Ga naar inhoud

jdvanroest

Lid
  • Items

    20
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door jdvanroest

  1. hijackthis is inmiddels heb ik inmiddels verwijderd. Die scan zal ik wekelijks uitvoeren. Hartelijk dank allemaal!
  2. op deze manier is het gelukt. dank u. nu probeer ik hetzelfde met hijackthis en malwarebytes- antimalware maar die twee willen niet weg?
  3. ik heb nog zo'n ouderwetse 'zoeken' knop in mijn start menu (niet direct boven start dus). toen ik deze opdracht in het zoeken veld plakte leverde dat geen enkele resultaten. Elke ComboFix geeft als resultaat het programma zelf en de snelkoppeling maar ook niet de uninstall.. waar kan dat aan liggen of is dat voor jou ook niet bekend?
  4. de pc is een stuk sneller geworden. Hartelijk dank daarvoor. ik kon de ComboFix /uninstall niet vinden bij zoeken. Weet niet waar dat aan kan liggen? heb de C:`Qoobox inmiddels wel verwijdert.
  5. ComboFix 12-05-22.02 - thera-johan 22-05-2012 17:25:51.2.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.511.219 [GMT 2:00] Gestart vanuit: c:\documents and settings\thera-johan\Mijn documenten\Downloads\ComboFix.exe gebruikte Opdracht switches :: e:\johan\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\autorun.ini c:\windows\system32\dllcache\dlimport.exe c:\windows\system32\dllcache\wmpvis.dll . . (((((((((((((((((((( Bestanden Gemaakt van 2012-04-22 to 2012-05-22 )))))))))))))))))))))))))))))) . . 2012-05-22 15:17 . 2012-05-22 15:17 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0C7D9B85-0E52-4AAA-982D-2CA239CD1FE9}\offreg.dll 2012-05-22 15:11 . 2012-05-22 15:11 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0C7D9B85-0E52-4AAA-982D-2CA239CD1FE9}\MpKsl5e387880.sys 2012-05-21 18:45 . 2012-05-08 16:40 6737808 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0C7D9B85-0E52-4AAA-982D-2CA239CD1FE9}\mpengine.dll 2012-05-20 16:32 . 2012-05-20 18:32 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-05-20 16:22 . 2012-05-08 16:40 6737808 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-19 13:26 . 2012-05-19 13:28 -------- d-----w- c:\windows\system32\drivers\AVG 2012-05-19 13:26 . 2012-05-19 13:26 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012 2012-05-19 13:24 . 2012-05-19 13:24 -------- d-----w- c:\program files\AVG 2012-05-19 13:22 . 2012-05-19 19:11 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData 2012-05-08 19:11 . 2012-05-08 19:11 -------- d-----w- c:\documents and settings\thera-johan\Application Data\Malwarebytes 2012-05-08 19:10 . 2012-05-08 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-05-08 19:10 . 2012-05-08 19:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-05-08 19:10 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-04-28 18:47 . 2012-04-28 18:47 -------- d-----w- c:\program files\Mozilla Maintenance Service 2012-04-28 18:47 . 2012-04-28 18:47 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-28 18:47 . 2012-04-28 18:47 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-04-28 13:07 . 2012-05-18 09:16 -------- d-----w- c:\documents and settings\jarco\Bureaublad . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-20 10:05 . 2010-05-09 18:53 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-05-20 10:05 . 2010-05-09 18:52 202448 ----a-w- c:\windows\system32\PnkBstrB.exe 2012-05-05 19:05 . 2012-04-07 12:13 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-05 19:05 . 2011-05-14 15:44 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-11 13:55 . 2002-09-09 13:17 2073472 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-11 13:55 . 2003-04-08 12:00 1862400 ----a-w- c:\windows\system32\win32k.sys 2012-04-11 13:55 . 2003-04-08 12:00 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-03-28 12:18 . 2012-03-28 12:18 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-03-28 12:18 . 2010-11-28 21:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-20 18:44 . 2009-06-18 17:48 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-01 11:00 . 2003-04-08 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-03-01 11:00 . 2003-04-08 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2012-03-01 11:00 . 2003-04-08 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-02-29 14:10 . 2003-04-08 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10 . 2003-04-08 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17 . 2009-10-31 21:43 385024 ----a-w- c:\windows\system32\html.iec 2012-04-28 18:47 . 2012-04-04 19:16 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys [-] 2003-04-08 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\atapi.sys . [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys [-] 2003-04-08 . 03F403B07A884FC2AA54A0916C410931 . 13568 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys . [-] 2003-04-08 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys [-] 2003-04-08 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys . [-] 2008-04-14 . 380397621E94B32C744E7B2CC1330390 . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys [-] 2008-04-14 . 380397621E94B32C744E7B2CC1330390 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys [-] 2003-04-08 . F1A07C34B2266ACF2801332D34DEEFDD . 23936 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys . [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys [-] 2003-04-08 . 3B350E5A2A5E951453F3993275A4523A . 167552 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ndis.sys . [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys [-] 2003-04-08 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntfs.sys . [-] 2003-04-08 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys [-] 2003-04-08 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys . [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys [-] 2003-04-08 . 244A2F9816BC9B593957281EF577D976 . 332928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tcpip.sys . [-] 2008-04-14 . 69EAA7501F53A40E8C04C69F2391224F . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll [-] 2008-04-14 . 69EAA7501F53A40E8C04C69F2391224F . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll [-] 2003-04-08 . 502BB10403C033D259CB451C8D7FB925 . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\browser.dll . [-] 2008-04-14 . 8754210A3399D19610CE2D71E0C3E5D9 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe [-] 2008-04-14 . 8754210A3399D19610CE2D71E0C3E5D9 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe [-] 2003-04-08 . 9345B1482734F8D6AFDB19347B7F16D6 . 11776 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\lsass.exe . [-] 2008-04-14 . 5431FB616ECAE0D587C5B97D0B86CBD8 . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll [-] 2008-04-14 . 5431FB616ECAE0D587C5B97D0B86CBD8 . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll [-] 2003-04-08 . 58FC56C40F0B9AAB972713242955E590 . 154112 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\netman.dll . [-] 2008-04-14 21:32 . 49DEEDAED168FD4723934755BF55CCFE . 822784 . . [2001.12.4414.700] . . c:\windows\ServicePackFiles\i386\comres.dll [-] 2008-04-14 21:32 . 49DEEDAED168FD4723934755BF55CCFE . 822784 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll [-] 2003-04-08 12:00 . 8F13292CC6BBA46A7D3ECBB5623BD5AB . 822784 . . [2001.12.4414.42] . . c:\windows\$NtServicePackUninstall$\comres.dll . [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll [-] 2003-04-08 . 9F93E038B7D35F4EA7F46D0CD392D018 . 223232 . . [6.2.2600.1106] . . c:\windows\$NtServicePackUninstall$\qmgr.dll . [-] 2009-02-09 . D8D28F6CABEC7D42B8E487E290563B9A . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll [-] 2009-02-09 . D9883335CC1C17AFC3A09C8AC3E4DBE4 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll [-] 2009-02-09 . D9883335CC1C17AFC3A09C8AC3E4DBE4 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll [-] 2008-04-14 . 70357A0F411DF464F9FF434F2DDCB68F . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll [-] 2008-04-14 . 70357A0F411DF464F9FF434F2DDCB68F . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll [-] 2003-04-08 . 18CC35AADF5D21F564246FC580A43378 . 260608 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\rpcss.dll . [-] 2009-02-09 . 657B69389B893F440B07590C9E963F23 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\services.exe [-] 2009-02-09 . 657B69389B893F440B07590C9E963F23 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe [-] 2009-02-09 . D98A222A707FFE40043E533FE7A6BA24 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe [-] 2008-04-14 . B77BC5CD88EB96D4352AF5202EC4AEC2 . 109056 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\services.exe [-] 2008-04-14 . B77BC5CD88EB96D4352AF5202EC4AEC2 . 109056 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe [-] 2003-04-08 . BD4B45F82F699D9977681403796716B8 . 101888 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\services.exe . [-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe [-] 2008-04-14 . DB454135DE1A09FE7FEDA7B554B5CCA2 . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe [-] 2008-04-14 . DB454135DE1A09FE7FEDA7B554B5CCA2 . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe [-] 2003-04-08 . 8E7A297C95DC2F21099AF213500359DE . 51200 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe . [-] 2008-04-14 . 1247D4D5444E28519BBE31BE8AB4C029 . 510464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe [-] 2008-04-14 . 1247D4D5444E28519BBE31BE8AB4C029 . 510464 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2003-04-08 . D375231CCA973A06C43E4B6087BFA706 . 519168 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\winlogon.exe . [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys [-] 2003-04-08 . 1C4802409CFD4A7051F458B744CFCAA5 . 57984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ipsec.sys . [-] 2010-08-23 . 7826282032F459694DE7BCE330FF31FC . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2010-08-23 . 7826282032F459694DE7BCE330FF31FC . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll [-] 2010-08-23 . 01D982636AFC3A79537B81D9C3DA897A . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll [-] 2008-04-14 . EFD9660AF9177D90018AC9A9AA42310F . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll [-] 2008-04-14 . EFD9660AF9177D90018AC9A9AA42310F . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll [-] 2008-04-14 . 1EAA8CD46BFB33307ACAF10EFF80E8BD . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [-] 2003-04-08 . 5F12538B78C66C67D49B9653DEED0DB9 . 557056 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll [-] 2003-04-08 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll [-] 2003-04-08 . 1B5D729AFC4B6FE3EC397B74DB7A1BAF . 921600 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll . [-] 2008-04-14 . 0A9CF5D3CF63A8699F28C814EF821C7E . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll [-] 2008-04-14 . 0A9CF5D3CF63A8699F28C814EF821C7E . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll [-] 2003-04-08 . 4563396E23EA861523C08AEDA0666014 . 53248 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll . [-] 2008-07-07 20:30 . 97912DC0679D2DA60CCE589BBC196D72 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll [-] 2008-07-07 20:30 . 97912DC0679D2DA60CCE589BBC196D72 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll [-] 2008-07-07 20:26 . F6C37073A269C163A5FDAE5BFF47F367 . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll [-] 2008-04-14 21:32 . 42A7FC383B174D91162EBF44C8AA5349 . 246272 . . [2001.12.4414.701] . . c:\windows\$NtUninstallKB950974$\es.dll [-] 2008-04-14 21:32 . 42A7FC383B174D91162EBF44C8AA5349 . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll [-] 2003-04-08 12:00 . 4A652DAF0BFD8FF8AA5DB61C7B798DCB . 225280 . . [2001.12.4414.46] . . c:\windows\$NtServicePackUninstall$\es.dll . [-] 2008-04-14 . 58211BB9D2F5C761BFB504C2BBBA8D99 . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll [-] 2008-04-14 . 58211BB9D2F5C761BFB504C2BBBA8D99 . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll [-] 2003-04-08 . E48F46B9788622EEC041F97C47419C2B . 103936 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\imm32.dll . [-] 2009-03-21 . CE7EFE07C7119C8CD09D953AD9ECA7CD . 1030656 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll [-] 2009-03-21 . CE7EFE07C7119C8CD09D953AD9ECA7CD . 1030656 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll [-] 2009-03-21 . 93E2307273AE7B2D5418E132902373A7 . 1032704 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll [-] 2008-04-14 . 09BCB7171F8172C2BA0189FE1F9C25CB . 1030656 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll [-] 2008-04-14 . 09BCB7171F8172C2BA0189FE1F9C25CB . 1030656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll [-] 2003-04-08 . CDE58E6276B4B9104ECC70B90AE386A2 . 971264 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\kernel32.dll . [-] 2008-04-14 . 9234F9A97016954CC67C01DA9C4F39C2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll [-] 2008-04-14 . 9234F9A97016954CC67C01DA9C4F39C2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll [-] 2003-04-08 . A4DF53419129963DCE45B16C44E7D182 . 