingen op het scherm.
        Als je gevraagd wordt om de computer opnieuw te starten doe je dit.
        Het zal wat langer duren voor de computer opnieuw volledig opgestart is. Dit is normaal.
        Zodra je Bureaublad geladen is, zal een tekstbestand openen (report.txt).
        Post dit samen met een nieuw HijackThislog.

        Comment


        • #5
          Username "Patricia Dam Cotino" - 09-01-2008 19:12:46 [Fixwareout edited 9/01/2007]

          ~~~~~ Prerun check
          HKLM\SOFTWARE\~\Winlogon\ "System"="kdyqg.exe"

          De DNS-omzettingscache is leeggemaakt.


          System was rebooted successfully.

          ~~~~~ Postrun check
          HKLM\SOFTWARE\~\Winlogon\ "system"=""
          ....
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}36A98AFE7D61-BECA-EAE4-2AFD-CE556217{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}024217286C67-52E9-EA64-FEDE-3A9A1A0E{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D6A2792833CE-3549-3AD4-EDFD-640553E0{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D2AE6CBDF9C6-DF1B-93D4-B12B-C26F5030{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}CE614B984B76-9E5B-C0C4-1121-E69EC5A6{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9B4E70C42FC9-DC0B-CC54-A484-D5D068BC{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}781B331CBAC8-BE58-9AF4-63D9-AC25A58C{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D6395E4A29D0-7048-9214-00BA-82026171{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}4E489D4F013B-1C4B-4674-55FB-182A8CCA{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}134A7AACD130-1888-7F54-3749-6B9433F1{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}253015B07EF4-CE4B-A0A4-3C35-C6E93A43{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0690153A3A1A-9C39-3D84-D728-AD9F2274{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}02E644FEC619-109B-F214-2992-38EEF574{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}549FA61242EB-BD98-E404-0A56-ED3DA397{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}79D166F005E6-CD08-6694-440F-EB51265C{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}4DC50CDF2729-5269-3274-1045-D499FABA{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}F55D8C1E56F8-E34B-C924-92ED-174836A6{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9D312A33B45C-B5D8-6B64-7734-2091A0EB{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}A6793883321F-B868-1BD4-3597-31899FDD{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}FBCB1FE4F677-DBFA-6874-1024-4BC07409{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}EAC3113F00BC-4BFB-9F64-EF33-095F1DF1{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0A2059222285-B83B-5D44-8930-A9F16275{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}4B7FAD0F8453-FD9A-9494-A6FF-CA618093{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}898184BAB615-A798-16C4-4FA7-6D3B62A4{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}60C9D15E9204-27F8-D994-7700-039AF1C4{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}3E48983AA263-2898-68B4-35AB-2ADF4F44{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}747A936A3A25-F498-FE34-3F09-D2F7D47B{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}DA1CB5B21FD0-BD89-3944-E9BC-4BE1A34E{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0B986AD6F74C-ECB9-2034-10AA-33105F85{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D169AF5425C4-2E1B-84F4-6C50-30FAC45C{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}4A39A3C35E84-6E5A-E544-0317-B1DE7B5A{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}99B8D3848947-04E9-2574-E616-163371C5{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}B23BA5F90C42-B119-5D44-67B4-1D438890{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D4C2C9A1A351-F088-7E64-C756-5A940CCC{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}2671ED219A12-6F48-F5F4-CACC-41EFA9F8{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9D1CD95F8EF7-C66A-5044-114A-015918BD{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}585D4FEA6EA4-DDAB-1A94-A323-B0658F58{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}EDBFCB65F810-5219-7554-AA35-937B17DC{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}F99C718F6C4F-255A-2254-0979-8736767F{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}D7C6131EC4D5-5ADB-5E04-0E3A-4641EB5E{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}AA862F3C84A5-368B-5634-1D34-67511A1F{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}821E75A82FCA-D98B-5FC4-B37E-88A0543E{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0AE4A43DE13A-33C9-2CE4-C946-1FF053BD{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}B748ADF04CAE-8399-CCF4-B7BE-89087B0F{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}EA5884CA6531-2729-9574-99CA-9982F958{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}3E5B7A973FC9-C83A-E914-4A1D-46D16541{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}64EF338B8003-7F49-DF44-4B37-897B605D{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}25F32AB889B2-E208-D924-5033-F83C8352{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}203D6F9ADD4C-7239-5744-35EE-434F22D5{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}8C7251EF7681-A638-4354-C2E2-6D446DEF{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}B60589F69DEE-BC49-EBC4-C9A3-6C5F9A4A{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}83A49FDBB167-5989-8EF4-3D1A-0E8905EB{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}2C44B0FE3E73-C32B-7614-1D55-D38A3201{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0B956352343A-1A3A-17F4-69CA-A56B7E92{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}2D13DBBB059C-3849-EE64-AF04-61F6C8A4{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}16C2756E859F-BF38-9704-CF3F-97AF8187{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0516D32F5A82-31B8-3F94-310E-5EDCCF80{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}5B9CA398AAF0-F769-A274-9D76-1D01B1BF{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}924CE46A708F-F448-7074-12D2-D125B1DA{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}491AB0E3FAD4-286B-B904-D558-C3A52563{" Deleted
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "deksc" Value deleted
          HKCR\CLSID\{EAC3C4DA-638D-4A51-913B-397B4E5B1795}\_h\4 Deleted.
          ....
          ~~~~~ Misc files.
          C:\WINDOWS\System32\kernel32.exe Deleted
          ....
          ~~~~~ Checking for older varients.
          ....

