Spring naar inhoud

Guest's Foto
Welkom,
Guest
Wenst u zich te registreren?


Foto
- - - - -

text enhance verwijderen


  • Dit onderwerp is gesloten Dit onderwerp is gesloten
21 reacties op dit onderwerp

#1 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 07 mei 2012 - 18:51


Beste,

Ook ik heb last van text enhance sinds enige tijd. Op nagenoeg elke pagina kom ik het wel weer tegen.
Zelf heb ik al alles geprobeerd was ik kan bedenken om dit probleem op te lossen.
Krijg het echter niet weg.

hoop dat jullie me verder kunnen helpen.

Het vast wat voorwerk gedaan door een hijackthis scan te doen.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:16, on 7-5-2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Microsoft\BingBar\BBSvc.EXE
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MyStart by IncrediBar.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Your Home Page Has Been Changed
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....19&affID=19405
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
R3 - URLSearchHook: (no name) - {3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: ADDICT-THING - {9024DD4E-5BBF-4612-B2DF-256B5E594B33} - C:\Documents and Settings\All Users\Application Data\ADDICT-THING\bhoclass.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.mark...geUploader5.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.neffi...ffyLauncher.cab
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprint...PSUploader4.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Google Updateservice (gupdate1ca0ddb241ef2ef) (gupdate1ca0ddb241ef2ef) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 11963 bytes

#2 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 07 mei 2012 - 21:45

Ga in Firefox -> Extra -> AddOns -> Plugins -> en verwijder daar alle onbekende plugins. Mocht je twijfelen mag je ALLE plugins daar verwijderen.

[FONT=&]Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:[/FONT]

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MyStart by IncrediBar.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Your Home Page Has Been Changed
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo...b81f39000000000 000001d6060f95b&tlver=1.4.19.19&affID=19405
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
R3 - URLSearchHook: (no name) - {3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} - (no file)
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
[FONT=&]O2 - BHO: ADDICT-THING - {9024DD4E-5BBF-4612-B2DF-256B5E594B33} - C:\Documents and Settings\All Users\Application Data\ADDICT-THING\bhoclass.dll[/FONT]
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
[FONT=&]
Klik op 'Fix checked' om de items te verwijderen.[/FONT]

[FONT=&]Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.[/FONT]
[FONT=&]
Download [/FONT][FONT=&]MBAM (Malwarebytes Anti-Malware)[/FONT][FONT=&]

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".
Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.
Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.
Het scannen kan een tijdje duren, dus wees geduldig.
Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.
Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.
Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.
MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.


Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht[/FONT][FONT=&], samen met een nieuw HijackThis log.[/FONT]

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#3 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 08 mei 2012 - 16:33

Heb alle AddOns uitgeschakeld. Het probleem zelf was daarna verholpen. Kreeg wel een nieuw probleem: de youtubefilmpjes wilden niet meer laden. Heb dit inmiddels opgelost door een aantal AddOns weer aan te zetten. Hoe moet ik de AddOns volledig verwijderen? Ik heb ze nu enkel uitgeschakeld.

Malware log:

Malwarebytes Anti-Malware 1.61.0.1400
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Databaseversie: v2012.05.08.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Kinderen :: R01 [administrator]

8-5-2012 15:09:44
mbam-log-2012-05-08 (15-09-44).txt

Scantype: Snelle scan
Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scanopties: P2P
Objecten gescand: 367643
Verstreken tijd: 1 uur/uren, 58 minuut/minuten, 52 seconde(n)

Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 2
C:\Documents and Settings\Kinderen\Mijn documenten\Downloads\DownloadSetup.exe (Affiliate.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Documents and Settings\Kinderen\Mijn documenten\Downloads\SoftonicDownloader_voor_virtual-dj.exe (PUP.ToolbarDownloader) -> Succesvol in quarantaine geplaatst en verwijderd.

(einde)

Nieuwe HiJackThis scan:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:33:11, on 8-5-2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Your Home Page Has Been Changed
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.mark...geUploader5.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.neffi...ffyLauncher.cab
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprint...PSUploader4.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Google Updateservice (gupdate1ca0ddb241ef2ef) (gupdate1ca0ddb241ef2ef) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 10124 bytes


Is het misschien mogelijk het aantal running processes te verlagen om zo mijn pc sneller te maken?

Bewerkt door jdvanroest, 08 mei 2012 - 16:37.


#4 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 08 mei 2012 - 16:57

Je hebt blijkbaar de AddOns aangepakt ... kon je door enkel verwijderen van onbekende Plugins niet hetzelfde bereiken ? Want dat was eigenlijk de bedoeling.

[FONT=&]Download Codestuff Starter[/FONT]

[FONT=&]Start Codestuff Starter op[/FONT]
[FONT=&]Selecteer het tabblad Automatisch Opstarten en vink volgende items uit. Deze programma’s worden onnodig mee opgestart.[/FONT]

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" –atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[FONT=&]Deze start MSN bij iedere systeemstart mee op. Persoonlijk zou ik deze uitschakelen in MSN zelf (bij Extra -> Opties -> tabblad Algemeen vinkjes weghalen onder "Aanmelden")[/FONT]

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

[FONT=&]Om deze uit te schakelen start je de Windows Messenger (Niet de MSN of Windows Live Messenger) op, ga naar Extra -> Opties -> tabblad Voorkeuren en haal de vinkjes weg bij de vier vakjes onder Algemeen[/FONT]

Bewerkt door kape, 08 mei 2012 - 17:08.

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#5 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 08 mei 2012 - 17:35

Je hebt blijkbaar de AddOns aangepakt ... kon je door enkel verwijderen van onbekende Plugins niet hetzelfde bereiken ? Want dat was eigenlijk de bedoeling.


Ik heb alle addOns uitgeschakeld. Heb er geen 1 verwijderd omdat ik niet kon vinden hoe dat moest.
Heb vervolgens even op google gezocht naar het handmatig verwijderen van die add ons.
dit was het resultaat en heb ik uitgevoerd:
Problemen met plug-ins oplossen | Probleemoplossing | Firefox Help
misschien is dat de reden dat alles verwijderd is?

bij extra-> addOns -> Plug-ins staan de volgende ingeschakeld:
Adobe acrobat 9.5.1.283
Google Earth Plugin 6.1.0.5001
Google update 1.3.21.111
Shockwave Flash 11.1.102.55
Silverlight Plug-In 5.0.61118.0
Unity Player 2.6.1.31223

uitgeschakeld staan:
3DVIA player 5.0.0.12
DNA Plug-in 1.0.0.1
EA Battlefield Heroes 5.0.134.0 (deze weet ik zeker dat hij verwijderd kan worden)
Jave Deployment Toolkiet 6.0.310.5
Java ™ Platform SE 6 U31 6.0.310.5
Microsoft Office Live Plug-in for Firefox 2.0.2313.0
Microsoft® Windows Media Player Firefox Plugin 1.0.0.8
Pando Web Plugin 1.0.0.1
Quicktime Plug-in 6.0 6.0.0.75
Shockwave for Director 11.5.6.606
SOE Web Installer 1.0.3.151
Windows Live® Photo Gallery 14.0.8117.416
Windows Presentation Foundation 3.5.30729.1

dacht nog redelijk verstand van computers te hebben maar dat blijkt wat tegen te vallen :o

De verdere aangegeven stappen zijn zojuist uitgevoerd.



nadat ik de computer nogmaals heb opgestart merk ik dat het probleem zich weer voordoet.
Ook wel: de text enhance was weer terug.
na de plugins aan en uit gezet te hebben is het probleem (waarschijnlijk tot de volgende keer herstarten) opgelost

Bewerkt door jdvanroest, 08 mei 2012 - 20:07.