15360 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll . [-] 2008-04-14 . FE6417AB01E9A5B124A58BE2B5DB663B . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll [-] 2008-04-14 . FE6417AB01E9A5B124A58BE2B5DB663B . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll [-] 2003-04-08 . 69BFF2682E81C712C3ED8852BD320244 . 18944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\lpk.dll . [-] 2012-03-01 . 6E0E7C508B5060F81992D5ED0B1A5556 . 5978624 . . [8.00.6001.19222] . . c:\windows\system32\mshtml.dll [-] 2012-03-01 . 6E0E7C508B5060F81992D5ED0B1A5556 . 5978624 . . [8.00.6001.19222] . . c:\windows\system32\dllcache\mshtml.dll [-] 2012-03-01 . 467D9D5FB15DD88E82768C6F31A7A5D4 . 5980672 . . [8.00.6001.23318] . . c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\mshtml.dll [-] 2011-12-17 . 5C55673322584D9F5A32D0971D83858B . 5979136 . . [8.00.6001.19190] . . c:\windows\ie8updates\KB2675157-IE8\mshtml.dll [-] 2011-12-17 . 46FE106946083872716147AD223F20C1 . 5980160 . . [8.00.6001.23286] . . c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll [-] 2011-11-04 . 958ECE072DA2D840BD3658A3AB708F58 . 5978112 . . [8.00.6001.19170] . . c:\windows\ie8updates\KB2647516-IE8\mshtml.dll [-] 2011-11-04 . E43D37858B634BDE1E099E92F0202458 . 5978624 . . [8.00.6001.23266] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll [-] 2011-10-03 . 2ECD546FB8594A4C5D807E489045627F . 5971456 . . [8.00.6001.19154] . . c:\windows\ie8updates\KB2618444-IE8\mshtml.dll [-] 2011-10-03 . 5AF7AC6924E7CB72D76A796262B1C25E . 5972992 . . [8.00.6001.23250] . . c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll [-] 2011-07-25 . 39ADF0F29F47896DD726833735AB825C . 5969920 . . [8.00.6001.19120] . . c:\windows\ie8updates\KB2586448-IE8\mshtml.dll [-] 2011-07-25 . 03B085EEE1DB5F2E32721CF5C72F7A26 . 5971456 . . [8.00.6001.23216] . . c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtml.dll [-] 2011-05-30 . 7EA2A988004ED9A3D9DC5192DC547C57 . 5964800 . . [8.00.6001.19088] . . c:\windows\ie8updates\KB2559049-IE8\mshtml.dll [-] 2011-05-30 . 6DE2D62A51F4C110AA995583B7463487 . 5967360 . . [8.00.6001.23181] . . c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\mshtml.dll [-] 2011-02-22 . 80A564DD39C82A79F34F5A093CE1A6BD . 5964800 . . [8.00.6001.23141] . . c:\windows\$hf_mig$\KB2497640-IE8\SP3QFE\mshtml.dll [-] 2011-02-22 . E7618AEF7203F57D94266153C7E514C4 . 5962240 . . [8.00.6001.19046] . . c:\windows\ie8updates\KB2530548-IE8\mshtml.dll [-] 2010-12-20 . 91F5FB2C81CBE00B36B7F90E8DFDEC9E . 5961216 . . [8.00.6001.19019] . . c:\windows\ie8updates\KB2497640-IE8\mshtml.dll [-] 2010-12-20 . 55F5920E04513ED481129E5E1DD94772 . 5962240 . . [8.00.6001.23111] . . c:\windows\$hf_mig$\KB2482017-IE8\SP3QFE\mshtml.dll [-] 2010-11-06 . F22C3F322F5291FECDCC13371E3909A4 . 5960704 . . [8.00.6001.23091] . . c:\windows\$hf_mig$\KB2416400-IE8\SP3QFE\mshtml.dll [-] 2010-11-06 . CB4E08223EFCEB7C9E534D7A2AB00D6A . 5959168 . . [8.00.6001.18999] . . c:\windows\ie8updates\KB2482017-IE8\mshtml.dll [-] 2010-09-10 . 83C01E6BEE0BAEAC11B7C681302E7F18 . 5957120 . . [8.00.6001.18975] . . c:\windows\ie8updates\KB2416400-IE8\mshtml.dll [-] 2010-09-10 . 90215AE398050E9510A5B71CD222A6FD . 5958656 . . [8.00.6001.23067] . . c:\windows\$hf_mig$\KB2360131-IE8\SP3QFE\mshtml.dll [-] 2010-06-24 . 4866ECEEFB5964BB1CB081FB3A2A370D . 5954560 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\mshtml.dll [-] 2010-06-24 . 1048BF4C23101A0404252A19A9151C16 . 5951488 . . [8.00.6001.18939] . . c:\windows\ie8updates\KB2360131-IE8\mshtml.dll [-] 2010-05-06 . E7CD22F3A8247FC3BFD283D30B4674D2 . 5950976 . . [8.00.6001.18928] . . c:\windows\ie8updates\KB2183461-IE8\mshtml.dll [-] 2010-05-06 . 47A7DDF5DF0F323F877EEFC75338C4A3 . 5953024 . . [8.00.6001.23019] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll [-] 2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . [8.00.6001.18904] . . c:\windows\ie8updates\KB982381-IE8\mshtml.dll [-] 2010-02-25 . 2399C13AE076A84037794AA0E9BF152A . 5946880 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll [-] 2009-12-21 . 0C92E8AAD0E68E0A5358813353F31CE3 . 5942784 . . [8.00.6001.18876] . . c:\windows\ie8updates\KB980182-IE8\mshtml.dll [-] 2009-12-21 . 585A8B2FD6373FC06D6893867754CF74 . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll [-] 2009-10-29 . 1185E34AB3243194BB57FD3C31385700 . 3091968 . . [6.00.2900.5897] . . c:\windows\ie8\mshtml.dll [-] 2009-10-29 . A66CEDA2AA6FA052D3F7A46CE7553D21 . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll [-] 2009-10-29 . A66CEDA2AA6FA052D3F7A46CE7553D21 . 5940736 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3GDR\mshtml.dll [-] 2009-10-29 . 6D626567986D37E021F44EE66446D515 . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll [-] 2009-10-29 . 6D626567986D37E021F44EE66446D515 . 5944320 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3QFE\mshtml.dll [-] 2009-10-29 . F7E06360F7DAFED78647AAFCC7ADBBC5 . 3094016 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll [-] 2009-10-19 . 0B2E964BEB51B4004329061F87B261FB . 3091968 . . [6.00.2900.5890] . . c:\windows\$NtUninstallKB976325$\mshtml.dll [-] 2009-10-19 . 2ECF5281C946A38CFDA0E591C2B1A258 . 3093504 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3QFE\mshtml.dll [-] 2009-09-25 . 03C83F354CDFAA7A804AC5B76D46AC07 . 3091968 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976749$\mshtml.dll [-] 2009-09-25 . A5C706F4A21ED747E30F93547A7CCA38 . 3093504 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll [-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll [-] 2008-04-14 . B937B964B164A7B588D09BF419F90875 . 3066880 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB974455$\mshtml.dll [-] 2008-04-14 . B937B964B164A7B588D09BF419F90875 . 3066880 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\mshtml.dll [-] 2003-04-08 . 28BA7BF8F2BB53E4DD9D43914142737E . 2833920 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\mshtml.dll . [-] 2008-04-14 . 074C38B50CE71E3EC6DD3F6DAABF4EEF . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll [-] 2008-04-14 . 074C38B50CE71E3EC6DD3F6DAABF4EEF . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll [-] 2008-04-14 . 61E70054981A2F9E64CEA7CA9479C0AA . 343040 . . [7.0.2600.5512] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll [-] 2003-04-08 . 33D03EC823482177D5171907AF19FFF9 . 323072 . . [7.0.2600.1106] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll [-] 2003-04-08 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll [-] 2003-04-08 . 1B2C477D8847E4123DD8761D2E9008F7 . 323072 . . [7.0.2600.1106] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.10.0_x-ww_d8862ba3\msvcrt.dll . [-] 2008-06-20 . 74816260AECBE87C473962A359007EEB . 247296 . . [5.1.2600.5625] . . c:\windows\$NtUninstallKB2509553$\mswsock.dll [-] 2008-06-20 . 18740E8EC5BE4B6D66FA0E4CBFD3B9C6 . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\mswsock.dll [-] 2008-06-20 . 18740E8EC5BE4B6D66FA0E4CBFD3B9C6 . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll [-] 2008-06-20 . 4522CBE00A9E9EEE36AA82ED4B319148 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll [-] 2008-06-20 . 4522CBE00A9E9EEE36AA82ED4B319148 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll [-] 2008-04-14 . 6BBC05038DF477F12E930A0F99F7D219 . 247296 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\mswsock.dll [-] 2008-04-14 . 6BBC05038DF477F12E930A0F99F7D219 . 247296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll [-] 2003-04-08 . 3F7E336DB0EFC89708EE53EC8B3617DB . 230400 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\mswsock.dll . [-] 2008-04-14 . E6A7071DF6855AB7CCCC220AC3AAD087 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll [-] 2008-04-14 . E6A7071DF6855AB7CCCC220AC3AAD087 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll [-] 2003-04-08 . 87BD1441F4DB1951A80365E236D7568E . 399360 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\netlogon.dll . [-] 2008-04-14 . 32167CE0150DC2A269D99689A143FB67 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll [-] 2008-04-14 . 32167CE0150DC2A269D99689A143FB67 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll [-] 2003-04-08 . 506AEC11B86CCFF9894FEA9BB1C1BDCD . 14848 . . [6.00.2600.0000] . . c:\windows\$NtServicePackUninstall$\powrprof.dll . [-] 2008-04-14 . 0E3B585761E23C1E35442E972B7E45F9 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll [-] 2008-04-14 . 0E3B585761E23C1E35442E972B7E45F9 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll [-] 2003-04-08 . 5BD3F85CFA1073712E4911BB5751AD86 . 179200 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\scecli.dll . [-] 2008-04-14 . E6DCF5DD55AC2655971A478718307D18 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll [-] 2008-04-14 . E6DCF5DD55AC2655971A478718307D18 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll [-] 2003-04-08 . 750A97F61172F0917AE97E8931E164CE . 4096 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\sfc.dll . [-] 2008-04-14 . E410EC73E2BE2A41D923B006F51C8427 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe [-] 2008-04-14 . E410EC73E2BE2A41D923B006F51C8427 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe [-] 2003-04-08 . 133733E07EF4FDA582BC56F3B281E0BC . 12800 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\svchost.exe . [-] 2008-04-14 . 2BC9FB448F0C2394FF53C83A7BB04731 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll [-] 2008-04-14 . 2BC9FB448F0C2394FF53C83A7BB04731 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll [-] 2003-04-08 . D482CBF778D95C532F3A4C2648EB4B8B . 233984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll . [-] 2008-04-14 . 4CF588D2F2363B73EB4AF57967D46DFF . 580096 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll [-] 2008-04-14 . 4CF588D2F2363B73EB4AF57967D46DFF . 580096 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2003-04-08 . 2E8CEC28BE4D9B830BA0AFF73C9279F7 . 561664 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\user32.dll . [-] 2008-04-14 . 6818A533ED3B2FA9936DF3DAF45352DF . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe [-] 2008-04-14 . 6818A533ED3B2FA9936DF3DAF45352DF . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe [-] 2003-04-08 . 54EB9CE26234AE9116555C587FAED658 . 22016 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\userinit.exe . [-] 2012-03-01 . CFF17B16BFF8179FBBA29075245E8BE1 . 916992 . . [8.00.6001.19222] . . c:\windows\system32\wininet.dll [-] 2012-03-01 . CFF17B16BFF8179FBBA29075245E8BE1 . 916992 . . [8.00.6001.19222] . . c:\windows\system32\dllcache\wininet.dll [-] 2012-03-01 . B2E54BC4C5B399547EE3C8188DBBA509 . 919552 . . [8.00.6001.23318] . . c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\wininet.dll [-] 2011-12-17 . 03CB14FB6B75EC8AC2FDEC54E904C30B . 916992 . . [8.00.6001.19190] . . c:\windows\ie8updates\KB2675157-IE8\wininet.dll [-] 2011-12-17 . 38C3CDBC40464D40C7B716C8E154B86C . 919552 . . [8.00.6001.23286] . . c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\wininet.dll [-] 2011-11-04 . D47FE623B45DF066647469DB73AE3215 . 916992 . . [8.00.6001.19165] . . c:\windows\ie8updates\KB2647516-IE8\wininet.dll [-] 2011-11-04 . A484703720C95391777DF05F2458FEF8 . 919552 . . [8.00.6001.23261] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll [-] 2011-08-22 . 381FDBF8A25C7629696E5EE2B213F8CC . 916480 . . [8.00.6001.19131] . . c:\windows\ie8updates\KB2618444-IE8\wininet.dll [-] 2011-08-22 . EDD945F6C0630DB8453673DF9E7B009E . 919552 . . [8.00.6001.23227] . . c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll [-] 2011-06-23 . 14FB4665EFBDCE6931A55752A44F7DE2 . 916480 . . [8.00.6001.19098] . . c:\windows\ie8updates\KB2586448-IE8\wininet.dll [-] 2011-06-23 . 3BC2081CD791584B4ED373F3B4959CC8 . 919552 . . [8.00.6001.23192] . . c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\wininet.dll [-] 2011-04-25 . 1C95CF3DBAEBB3CCA34845CD884FB8CA . 916480 . . [8.00.6001.19072] . . c:\windows\ie8updates\KB2559049-IE8\wininet.dll [-] 2011-04-25 . 00F17371D9145B114061564BDABD8C24 . 919552 . . [8.00.6001.23165] . . c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\wininet.dll [-] 2011-02-22 . CC5AE9A79DA18AFD29FB7CF95F23A143 . 919552 . . [8.00.6001.23139] . . c:\windows\$hf_mig$\KB2497640-IE8\SP3QFE\wininet.dll [-] 2011-02-22 . 51B29ABC95E882F7AD80FDBFD5E729CC . 916480 . . [8.00.6001.19044] . . c:\windows\ie8updates\KB2530548-IE8\wininet.dll [-] 2010-12-20 . 81BB5AF5584545323F20AA75610EBD01 . 916480 . . [8.00.6001.19019] . . c:\windows\ie8updates\KB2497640-IE8\wininet.dll [-] 2010-12-20 . 21A739156ED963C45419D3EB02E44F0C . 919552 . . [8.00.6001.23111] . . c:\windows\$hf_mig$\KB2482017-IE8\SP3QFE\wininet.dll [-] 2010-11-06 . 51964C721E751FD4E798252CC0E4FFB9 . 919552 . . [8.00.6001.23084] . . c:\windows\$hf_mig$\KB2416400-IE8\SP3QFE\wininet.dll [-] 2010-11-06 . BCEB709EF4C751E0BE355B76D834A954 . 916480 . . [8.00.6001.18992] . . c:\windows\ie8updates\KB2482017-IE8\wininet.dll [-] 2010-09-10 . EA2E4CFB3F124DD54F3B02F3BCCF6E82 . 916480 . . [8.00.6001.18968] . . c:\windows\ie8updates\KB2416400-IE8\wininet.dll [-] 2010-09-10 . 5D081F5E3E46966C4F63D32231C93511 . 