          ~~~~~ Current runs (hklm hkcu "run" Keys Only)
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
          "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
          "P17Helper"="Rundll32 P17.dll,P17Helper"
          "HP Software Update"="D:\\HP Software Update\\HPWuSchd2.exe"
          "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
          "NWEReboot"=""
          "HotKey"="C:\\WINDOWS\\Twain_32\\SlimU2\\HotKey.exe"
          "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
          "PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
          "NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""
          "NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
          "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
          ....
          Hosts file was reset, If you use a custom hosts file please replace it...
          ~~~~~ End report ~~~~~


          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:20:18, on 9-1-2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\system32\CTsvcCDA.EXE
          C:\Program Files\Eset\nod32krn.exe
          C:\WINDOWS\system32\PSIService.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\System32\snmp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Canon\CAL\CALMAIN.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\notepad.exe
          C:\WINDOWS\system32\Rundll32.exe
          D:\HP Software Update\HPWuSchd2.exe
          C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
          C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Program Files\PowerISO\PWRISOVM.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\PROGRA~1\MICROS~2\rapimgr.exe
          C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
          D:\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          D:\Digital Imaging\bin\hpqimzone.exe
          D:\Digital Imaging\bin\hpqSTE08.exe
          D:\Digital Imaging\Product Assistant\bin\hprblog.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.msn.com
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
          R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
          O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
          O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\nl\msntb.dll
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
          O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
          O4 - HKLM\..\Run: [HP Software Update] D:\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Lokale service')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Snelstart HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
          O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sterre-luna.spaces.live.com//PhotoUpload/MsnPUpld.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160813015843
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183295552062
          O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab
          O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader4.cab
          O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{6FA806C5-0DA5-4C88-9F31-7680E47AE032}: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\..\{7318A03F-5C73-4FD4-BDED-B95F3A1298D8}: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\..\{DC36004B-E332-499D-80E7-0F72E7E124DC}: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O20 - AppInit_DLLs:
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
          O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
          O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Program Files\Spyware Doctor\sdhelp.exe (file missing)
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
          O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
          O23 - Service: SPYWAREfighterRP - Unknown owner - C:\Program Files\SPYWAREfighter\spfprc.exe (file missing)

          --
          End of file - 9402 bytes

          Comment


          • #6
            Download combofix.exe: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            Plaats het op je bureaublad.
            Dubbelklik er op om het programma te starten.
            In het scherm dat verschijnt tik je een 1 in om het cleaning- en analysesproces te laten uitvoeren.
            Volg de instructies op het scherm.
            Als het tooltje klaar is, opent er een logfile (combofix.txt).
            Post de inhoud van dit bestandje samen met een nieuwe hijackthislog.