#6 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 09 mei 2012 - 05:10

Download ComboFix van één van deze locaties:

Link 1
Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:
Klik hier

Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap.

2. Dubbelklik op ComboFix.exe en volg de meldingen op het scherm.
3. ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.

**Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware.

4. Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.

Geplaatste Afbeelding

Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:
[FONT="]
Geplaatste Afbeelding

Klik op Ja om verder te gaan met het scannen naar malware.

5. Wanneer ComboFix klaar is, zal het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

[/FONT]

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#7 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 09 mei 2012 - 17:16

ComboFix 12-05-09.01 - Kinderen 09-05-2012 17:38:37.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1023.315 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Kinderen\Mijn documenten\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Kinderen\Application Data\facemoods.com
c:\documents and settings\Kinderen\Bureaublad\Internet Explorer.lnk
c:\documents and settings\Kinderen\Onlangs geopend\Thumbs.db
C:\Thumbs.db
c:\windows\EventSystem.log
c:\windows\system32\asycfilt.dll.tmp
c:\windows\system32\OLD20.tmp
c:\windows\system32\PowerToyReadme.htm
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-04-09 to 2012-05-09 ))))))))))))))))))))))))))))))
.
.
2012-05-09 15:22 . 2012-05-09 15:22 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\offreg.dll
2012-05-09 13:29 . 2012-05-09 13:29 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\MpKsl3eb90a35.sys
2012-05-09 13:03 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\mpengine.dll
2012-05-08 16:38 . 2012-05-08 16:38 -------- d-----w- c:\program files\CodeStuff
2012-05-08 13:08 . 2012-05-08 13:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-08 13:08 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-08 12:11 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-02 13:33 . 2012-05-04 06:02 -------- d-----w- c:\program files\Optimizer Pro
2012-05-02 13:32 . 2012-05-08 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ADDICT-THING
2012-05-02 12:14 . 2012-05-02 12:29 -------- d-----w- c:\program files\Maxis
2012-05-01 06:54 . 2012-05-01 06:54 -------- d-----w- C:\found.003
2012-04-27 17:11 . 2012-04-27 17:11 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Malwarebytes
2012-04-27 17:10 . 2012-04-27 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-04-27 15:58 . 2012-04-27 15:58 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG2012
2012-04-27 15:48 . 2012-04-27 15:48 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG Secure Search
2012-04-27 15:42 . 2012-04-27 15:42 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2012-04-27 15:42 . 2012-04-28 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2012-04-26 17:57 . 2012-04-26 17:57 388096 ----a-r- c:\documents and settings\Kinderen\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-04-26 17:57 . 2012-04-26 17:57 -------- d-----w- c:\program files\Trend Micro
2012-04-25 16:52 . 2012-04-25 16:52 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 16:52 . 2012-04-25 16:52 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-25 16:52 . 2012-04-25 16:52 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-25 13:26 . 2012-04-25 13:26 -------- d-----w- c:\program files\Common Files\Skype
2012-04-24 16:42 . 2012-04-24 16:42 -------- d-----w- c:\program files\Video Codec
2012-04-24 16:32 . 2012-04-24 16:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Premium
2012-04-24 16:31 . 2012-04-24 16:42 684 ----a-w- C:\user.js
2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon
2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Babylon
2012-04-24 16:31 . 2012-04-27 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Bcool
2012-04-24 16:30 . 2012-05-02 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate
2012-04-22 06:10 . 2012-04-22 06:10 -------- d-----w- c:\documents and settings\Kinderen\Application Data\LolClient
2012-04-21 19:11 . 2012-04-21 19:11 -------- d-----w- C:\Riot Games
2012-04-20 19:09 . 2012-04-20 19:09 -------- d-----w- C:\found.002
2012-04-12 05:16 . 2012-04-12 05:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2012-04-11 10:04 . 2012-04-11 10:04 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2012-04-09 20:17 . 2012-05-08 16:42 1409 ----a-w- c:\windows\QTFont.for
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-17 15:39 . 2010-03-14 11:26 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-04-03 18:19 . 2012-04-03 18:20 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-03 18:19 . 2011-07-22 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-20 18:44 . 2009-12-02 13:23 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-01 14:43 . 2012-03-01 14:42 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-03-01 11:00 . 2004-09-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:00 . 2004-09-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:00 . 2004-09-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 20:30 . 2010-03-14 11:26 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-02-29 20:17 . 2012-02-29 20:17 138056 ----a-w- c:\documents and settings\Kinderen\Application Data\PnkBstrK.sys
2012-02-29 14:10 . 2004-09-02 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2004-09-02 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-09-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-16 20:52 . 2012-02-07 20:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 09:01 . 2012-04-09 09:25 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 09:01 . 2012-04-09 09:25 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-04-25 16:52 . 2012-02-07 20:09 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
[-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SkyTel"="SkyTel.EXE" [2009-03-17 2879488]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
.
c:\documents and settings\Kinderen\Menu Start\Programma's\Opstarten\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-3-17 303104]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\I:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56388:TCP"= 56388:TCP:Pando Media Booster
"56388:UDP"= 56388:UDP:Pando Media Booster
.
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;c:\windows\system32\drivers\hcw88aud.sys [17-3-2009 21:57 12928]
R1 MpKsl3eb90a35;MpKsl3eb90a35;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\MpKsl3eb90a35.sys [9-5-2012 15:29 29904]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 18:21 249648]
R2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [17-3-2009 22:00 434176]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys [17-3-2009 21:57 182400]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys [17-3-2009 21:57 320256]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [17-3-2009 21:57 74624]
R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [17-3-2009 21:57 394880]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [17-3-2009 21:57 17280]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 16:23 196176]
S2 gupdate1ca0ddb241ef2ef;Google Updateservice (gupdate1ca0ddb241ef2ef);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 8:50 158856]
S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:25 24448]
S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25-4-2012 18:52 129976]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - MPKSL3EB90A35
.
Inhoud van de 'Gedeelde Taken' map
.
2012-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23]
.
2012-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23]
.
2012-05-09 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03]
.
.
------- Bijkomende Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\Kinderen\Application Data\Mozilla\Firefox\Profiles\0g756rsy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.startpagina.nl/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111252
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.BabylonToolbar_i.hardId - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15454
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1718:31
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyzRaMCX2&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.incredibar_i.instlDay - 15454
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1418:42
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6OyzRaMCX2
FF - user.js: extensions.incredibar_i.upn2n - 92261296176075556
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10595
FF - user.js: extensions.incredibar_i.ppd -
.
- - - - ORPHANS VERWIJDERD - - - -
.
WebBrowser-{3AD798D0-4642-4C55-BC14-CFE7DD19E0D1} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
AddRemove-Free Studio_is1 - c:\kinderen bestanden\Free Studio\unins000.exe
AddRemove-PunkBusterSvc - c:\program files\EA Games\Battlefield Heroes\pbsvc_heroes.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-05-09 18:05
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-1770027372-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C4684E37-EFF7-CB9C-94C3-06BB7F8AD9EA}*]
"hahhphpbcigacdml"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61,
70,6b,00,ff
"iajhnihobokimciimd"=hex:63,61,6f,62,6f,70,00,7c
"iangnhnhodclokigco"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61,
70,6b,00,ff
"dbpbddiedeakjooomdajkjkdmhbhgogjacffnkac"=hex:68,61,63,66,6f,67,6b,68,62,65,
6e,70,6d,67,6a,66,00,00
"jbpbddiedeakjooomdajjggcjcdpijjdgkcaldonlgeaajmnfoel"=hex:68,61,63,66,6f,67,
6b,68,62,65,6e,70,6d,67,6a,66,00,00
"dbpbddiedeakjooomdajhgjdgmghloofnnlicolf"=hex:62,61,68,62,00,00
.
Voltooingstijd: 2012-05-09 18:10:00
ComboFix-quarantined-files.txt 2012-05-09 16:09
.
Pre-Run: 80.180.736.000 bytes beschikbaar
Post-Run: 86.134.370.304 bytes beschikbaar
.
WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 6DDD4AFE7FC078AE9CF070795C4AD1DB