919552 . . [8.00.6001.23060] . . c:\windows\$hf_mig$\KB2360131-IE8\SP3QFE\wininet.dll [-] 2010-06-24 . 8168F7D81CD04C83D7E04F3981A7D0F5 . 919040 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\wininet.dll [-] 2010-06-24 . A3D63C0EF4D32F1F04D9E9596AEA0FFE . 916480 . . [8.00.6001.18939] . . c:\windows\ie8updates\KB2360131-IE8\wininet.dll [-] 2010-05-06 . 109D1EFA1C0BC4EC65EBA39707F31A19 . 916480 . . [8.00.6001.18923] . . c:\windows\ie8updates\KB2183461-IE8\wininet.dll [-] 2010-05-06 . A319118B77A91EB08AB2BF098D91900E . 919040 . . [8.00.6001.23014] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll [-] 2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . [8.00.6001.18904] . . c:\windows\ie8updates\KB982381-IE8\wininet.dll [-] 2010-02-25 . BB424C9406140FEAFB4732025BEBB69B . 919040 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll [-] 2009-12-21 . FA2B753F8FE84904A6940589A43F30B4 . 916480 . . [8.00.6001.18876] . . c:\windows\ie8updates\KB980182-IE8\wininet.dll [-] 2009-12-21 . 4C145AB616871611FCE38F053C75807C . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll [-] 2009-10-29 . 765E049E1F6E2EF9265B85E02DE487B5 . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll [-] 2009-10-29 . 765E049E1F6E2EF9265B85E02DE487B5 . 916480 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3GDR\wininet.dll [-] 2009-10-29 . D906535CAB4BB8A60AC060351EDE159F . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll [-] 2009-10-29 . D906535CAB4BB8A60AC060351EDE159F . 916480 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3QFE\wininet.dll [-] 2009-10-29 . 772A3480B543FB5280DE1679FA73E799 . 670208 . . [6.00.2900.5897] . . c:\windows\ie8\wininet.dll [-] 2009-10-29 . 77DA6400FF88337FE260CF87A530D64C . 671744 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\wininet.dll [-] 2009-09-25 . E3A0D172FF21D1F0B30CB3B9671ADEBF . 670208 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976325$\wininet.dll [-] 2009-09-25 . 2A7566FCBB31765DC1D710EA5928D059 . 671744 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\wininet.dll [-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll [-] 2008-04-14 . 80CA4DCDD3DAD65CB8800508076712E7 . 669184 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB974455$\wininet.dll [-] 2008-04-14 . 80CA4DCDD3DAD65CB8800508076712E7 . 669184 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\wininet.dll [-] 2003-04-08 . 87DF44F9B70BBF94D4143C21A5CB42BA . 602112 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\wininet.dll . [-] 2008-04-14 . 520391367546218929749612ABFE840C . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll [-] 2008-04-14 . 520391367546218929749612ABFE840C . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll [-] 2003-04-08 . 3EA6EDC08BB3F373839060EA8B40CE72 . 75264 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll . [-] 2008-04-14 . 7ED22EA6D840CD388BD68B68580468E1 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll [-] 2008-04-14 . 7ED22EA6D840CD388BD68B68580468E1 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll [-] 2003-04-08 . D1588F506FD5CF8DAE843E6A534ADBB1 . 18944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ws2help.dll . [-] 2008-04-14 . AA04F042A820BF1868E643575887E1A6 . 1037312 . . [6.00.2900.5512] . . c:\windows\explorer.exe [-] 2008-04-14 . AA04F042A820BF1868E643575887E1A6 . 1037312 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe [-] 2003-04-08 . 040CC36796BBA354B678BCE9DCB25A3A . 1007616 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\explorer.exe . [-] 2008-04-14 . E67C9B97306DEEFBB481072CE5FF8E07 . 153088 . . [5.1.2600.5512] . . c:\windows\regedit.exe [-] 2008-04-14 . E67C9B97306DEEFBB481072CE5FF8E07 . 153088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regedit.exe [-] 2003-04-08 . 6946EA65B65D24B0EFB9DB2EC7B2798B . 140800 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\regedit.exe . [-] 2011-11-01 . DB355CEF2B35481C21DD213C28560E86 . 1288192 . . [5.1.2600.6168] . . c:\windows\system32\ole32.dll [-] 2011-11-01 . DB355CEF2B35481C21DD213C28560E86 . 1288192 . . [5.1.2600.6168] . . c:\windows\system32\dllcache\ole32.dll [-] 2011-11-01 . 02AF8E4C7B851A213AC70BF6DD6E3537 . 1288704 . . [5.1.2600.6168] . . c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll [-] 2010-07-16 . AD2B41BEAB5BB7A258F6A2CCDCA09B82 . 1287680 . . [5.1.2600.6010] . . c:\windows\$NtUninstallKB2624667$\ole32.dll [-] 2010-07-16 . 57F12B548695C680421CD1EB8169A1C8 . 1288704 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll [-] 2008-04-14 . B2EE0E38A8025D6D7A7F3EEC8CA2829E . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll [-] 2008-04-14 . B2EE0E38A8025D6D7A7F3EEC8CA2829E . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll [-] 2003-04-08 . 8C57515321D7FFD77ADD70517D7BE737 . 1169920 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ole32.dll . [-] 2010-04-16 . 36BA0AAABD0AA4798403CB3FF08D5DDD . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\usp10.dll [-] 2010-04-16 . 36BA0AAABD0AA4798403CB3FF08D5DDD . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\dllcache\usp10.dll [-] 2010-04-16 . 7BB3922CB9973877D2BF4C7222EA8E70 . 406016 . . [1.0420.2600.5969] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll [-] 2008-04-14 . 0996802B726C0CFE94A44CDBD661983A . 406016 . . [1.0420.2600.5512] . . c:\windows\$NtUninstallKB981322$\usp10.dll [-] 2008-04-14 . 0996802B726C0CFE94A44CDBD661983A . 406016 . . [1.0420.2600.5512] . . c:\windows\ServicePackFiles\i386\usp10.dll [-] 2003-04-08 . 628A315978A88D1E4C9B45C93BA6478D . 339456 . . [1.0409.2600.1106] . . c:\windows\$NtServicePackUninstall$\usp10.dll . [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\ksuser.dll [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\system32\ksuser.dll [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\system32\dllcache\ksuser.dll [-] 2002-12-11 22:14 . 15914E0BF4DDA56CF797993DCCB637D1 . 4096 . . [5.3.0000000.900 built by: DIRECTX] . . c:\windows\Driver Cache\i386\ksuser.dll [-] 2002-12-11 22:14 . 15914E0BF4DDA56CF797993DCCB637D1 . 4096 . . [5.3.0000000.900 built by: DIRECTX] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ksuser.dll [-] 2001-09-06 . 7C025E147BE747A7AD038E33B10A923B . 4096 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ksuser.dll . [-] 2008-04-14 . E98A8C802CDB31FCF4121D9DFBEA3677 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe [-] 2008-04-14 . E98A8C802CDB31FCF4121D9DFBEA3677 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe [-] 2003-04-08 . BC69FEECC644021E56745C2E10C49EF2 . 13312 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe . [-] 2009-07-27 . 2D5D4156292150FE571872C1B88E9299 . 135680 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll [-] 2009-07-27 . 2D5D4156292150FE571872C1B88E9299 . 135680 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll [-] 2009-07-27 . C28A9E9D28ACDAF8097BE4578C49559B . 135680 . . [6.00.2900.5853] . . c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll [-] 2008-04-14 . CFB406497D9CF95DFFE17594899FD367 . 135680 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll [-] 2008-04-14 . CFB406497D9CF95DFFE17594899FD367 . 135680 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll [-] 2003-04-08 . 99792E295E5A4E7BCD08F4D708E16AAB . 116736 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll . [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll [-] 2003-04-08 . 323020B1DF45D8B80886C1806AF35595 . 158720 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\srsvc.dll . [-] 2008-04-14 . 6F1E5DBA783B147536659395D7B15485 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe [-] 2008-04-14 . 6F1E5DBA783B147536659395D7B15485 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe . [-] 2008-04-14 . FD3C38635808920F8235BF2FED642F54 . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll [-] 2008-04-14 . FD3C38635808920F8235BF2FED642F54 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll . [-] 2008-04-14 . CA64B9406EEDA4FFA2DAEAE1DABCCE42 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll [-] 2008-04-14 . CA64B9406EEDA4FFA2DAEAE1DABCCE42 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll [-] 2003-04-08 . 7593FA76DAFDBD9511A9A2B1465FF8C2 . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\eventlog.dll . [-] 2008-04-14 . 328CBDD2445F5B3A047644567EEB557F . 1571840 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll [-] 2008-04-14 . 328CBDD2445F5B3A047644567EEB557F . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll [-] 2003-04-08 . 3B8FA96FF436D4CD4E0D13223F965FAB . 1145856 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll . [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys [-] 2003-04-08 . 1C4802409CFD4A7051F458B744CFCAA5 . 57984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ipsec.sys . [-] 2008-04-14 . 2FD5B89BF9289C774C5C730DEA96CD91 . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll [-] 2008-04-14 . 2FD5B89BF9289C774C5C730DEA96CD91 . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll [-] 2003-04-08 . 548ACD377576BDABAC2E190F6D156906 . 51712 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\regsvc.dll . [-] 2008-04-14 . 7C288AE0F75CB18CFF1DF6179A67AD8F . 193536 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll [-] 2008-04-14 . 7C288AE0F75CB18CFF1DF6179A67AD8F . 193536 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll [-] 2003-04-08 . 5239C9913F5166838D772BF4A61C7844 . 160256 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll . [-] 2008-04-14 . 5B9D0DE64BE96A806819516440FD211C . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll [-] 2008-04-14 . 5B9D0DE64BE96A806819516440FD211C . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll [-] 2003-04-08 . 41F71DCF93421F867B0D40ECF1A74287 . 43008 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll . [-] 2008-04-14 . E0AEF86A594C9990D6321C5CA239C5B7 . 297472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll [-] 2008-04-14 . E0AEF86A594C9990D6321C5CA239C5B7 . 297472 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll [-] 2003-04-08 . 6AF0C847079356FE152BFD53A60D7487 . 202240 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\termsrv.dll . [-] 2008-04-14 . 6F18B42068D29B1F6F283DC37057836D . 347648 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\hnetcfg.dll [-] 2008-04-14 . 6F18B42068D29B1F6F283DC37057836D . 347648 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll [-] 2003-04-08 . B176F863C9B6A5773E58D98770F9BAC5 . 244224 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\hnetcfg.dll . [-] 2003-04-08 . 63F517B1A87DABF3F5ACB8A7952FC1D1 . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys . [-] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys [-] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys [-] 2002-08-28 23:16 . FF773FEDA15E8BD97FD54FE87A0ACDBE . 142208 . . [5.1.2601.1095 built by: xpsp1] . . c:\windows\$NtServicePackUninstall$\aec.sys . [-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys [-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys . [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys . [-] 2010-09-18 07:18 . C7F383764824117AEE9C3ED0FCA78044 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll [-] 2010-09-18 06:53 . 7892005CE5CDC809783F452B21FAF58F . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll [-] 2010-09-18 06:53 . 7892005CE5CDC809783F452B21FAF58F . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll [-] 2008-04-14 21:32 . 2407EADA5E2E146AB51E925F151DDAA5 . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll [-] 2008-04-14 21:32 . 2407EADA5E2E146AB51E925F151DDAA5 . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll [-] 2003-04-08 12:00 . 8EED1D71C14C356684E586B0A7DB6BCE . 924432 . . [4.1.6140] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll . [-] 2008-04-14 . C56A45A03DCA11712DE9FDF98224230B . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll [-] 2008-04-14 . C56A45A03DCA11712DE9FDF98224230B . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll [-] 2003-04-08 . F9DAEE255E7ED81BC6DCD67BFEF826EA . 34304 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll . [-] 2008-04-14 21:32 . 2628076412EC86C92827AE5202501E5D . 52736 . . [9.0.1.56] . . c:\windows\system32\mspmsnsv.dll [-] 2008-04-14 21:32 . 2628076412EC86C92827AE5202501E5D . 52736 . . [9.0.1.56] . . c:\windows\system32\dllcache\mspmsnsv.dll . [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\system32\ntkrnlpa.exe [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\system32\dllcache\ntkrnlpa.exe [-] 2012-04-11 . 44F045B4BE9D99929DDD48C045480237 . 2073472 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe [-] 2011-10-26 . 2820129F67352B99B032DE2CF328C767 . 2073728 . . [5.1.2600.6165] . . c:\windows\$NtUninstallKB2676562$\ntkrnlpa.exe [-] 2011-10-26 . 769A1C9E9641DCED4D0AC50968ADDA4E . 2073728 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe [-] 2010-12-09 . BAD22963CD6046C0B2834D2BFFAB56B5 . 2073728 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe [-] 2010-12-09 . 63905B20972EFB06169008F6F4BC8697 . 2073728 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe [-] 2010-04-28 . 