            Comment


            • #7
              De pc liep vast. Ik heb hem gewoon uitgezet. Ga het nog een keer proberen.

              Comment


              • #8
                ComboFix 08-01-09.2 - Patricia Dam Cotino 2008-01-09 20:08:32.2 - NTFSx86
                Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.185 [GMT 1:00]
                Gestart vanuit: C:\Documents and Settings\Patricia Dam Cotino\Bureaublad\ComboFix.exe
                .

                (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                .

                C:\Documents and Settings\christiaan\Application Data\HbTools
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\buttondir.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\components.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_1000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_2000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_3000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bar.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar1.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_logos.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_other.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_weather.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\default.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_511745-514279.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz1.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz10.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz11.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz12.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz13.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz14.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz15.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz16.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz17.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz18.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz19.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz2.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz20.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz3.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz4.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz5.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz6.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz7.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz8.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz9.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_categorize.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_comparison.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-Mails.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-people.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_favorites.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_Games.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hide.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_hotbarcom.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hotmail.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_hsskin.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemster.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemsterie.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemsteruk.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_jobsearch.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_Mails.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_new.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_premium.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_reun.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_ringtones.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_SearchBoxTrapper.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchfor.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchgo.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_weather.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Default_yellowpages.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-548964.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-9595.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\email-t1-bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\hbtwallpaper.exe
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium-hotbar-premium.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\hotbar_promo.htm
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\icons2.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\keywords.idx
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\keywords1.dat
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\layout.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\linkpathlegal.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\progress.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\s_icons_buttons.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\sales_buttons.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\t2_bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\theweb.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\top7.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\Top7_theweb.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\1\tsd_bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\ads.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\btntrans.idx
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\btntrans1.dat
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\business_promo.htm
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\buttondir.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\components.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_1000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_2000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_3000.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_bar.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_bbar1.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_logos.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_buttons_other.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\d_icons_weather.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\default.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_511745-514279.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz1.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz10.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz11.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz12.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz13.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz14.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz15.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz16.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz17.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz18.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz19.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz2.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz20.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz3.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz4.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz5.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz6.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz7.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz8.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_bidz9.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_categorize.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_comparison.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_explorer-Mails.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_explorer-people.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_favorites.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_Games.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_Hide.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_hotbarcom.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_Hotmail.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_hsskin.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_jemster.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_jemsterie.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_jemsteruk.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_jobsearch.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_Mails.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_new.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_premium.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_reun.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_ringtones.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_SearchBoxTrapper.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_searchfor.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_searchgo.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_weather.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Default_yellowpages.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\email-def-511724-548964.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\email-def-511724-9595.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\email-t1-bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\hbtwallpaper.exe
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\hotbar-premium-hotbar-premium.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\hotbar-premium.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\hotbar_promo.htm
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\icons2.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\keywords.idx
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\keywords1.dat
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\layout.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\linkpathlegal.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\progress.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\s_icons_buttons.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\sales_buttons.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\t2_bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\theweb.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\top7.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\Top7_theweb.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\2\tsd_bg.res
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\ads.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans1.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\business_promo.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\buttondir.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_1000.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_2000.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_3000.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_bar.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_bbar1.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_logos.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_other.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_weather.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\default.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\email-t1-bg.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\hbtwallpaper.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\hotbar-premium.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\hotbar_promo.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\icons2.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\keywords.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\keywords1.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\layout.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\linkpathlegal.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\progress.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\s_icons_buttons.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\sales_buttons.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\samplegroups2.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\samplegroups2.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\t2_bg.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\top7.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HbTools\static\DownLoad\tsd_bg.xip
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte10_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte11_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte12_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte13_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte14_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte19_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte20_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte21_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030104_emte9_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\030203lib_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102angel_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102bigluf_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102bigsmile_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102birthday_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102cheers_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102flo_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102good_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102jump_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102king_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102lough_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102luf_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102smile_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102smiled_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102sor_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102thanx_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\033102uhu_1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\040103ahh_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\040103wow_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\040104_emi2_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\042102_1134_112_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\050103big_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\050103gig_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\050103hm_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\050103nomail_emoti_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\050103norm_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema15_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema16_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema17_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema18_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema19_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema20_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema21_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema24_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema25_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema26_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema30_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema33_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\060104_ema34_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\062802hippi_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\062802jumpie_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\080402argh_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\080402oops_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\080402ouch_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\082502no_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\082502yes_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_boring1_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_confused_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_crying_ugly_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_fantastic_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_feel_better_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_gimme_break_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_heehee_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_hlopaet_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_ign_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_lol_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_no_comment_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_peace_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_smashing_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\110103_talk2thehand_prv.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\block_sm.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\block_sm2.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\block_smli.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\block_smli2.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\blocked.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\blocked2.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_add-but.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_back-but.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_left_cut_enabled_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_left_enabled_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_left_pressed_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_middle_enabled_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_middle_pressed_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_right_cut_enabled_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_right_enabled_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\btn_right_pressed_1.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\business_promo.htm
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\buttondir.txt
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\components.cdf
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\css_cattree.css
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\css_flashpreview.css
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\css2_main.css
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\css2_pagingmodule.css
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\css2_topbuttons.css
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\delete.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\edit_clear_sound.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\edit_fs.htm
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\edit_select.gif
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-543450.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-548964.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-589306.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-591943.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-592579.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-598579.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-603763.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-9595.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511724-9696.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-511745-514279.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-backgrounds.mnu
                C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-bcards.mnu