de text enhance komt elke keer als de pc opnieuw opgestart wordt weer terug. Weet niet of dat hierdoor opgelost zal zijn.
De plug-ins heb ik enkel uitgeschakeld en niet verwijderd. Als ik de plugins allemaal uitschakel en vervolgens weer inschakel is de text enhance totdat ik de pc opnieuw opstart wel verdwenen.

#8 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 09 mei 2012 - 20:02

[FONT=&]Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.[/FONT]

File::
C:\user.js

Folder::
c:\program files\Optimizer Pro
C:\found.003
c:\documents and settings\All Users\Application Data\Premium
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon
c:\documents and settings\All Users\Application Data\Babylon
c:\documents and settings\Kinderen\Application Data\Babylon
C:\found.002
C:\found.001

Firefox::
FF - ProfilePath - c:\documents and settings\Kinderen\Application Data\Mozilla\Firefox\Profiles\0g756rsy.default\
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111252
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.BabylonToolbar_i.hardId - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15454
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1718:31
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyzRaMCX2&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 68b81f39000000000000001d6060f95b
FF - user.js: extensions.incredibar_i.instlDay - 15454
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1418:42
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id –
FF - user.js: extensions.incredibar_i.upn2 - 6OyzRaMCX2
FF - user.js: extensions.incredibar_i.upn2n - 92261296176075556
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10595
FF - user.js: extensions.incredibar_i.ppd –


[FONT=&]Sla dit bestand op je bureaublad op als CFScript.[/FONT]

[FONT=&]Sleep CFScript.txt in ComboFix.exe[/FONT]
[FONT=&]Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.[/FONT]

[FONT=&]Post na herstart de inhoud van de Combofix.txt in je volgende bericht[/FONT][FONT=&].[/FONT]

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#9 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 10 mei 2012 - 15:42