75EA98BC36C13E976653400F8183D356 . 2071296 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe [-] 2010-04-28 . F98305BD47DC7A0B2A978000E3C31FAB . 2071168 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe [-] 2010-02-16 . F6049CA4515D37D5DA502D162E9B6AA0 . 2071168 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe [-] 2010-02-16 . 7C4F935FC449E4D27C685A5BC1792664 . 2071296 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe [-] 2009-12-09 . 6A42A70506E7ACFF6C3ACD740E22A01F . 2070528 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe [-] 2009-12-09 . F63B0CC3CE1E6E8EA39B4933B595C73A . 2070400 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe [-] 2009-08-04 . AB21A63A3B15653043E71126E5BBE3DE . 2070528 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe [-] 2009-08-04 . BF6965EA17CC1E48DA287783AEEF3CDB . 2070400 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe [-] 2009-02-09 . 07EE73D79A7CA142463470AEF230082B . 2070528 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe [-] 2008-04-14 . 6129DA5C68C13DCA12E77580730FD770 . 2070272 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe [-] 2008-04-14 . 6129DA5C68C13DCA12E77580730FD770 . 2070272 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe [-] 2003-04-08 . 13C45289C0E4F23CF129417DCA1F2F6E . 1952128 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe . [-] 2008-04-14 21:32 . AC1A78237B53044735693633F8235468 . 437248 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll [-] 2008-04-14 21:32 . AC1A78237B53044735693633F8235468 . 437248 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll [-] 2003-04-08 12:00 . 5117C60E5FC52F0E2BD02E6B0451AE9F . 394752 . . [5.1.2400.1106] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll . [-] 2008-04-14 . 01653D6C9604F1FB31A76EC94E08954F . 186368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll [-] 2008-04-14 . 01653D6C9604F1FB31A76EC94E08954F . 186368 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll [-] 2003-04-08 . 5B2B6BA37D7AA9BC8BF9669F30CE138A . 165376 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\upnphost.dll . [-] 2008-04-14 . 3A9974C925F4500BFF226F61DE1C4AF8 . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll [-] 2008-04-14 . 3A9974C925F4500BFF226F61DE1C4AF8 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll [-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll [-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\dsound.dll [-] 2003-04-08 . 3CDD0C6B44422DF1432947FA256F84F2 . 338944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\dsound.dll . [-] 2008-04-14 . 85F98F220C5E69E08149186BFEEF7B70 . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll [-] 2008-04-14 . 85F98F220C5E69E08149186BFEEF7B70 . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll . [-] 2008-04-14 . 7D2ABE7AA2D6CBC1CB0A1EB8B2619FCF . 279552 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll [-] 2008-04-14 . 7D2ABE7AA2D6CBC1CB0A1EB8B2619FCF . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll [-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll [-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\ddraw.dll [-] 2003-04-08 . 16C2C306A75567A957F6B7A80DF512A2 . 253440 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ddraw.dll . [-] 2008-04-14 21:32 . 6508ED3152C29B28B5E9183160DD2686 . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll [-] 2008-04-14 21:32 . 6508ED3152C29B28B5E9183160DD2686 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll [-] 2003-04-08 12:00 . 11171D442A392E556EBDCE15EA7E62CD . 106496 . . [5.0.5014] . . c:\windows\$NtServicePackUninstall$\olepro32.dll . [-] 2008-04-14 . E62337E275E82AA3F0ABFFED7E6E01E2 . 41472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll [-] 2008-04-14 . E62337E275E82AA3F0ABFFED7E6E01E2 . 41472 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll [-] 2003-04-08 . 431AA2EC8F7F4D6F6112D17D4C76DAAE . 38912 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\perfctrs.dll . [-] 2008-04-14 . 85844EC167674A67F547E13747E3E0E3 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\version.dll [-] 2008-04-14 . 85844EC167674A67F547E13747E3E0E3 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll [-] 2003-04-08 . 049F5724E94B45B8F01EFEDAF5218C21 . 16384 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\version.dll . [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\Driver Cache\i386\ntoskrnl.exe [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\system32\ntoskrnl.exe [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\system32\dllcache\ntoskrnl.exe [-] 2012-04-11 . 46190EF7B8A978A3B677248A377F43D3 . 2196992 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntoskrnl.exe [-] 2011-10-26 . 8E305C5AC846388E99C1204D619AE77A . 2197120 . . [5.1.2600.6165] . . c:\windows\$NtUninstallKB2676562$\ntoskrnl.exe [-] 2011-10-26 . CA76947F97276D52D4731EA2364ECBD8 . 2197120 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe [-] 2010-12-09 . 431D614A7395BADB939FE552DBDD8723 . 2197120 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe [-] 2010-12-09 . EA2A3B68CCF886B76403C37954F2E6EE . 2197120 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe [-] 2010-04-28 . 548AED38DF451C1783037390194A04DC . 2194304 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe [-] 2010-04-28 . 59582F46CAAAA049DB613B4005AF57B5 . 2194432 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe [-] 2010-02-17 . FD62829F3524A1BE95FD384A3C445AAB . 2194304 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe [-] 2010-02-16 . B79C48187CA08D2EC27DA4939953F082 . 2194432 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe [-] 2009-12-09 . 5037978D6ED651AEC5D6ACC87D65C715 . 2193664 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe [-] 2009-12-09 . 13C15BFF7E82D3F9FD215ADD54A3929D . 2193536 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe [-] 2009-08-04 . 270DE336026B0815F064BB8BD4CFD336 . 2193536 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe [-] 2009-08-04 . 2F1443AB72A64182FD8258BBAE801EA7 . 2193664 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe [-] 2009-02-10 . 7625D5BAFD2A4A8458468B139C893BB7 . 2193536 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe [-] 2008-04-14 . 140A1BAD8A6642C1386BB5B388EB447F . 2193408 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe [-] 2008-04-14 . 140A1BAD8A6642C1386BB5B388EB447F . 2193408 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe [-] 2003-04-08 . ED3086CF7C835D8A3FD0E6FBD95C0F53 . 2046464 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe . [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll [-] 2003-04-08 . 323020B1DF45D8B80886C1806AF35595 . 158720 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\srsvc.dll . [-] 2008-04-14 . 390D8E65F362327AD510B08971478301 . 176128 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\w32time.dll [-] 2008-04-14 . 390D8E65F362327AD510B08971478301 . 176128 . . [5.1.2600.5512] . . c:\windows\system32\w32time.dll [-] 2003-04-08 . 910C770BBEB488B2163924988FB6B07A . 166400 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\w32time.dll . [-] 2008-04-14 . 5AE996186D2DC694FEF88F14A3FC9242 . 334336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wiaservc.dll [-] 2008-04-14 . 5AE996186D2DC694FEF88F14A3FC9242 . 334336 . . [5.1.2600.5512] . . c:\windows\system32\wiaservc.dll [-] 2003-04-08 . 415531BDA25C2F8D1D342CD47A3BBC8C . 316928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\wiaservc.dll . [-] 2008-04-14 . 5203C84A11E39CBB1408F5E2767B04ED . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\midimap.dll [-] 2008-04-14 . 5203C84A11E39CBB1408F5E2767B04ED . 18944 . . [5.1.2600.5512] . . c:\windows\system32\midimap.dll [-] 2003-04-08 . 96DF0DD74F5BB1A16CCCF707793875FB . 17920 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\midimap.dll . [-] 2008-04-14 . 3D5CC4BFF926A0ABD4F5A117825629A3 . 7680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rasadhlp.dll [-] 2008-04-14 . 3D5CC4BFF926A0ABD4F5A117825629A3 . 7680 . . [5.1.2600.5512] . . c:\windows\system32\rasadhlp.dll [-] 2003-04-08 . 8B36031EB26860D00D12C87941D27471 . 6144 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\rasadhlp.dll . ((((((((((((((((((((((((((((( SnapShot@2012-05-21_19.18.22 ))))))))))))))))))))))))))))))))))))))))) . + 2012-05-22 15:11 . 2012-05-22 15:11 16384 c:\windows\Temp\Perflib_Perfdata_7e0.dat . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\thera-johan\Menu Start\Programma's\Opstarten\ OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Joke en Geert^Menu Start^Programma's^Opstarten^OneNote 2007 Schermopname en Snel starten.lnk] path=c:\documents and settings\Joke en Geert\Menu Start\Programma's\Opstarten\OneNote 2007 Schermopname en Snel starten.lnk backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-02 09:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-11-01 22:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY] 2012-01-24 15:24 2416480 ----a-w- c:\program files\AVG\AVG2012\avgtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116] 1998-11-30 16:04 497376 ----a-w- c:\windows\p_981116.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2003-06-25 10:24 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-12-08 00:36 421736 ----a-w- d:\itunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 21:33 1695232 ------w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2010-02-10 21:32 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.EXE"= "c:\\Program Files\\Call of Duty\\CoDMP.exe"= "c:\\Documents and Settings\\Ro-elle\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Call of Duty\\CoDUOMP.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "d:\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56872:TCP"= 56872:TCP:Pando Media Booster "56872:UDP"= 56872:UDP:Pando Media Booster . R1 MpKsl5e387880;MpKsl5e387880;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0C7D9B85-0E52-4AAA-982D-2CA239CD1FE9}\MpKsl5e387880.sys [22-5-2012 17:11 29904] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8-5-2012 21:10 654408] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8-5-2012 21:10 22344] S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [16-11-2009 17:58 135664] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 9:16 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7-4-2012 14:13 257696] S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:37 24448] S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [16-11-2009 17:58 135664] S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [29-7-2010 0:25 25112] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [20-5-2012 18:32 40776] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [28-4-2012 20:47 129976] S3 XDva343;XDva343;\??\c:\windows\system32\XDva343.sys --> c:\windows\system32\XDva343.sys [?] . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - MPKSL5E387880 . Inhoud van de 'Gedeelde Taken' map . 2012-05-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 19:05] . 2012-05-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:57] . 2012-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc705a23128c8c.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-16 15:58] . 2012-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc705a2319b39a.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-16 15:58] . 2012-05-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-261478967-725345543-1006Core.job - c:\documents and settings\Ro-elle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-20 15:19] . 2012-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-261478967-725345543-1006UA.job - c:\documents and settings\Ro-elle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-20 15:19] . 2012-05-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . 2012-05-22 c:\windows\Tasks\MpIdleTask.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . 2012-05-22 c:\windows\Tasks\User_Feed_Synchronization-{7F81D862-2402-4401-B041-45603D31C752}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31] . . ------- Bijkomende Scan ------- . mSearch Bar = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\documents and settings\thera-johan\Application Data\Mozilla\Firefox\Profiles\goggo5vg.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-05-22 17:34 Windows 5.1.2600 Service Pack 3 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . --------------------- DLLs Geladen Onder Lopende Processen --------------------- . - - - - - - - > 'winlogon.exe'(628) c:\windows\system32\Ati2evxx.dll . Voltooingstijd: 2012-05-22 17:38:26 ComboFix-quarantined-files.txt 2012-05-22 15:38 ComboFix2.txt 2012-05-21 19:24 . Pre-Run: 32.070.139.904 bytes beschikbaar Post-Run: 32.060.751.872 bytes beschikbaar . - - End Of File - - EACFD2F0C0E45A5B796912518E2BD482 snelheid wordt op zich wel beter. de pc was echt verschrikkelijk traag en nu is het net iets sneller. dat het niet meer geweldig zou gaan lopen had ik al wel verwacht dus vind het wel voldoende zo. Hartelijk dank! Weet niet of ik combofix etc nog weer moet verwijderen?