                Comment


                • #9
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-ecards.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-emoticons.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-estationery.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-funny.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-help.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-images.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-info.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-more.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-my.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-new.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-new2.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-options.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-people.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-photo.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-tell.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-temp.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-text.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def-email-voice.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-def.cdf
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-premium-email-premium.mnu
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-t1-bg.res
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\email-temp-bg.res
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\estatationery.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\flashpatch.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\flashpreview.htm
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\fs3.htm
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\hotbar_promo.htm
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_checked_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_close_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_close_pressed_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_edit_preview.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_edit_send.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_flash_preview.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_recently_used.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_remove_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_remove_pressed_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_sand-clock2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_tell_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_tell_pressed_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_tree_null.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_unchecked_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\icon_unchecked_pressed_1.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\img_barlayout.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\img_barlayout2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\img_barlayout4.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\img_corner_left.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\img_local_logo.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_basetemplate.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_hbgroups.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_hbobject3.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_hbobjectset3.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_hotbarwrapper.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_iteratorsandreaders3nf.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_pagingmoduleobj3.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_texts3.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\js2_xmltree3nf.js
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\layout.cdf
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\linkpathlegal.txt
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\n.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\nav_b_2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\nav_bb_2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\nav_f_2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\nav_ff_2.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\progress.res
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\sales_buttons.res
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\searchbtn.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\submit.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_bg.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_bga.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_bgia.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_l.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_la.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_lia.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_r.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_ra.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tab_ria.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tree_dots.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tree_minus.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\tree_plus.gif
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_animations.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_backgrounds.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_ecards.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_emoticons.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_notifiers.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\1\treedata_text.xml
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\business_promo.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\buttondir.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\code.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\email-def.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\email-t1-bg.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\email-temp-bg.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\hotbar_promo.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\images.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\layout.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\linkpathlegal.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\localcontent.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\progress.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\sales_buttons.xip
                  C:\Documents and Settings\christiaan\Application Data\HbTools\v3.0\HostOL\static\DownLoad\treexml.xip
                  C:\Documents and Settings\Teddy lover\Application Data\HbTools
                  C:\WINDOWS\system32\kr_done1

                  .
                  ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

                  .
                  -------\LEGACY_MZU_RK
                  -------\MZU_RK


                  (((((((((((((((((((( Bestanden Gemaakt van 2007-12-09 to 2008-01-09 ))))))))))))))))))))))))))))))
                  .