ComboFix 12-05-10.02 - Kinderen 10-05-2012 16:16:27.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1023.505 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Kinderen\Mijn documenten\Downloads\ComboFix.exe
gebruikte Opdracht switches :: c:\kinderen bestanden\jarco\vrijetijd\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"C:\user.js"
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Babylon
c:\documents and settings\All Users\Application Data\Premium
c:\documents and settings\Kinderen\Application Data\Babylon
c:\documents and settings\Kinderen\Application Data\Babylon\log_file.txt
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\bab033.tbinst.dat
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\bab091.norecovericon.dat
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Babylon.dat
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\BExternal.dll
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\blueStar.png
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\eula.html
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\globe.png
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\options.js
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page0.html
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2.css
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2.html
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2Lrg.css
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3.css
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3.html
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3Lrg.css
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\pBar.gif
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\progress.png
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\setup.js
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\title.png
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\toolBar.jpg
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\IECookieLow.dll
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Setup-tbmntr903.zpb
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Setup.exe
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\SetupStrings.dat
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\sign
c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\sqlite3.dll
C:\found.001
c:\found.001\dir0000.chk\resume.dat.old
c:\found.001\dir0000.chk\rss.dat.old
C:\found.002
c:\found.002\dir0000.chk\Age of Empires II\00000409.016
c:\found.002\dir0000.chk\Age of Empires II\00000409.256
c:\found.002\dir0000.chk\Age of Empires II\AI\AI.txt
c:\found.002\dir0000.chk\Age of Empires II\AVI\AGE2.AVI
c:\found.002\dir0000.chk\Age of Empires II\AVI\AVI.TXT
c:\found.002\dir0000.chk\Age of Empires II\AVI\ESLOGO.AVI
c:\found.002\dir0000.chk\Age of Empires II\AVI\MSLOGO.AVI
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam1.cpn
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam2.cpn
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam3.cpn
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam4.cpn
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam8.cpn
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_BEG.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_BEG.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_END.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_END.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM1.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM2.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM3.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM4.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM8.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.BLN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.MM
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.PAL
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.SIN
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.SLP
c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTROBKG.SLP
c:\found.002\dir0000.chk\Age of Empires II\clcd16.dll
c:\found.002\dir0000.chk\Age of Empires II\clcd32.dll
c:\found.002\dir0000.chk\Age of Empires II\clokspl.exe
c:\found.002\dir0000.chk\Age of Empires II\DATA\blendomatic.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\BlkEdge.Dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\closedpw.exe
c:\found.002\dir0000.chk\Age of Empires II\DATA\EMPIRES2.DAT
c:\found.002\dir0000.chk\Age of Empires II\DATA\FilterMaps.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\gamedata.drs
c:\found.002\dir0000.chk\Age of Empires II\DATA\graphics.drs
c:\found.002\dir0000.chk\Age of Empires II\DATA\interfac.drs
c:\found.002\dir0000.chk\Age of Empires II\DATA\lightMaps.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\list.cr
c:\found.002\dir0000.chk\Age of Empires II\DATA\Load\Load.txt
c:\found.002\dir0000.chk\Age of Empires II\DATA\LoQMaps.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\PatternMasks.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\shadow.col
c:\found.002\dir0000.chk\Age of Empires II\DATA\sounds.drs
c:\found.002\dir0000.chk\Age of Empires II\DATA\STemplet.dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\terrain.drs
c:\found.002\dir0000.chk\Age of Empires II\DATA\TileEdge.Dat
c:\found.002\dir0000.chk\Age of Empires II\DATA\view_icm.dat
c:\found.002\dir0000.chk\Age of Empires II\DPLAY61A.EXE
c:\found.002\dir0000.chk\Age of Empires II\dplayerx.dll
c:\found.002\dir0000.chk\Age of Empires II\drvmgt.dll
c:\found.002\dir0000.chk\Age of Empires II\EBUEula.dll
c:\found.002\dir0000.chk\Age of Empires II\EMPIRES2.EXE
c:\found.002\dir0000.chk\Age of Empires II\EMPIRES2.ICD
c:\found.002\dir0000.chk\Age of Empires II\EULA.RTF
c:\found.002\dir0000.chk\Age of Empires II\HA312W32.DLL
c:\found.002\dir0000.chk\Age of Empires II\History\Armies.txt
c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesMongols.txt
c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesOrg.txt
c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesStrat.txt
c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesTactics.txt
c:\found.002\dir0000.chk\Age of Empires II\History\barbarianinvaders.txt
c:\found.002\dir0000.chk\Age of Empires II\History\British original.txt
c:\found.002\dir0000.chk\Age of Empires II\History\british regular.txt
c:\found.002\dir0000.chk\Age of Empires II\History\british test.txt
c:\found.002\dir0000.chk\Age of Empires II\History\british.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Byzantines.txt
c:\found.002\dir0000.chk\Age of Empires II\History\CastleDefenses.txt
c:\found.002\dir0000.chk\Age of Empires II\History\CastleEvolution.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Castles.txt
c:\found.002\dir0000.chk\Age of Empires II\History\CastleSiege.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Celts.txt
c:\found.002\dir0000.chk\Age of Empires II\History\charlemagne.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Chinese.txt
c:\found.002\dir0000.chk\Age of Empires II\History\darkagereligion.txt
c:\found.002\dir0000.chk\Age of Empires II\History\darkages.txt
c:\found.002\dir0000.chk\Age of Empires II\History\DarkArmies.txt
c:\found.002\dir0000.chk\Age of Empires II\History\economy.txt
c:\found.002\dir0000.chk\Age of Empires II\History\feudalcontract.txt
c:\found.002\dir0000.chk\Age of Empires II\History\feudalism.txt
c:\found.002\dir0000.chk\Age of Empires II\History\feudalismdecline.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Franks.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Goths.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Gunpowder.txt
c:\found.002\dir0000.chk\Age of Empires II\History\history.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Japanese.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Knights.txt
c:\found.002\dir0000.chk\Age of Empires II\History\latemiddleages.txt
c:\found.002\dir0000.chk\Age of Empires II\History\middleages.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Mongols.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Naval.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Persians.txt
c:\found.002\dir0000.chk\Age of Empires II\History\politics.txt
c:\found.002\dir0000.chk\Age of Empires II\History\religion.txt
c:\found.002\dir0000.chk\Age of Empires II\History\renaissance.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Saracens.txt
c:\found.002\dir0000.chk\Age of Empires II\History\technology.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Teutons.txt
c:\found.002\dir0000.chk\Age of Empires II\History\thecrusades.txt
c:\found.002\dir0000.chk\Age of Empires II\History\thefallofrome.txt
c:\found.002\dir0000.chk\Age of Empires II\History\themanor.txt
c:\found.002\dir0000.chk\Age of Empires II\History\thevikings.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Turks.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Vikings.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Warfare.txt
c:\found.002\dir0000.chk\Age of Empires II\History\Weapons.txt
c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsCav.txt
c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsHand.txt
c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsMissile.txt
c:\found.002\dir0000.chk\Age of Empires II\LANGUAGE.DLL
c:\found.002\dir0000.chk\Age of Empires II\Learn\Default.uh
c:\found.002\dir0000.chk\Age of Empires II\Learn\GanGstaNL.uh
c:\found.002\dir0000.chk\Age of Empires II\Learn\kingjarco.uh
c:\found.002\dir0000.chk\Age of Empires II\Learn\Learn.txt
c:\found.002\dir0000.chk\Age of Empires II\mcp.dll
c:\found.002\dir0000.chk\Age of Empires II\player.nfo
c:\found.002\dir0000.chk\Age of Empires II\Readme.rtf
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco III.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco IIII.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco1.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarcoII.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan 3 opgeslagen door thera!;)!hipperdehipperdehoihoihoi!!!hoeraaaaajjaaajjaa.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan 3.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan2!!.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan2.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan4.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan5.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan6.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johannes.gam
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\Multi\Multi.txt
c:\found.002\dir0000.chk\Age of Empires II\SaveGame\SaveGame.txt
c:\found.002\dir0000.chk\Age of Empires II\Scenario\default0.scn
c:\found.002\dir0000.chk\Age of Empires II\Scenario\jarco1.scn
c:\found.002\dir0000.chk\Age of Empires II\Scenario\jarco2.scn
c:\found.002\dir0000.chk\Age of Empires II\Scenario\scenario.inf
c:\found.002\dir0000.chk\Age of Empires II\scenariobkg.bmp
c:\found.002\dir0000.chk\Age of Empires II\SETUPENU.DLL
c:\found.002\dir0000.chk\Age of Empires II\SHW32.DLL
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S1END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S2END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S3.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S3END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S4.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S4END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S5.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S5END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S6.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S6END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S1END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S2END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S3.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S3END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S4.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S4END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S5.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S5END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S6.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S6END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S1END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S2END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S3.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S3END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S4.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S4END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S5.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S5END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S6.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S6END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S1END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S2END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S3.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S3END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S4.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S4END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S5.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S5END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S6.