  6. het mbam-logje is inderdaad wat verouderd. heb al een tijd last van deze trage pc maar nooit de tijd/zin om er wat aan te doen. Pas had ik text enhance op mn andere pc zitten en merk direct dat het er beter op is geworden na jullie te raadplegen en de stappen zoals jullie zeggen uit te voeren. vandaar dat ik dacht: laat ik dit ook maar eens aan gaan pakken ComboFix 12-05-21.05 - thera-johan 21-05-2012 21:05:42.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.511.130 [GMT 2:00] Gestart vanuit: c:\documents and settings\thera-johan\Mijn documenten\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\IsUn0413.exe c:\windows\system32\PowerToyReadme.htm c:\windows\system32\SET51.tmp c:\windows\system32\SET5B.tmp c:\windows\system32\SET76.tmp c:\windows\system32\SET78.tmp c:\windows\system32\SET86.tmp c:\windows\system32\SETA9.tmp . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_MYWEBSEARCHSERVICE . . (((((((((((((((((((( Bestanden Gemaakt van 2012-04-21 to 2012-05-21 )))))))))))))))))))))))))))))) . . 2012-05-21 18:45 . 2012-05-08 16:40 6737808 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0C7D9B85-0E52-4AAA-982D-2CA239CD1FE9}\mpengine.dll 2012-05-20 16:32 . 2012-05-20 18:32 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-05-20 16:22 . 2012-05-08 16:40 6737808 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-19 13:26 . 2012-05-19 13:28 -------- d-----w- c:\windows\system32\drivers\AVG 2012-05-19 13:26 . 2012-05-19 13:26 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012 2012-05-19 13:24 . 2012-05-19 13:24 -------- d-----w- c:\program files\AVG 2012-05-19 13:22 . 2012-05-19 19:11 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData 2012-05-08 19:11 . 2012-05-08 19:11 -------- d-----w- c:\documents and settings\thera-johan\Application Data\Malwarebytes 2012-05-08 19:10 . 2012-05-08 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-05-08 19:10 . 2012-05-08 19:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-05-08 19:10 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-04-28 18:47 . 2012-04-28 18:47 -------- d-----w- c:\program files\Mozilla Maintenance Service 2012-04-28 18:47 . 2012-04-28 18:47 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-28 18:47 . 2012-04-28 18:47 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-04-28 13:07 . 2012-05-18 09:16 -------- d-----w- c:\documents and settings\jarco\Bureaublad . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-20 10:05 . 2010-05-09 18:53 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-05-20 10:05 . 2010-05-09 18:52 202448 ----a-w- c:\windows\system32\PnkBstrB.exe 2012-05-05 19:05 . 2012-04-07 12:13 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-05 19:05 . 2011-05-14 15:44 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-11 13:55 . 2002-09-09 13:17 2073472 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-11 13:55 . 2003-04-08 12:00 1862400 ----a-w- c:\windows\system32\win32k.sys 2012-04-11 13:55 . 2003-04-08 12:00 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-03-28 12:18 . 2012-03-28 12:18 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-03-28 12:18 . 2010-11-28 21:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-20 18:44 . 2009-06-18 17:48 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-01 11:00 . 2003-04-08 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-03-01 11:00 . 2003-04-08 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2012-03-01 11:00 . 2003-04-08 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-02-29 14:10 . 2003-04-08 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10 . 2003-04-08 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17 . 2009-10-31 21:43 385024 ----a-w- c:\windows\system32\html.iec 2012-04-28 18:47 . 2012-04-04 19:16 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys [-] 2003-04-08 . 95B858761A00E1D4F81F79A0DA019ACA . 86912 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\atapi.sys . [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys [-] 2003-04-08 . 03F403B07A884FC2AA54A0916C410931 . 13568 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys . [-] 2003-04-08 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys [-] 2003-04-08 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys . [-] 2008-04-14 . 380397621E94B32C744E7B2CC1330390 . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys [-] 2008-04-14 . 380397621E94B32C744E7B2CC1330390 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys [-] 2003-04-08 . F1A07C34B2266ACF2801332D34DEEFDD . 23936 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys . [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys [-] 2003-04-08 . 3B350E5A2A5E951453F3993275A4523A . 167552 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ndis.sys . [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys [-] 2003-04-08 . E3AE9C79498210A5F39FE5A9AD62BC55 . 561920 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntfs.sys . [-] 2003-04-08 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys [-] 2003-04-08 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys . [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys [-] 2003-04-08 . 244A2F9816BC9B593957281EF577D976 . 332928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tcpip.sys . [-] 2008-04-14 . 69EAA7501F53A40E8C04C69F2391224F . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll [-] 2008-04-14 . 69EAA7501F53A40E8C04C69F2391224F . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll [-] 2003-04-08 . 502BB10403C033D259CB451C8D7FB925 . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\browser.dll . [-] 2008-04-14 . 8754210A3399D19610CE2D71E0C3E5D9 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe [-] 2008-04-14 . 8754210A3399D19610CE2D71E0C3E5D9 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe [-] 2003-04-08 . 9345B1482734F8D6AFDB19347B7F16D6 . 11776 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\lsass.exe . [-] 2008-04-14 . 5431FB616ECAE0D587C5B97D0B86CBD8 . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll [-] 2008-04-14 . 5431FB616ECAE0D587C5B97D0B86CBD8 . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll [-] 2003-04-08 . 58FC56C40F0B9AAB972713242955E590 . 154112 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\netman.dll . [-] 2008-04-14 21:32 . 49DEEDAED168FD4723934755BF55CCFE . 822784 . . [2001.12.4414.700] . . c:\windows\ServicePackFiles\i386\comres.dll [-] 2008-04-14 21:32 . 49DEEDAED168FD4723934755BF55CCFE . 822784 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll [-] 2003-04-08 12:00 . 8F13292CC6BBA46A7D3ECBB5623BD5AB . 822784 . . [2001.12.4414.42] . . c:\windows\$NtServicePackUninstall$\comres.dll . [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll [-] 2008-04-14 . 5C0073A51C4873430FA8B262E92183FF . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll [-] 2003-04-08 . 9F93E038B7D35F4EA7F46D0CD392D018 . 223232 . . [6.2.2600.1106] . . c:\windows\$NtServicePackUninstall$\qmgr.dll . [-] 2009-02-09 . D8D28F6CABEC7D42B8E487E290563B9A . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll [-] 2009-02-09 . D9883335CC1C17AFC3A09C8AC3E4DBE4 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll [-] 2009-02-09 . D9883335CC1C17AFC3A09C8AC3E4DBE4 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll [-] 2008-04-14 . 70357A0F411DF464F9FF434F2DDCB68F . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll [-] 2008-04-14 . 70357A0F411DF464F9FF434F2DDCB68F . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll [-] 2003-04-08 . 18CC35AADF5D21F564246FC580A43378 . 260608 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\rpcss.dll . [-] 2009-02-09 . 657B69389B893F440B07590C9E963F23 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\services.exe [-] 2009-02-09 . 657B69389B893F440B07590C9E963F23 . 111104 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe [-] 2009-02-09 . D98A222A707FFE40043E533FE7A6BA24 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe [-] 2008-04-14 . B77BC5CD88EB96D4352AF5202EC4AEC2 . 109056 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\services.exe [-] 2008-04-14 . B77BC5CD88EB96D4352AF5202EC4AEC2 . 109056 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe [-] 2003-04-08 . BD4B45F82F699D9977681403796716B8 . 101888 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\services.exe . [-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe [-] 2008-04-14 . DB454135DE1A09FE7FEDA7B554B5CCA2 . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe [-] 2008-04-14 . DB454135DE1A09FE7FEDA7B554B5CCA2 . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe [-] 2003-04-08 . 8E7A297C95DC2F21099AF213500359DE . 51200 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe . [-] 2008-04-14 . 1247D4D5444E28519BBE31BE8AB4C029 . 510464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe [-] 2008-04-14 . 1247D4D5444E28519BBE31BE8AB4C029 . 510464 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2003-04-08 . D375231CCA973A06C43E4B6087BFA706 . 519168 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\winlogon.exe . [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys [-] 2003-04-08 . 1C4802409CFD4A7051F458B744CFCAA5 . 57984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ipsec.sys . [-] 2010-08-23 . 7826282032F459694DE7BCE330FF31FC . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2010-08-23 . 7826282032F459694DE7BCE330FF31FC . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll [-] 2010-08-23 . 01D982636AFC3A79537B81D9C3DA897A . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll [-] 2008-04-14 . EFD9660AF9177D90018AC9A9AA42310F . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll [-] 2008-04-14 . EFD9660AF9177D90018AC9A9AA42310F . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll [-] 2008-04-14 . 1EAA8CD46BFB33307ACAF10EFF80E8BD . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [-] 2003-04-08 . 5F12538B78C66C67D49B9653DEED0DB9 . 557056 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll [-] 2003-04-08 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll [-] 2003-04-08 . 1B5D729AFC4B6FE3EC397B74DB7A1BAF . 921600 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll . [-] 2008-04-14 . 0A9CF5D3CF63A8699F28C814EF821C7E . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll [-] 2008-04-14 . 0A9CF5D3CF63A8699F28C814EF821C7E . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll [-] 2003-04-08 . 4563396E23EA861523C08AEDA0666014 . 53248 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll . [-] 2008-07-07 20:30 . 97912DC0679D2DA60CCE589BBC196D72 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll [-] 2008-07-07 20:30 . 97912DC0679D2DA60CCE589BBC196D72 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll [-] 2008-07-07 20:26 . F6C37073A269C163A5FDAE5BFF47F367 . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll [-] 2008-04-14 21:32 . 42A7FC383B174D91162EBF44C8AA5349 . 246272 . . [2001.12.4414.701] . . c:\windows\$NtUninstallKB950974$\es.dll [-] 2008-04-14 21:32 . 42A7FC383B174D91162EBF44C8AA5349 . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll [-] 2003-04-08 12:00 . 4A652DAF0BFD8FF8AA5DB61C7B798DCB . 225280 . . [2001.12.4414.46] . . c:\windows\$NtServicePackUninstall$\es.dll . [-] 2008-04-14 . 58211BB9D2F5C761BFB504C2BBBA8D99 . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll [-] 2008-04-14 . 58211BB9D2F5C761BFB504C2BBBA8D99 . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll [-] 2003-04-08 . E48F46B9788622EEC041F97C47419C2B . 