                  2008-01-09 19:40 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
                  2008-01-08 22:48 . 2008-01-08 22:48 <DIR> d-------- C:\Program Files\Lavasoft
                  2008-01-08 22:48 . 2008-01-08 22:48 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
                  2008-01-08 22:15 . 2008-01-08 22:23 21,216,112 --a------ C:\Program Files\aaw2007.exe
                  2008-01-08 18:50 . 2008-01-08 18:50 <DIR> d-------- C:\Program Files\Trend Micro
                  2008-01-08 18:49 . 2008-01-08 18:49 812,344 --a------ C:\HJTInstall.exe
                  2007-12-28 22:41 . 2007-12-28 22:41 <DIR> d-------- C:\Program Files\Nero
                  2007-12-26 22:57 . 2007-12-26 23:08 <DIR> d-------- C:\Program Files\WinAVI VideoConverter
                  2007-12-26 22:55 . 2007-12-26 22:55 <DIR> d-------- C:\Program Files\WinAVI Video Converter 6.3
                  2007-12-26 22:47 . 2007-12-26 22:47 <DIR> d-------- C:\Program Files\Gabest
                  2007-12-26 22:46 . 2007-12-26 22:46 734,160 --a------ C:\Program Files\VobSub_2.23.exe

                  .
                  ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-01-09 15:55 --------- d-----w C:\Documents and Settings\Patricia Dam Cotino\Application Data\AVG7
                  2008-01-08 21:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
                  2008-01-04 08:41 --------- d-----w C:\Documents and Settings\Patricia Dam Cotino\Application Data\uTorrent
                  2008-01-01 13:02 --------- d-----w C:\Documents and Settings\Patricia Dam Cotino\Application Data\ZoomBrowser EX
                  2008-01-01 12:31 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\ZoomBrowser
                  2007-12-28 21:44 --------- d-----w C:\Program Files\Common Files\Ahead
                  2007-12-28 21:41 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
                  2007-12-26 21:54 2,382 ----a-w C:\Program Files\WinAVI_Video_Converter_6_3_Incl__Crack.torrent
                  2007-12-05 17:59 --------- d-----w C:\Program Files\Google
                  2007-12-05 17:14 --------- d-----w C:\Program Files\Java
                  2007-11-21 21:42 23,405,072 ----a-w C:\Program Files\AdbeRdr811_en_US.exe
                  2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                  2007-11-10 20:24 --------- d-----w C:\Documents and Settings\Patricia Dam Cotino\Application Data\U3
                  2007-11-10 09:08 --------- d-----w C:\Documents and Settings\Patricia Dam Cotino\Application Data\Nero
                  2007-11-10 08:38 --------- d-----w C:\Program Files\PowerISO
                  2007-11-10 08:37 1,043,036 ----a-w C:\Program Files\PowerISO38.exe
                  2007-09-20 20:33 7,467,056 ----a-w C:\Program Files\spybotsd15.exe
                  2007-09-16 20:21 3,003,113 ----a-w C:\Program Files\Setup_MagicISO.exe
                  2007-09-07 07:27 4,781,349 ----a-w C:\Program Files\Timbaland - Way I Are (feat. Keri Hilson And D.O.E.) [300k-2007-Single].rar
                  2007-07-27 13:38 29,984 ----a-w C:\Documents and Settings\Patricia Dam Cotino\Application Data\GDIPFONTCACHEV1.DAT
                  2006-12-03 17:59 663,244,725 ----a-w C:\Program Files\Common Files\Ahead Nero Premium Suite 7.5.1.1.rar
                  2006-02-26 17:32 29,680 ----a-w C:\Documents and Settings\Teddy lover\Application Data\GDIPFONTCACHEV1.DAT
                  2005-05-11 21:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
                  .

                  ((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  ----a-w 102,400 2004-12-02 16:23:34 C:\Program Files\Creative\MediaSource\Detector\bak\CTDetect.exe

                  ----a-w 135,168 2004-11-30 09:00:00 C:\Program Files\Creative\MediaSource\Go\bak\CTCMSGo.exe

                  ----a-w 57,344 2005-02-15 14:10:16 C:\Program Files\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe

                  ----a-w 90,112 2000-05-10 23:00:00 C:\WINDOWS\bak\UpdReg.EXE

                  ----a-w 208,952 2006-03-02 12:00:00 C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE
                  ----a-w 208,952 2006-03-02 12:00:00 C:\WINDOWS\ime\imjp8_1\imjpmig.exe