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S6END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S1END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S2END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S3.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S3END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S4.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S4END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S5.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S5END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S6.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S6END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S7.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S7END.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\INTRO.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3aa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1lold.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1r.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1t.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1u.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1v.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1w.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1x.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1y.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1z.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4c2.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6a2.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\S1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1r.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1s.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1t.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wb.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wc.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2aa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2wa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3e2.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3wa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wb.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wc.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5a2.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5r.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5s.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5t.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5u.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5v.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5w.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wa.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wd.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5we.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wf.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wg.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wh.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5x.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5y.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z2.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z3.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z4.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6r.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6s.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6t.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6u.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6v.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6w.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7a.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7b.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7c.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7d.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7e.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7f.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7g.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7h.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7i.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7j.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7k.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7l.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7m.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7n.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7o.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7p.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7q.mp3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\BRITISH.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\BYZANTIN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CELT.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CHINESE.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\COUNTDWN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CREDITS.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\FRENCH.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\GOTH.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\JAPANESE.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\LOST.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\MONGOL.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\OPEN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\PERSIAN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\RANDOM.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\SARACEN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TEUTON.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TOWN.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TURK.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\VIKING.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\WON1.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\WON2.MP3
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Cricket.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf1.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf2.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf3.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf4.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf6.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf7.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf8.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave1.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave2.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave3.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave4.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave5.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind1.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind2.wav
c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind3.wav
c:\found.002\dir0000.chk\Age of Empires II\Taunt\01 Yes.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\02 No.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\03 Food, please.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\04 Wood, please.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\05 Gold, PLease.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\06 Stone, please.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\07 Ahh.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\08 All hail.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\09 Oooh.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\10 Back to Age 1.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\11 Herb laugh.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\12 Being rushed.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\13 Blame your isp.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\14 Start the game.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\15 Don't Point That Thing.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\16 Enemy Sighted.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\17 It Is Good.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\18 I Need a Monk.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\19 Long Time No Siege.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\20 My granny.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\21 Nice Town I'll Take It.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\22 Quit Touchin.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\23 Raiding Party.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\24 Dadgum.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\25 Smite Me.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\26 The wonder.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\27 You play 2 hours.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\28 You Should See the Other Guy.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\29 Roggan.mp3
c:\found.002\dir0000.chk\Age of Empires II\Taunt\30 Wololo.mp3
c:\found.002\dir0000.chk\Age of Empires II\UNINSTAL.EXE
c:\found.002\dir0000.chk\Age of Empires II\WARRANTY.RTF
c:\found.002\dir0000.chk\Age of Empires III\art\ui\random_map\large_maps.ddt
c:\found.002\dir0000.chk\Age of Empires III\privacy.rtf
c:\found.002\dir0000.chk\Age of Empires III\SetupENU2.dll
C:\found.003
c:\found.003\file0000.chk
c:\program files\Optimizer Pro
C:\user.js
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-04-10 to 2012-05-10 ))))))))))))))))))))))))))))))
.
.
2012-05-10 14:13 . 2012-05-10 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\offreg.dll
2012-05-10 11:14 . 2012-05-10 11:14 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsl47eb3b3e.sys
2012-05-09 18:33 . 2012-05-09 18:33 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsle44fdd8b.sys
2012-05-09 16:18 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\mpengine.dll
2012-05-08 16:38 . 2012-05-08 16:38 -------- d-----w- c:\program files\CodeStuff
2012-05-08 13:08 . 2012-05-08 13:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-08 13:08 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-08 12:11 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-02 13:32 . 2012-05-08 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ADDICT-THING
2012-05-02 12:14 . 2012-05-02 12:29 -------- d-----w- c:\program files\Maxis
2012-04-27 17:11 . 2012-04-27 17:11 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Malwarebytes
2012-04-27 17:10 . 2012-04-27 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-04-27 15:58 . 2012-04-27 15:58 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG2012
2012-04-27 15:48 . 2012-04-27 15:48 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG Secure Search
2012-04-27 15:42 . 2012-04-27 15:42 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2012-04-27 15:42 . 2012-04-28 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2012-04-26 17:57 . 2012-04-26 17:57 388096 ----a-r- c:\documents and settings\Kinderen\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-04-26 17:57 . 2012-04-26 17:57 -------- d-----w- c:\program files\Trend Micro
2012-04-25 16:52 . 2012-04-25 16:52 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 16:52 . 2012-04-25 16:52 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-25 16:52 . 2012-04-25 16:52 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-25 13:26 . 2012-04-25 13:26 -------- d-----w- c:\program files\Common Files\Skype
2012-04-24 16:42 . 2012-04-24 16:42 -------- d-----w- c:\program files\Video Codec
2012-04-24 16:31 . 2012-04-27 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Bcool
2012-04-24 16:30 . 2012-05-02 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate
2012-04-22 06:10 . 2012-04-22 06:10 -------- d-----w- c:\documents and settings\Kinderen\Application Data\LolClient
2012-04-21 19:11 . 2012-04-21 19:11 -------- d-----w- C:\Riot Games
2012-04-12 05:16 . 2012-04-12 05:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2012-04-11 10:04 . 2012-04-11 10:04 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-08 16:42 . 2012-04-09 20:17 1409 ----a-w- c:\windows\QTFont.for
2012-04-17 15:39 . 2010-03-14 11:26 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-04-11 13:55 . 2004-08-04 00:58 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:55 . 2004-09-02 12:00 2152960 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 13:55 . 2004-09-02 12:00 1862400 ----a-w- c:\windows\system32\win32k.sys
2012-04-03 18:19 . 2012-04-03 18:20 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-03 18:19 . 2011-07-22 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-20 18:44 . 2009-12-02 13:23 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-01 14:43 . 2012-03-01 14:42 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-03-01 11:00 . 2004-09-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:00 . 2004-09-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:00 . 2004-09-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 20:30 . 2010-03-14 11:26 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-02-29 20:17 . 2012-02-29 20:17 138056 ----a-w- c:\documents and settings\Kinderen\Application Data\PnkBstrK.sys
2012-02-29 14:10 . 2004-09-02 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2004-09-02 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-09-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-16 20:52 . 2012-02-07 20:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 09:01 . 2012-04-09 09:25 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 09:01 . 2012-04-09 09:25 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-04-25 16:52 . 2012-02-07 20:09 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