103936 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\imm32.dll . [-] 2009-03-21 . CE7EFE07C7119C8CD09D953AD9ECA7CD . 1030656 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll [-] 2009-03-21 . CE7EFE07C7119C8CD09D953AD9ECA7CD . 1030656 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll [-] 2009-03-21 . 93E2307273AE7B2D5418E132902373A7 . 1032704 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll [-] 2008-04-14 . 09BCB7171F8172C2BA0189FE1F9C25CB . 1030656 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll [-] 2008-04-14 . 09BCB7171F8172C2BA0189FE1F9C25CB . 1030656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll [-] 2003-04-08 . CDE58E6276B4B9104ECC70B90AE386A2 . 971264 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\kernel32.dll . [-] 2008-04-14 . 9234F9A97016954CC67C01DA9C4F39C2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll [-] 2008-04-14 . 9234F9A97016954CC67C01DA9C4F39C2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll [-] 2003-04-08 . A4DF53419129963DCE45B16C44E7D182 . 15360 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll . [-] 2008-04-14 . FE6417AB01E9A5B124A58BE2B5DB663B . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll [-] 2008-04-14 . FE6417AB01E9A5B124A58BE2B5DB663B . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll [-] 2003-04-08 . 69BFF2682E81C712C3ED8852BD320244 . 18944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\lpk.dll . [-] 2012-03-01 . 6E0E7C508B5060F81992D5ED0B1A5556 . 5978624 . . [8.00.6001.19222] . . c:\windows\system32\mshtml.dll [-] 2012-03-01 . 6E0E7C508B5060F81992D5ED0B1A5556 . 5978624 . . [8.00.6001.19222] . . c:\windows\system32\dllcache\mshtml.dll [-] 2012-03-01 . 467D9D5FB15DD88E82768C6F31A7A5D4 . 5980672 . . [8.00.6001.23318] . . c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\mshtml.dll [-] 2011-12-17 . 5C55673322584D9F5A32D0971D83858B . 5979136 . . [8.00.6001.19190] . . c:\windows\ie8updates\KB2675157-IE8\mshtml.dll [-] 2011-12-17 . 46FE106946083872716147AD223F20C1 . 5980160 . . [8.00.6001.23286] . . c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll [-] 2011-11-04 . 958ECE072DA2D840BD3658A3AB708F58 . 5978112 . . [8.00.6001.19170] . . c:\windows\ie8updates\KB2647516-IE8\mshtml.dll [-] 2011-11-04 . E43D37858B634BDE1E099E92F0202458 . 5978624 . . [8.00.6001.23266] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll [-] 2011-10-03 . 2ECD546FB8594A4C5D807E489045627F . 5971456 . . [8.00.6001.19154] . . c:\windows\ie8updates\KB2618444-IE8\mshtml.dll [-] 2011-10-03 . 5AF7AC6924E7CB72D76A796262B1C25E . 5972992 . . [8.00.6001.23250] . . c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll [-] 2011-07-25 . 39ADF0F29F47896DD726833735AB825C . 5969920 . . [8.00.6001.19120] . . c:\windows\ie8updates\KB2586448-IE8\mshtml.dll [-] 2011-07-25 . 03B085EEE1DB5F2E32721CF5C72F7A26 . 5971456 . . [8.00.6001.23216] . . c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtml.dll [-] 2011-05-30 . 7EA2A988004ED9A3D9DC5192DC547C57 . 5964800 . . [8.00.6001.19088] . . c:\windows\ie8updates\KB2559049-IE8\mshtml.dll [-] 2011-05-30 . 6DE2D62A51F4C110AA995583B7463487 . 5967360 . . [8.00.6001.23181] . . c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\mshtml.dll [-] 2011-02-22 . 80A564DD39C82A79F34F5A093CE1A6BD . 5964800 . . [8.00.6001.23141] . . c:\windows\$hf_mig$\KB2497640-IE8\SP3QFE\mshtml.dll [-] 2011-02-22 . E7618AEF7203F57D94266153C7E514C4 . 5962240 . . [8.00.6001.19046] . . c:\windows\ie8updates\KB2530548-IE8\mshtml.dll [-] 2010-12-20 . 91F5FB2C81CBE00B36B7F90E8DFDEC9E . 5961216 . . [8.00.6001.19019] . . c:\windows\ie8updates\KB2497640-IE8\mshtml.dll [-] 2010-12-20 . 55F5920E04513ED481129E5E1DD94772 . 5962240 . . [8.00.6001.23111] . . c:\windows\$hf_mig$\KB2482017-IE8\SP3QFE\mshtml.dll [-] 2010-11-06 . F22C3F322F5291FECDCC13371E3909A4 . 5960704 . . [8.00.6001.23091] . . c:\windows\$hf_mig$\KB2416400-IE8\SP3QFE\mshtml.dll [-] 2010-11-06 . CB4E08223EFCEB7C9E534D7A2AB00D6A . 5959168 . . [8.00.6001.18999] . . c:\windows\ie8updates\KB2482017-IE8\mshtml.dll [-] 2010-09-10 . 83C01E6BEE0BAEAC11B7C681302E7F18 . 5957120 . . [8.00.6001.18975] . . c:\windows\ie8updates\KB2416400-IE8\mshtml.dll [-] 2010-09-10 . 90215AE398050E9510A5B71CD222A6FD . 5958656 . . [8.00.6001.23067] . . c:\windows\$hf_mig$\KB2360131-IE8\SP3QFE\mshtml.dll [-] 2010-06-24 . 4866ECEEFB5964BB1CB081FB3A2A370D . 5954560 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\mshtml.dll [-] 2010-06-24 . 1048BF4C23101A0404252A19A9151C16 . 5951488 . . [8.00.6001.18939] . . c:\windows\ie8updates\KB2360131-IE8\mshtml.dll [-] 2010-05-06 . E7CD22F3A8247FC3BFD283D30B4674D2 . 5950976 . . [8.00.6001.18928] . . c:\windows\ie8updates\KB2183461-IE8\mshtml.dll [-] 2010-05-06 . 47A7DDF5DF0F323F877EEFC75338C4A3 . 5953024 . . [8.00.6001.23019] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll [-] 2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . [8.00.6001.18904] . . c:\windows\ie8updates\KB982381-IE8\mshtml.dll [-] 2010-02-25 . 2399C13AE076A84037794AA0E9BF152A . 5946880 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll [-] 2009-12-21 . 0C92E8AAD0E68E0A5358813353F31CE3 . 5942784 . . [8.00.6001.18876] . . c:\windows\ie8updates\KB980182-IE8\mshtml.dll [-] 2009-12-21 . 585A8B2FD6373FC06D6893867754CF74 . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll [-] 2009-10-29 . 1185E34AB3243194BB57FD3C31385700 . 3091968 . . [6.00.2900.5897] . . c:\windows\ie8\mshtml.dll [-] 2009-10-29 . A66CEDA2AA6FA052D3F7A46CE7553D21 . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll [-] 2009-10-29 . A66CEDA2AA6FA052D3F7A46CE7553D21 . 5940736 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3GDR\mshtml.dll [-] 2009-10-29 . 6D626567986D37E021F44EE66446D515 . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll [-] 2009-10-29 . 6D626567986D37E021F44EE66446D515 . 5944320 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3QFE\mshtml.dll [-] 2009-10-29 . F7E06360F7DAFED78647AAFCC7ADBBC5 . 3094016 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll [-] 2009-10-19 . 0B2E964BEB51B4004329061F87B261FB . 3091968 . . [6.00.2900.5890] . . c:\windows\$NtUninstallKB976325$\mshtml.dll [-] 2009-10-19 . 2ECF5281C946A38CFDA0E591C2B1A258 . 3093504 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3QFE\mshtml.dll [-] 2009-09-25 . 03C83F354CDFAA7A804AC5B76D46AC07 . 3091968 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976749$\mshtml.dll [-] 2009-09-25 . A5C706F4A21ED747E30F93547A7CCA38 . 3093504 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll [-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll [-] 2008-04-14 . B937B964B164A7B588D09BF419F90875 . 3066880 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB974455$\mshtml.dll [-] 2008-04-14 . B937B964B164A7B588D09BF419F90875 . 3066880 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\mshtml.dll [-] 2003-04-08 . 28BA7BF8F2BB53E4DD9D43914142737E . 2833920 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\mshtml.dll . [-] 2008-04-14 . 074C38B50CE71E3EC6DD3F6DAABF4EEF . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll [-] 2008-04-14 . 074C38B50CE71E3EC6DD3F6DAABF4EEF . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll [-] 2008-04-14 . 61E70054981A2F9E64CEA7CA9479C0AA . 343040 . . [7.0.2600.5512] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll [-] 2003-04-08 . 33D03EC823482177D5171907AF19FFF9 . 323072 . . [7.0.2600.1106] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll [-] 2003-04-08 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll [-] 2003-04-08 . 1B2C477D8847E4123DD8761D2E9008F7 . 323072 . . [7.0.2600.1106] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.10.0_x-ww_d8862ba3\msvcrt.dll . [-] 2008-06-20 . 74816260AECBE87C473962A359007EEB . 247296 . . [5.1.2600.5625] . . c:\windows\$NtUninstallKB2509553$\mswsock.dll [-] 2008-06-20 . 18740E8EC5BE4B6D66FA0E4CBFD3B9C6 . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\mswsock.dll [-] 2008-06-20 . 18740E8EC5BE4B6D66FA0E4CBFD3B9C6 . 247296 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll [-] 2008-06-20 . 4522CBE00A9E9EEE36AA82ED4B319148 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll [-] 2008-06-20 . 4522CBE00A9E9EEE36AA82ED4B319148 . 247296 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll [-] 2008-04-14 . 6BBC05038DF477F12E930A0F99F7D219 . 247296 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\mswsock.dll [-] 2008-04-14 . 6BBC05038DF477F12E930A0F99F7D219 . 247296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll [-] 2003-04-08 . 3F7E336DB0EFC89708EE53EC8B3617DB . 230400 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\mswsock.dll . [-] 2008-04-14 . E6A7071DF6855AB7CCCC220AC3AAD087 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll [-] 2008-04-14 . E6A7071DF6855AB7CCCC220AC3AAD087 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll [-] 2003-04-08 . 87BD1441F4DB1951A80365E236D7568E . 399360 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\netlogon.dll . [-] 2008-04-14 . 32167CE0150DC2A269D99689A143FB67 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll [-] 2008-04-14 . 32167CE0150DC2A269D99689A143FB67 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll [-] 2003-04-08 . 506AEC11B86CCFF9894FEA9BB1C1BDCD . 14848 . . [6.00.2600.0000] . . c:\windows\$NtServicePackUninstall$\powrprof.dll . [-] 2008-04-14 . 0E3B585761E23C1E35442E972B7E45F9 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll [-] 2008-04-14 . 0E3B585761E23C1E35442E972B7E45F9 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll [-] 2003-04-08 . 5BD3F85CFA1073712E4911BB5751AD86 . 179200 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\scecli.dll . [-] 2008-04-14 . E6DCF5DD55AC2655971A478718307D18 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll [-] 2008-04-14 . E6DCF5DD55AC2655971A478718307D18 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll [-] 2003-04-08 . 750A97F61172F0917AE97E8931E164CE . 4096 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\sfc.dll . [-] 2008-04-14 . E410EC73E2BE2A41D923B006F51C8427 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe [-] 2008-04-14 . E410EC73E2BE2A41D923B006F51C8427 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe [-] 2003-04-08 . 133733E07EF4FDA582BC56F3B281E0BC . 12800 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\svchost.exe . [-] 2008-04-14 . 2BC9FB448F0C2394FF53C83A7BB04731 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll [-] 2008-04-14 . 2BC9FB448F0C2394FF53C83A7BB04731 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll [-] 2003-04-08 . D482CBF778D95C532F3A4C2648EB4B8B . 233984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll . [-] 2008-04-14 . 4CF588D2F2363B73EB4AF57967D46DFF . 580096 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll [-] 2008-04-14 . 4CF588D2F2363B73EB4AF57967D46DFF . 580096 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2003-04-08 . 2E8CEC28BE4D9B830BA0AFF73C9279F7 . 561664 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\user32.dll . [-] 2008-04-14 . 6818A533ED3B2FA9936DF3DAF45352DF . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe [-] 2008-04-14 . 6818A533ED3B2FA9936DF3DAF45352DF . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe [-] 2003-04-08 . 54EB9CE26234AE9116555C587FAED658 . 22016 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\userinit.exe . [-] 2012-03-01 . CFF17B16BFF8179FBBA29075245E8BE1 . 916992 . . [8.00.6001.19222] . . c:\windows\system32\wininet.dll [-] 2012-03-01 . CFF17B16BFF8179FBBA29075245E8BE1 . 