                  ----a-w 15,360 2006-03-02 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
                  ----a-w 15,360 2006-03-02 12:00:00 C:\WINDOWS\system32\ctfmon.exe

                  ----a-w 59,392 2006-03-02 12:00:00 C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe
                  ----a-w 59,392 2006-03-02 12:00:00 C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe

                  ----a-w 455,168 2006-03-02 12:00:00 C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE
                  ----a-w 455,168 2006-03-02 12:00:00 C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe

                  .
                  ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
                  "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
                  "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 20:50 1204224]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2006-03-02 13:00 208952]
                  "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-02 13:00 59392]
                  "P17Helper"="P17.dll" [2005-05-03 12:38 64512 C:\WINDOWS\system32\P17.dll]
                  "HP Software Update"="D:\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
                  "AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-20 18:03 579072]
                  "NWEReboot"=""
                  "HotKey"="C:\WINDOWS\Twain_32\SlimU2\HotKey.exe" [2002-08-07 10:38 618496]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                  "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05 200704]
                  "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
                  "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 13:00 15360]
                  "Spyware Doctor"=""
                  "AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 17:50 219136]

                  C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
                  HP Digital Imaging Monitor.lnk - D:\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26]
                  Snelstart HP Image Zone.lnk - D:\Digital Imaging\bin\hpqthb08.exe [2005-05-11 23:49:24]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                  "AppInit_DLLs"=

                  S3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys
                  S3 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe"

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
                  \Shell\AutoRun\command - L:\LaunchU3.exe -a

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ecb45ea-7186-11db-9433-0020edbaa6e6}]
                  \Shell\AutoRun\command - L:\LaunchU3.exe -a

                  .
                  **************************************************************************

                  catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-01-09 20:19:21
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scannen van verborgen processen ...

                  scannen van verborgen autostart items ...

                  scannen van verborgen bestanden ...

                  Scan succesvol afgerond
                  verborgen bestanden: 0

                  **************************************************************************
                  .
                  Voltooingstijd: 2008-01-09 20:26:06 - machine was rebooted [Patricia Dam Cotino]
                  ComboFix-quarantined-files.txt 2008-01-09 19:26:02
                  .
                  2008-01-09 16:47:32 --- E O F ---

                  Comment


                  • #10
                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 20:37:37, on 9-1-2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\WINDOWS\system32\CTsvcCDA.EXE
                    C:\Program Files\Eset\nod32krn.exe
                    C:\WINDOWS\system32\PSIService.exe
                    C:\WINDOWS\System32\snmp.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Canon\CAL\CALMAIN.exe
                    C:\WINDOWS\system32\Rundll32.exe
                    D:\HP Software Update\HPWuSchd2.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                    C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\Program Files\PowerISO\PWRISOVM.EXE
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                    C:\PROGRA~1\MICROS~2\rapimgr.exe
                    D:\Digital Imaging\bin\hpqtra08.exe
                    D:\Digital Imaging\bin\hpqSTE08.exe
                    D:\Digital Imaging\Product Assistant\bin\hprblog.exe
                    D:\Digital Imaging\bin\hpqimzone.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.msn.com
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\nl\msntb.dll
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
                    O4 - HKLM\..\Run: [HP Software Update] D:\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                    O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\SlimU2\HotKey.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Lokale service')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
                    O4 - Global Startup: Snelstart HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
                    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
                    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
                    O9 - Extra 'Tools' menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sterre-luna.spaces.live.com//PhotoUpload/MsnPUpld.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160813015843
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183295552062
                    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab
                    O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader4.cab
                    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{6FA806C5-0DA5-4C88-9F31-7680E47AE032}: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{7318A03F-5C73-4FD4-BDED-B95F3A1298D8}: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{DC36004B-E332-499D-80E7-0F72E7E124DC}: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
                    O20 - AppInit_DLLs:
                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
                    O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Program Files\Spyware Doctor\sdhelp.exe (file missing)
                    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
                    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                    O23 - Service: SPYWAREfighterRP - Unknown owner - C:\Program Files\SPYWAREfighter\spfprc.exe (file missing)

                    --
                    End of file - 9304 bytes

                    Comment


                    • #11
                      Download FindAWF: http://noahdfear.geekstogo.com/FindAWF.exe
                      Selecteer optie 1 - Scan for bak folders by typing 1
                      En druk op Enter.
                      Wanneer het tooltje klaar is post je de inhoud van de logfile die opent.