[-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-05-09_16.05.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-05-10 11:13 . 2012-05-10 11:13 16384 c:\windows\Temp\Perflib_Perfdata_1a4.dat
- 2004-09-02 12:00 . 2012-04-11 20:50 91150 c:\windows\system32\perfc013.dat
+ 2004-09-02 12:00 . 2012-05-09 21:06 91150 c:\windows\system32\perfc013.dat
- 2004-09-02 12:00 . 2012-04-11 20:50 71624 c:\windows\system32\perfc009.dat
+ 2004-09-02 12:00 . 2012-05-09 21:06 71624 c:\windows\system32\perfc009.dat
- 2009-03-17 16:59 . 2011-07-05 13:46 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
+ 2009-03-17 16:59 . 2012-01-13 15:03 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
+ 2009-03-17 16:59 . 2012-01-13 15:03 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
- 2009-03-17 16:59 . 2011-07-05 13:46 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
- 2009-03-17 16:59 . 2011-07-06 07:57 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
+ 2009-03-17 16:59 . 2012-01-13 15:54 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
- 2009-03-17 16:59 . 2011-07-06 07:57 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2009-03-17 16:59 . 2012-01-13 15:54 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-04 07:22 . 2012-02-08 14:56 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-06-04 07:22 . 2012-05-09 21:01 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2012-05-10 11:14 . 2012-05-10 11:14 90112 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_08e40963\System.Drawing.Design.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 61440 c:\windows\assembly\NativeImages1_v1.0.3705\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a_33e6d197\CustomMarshalers.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\ff0e98a47a1aaa29100976e9e2cc430a\WindowsLiveWriter.ni.exe
+ 2012-05-10 12:02 . 2012-05-10 12:02 99840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5d4d60e3cb7f6b19d1dc6452e735a360\WindowsLive.Writer.Api.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\316e223f2ab8c69cd6a5a06de21650ec\System.Windows.Presentation.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\7aac1fe67890463655aeeb3b8e4f2884\System.Web.DynamicData.Design.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\34c988dea48c291b4e648941207e83fb\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\7bb7e51275fa19f8b4894c772bdb1e10\System.AddIn.Contract.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\f0c4a4528f130ef2ff1ae63dd7b39075\PresentationFontCache.ni.exe
+ 2012-05-09 21:07 . 2012-05-09 21:07 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\53931181e5a5e194da82605613cda6af\PresentationCFFRasterizer.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2be3ad4cda6853d7959a84cec0414c5\Microsoft.Vsa.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\f00a18225430e7531135589688d650a1\Microsoft.VisualC.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\8fab9cd28bbc860a34feec119512664d\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\0eac132c7c36f1c100ae23c956b379e7\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\d66bc03eb7eae89b4dde2d09eda1414f\dfsvc.ni.exe
+ 2012-05-09 21:11 . 2012-05-09 21:11 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2009-03-17 16:59 . 2011-07-12 16:05 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2009-03-17 16:59 . 2012-01-16 23:19 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2012-05-09 21:06 . 2012-05-09 21:06 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-04-11 20:50 . 2012-04-11 20:50 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-04-11 20:50 . 2012-04-11 20:50 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2012-04-05 21:13 . 2012-04-05 21:13 299080 c:\windows\system32\XPSViewer\XPSViewer.exe
- 2004-09-02 12:00 . 2012-04-11 20:50 509474 c:\windows\system32\perfh013.dat
+ 2004-09-02 12:00 . 2012-05-09 21:06 509474 c:\windows\system32\perfh013.dat
- 2004-09-02 12:00 . 2012-04-11 20:50 441688 c:\windows\system32\perfh009.dat
+ 2004-09-02 12:00 . 2012-05-09 21:06 441688 c:\windows\system32\perfh009.dat
+ 2009-03-17 17:42 . 2012-05-10 11:13 158752 c:\windows\system32\FNTCACHE.DAT
- 2009-03-17 17:42 . 2012-03-15 06:52 158752 c:\windows\system32\FNTCACHE.DAT
+ 2012-04-05 21:52 . 2012-04-05 21:52 131168 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 989968 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2009-03-17 16:59 . 2012-01-13 14:59 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
- 2009-03-17 16:59 . 2011-07-05 13:44 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
+ 2009-03-17 16:59 . 2012-01-13 15:54 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
- 2009-03-17 16:59 . 2011-07-06 07:57 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2011-12-22 14:50 . 2011-12-22 14:50 256000 c:\windows\Installer\870f71.msp
+ 2009-03-24 18:28 . 2012-05-09 21:13 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-03-24 18:28 . 2012-04-11 20:52 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2011-09-15 19:41 . 2011-09-15 19:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WINWORD.EXE
+ 2012-05-10 11:14 . 2012-05-10 11:14 851968 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_7a8e096d\System.Drawing.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\ac4fc3032c19946f9b2729468888206d\WsatConfig.ni.exe
+ 2012-05-10 12:02 . 2012-05-10 12:02 626688 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\218b4362202a2f432bb3714221ff2aa4\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fb438f62f426ff28b4a9949d699051b8\WindowsLive.Writer.Extensibility.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ccc14b04d082666155d2c355ef1f6563\WindowsLive.Writer.FileDestinations.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c954ba830b50bd4a6cf0ee094e2ea928\WindowsLive.Writer.Mshtml.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c627e81fcd97ecd7c70b7eedf7928713\WindowsLive.Writer.Localization.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bdeb63577afc142cf5b377b9e2565660\WindowsLive.Writer.Controls.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\baacfa565b2f46f4501cd89b067a8a47\WindowsLive.Writer.HtmlParser.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 334848 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ab181ae110294c0c572059dea0a4332c\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\809bd32a5211d9cd4115fba88f370a74\WindowsLive.Writer.BrowserControl.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6d9c4d236bacb711597c5aca6c04200e\WindowsLive.Writer.Interop.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\678f35b523dbb63a4f247c1ffdf359cd\WindowsLive.Writer.Instrumentation.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\313958002b6415baf438056e452f23c3\WindowsLive.Writer.Passport.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\29e8f27943707613416f76a0357c8f41\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\228e3d0a57dc24f37a2b2259104749c1\WindowsLive.Writer.BlogClient.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1b316a40898d5a62af81ed70a3b708d0\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\130bc8fe5ff6eb69e4c7f0ba24fba59a\WindowsLive.Writer.SpellChecker.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\d74a2a15b12d1d7c33eb64df4879cf7e\WindowsLive.Client.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\6198de2c5b8f7d89404c2ba39d69ae56\WindowsFormsIntegration.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\be27ab5913cec2b292a019c2a13ec701\UIAutomationTypes.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\04e5e2be34a70ee7f4c87550238095a0\UIAutomationClient.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP474.tmp\WindowsLive.Writer.Passport.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\1c13b08593e99d6f5bef49ae7939c78b\System.Xml.Linq.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\8bffbaa5d5abe40674d0bc124dfe8622\System.Web.Routing.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6c7765c10516d375e9ddedad2dbab848\System.Web.RegularExpressions.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\a7908debe80c209b599529685a159fa0\System.Web.Extensions.Design.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\44ecb9f7be54a2ba46e6102d343e2e7e\System.Web.Entity.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\fee8237aa2daa36e48aec379ee642422\System.Web.Entity.Design.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\40d90d2c1484164b786067320ce778f4\System.Web.DynamicData.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\6b4ce8cf2c3307b75ea7ebe77258bb26\System.Web.Abstractions.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\41f6f6dd0c8427d4a8e6fd3915505a6b\System.Transactions.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8dc4a28c456f81ee7399da21bd9d55aa\System.ServiceProcess.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\129b15861e200613ff78ae15581f9093\System.Security.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a644ec04e18202b60f9d828bc207972b\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\4a9eb43005a041959ddc5c7e586ab746\System.Net.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\3182a049ba953010dec649cf290a9e90\System.Management.Instrumentation.ni.dll
+ 2012-05-09 21:10 . 2012-05-09 21:10 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\8991f21d4b3676bf6f779110db8d4ac9\System.IO.Log.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cd9c60a35d4958e94d2e3dd2f778e2e9\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\29bce0113d611084a9329349e33528ac\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\29bce0113d611084a9329349e33528ac\System.EnterpriseServices.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\88aa4f80c7e5ac25f06f8950e42a1678\System.Drawing.Design.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ca484772955bc4db03b5dcb611c09423\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8ba5e68dddfd3279a8469d39eded48f3\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a0109fce606a3110a5e7f9a4773f517e\System.Data.Services.Design.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3a68d0441f509ffa6f8f0fb9cfcc5780\System.Data.Services.Client.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\04440b3dd5d822da4973a525ee04b05d\System.Data.Entity.Design.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\7bbb5d9e3b161b4d4b968e590442d3ae\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\bf7d6af03e1230ccad546a8659245ae9\System.Configuration.Install.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\931a2bece4668863db4f852401c828cf\System.AddIn.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6762f1ee780fa9c0b4ef66b285c64844\SMSvcHost.ni.exe
+ 2012-05-09 21:11 . 2012-05-09 21:11 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\47ed5bc9f42ea0054ce9acfde5e640b8\ServiceModelReg.ni.exe
+ 2012-05-09 21:08 . 2012-05-09 21:08 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a4706b850df9a3483f2fc439b6abe616\PresentationFramework.Royale.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7416fe825e6e49a87fa8ff60c8971813\PresentationFramework.Classic.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\186c27fbd7b38b5551889274f6fa2ccd\PresentationFramework.Aero.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5a121969a115d11b6256eb960c145686\MSBuild.ni.exe
+ 2012-05-09 21:11 . 2012-05-09 21:11 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\97c613d3899b320a6765793bdf490272\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\dec22fb7d6b8929a41380e5359741a07\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\1009b31c86a1b798fffa9e0127cec29c\Microsoft.Build.Utilities.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\21d88631ef629715d3eecdd08e62e0b8\Microsoft.Build.Engine.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a0f38c6478cca8297fb160291346c1c9\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bb26dd100d656605c576881a1a823667\CustomMarshalers.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\9869c02d18825fdd32e64135a3e7246b\ComSvcConfig.ni.exe
+ 2012-05-09 21:11 . 2012-05-09 21:11 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e414683ec4cff1cac0c77aaefd67144e\AspNetMMCExt.ni.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2009-08-15 20:30 . 2009-08-15 20:30 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-05-09 21:02 . 2012-05-09 21:02 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-05-09 21:02 . 2012-05-09 21:02 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2009-08-15 20:29 . 2009-08-15 20:29 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2012-05-09 16:27 . 2012-02-09 15:43 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll
+ 2010-05-02 08:10 . 2012-04-11 13:55 1862400 c:\windows\system32\dllcache\win32k.sys
+ 2010-06-11 14:23 . 2012-04-11 13:55 2196992 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2010-06-11 14:23 . 2012-04-11 13:55 2031104 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-10 17:10 . 2012-04-11 13:55 2073472 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2010-06-11 14:23 . 2012-04-11 13:55 2152960 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2011-12-25 01:50 . 2011-12-25 01:50 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2011-03-25 04:15 . 2011-03-25 04:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2011-10-26 02:39 . 2011-10-26 02:39 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 5913360 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-07-07 03:18 . 2011-07-07 03:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-12-25 01:50 . 2011-12-25 01:50 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2009-03-17 16:59 . 2004-07-19 17:54 2002944 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.dll