916992 . . [8.00.6001.19222] . . c:\windows\system32\dllcache\wininet.dll [-] 2012-03-01 . B2E54BC4C5B399547EE3C8188DBBA509 . 919552 . . [8.00.6001.23318] . . c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\wininet.dll [-] 2011-12-17 . 03CB14FB6B75EC8AC2FDEC54E904C30B . 916992 . . [8.00.6001.19190] . . c:\windows\ie8updates\KB2675157-IE8\wininet.dll [-] 2011-12-17 . 38C3CDBC40464D40C7B716C8E154B86C . 919552 . . [8.00.6001.23286] . . c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\wininet.dll [-] 2011-11-04 . D47FE623B45DF066647469DB73AE3215 . 916992 . . [8.00.6001.19165] . . c:\windows\ie8updates\KB2647516-IE8\wininet.dll [-] 2011-11-04 . A484703720C95391777DF05F2458FEF8 . 919552 . . [8.00.6001.23261] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll [-] 2011-08-22 . 381FDBF8A25C7629696E5EE2B213F8CC . 916480 . . [8.00.6001.19131] . . c:\windows\ie8updates\KB2618444-IE8\wininet.dll [-] 2011-08-22 . EDD945F6C0630DB8453673DF9E7B009E . 919552 . . [8.00.6001.23227] . . c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll [-] 2011-06-23 . 14FB4665EFBDCE6931A55752A44F7DE2 . 916480 . . [8.00.6001.19098] . . c:\windows\ie8updates\KB2586448-IE8\wininet.dll [-] 2011-06-23 . 3BC2081CD791584B4ED373F3B4959CC8 . 919552 . . [8.00.6001.23192] . . c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\wininet.dll [-] 2011-04-25 . 1C95CF3DBAEBB3CCA34845CD884FB8CA . 916480 . . [8.00.6001.19072] . . c:\windows\ie8updates\KB2559049-IE8\wininet.dll [-] 2011-04-25 . 00F17371D9145B114061564BDABD8C24 . 919552 . . [8.00.6001.23165] . . c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\wininet.dll [-] 2011-02-22 . CC5AE9A79DA18AFD29FB7CF95F23A143 . 919552 . . [8.00.6001.23139] . . c:\windows\$hf_mig$\KB2497640-IE8\SP3QFE\wininet.dll [-] 2011-02-22 . 51B29ABC95E882F7AD80FDBFD5E729CC . 916480 . . [8.00.6001.19044] . . c:\windows\ie8updates\KB2530548-IE8\wininet.dll [-] 2010-12-20 . 81BB5AF5584545323F20AA75610EBD01 . 916480 . . [8.00.6001.19019] . . c:\windows\ie8updates\KB2497640-IE8\wininet.dll [-] 2010-12-20 . 21A739156ED963C45419D3EB02E44F0C . 919552 . . [8.00.6001.23111] . . c:\windows\$hf_mig$\KB2482017-IE8\SP3QFE\wininet.dll [-] 2010-11-06 . 51964C721E751FD4E798252CC0E4FFB9 . 919552 . . [8.00.6001.23084] . . c:\windows\$hf_mig$\KB2416400-IE8\SP3QFE\wininet.dll [-] 2010-11-06 . BCEB709EF4C751E0BE355B76D834A954 . 916480 . . [8.00.6001.18992] . . c:\windows\ie8updates\KB2482017-IE8\wininet.dll [-] 2010-09-10 . EA2E4CFB3F124DD54F3B02F3BCCF6E82 . 916480 . . [8.00.6001.18968] . . c:\windows\ie8updates\KB2416400-IE8\wininet.dll [-] 2010-09-10 . 5D081F5E3E46966C4F63D32231C93511 . 919552 . . [8.00.6001.23060] . . c:\windows\$hf_mig$\KB2360131-IE8\SP3QFE\wininet.dll [-] 2010-06-24 . 8168F7D81CD04C83D7E04F3981A7D0F5 . 919040 . . [8.00.6001.23037] . . c:\windows\$hf_mig$\KB2183461-IE8\SP3QFE\wininet.dll [-] 2010-06-24 . A3D63C0EF4D32F1F04D9E9596AEA0FFE . 916480 . . [8.00.6001.18939] . . c:\windows\ie8updates\KB2360131-IE8\wininet.dll [-] 2010-05-06 . 109D1EFA1C0BC4EC65EBA39707F31A19 . 916480 . . [8.00.6001.18923] . . c:\windows\ie8updates\KB2183461-IE8\wininet.dll [-] 2010-05-06 . A319118B77A91EB08AB2BF098D91900E . 919040 . . [8.00.6001.23014] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll [-] 2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . [8.00.6001.18904] . . c:\windows\ie8updates\KB982381-IE8\wininet.dll [-] 2010-02-25 . BB424C9406140FEAFB4732025BEBB69B . 919040 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll [-] 2009-12-21 . FA2B753F8FE84904A6940589A43F30B4 . 916480 . . [8.00.6001.18876] . . c:\windows\ie8updates\KB980182-IE8\wininet.dll [-] 2009-12-21 . 4C145AB616871611FCE38F053C75807C . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll [-] 2009-10-29 . 765E049E1F6E2EF9265B85E02DE487B5 . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll [-] 2009-10-29 . 765E049E1F6E2EF9265B85E02DE487B5 . 916480 . . [8.00.6001.18854] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3GDR\wininet.dll [-] 2009-10-29 . D906535CAB4BB8A60AC060351EDE159F . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll [-] 2009-10-29 . D906535CAB4BB8A60AC060351EDE159F . 916480 . . [8.00.6001.22945] . . c:\windows\SoftwareDistribution\Download\792c3010f653aab38ec50674cded8698\SP3QFE\wininet.dll [-] 2009-10-29 . 772A3480B543FB5280DE1679FA73E799 . 670208 . . [6.00.2900.5897] . . c:\windows\ie8\wininet.dll [-] 2009-10-29 . 77DA6400FF88337FE260CF87A530D64C . 671744 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\wininet.dll [-] 2009-09-25 . E3A0D172FF21D1F0B30CB3B9671ADEBF . 670208 . . [6.00.2900.5880] . . c:\windows\$NtUninstallKB976325$\wininet.dll [-] 2009-09-25 . 2A7566FCBB31765DC1D710EA5928D059 . 671744 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\wininet.dll [-] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll [-] 2008-04-14 . 80CA4DCDD3DAD65CB8800508076712E7 . 669184 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB974455$\wininet.dll [-] 2008-04-14 . 80CA4DCDD3DAD65CB8800508076712E7 . 669184 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\wininet.dll [-] 2003-04-08 . 87DF44F9B70BBF94D4143C21A5CB42BA . 602112 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\wininet.dll . [-] 2008-04-14 . 520391367546218929749612ABFE840C . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll [-] 2008-04-14 . 520391367546218929749612ABFE840C . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll [-] 2003-04-08 . 3EA6EDC08BB3F373839060EA8B40CE72 . 75264 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll . [-] 2008-04-14 . 7ED22EA6D840CD388BD68B68580468E1 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll [-] 2008-04-14 . 7ED22EA6D840CD388BD68B68580468E1 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll [-] 2003-04-08 . D1588F506FD5CF8DAE843E6A534ADBB1 . 18944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ws2help.dll . [-] 2008-04-14 . AA04F042A820BF1868E643575887E1A6 . 1037312 . . [6.00.2900.5512] . . c:\windows\explorer.exe [-] 2008-04-14 . AA04F042A820BF1868E643575887E1A6 . 1037312 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe [-] 2003-04-08 . 040CC36796BBA354B678BCE9DCB25A3A . 1007616 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\explorer.exe . [-] 2008-04-14 . E67C9B97306DEEFBB481072CE5FF8E07 . 153088 . . [5.1.2600.5512] . . c:\windows\regedit.exe [-] 2008-04-14 . E67C9B97306DEEFBB481072CE5FF8E07 . 153088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regedit.exe [-] 2003-04-08 . 6946EA65B65D24B0EFB9DB2EC7B2798B . 140800 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\regedit.exe . [-] 2011-11-01 . DB355CEF2B35481C21DD213C28560E86 . 1288192 . . [5.1.2600.6168] . . c:\windows\system32\ole32.dll [-] 2011-11-01 . DB355CEF2B35481C21DD213C28560E86 . 1288192 . . [5.1.2600.6168] . . c:\windows\system32\dllcache\ole32.dll [-] 2011-11-01 . 02AF8E4C7B851A213AC70BF6DD6E3537 . 1288704 . . [5.1.2600.6168] . . c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll [-] 2010-07-16 . AD2B41BEAB5BB7A258F6A2CCDCA09B82 . 1287680 . . [5.1.2600.6010] . . c:\windows\$NtUninstallKB2624667$\ole32.dll [-] 2010-07-16 . 57F12B548695C680421CD1EB8169A1C8 . 1288704 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll [-] 2008-04-14 . B2EE0E38A8025D6D7A7F3EEC8CA2829E . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll [-] 2008-04-14 . B2EE0E38A8025D6D7A7F3EEC8CA2829E . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll [-] 2003-04-08 . 8C57515321D7FFD77ADD70517D7BE737 . 1169920 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ole32.dll . [-] 2010-04-16 . 36BA0AAABD0AA4798403CB3FF08D5DDD . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\usp10.dll [-] 2010-04-16 . 36BA0AAABD0AA4798403CB3FF08D5DDD . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\dllcache\usp10.dll [-] 2010-04-16 . 7BB3922CB9973877D2BF4C7222EA8E70 . 406016 . . [1.0420.2600.5969] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll [-] 2008-04-14 . 0996802B726C0CFE94A44CDBD661983A . 406016 . . [1.0420.2600.5512] . . c:\windows\$NtUninstallKB981322$\usp10.dll [-] 2008-04-14 . 0996802B726C0CFE94A44CDBD661983A . 406016 . . [1.0420.2600.5512] . . c:\windows\ServicePackFiles\i386\usp10.dll [-] 2003-04-08 . 628A315978A88D1E4C9B45C93BA6478D . 339456 . . [1.0409.2600.1106] . . c:\windows\$NtServicePackUninstall$\usp10.dll . [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\ksuser.dll [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\system32\ksuser.dll [-] 2008-04-14 . 2D54DB081CDACF8C0B738B9F25B25DCD . 4096 . . [5.3.2600.5512] . . c:\windows\system32\dllcache\ksuser.dll [-] 2002-12-11 22:14 . 15914E0BF4DDA56CF797993DCCB637D1 . 4096 . . [5.3.0000000.900 built by: DIRECTX] . . c:\windows\Driver Cache\i386\ksuser.dll [-] 2002-12-11 22:14 . 15914E0BF4DDA56CF797993DCCB637D1 . 4096 . . [5.3.0000000.900 built by: DIRECTX] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ksuser.dll [-] 2001-09-06 . 7C025E147BE747A7AD038E33B10A923B . 4096 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\ksuser.dll . [-] 2008-04-14 . E98A8C802CDB31FCF4121D9DFBEA3677 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe [-] 2008-04-14 . E98A8C802CDB31FCF4121D9DFBEA3677 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe [-] 2003-04-08 . BC69FEECC644021E56745C2E10C49EF2 . 13312 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe . [-] 2009-07-27 . 2D5D4156292150FE571872C1B88E9299 . 135680 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll [-] 2009-07-27 . 2D5D4156292150FE571872C1B88E9299 . 135680 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll [-] 2009-07-27 . C28A9E9D28ACDAF8097BE4578C49559B . 135680 . . [6.00.2900.5853] . . c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll [-] 2008-04-14 . CFB406497D9CF95DFFE17594899FD367 . 135680 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll [-] 2008-04-14 . CFB406497D9CF95DFFE17594899FD367 . 135680 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll [-] 2003-04-08 . 99792E295E5A4E7BCD08F4D708E16AAB . 116736 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll . [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll [-] 2003-04-08 . 323020B1DF45D8B80886C1806AF35595 . 158720 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\srsvc.dll . [-] 2008-04-14 . 6F1E5DBA783B147536659395D7B15485 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe [-] 2008-04-14 . 6F1E5DBA783B147536659395D7B15485 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe . [-] 2008-04-14 . FD3C38635808920F8235BF2FED642F54 . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll [-] 2008-04-14 . FD3C38635808920F8235BF2FED642F54 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll . [-] 2008-04-14 . CA64B9406EEDA4FFA2DAEAE1DABCCE42 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll [-] 2008-04-14 . CA64B9406EEDA4FFA2DAEAE1DABCCE42 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll [-] 2003-04-08 . 7593FA76DAFDBD9511A9A2B1465FF8C2 . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\eventlog.dll . [-] 2008-04-14 . 328CBDD2445F5B3A047644567EEB557F . 1571840 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll [-] 2008-04-14 . 328CBDD2445F5B3A047644567EEB557F . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll [-] 2003-04-08 . 3B8FA96FF436D4CD4E0D13223F965FAB . 1145856 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll . [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys [-] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ipsec.sys [-] 2003-04-08 . 1C4802409CFD4A7051F458B744CFCAA5 . 