                      Comment


                      • #12
                        Find AWF report by noahdfear ©2006
                        Version 1.40



                        bak folders found
                        ~~~~~~~~~~~

                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\WINDOWS\BAK

                        11-05-2000 00:00 90.112 UpdReg.EXE
                        1 bestand(en) 90.112 bytes
                        2 map(pen) 2.665.328.640 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\WINDOWS\SYSTEM32\BAK

                        02-03-2006 13:00 15.360 ctfmon.exe
                        1 bestand(en) 15.360 bytes
                        2 map(pen) 2.665.328.640 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\WINDOWS\IME\IMJP8_1\BAK

                        02-03-2006 13:00 208.952 IMJPMIG.EXE
                        1 bestand(en) 208.952 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\PROGRA~1\CREATIVE\MEDIAS~1\DETECTOR\BAK

                        02-12-2004 17:23 102.400 CTDetect.exe
                        1 bestand(en) 102.400 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\PROGRA~1\CREATIVE\MEDIAS~1\GO\BAK

                        30-11-2004 10:00 135.168 CTCMSGo.exe
                        1 bestand(en) 135.168 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\PROGRA~1\CREATIVE\SBAUDIGY\SURROU~1\BAK

                        15-02-2005 15:10 57.344 CTSysVol.exe
                        1 bestand(en) 57.344 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\WINDOWS\SYSTEM32\IME\PINTLGNT\BAK

                        02-03-2006 13:00 59.392 ImScInst.exe
                        1 bestand(en) 59.392 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar
                        Het volume in station C heeft geen naam.
                        Het volumenummer is 0CE2-8358

                        Map van C:\WINDOWS\SYSTEM32\IME\TINTLGNT\BAK

                        02-03-2006 13:00 455.168 TINTSETP.EXE
                        1 bestand(en) 455.168 bytes
                        2 map(pen) 2.665.324.544 bytes beschikbaar


                        Duplicate files of bak directory contents
                        ~~~~~~~~~~~~~~~~~~~~~~~

                        90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE"
                        15360 Mar 2 2006 "C:\WINDOWS\system32\ctfmon.exe"
                        15360 Mar 2 2006 "C:\WINDOWS\system32\bak\ctfmon.exe"
                        208952 Mar 2 2006 "C:\WINDOWS\ime\imjp8_1\imjpmig.exe"
                        208952 Mar 2 2006 "C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE"
                        102400 Dec 2 2004 "C:\Program Files\Creative\MediaSource\Detector\bak\CTDetect.exe"
                        135168 Nov 30 2004 "C:\Program Files\Creative\MediaSource\Go\bak\CTCMSGo.exe"
                        57344 Feb 15 2005 "C:\Program Files\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe"
                        59392 Mar 2 2006 "C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe"
                        59392 Mar 2 2006 "C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe"
                        455168 Mar 2 2006 "C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe"
                        455168 Mar 2 2006 "C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE"


                        end of report

                        Comment


                        • #13
                          Dubbelklik op FindAWF.exe selecteer nu optie 2: Restore files from bak folders e
                          en druk dan op Enter.
                          Er opent een kladblokbestand.
                          Kopieer onderstaande code in dit kladblokbestand:
                          Code:
                          "C:\WINDOWS\bak\UpdReg.EXE"
                          "C:\WINDOWS\system32\ctfmon.exe"
                          "C:\WINDOWS\system32\bak\ctfmon.exe"
                          "C:\WINDOWS\ime\imjp8_1\imjpmig.exe"
                          "C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE"
                          "C:\Program Files\Creative\MediaSource\Detector\bak\CTDetect.exe"
                          "C:\Program Files\Creative\MediaSource\Go\bak\CTCMSGo.exe"
                          "C:\Program Files\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe"
                          Sluit het bestandje en wanneer gevraagd wordt om het bestand op te slaan, sta je dit toe.
                          Wanneer de tool klaar is opent er een logfile (awf.txt).
                          Post de inhoud van de logfile.
                          Last edited by Marckie; 10-01-08, 19:53.