+ 2009-03-17 16:59 . 2012-01-16 23:19 2002944 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.dll
+ 2009-03-17 16:59 . 2012-01-16 23:20 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
- 2009-03-17 16:59 . 2011-07-12 16:04 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
- 2009-03-17 16:59 . 2007-12-17 15:29 1179648 c:\windows\Microsoft.NET\Framework\v1.0.3705\system.dll
+ 2009-03-17 16:59 . 2012-01-16 23:19 1179648 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.dll
+ 2009-03-17 16:59 . 2012-01-13 14:59 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- 2009-03-17 16:59 . 2011-07-05 13:45 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
+ 2009-03-17 16:59 . 2012-01-13 14:59 2273280 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
+ 2009-03-17 16:59 . 2012-01-16 23:19 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
- 2009-03-17 16:59 . 2011-07-12 16:05 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
+ 2012-04-04 20:38 . 2012-04-04 20:38 2831360 c:\windows\Installer\870f9a.msp
+ 2012-04-28 19:44 . 2012-04-28 19:44 9101824 c:\windows\Installer\870f89.msp
+ 2012-04-28 19:44 . 2012-04-28 19:44 9586176 c:\windows\Installer\870f5d.msp
+ 2012-04-04 20:38 . 2012-04-04 20:38 3620864 c:\windows\Installer\870f4b.msp
+ 2012-03-15 00:24 . 2012-03-15 00:24 1795584 c:\windows\Installer\870f2e.msp
+ 2012-04-28 19:43 . 2012-04-28 19:43 8459264 c:\windows\Installer\870f1d.msp
+ 2012-02-17 06:45 . 2012-02-17 06:45 2299392 c:\windows\Installer\870f01.msp
- 2009-03-24 18:28 . 2012-04-11 20:52 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-24 18:28 . 2012-05-09 21:13 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-08-17 08:49 . 2011-08-17 08:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
+ 2011-07-07 01:58 . 2011-07-07 01:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGL.DLL
+ 2010-06-11 14:23 . 2012-04-11 13:55 2196992 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2010-06-11 14:23 . 2012-04-11 13:55 2031104 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-10 17:10 . 2012-04-11 13:55 2073472 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2010-06-11 14:23 . 2012-04-11 13:55 2152960 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2012-05-09 21:14 . 2012-05-09 21:14 1855488 c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_b3fe6eb5\System.dll
+ 2012-05-10 11:14 . 2012-05-10 11:14 2027520 c:\windows\assembly\NativeImages1_v1.0.3705\System.Xml\1.0.3300.0__b77a5c561934e089_6cd9d84c\System.Xml.dll
+ 2012-05-10 11:14 . 2012-05-10 11:14 2953216 c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_41b2cdaf\System.Windows.Forms.dll
+ 2012-05-10 11:14 . 2012-05-10 11:14 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_49478551\System.Design.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 3301376 c:\windows\assembly\NativeImages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_f3325456\mscorlib.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ed14765fc0f1a92b9211a088455799fc\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\724479ec2aae6cebefd965ac1bacdce6\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 2018816 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5b93d79ffd230432a9448c110a76d6b6\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\41a81b97625c113b591ed082c95276e2\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 7953408 c:\windows\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
+ 2012-05-09 21:09 . 2012-05-09 21:09 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\33fa6a2055bf857bff2e31020279b5e9\System.WorkflowServices.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5eccf6fef6bee8a2f93bc65ff33699bb\System.Workflow.Runtime.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\62bd2e1bf98b04ceca2102c8f54aab9d\System.Workflow.ComponentModel.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\8215548b3d4aabbaa0557ab747700778\System.Workflow.Activities.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\3e11aea7d742b5eddbd0b6bd1012f7df\System.Web.Services.ni.dll
+ 2012-05-10 12:04 . 2012-05-10 12:04 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\ff995dde9cd34ff1e8ac7ab55fc92d32\System.Web.Mobile.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\8899d1091e64a4d0b6ae69060197091a\System.Web.Extensions.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5efb50c91f3c5e49be2079f625d933b7\System.Speech.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll
+ 2012-05-09 21:10 . 2012-05-09 21:10 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\1d6707a5a9da16c1d1b88529837884d6\System.Printing.ni.dll
+ 2012-05-09 21:10 . 2012-05-09 21:10 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e09496ddb2bf6f3b69707924f2e6b5ff\System.IdentityModel.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 1591808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8ca00132a08c69697adf1cda32ebd835\System.Drawing.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\b55887436d2cfbe1fb32dd18d554185b\System.DirectoryServices.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\832196527f0497078f085eaf9189265f\System.Deployment.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\12c6fe8d4dd78f9bddf847d3b2821c03\System.Data.ni.dll
+ 2012-05-09 21:13 . 2012-05-09 21:13 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\982b508698278c6ffb3d143bbe1e8bb8\System.Data.SqlXml.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\2de7666b1cd0a1bc363726c9553dc39c\System.Data.Services.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\7afb1abdbb8ba32cf578ff8ea4e45d99\System.Data.OracleClient.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\44a5fc9e7c71b1fe1e2c79b03ecc3bc7\System.Data.Linq.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\772c94f595cd87b7fa187d592ef46fcf\System.Data.Entity.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 2146304 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\2ecefd16184a78f19aaf0f02cc0a7e1f\ReachFramework.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\51204805c71113e0db2103faa064b313\PresentationUI.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\8c509044eea2ab22689ea43926b30108\PresentationBuildTasks.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\b49dd780ba8e3501b0adcf108b431e7b\Microsoft.VisualBasic.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\42145ebf75f77cabad442f0801a81c64\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-10 12:03 . 2012-05-10 12:03 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\cfe15312373b4668398404b5822bab7d\Microsoft.JScript.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\f3fcd65eca42d13b746cf3f5bd993ee0\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\2091903cd9b359e96f05ac2d6d25ef4e\Microsoft.Build.Tasks.ni.dll
+ 2012-05-10 12:02 . 2012-05-10 12:02 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5aa63a1cb41e3a5e1e8ed17072e60ec3\Microsoft.Build.Engine.ni.dll
+ 2012-05-09 21:02 . 2012-05-09 21:02 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2010-06-23 20:27 . 2010-06-23 20:27 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-05-09 21:02 . 2012-05-09 21:02 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-05-09 21:05 . 2012-05-09 21:05 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-09 21:02 . 2012-05-09 21:02 4214784 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-05-09 21:06 . 2012-05-09 21:06 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-04-11 20:50 . 2012-04-11 20:50 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 1179648 c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
- 2010-06-11 13:23 . 2010-06-11 13:23 1179648 c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 2002944 c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-06-11 13:23 . 2010-06-11 13:23 2002944 c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-10-13 05:08 . 2011-10-13 05:08 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-09-05 11:42 . 2012-05-09 21:06 55656824 c:\windows\system32\MRT.exe
+ 2012-04-06 00:12 . 2012-04-06 00:12 15709696 c:\windows\Installer\870f78.msp
+ 2012-01-04 00:25 . 2012-01-04 00:25 17751552 c:\windows\Installer\870f6a.msp
+ 2012-04-06 01:13 . 2012-04-06 01:13 16527872 c:\windows\Installer\870f3a.msp
+ 2012-05-09 21:00 . 2012-05-09 21:00 23771136 c:\windows\Installer\870f0d.msp
+ 2011-09-15 19:42 . 2011-09-15 19:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WWLIB.DLL
+ 2012-05-09 21:09 . 2012-05-09 21:09 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\995fcf39ead2c2a53e084505c2c67d49\System.Windows.Forms.ni.dll
+ 2012-05-09 21:14 . 2012-05-09 21:14 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\7861cd979ea5db3fb7d30ed94fb0edd2\System.Web.ni.dll
+ 2012-05-09 21:11 . 2012-05-09 21:11 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\a9256d2ad7e4be2bbb4e9b18c3997b84\System.Design.ni.dll
+ 2012-05-09 21:08 . 2012-05-09 21:08 14329856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5b8ff47c1db373a2a4c638ca31988bd2\PresentationFramework.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 12218368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\4eb3cd1f1d5a83617524a9dfb96a657d\PresentationCore.ni.dll
+ 2012-05-09 21:07 . 2012-05-09 21:07 11492352 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
.
-- Snapshot teruggezet naar huidige datum --
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SkyTel"="SkyTel.EXE" [2009-03-17 2879488]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
.
c:\documents and settings\Kinderen\Menu Start\Programma's\Opstarten\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-3-17 303104]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\I:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56388:TCP"= 56388:TCP:Pando Media Booster
"56388:UDP"= 56388:UDP:Pando Media Booster
.
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;c:\windows\system32\drivers\hcw88aud.sys [17-3-2009 21:57 12928]
R1 MpKsl47eb3b3e;MpKsl47eb3b3e;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsl47eb3b3e.sys [10-5-2012 13:14 29904]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 18:21 249648]
R2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [17-3-2009 22:00 434176]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys [17-3-2009 21:57 182400]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys [17-3-2009 21:57 320256]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [17-3-2009 21:57 74624]
R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [17-3-2009 21:57 394880]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [17-3-2009 21:57 17280]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 16:23 196176]
S2 gupdate1ca0ddb241ef2ef;Google Updateservice (gupdate1ca0ddb241ef2ef);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 8:50 158856]
S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:25 24448]
S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25-4-2012 18:52 129976]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - MPKSL47EB3B3E
.
Inhoud van de 'Gedeelde Taken' map
.
2012-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23]
.
2012-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23]
.
2012-05-10 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03]
.
.
------- Bijkomende Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\Kinderen\Application Data\Mozilla\Firefox\Profiles\0g756rsy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.startpagina.nl/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6OyzRaMCX2
FF - user.js: extensions.incredibar_i.upn2n - 92261296176075556
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10595
FF - user.js: extensions.incredibar_i.ppd -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-05-10 16:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-1770027372-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C4684E37-EFF7-CB9C-94C3-06BB7F8AD9EA}*]
"hahhphpbcigacdml"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61,
70,6b,00,ff
"iajhnihobokimciimd"=hex:63,61,6f,62,6f,70,00,7c
"iangnhnhodclokigco"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61,
70,6b,00,ff
"dbpbddiedeakjooomdajkjkdmhbhgogjacffnkac"=hex:68,61,63,66,6f,67,6b,68,62,65,
6e,70,6d,67,6a,66,00,00
"jbpbddiedeakjooomdajjggcjcdpijjdgkcaldonlgeaajmnfoel"=hex:68,61,63,66,6f,67,
6b,68,62,65,6e,70,6d,67,6a,66,00,00
"dbpbddiedeakjooomdajhgjdgmghloofnnlicolf"=hex:62,61,68,62,00,00
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
.
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\SensApi.dll
.
Voltooingstijd: 2012-05-10 16:35:33
ComboFix-quarantined-files.txt 2012-05-10 14:35
ComboFix2.txt 2012-05-09 16:10
.
Pre-Run: 85.176.938.496 bytes beschikbaar
Post-Run: 85.176.934.400 bytes beschikbaar
.
- - End Of File - - 568B19D566C1F9C966FA4255E55694B9