                          Comment


                          • #14
                            Find AWF report by noahdfear ©2006
                            Version 1.40
                            Option 2 run successfully



                            bak folders found
                            ~~~~~~~~~~~

                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\WINDOWS\BAK

                            11-05-2000 00:00 90.112 UpdReg.EXE
                            1 bestand(en) 90.112 bytes
                            2 map(pen) 2.618.867.712 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\WINDOWS\SYSTEM32\BAK

                            02-03-2006 13:00 15.360 ctfmon.exe
                            1 bestand(en) 15.360 bytes
                            2 map(pen) 2.618.867.712 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\WINDOWS\IME\IMJP8_1\BAK

                            02-03-2006 13:00 208.952 IMJPMIG.EXE
                            1 bestand(en) 208.952 bytes
                            2 map(pen) 2.618.863.616 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\PROGRA~1\CREATIVE\MEDIAS~1\DETECTOR\BAK

                            02-12-2004 17:23 102.400 CTDetect.exe
                            1 bestand(en) 102.400 bytes
                            2 map(pen) 2.618.908.672 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\PROGRA~1\CREATIVE\MEDIAS~1\GO\BAK

                            30-11-2004 10:00 135.168 CTCMSGo.exe
                            1 bestand(en) 135.168 bytes
                            2 map(pen) 2.618.908.672 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\PROGRA~1\CREATIVE\SBAUDIGY\SURROU~1\BAK

                            15-02-2005 15:10 57.344 CTSysVol.exe
                            1 bestand(en) 57.344 bytes
                            2 map(pen) 2.618.908.672 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\WINDOWS\SYSTEM32\IME\PINTLGNT\BAK

                            02-03-2006 13:00 59.392 ImScInst.exe
                            1 bestand(en) 59.392 bytes
                            2 map(pen) 2.618.908.672 bytes beschikbaar
                            Het volume in station C heeft geen naam.
                            Het volumenummer is 0CE2-8358

                            Map van C:\WINDOWS\SYSTEM32\IME\TINTLGNT\BAK

                            02-03-2006 13:00 455.168 TINTSETP.EXE
                            1 bestand(en) 455.168 bytes
                            2 map(pen) 2.618.908.672 bytes beschikbaar


                            Duplicate files of bak directory contents
                            ~~~~~~~~~~~~~~~~~~~~~~~

                            90112 May 11 2000 "C:\WINDOWS\UpdReg.EXE"
                            90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE"
                            15360 Mar 2 2006 "C:\WINDOWS\system32\ctfmon.exe"
                            15360 Mar 2 2006 "C:\WINDOWS\system32\bak\ctfmon.exe"
                            208952 Mar 2 2006 "C:\WINDOWS\ime\imjp8_1\IMJPMIG.EXE"
                            208952 Mar 2 2006 "C:\WINDOWS\ime\imjp8_1\bak\IMJPMIG.EXE"
                            102400 Dec 2 2004 "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe"
                            102400 Dec 2 2004 "C:\Program Files\Creative\MediaSource\Detector\bak\CTDetect.exe"
                            135168 Nov 30 2004 "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe"
                            135168 Nov 30 2004 "C:\Program Files\Creative\MediaSource\Go\bak\CTCMSGo.exe"
                            57344 Feb 15 2005 "C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe"
                            57344 Feb 15 2005 "C:\Program Files\Creative\SBAudigy\Surround Mixer\bak\CTSysVol.exe"
                            59392 Mar 2 2006 "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe"
                            59392 Mar 2 2006 "C:\WINDOWS\system32\IME\PINTLGNT\bak\ImScInst.exe"
                            455168 Mar 2 2006 "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE"
                            455168 Mar 2 2006 "C:\WINDOWS\system32\IME\TINTLGNT\bak\TINTSETP.EXE"


                            end of report

                            Comment


                            • #15
                              Verwijder AWF.txt
                              En herhaal de instructies in post 13.
                              Ik heb die post even aangepast.

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X