#10 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 10 mei 2012 - 19:16

En laat Text Enhance zich nu nog zien ?

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#11 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 10 mei 2012 - 19:45

elke keer na het herstarten van de pc laat de text enhance zich gewoon weer zien. :(
nog verdere opties (addons zijn enkel uitgeschakeld, misschien kunnen die ook volledig verwijderd worden en ligt het daar aan?)

#12 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 10 mei 2012 - 19:54

Kan je eerst eens kijken wat deze map is c:\program files\Video Codec en of je die bewust hebt gedownload ?

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#13 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 11 mei 2012 - 12:30

Is in ieder geval niet door mij bewust gedownload. Eventueel kan het door mijn broertje zijn gebeurd.
Het is een lege bestandmap
eigenschappen:
type: Bestandsmap
Locatie: C:\Program Files
Grootte: 0 bytes
Grootte op schijf: 0 bytes
Bevat: 0 bestanden, 0 mappen
Gemaakt: dinsdag 24 april 2012

Dit is volgens mij exact de dag waarop het probleem voor het eerst voorkwam.

#14 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 11 mei 2012 - 19:24

Verwijder volgende vetgedrukte mappen :

c:\program files\Video Codec
c:\documents and settings\All Users\Application Data\Premium
c:\documents and settings\All Users\Application Data\Bcool
c:\documents and settings\All Users\Application Data\InstallMate

... en dan maar weer naar Text Enhance kijken ?

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#15 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 11 mei 2012 - 19:50

c:\program files\Video Codec
c:\documents and settings\All Users\Application Data\Premium
heb ik kunnen verwijderen.

ik blijk echter niet bij de map application data te kunnen. Kan zijn dat m'n vader die voor mij heeft geblokkeerd al zie ik geen reden waarom...

c:\documents and settings\All Users\Application Data\Premium kon de zoekmachine vinden maar die andere 2 werden niet gevonden...

zal de malwarebytes scanner er nog eens over laten lopen en nieuw hijack this logje maken vanavond. weet niet of je daar wat mee kunt?

#16 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 11 mei 2012 - 20:00

Heb je na het verwijderen van deze twee

c:\program files\Video Codec
c:\documents and settings\All Users\Application Data\Premium

nog problemen met Text Enhance ?

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#17 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 12 mei 2012 - 18:58

nog altijd problemen met Text Enhance.

weet niet of je in deze link ook de afbeelding kan zien
http://postimage.org/image/ahpi1lkuj/

dit is namelijk hoe mijn site er uit ziet..

Bewerkt door jdvanroest, 12 mei 2012 - 19:06.


#18 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 12 mei 2012 - 19:27

Dan wordt het tijd om ALLE addons en plugins volledig te verwijderen.

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​


#19 jdvanroest

jdvanroest

    Lid

  • Lid
  • PipPip
  • 20 berichten

Geplaatst 12 mei 2012 - 19:39

ok. Heb je daar een handleiding voor want ik kan wel uitschakelen maar verwijderen lukt mij niet..

#20 kape

kape

    Website Beheerder

  • Website Beheerder
  • 40894 berichten

Geplaatst 13 mei 2012 - 05:53

Heb je bij de actieve addons geen keuze uit opties-uitschakelen-verwijderen ?

Hebben we je goed geholpen? Overweeg eens een donatie aan PC Helpforum.​





0 gebruiker(s) lezen dit onderwerp

0 leden, 0 gasten, 0 anonieme gebruikers

Over ons

PC Helpforum helpt GRATIS computergebruikers sinds juli 2006. Ons team geeft via het forum professioneel antwoord op uw vragen en probeert uw pc problemen zo snel mogelijk op te lossen. Word lid vandaag, plaats je vraag online en het PC Helpforum-team helpt u graag verder!