57984 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ipsec.sys . [-] 2008-04-14 . 2FD5B89BF9289C774C5C730DEA96CD91 . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll [-] 2008-04-14 . 2FD5B89BF9289C774C5C730DEA96CD91 . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll [-] 2003-04-08 . 548ACD377576BDABAC2E190F6D156906 . 51712 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\regsvc.dll . [-] 2008-04-14 . 7C288AE0F75CB18CFF1DF6179A67AD8F . 193536 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll [-] 2008-04-14 . 7C288AE0F75CB18CFF1DF6179A67AD8F . 193536 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll [-] 2003-04-08 . 5239C9913F5166838D772BF4A61C7844 . 160256 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll . [-] 2008-04-14 . 5B9D0DE64BE96A806819516440FD211C . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll [-] 2008-04-14 . 5B9D0DE64BE96A806819516440FD211C . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll [-] 2003-04-08 . 41F71DCF93421F867B0D40ECF1A74287 . 43008 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll . [-] 2008-04-14 . E0AEF86A594C9990D6321C5CA239C5B7 . 297472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll [-] 2008-04-14 . E0AEF86A594C9990D6321C5CA239C5B7 . 297472 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll [-] 2003-04-08 . 6AF0C847079356FE152BFD53A60D7487 . 202240 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\termsrv.dll . [-] 2008-04-14 . 6F18B42068D29B1F6F283DC37057836D . 347648 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\hnetcfg.dll [-] 2008-04-14 . 6F18B42068D29B1F6F283DC37057836D . 347648 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll [-] 2003-04-08 . B176F863C9B6A5773E58D98770F9BAC5 . 244224 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\hnetcfg.dll . [-] 2003-04-08 . 63F517B1A87DABF3F5ACB8A7952FC1D1 . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys . [-] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys [-] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys [-] 2002-08-28 23:16 . FF773FEDA15E8BD97FD54FE87A0ACDBE . 142208 . . [5.1.2601.1095 built by: xpsp1] . . c:\windows\$NtServicePackUninstall$\aec.sys . [-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys [-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys . [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys . [-] 2010-09-18 07:18 . C7F383764824117AEE9C3ED0FCA78044 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll [-] 2010-09-18 06:53 . 7892005CE5CDC809783F452B21FAF58F . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll [-] 2010-09-18 06:53 . 7892005CE5CDC809783F452B21FAF58F . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll [-] 2008-04-14 21:32 . 2407EADA5E2E146AB51E925F151DDAA5 . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll [-] 2008-04-14 21:32 . 2407EADA5E2E146AB51E925F151DDAA5 . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll [-] 2003-04-08 12:00 . 8EED1D71C14C356684E586B0A7DB6BCE . 924432 . . [4.1.6140] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll . [-] 2008-04-14 . C56A45A03DCA11712DE9FDF98224230B . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll [-] 2008-04-14 . C56A45A03DCA11712DE9FDF98224230B . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll [-] 2003-04-08 . F9DAEE255E7ED81BC6DCD67BFEF826EA . 34304 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll . [-] 2008-04-14 21:32 . 2628076412EC86C92827AE5202501E5D . 52736 . . [9.0.1.56] . . c:\windows\system32\mspmsnsv.dll [-] 2008-04-14 21:32 . 2628076412EC86C92827AE5202501E5D . 52736 . . [9.0.1.56] . . c:\windows\system32\dllcache\mspmsnsv.dll . [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\86f34e8e8337fe6cdc7fe05b56b200e0\sp3gdr\ntkrnlpa.exe [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\system32\ntkrnlpa.exe [-] 2012-04-11 . E7A9D6E071F8ABDAED0D8610FEA3F828 . 2073472 . . [5.1.2600.6206] . . c:\windows\system32\dllcache\ntkrnlpa.exe [-] 2012-04-11 . 44F045B4BE9D99929DDD48C045480237 . 2073472 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe [-] 2012-04-11 . 44F045B4BE9D99929DDD48C045480237 . 2073472 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\86f34e8e8337fe6cdc7fe05b56b200e0\sp3qfe\ntkrnlpa.exe [-] 2011-10-26 . 2820129F67352B99B032DE2CF328C767 . 2073728 . . [5.1.2600.6165] . . c:\windows\$NtUninstallKB2676562$\ntkrnlpa.exe [-] 2011-10-26 . 769A1C9E9641DCED4D0AC50968ADDA4E . 2073728 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe [-] 2010-12-09 . BAD22963CD6046C0B2834D2BFFAB56B5 . 2073728 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe [-] 2010-12-09 . 63905B20972EFB06169008F6F4BC8697 . 2073728 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe [-] 2010-04-28 . 75EA98BC36C13E976653400F8183D356 . 2071296 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe [-] 2010-04-28 . F98305BD47DC7A0B2A978000E3C31FAB . 2071168 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe [-] 2010-02-16 . F6049CA4515D37D5DA502D162E9B6AA0 . 2071168 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe [-] 2010-02-16 . 7C4F935FC449E4D27C685A5BC1792664 . 2071296 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe [-] 2009-12-09 . 6A42A70506E7ACFF6C3ACD740E22A01F . 2070528 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe [-] 2009-12-09 . F63B0CC3CE1E6E8EA39B4933B595C73A . 2070400 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe [-] 2009-08-04 . AB21A63A3B15653043E71126E5BBE3DE . 2070528 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe [-] 2009-08-04 . BF6965EA17CC1E48DA287783AEEF3CDB . 2070400 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe [-] 2009-02-09 . 07EE73D79A7CA142463470AEF230082B . 2070528 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe [-] 2008-04-14 . 6129DA5C68C13DCA12E77580730FD770 . 2070272 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe [-] 2008-04-14 . 6129DA5C68C13DCA12E77580730FD770 . 2070272 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe [-] 2003-04-08 . 13C45289C0E4F23CF129417DCA1F2F6E . 1952128 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe . [-] 2008-04-14 21:32 . AC1A78237B53044735693633F8235468 . 437248 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll [-] 2008-04-14 21:32 . AC1A78237B53044735693633F8235468 . 437248 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll [-] 2003-04-08 12:00 . 5117C60E5FC52F0E2BD02E6B0451AE9F . 394752 . . [5.1.2400.1106] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll . [-] 2008-04-14 . 01653D6C9604F1FB31A76EC94E08954F . 186368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll [-] 2008-04-14 . 01653D6C9604F1FB31A76EC94E08954F . 186368 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll [-] 2003-04-08 . 5B2B6BA37D7AA9BC8BF9669F30CE138A . 165376 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\upnphost.dll . [-] 2008-04-14 . 3A9974C925F4500BFF226F61DE1C4AF8 . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll [-] 2008-04-14 . 3A9974C925F4500BFF226F61DE1C4AF8 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll [-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll [-] 2004-07-09 02:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\dsound.dll [-] 2003-04-08 . 3CDD0C6B44422DF1432947FA256F84F2 . 338944 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\dsound.dll . [-] 2008-04-14 . 85F98F220C5E69E08149186BFEEF7B70 . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll [-] 2008-04-14 . 85F98F220C5E69E08149186BFEEF7B70 . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll . [-] 2008-04-14 . 7D2ABE7AA2D6CBC1CB0A1EB8B2619FCF . 279552 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll [-] 2008-04-14 . 7D2ABE7AA2D6CBC1CB0A1EB8B2619FCF . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll [-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll [-] 2004-07-09 02:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\ddraw.dll [-] 2003-04-08 . 16C2C306A75567A957F6B7A80DF512A2 . 253440 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ddraw.dll . [-] 2008-04-14 21:32 . 6508ED3152C29B28B5E9183160DD2686 . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll [-] 2008-04-14 21:32 . 6508ED3152C29B28B5E9183160DD2686 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll [-] 2003-04-08 12:00 . 11171D442A392E556EBDCE15EA7E62CD . 106496 . . [5.0.5014] . . c:\windows\$NtServicePackUninstall$\olepro32.dll . [-] 2008-04-14 . E62337E275E82AA3F0ABFFED7E6E01E2 . 41472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll [-] 2008-04-14 . E62337E275E82AA3F0ABFFED7E6E01E2 . 41472 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll [-] 2003-04-08 . 431AA2EC8F7F4D6F6112D17D4C76DAAE . 38912 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\perfctrs.dll . [-] 2008-04-14 . 85844EC167674A67F547E13747E3E0E3 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\version.dll [-] 2008-04-14 . 85844EC167674A67F547E13747E3E0E3 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll [-] 2003-04-08 . 049F5724E94B45B8F01EFEDAF5218C21 . 16384 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\version.dll . [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\Driver Cache\i386\ntoskrnl.exe [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\86f34e8e8337fe6cdc7fe05b56b200e0\sp3gdr\ntoskrnl.exe [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\system32\ntoskrnl.exe [-] 2012-04-11 . 8E5DFDF86DF4B5E66CFA794C92C4606C . 2196992 . . [5.1.2600.6206] . . c:\windows\system32\dllcache\ntoskrnl.exe [-] 2012-04-11 . 46190EF7B8A978A3B677248A377F43D3 . 2196992 . . [5.1.2600.6206] . . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntoskrnl.exe [-] 2012-04-11 . 46190EF7B8A978A3B677248A377F43D3 . 2196992 . . [5.1.2600.6206] . . c:\windows\SoftwareDistribution\Download\86f34e8e8337fe6cdc7fe05b56b200e0\sp3qfe\ntoskrnl.exe [-] 2011-10-26 . 8E305C5AC846388E99C1204D619AE77A . 2197120 . . [5.1.2600.6165] . . c:\windows\$NtUninstallKB2676562$\ntoskrnl.exe [-] 2011-10-26 . CA76947F97276D52D4731EA2364ECBD8 . 2197120 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe [-] 2010-12-09 . 431D614A7395BADB939FE552DBDD8723 . 2197120 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe [-] 2010-12-09 . EA2A3B68CCF886B76403C37954F2E6EE . 2197120 . . [5.1.2600.6055] . . c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe [-] 2010-04-28 . 548AED38DF451C1783037390194A04DC . 2194304 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe [-] 2010-04-28 . 59582F46CAAAA049DB613B4005AF57B5 . 2194432 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe [-] 2010-02-17 . FD62829F3524A1BE95FD384A3C445AAB . 2194304 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe [-] 2010-02-16 . B79C48187CA08D2EC27DA4939953F082 . 2194432 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe [-] 2009-12-09 . 5037978D6ED651AEC5D6ACC87D65C715 . 2193664 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe [-] 2009-12-09 . 13C15BFF7E82D3F9FD215ADD54A3929D . 2193536 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe [-] 2009-08-04 . 270DE336026B0815F064BB8BD4CFD336 . 2193536 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe [-] 2009-08-04 . 2F1443AB72A64182FD8258BBAE801EA7 . 2193664 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe [-] 2009-02-10 . 7625D5BAFD2A4A8458468B139C893BB7 . 2193536 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe [-] 2008-04-14 . 140A1BAD8A6642C1386BB5B388EB447F . 2193408 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe [-] 2008-04-14 . 140A1BAD8A6642C1386BB5B388EB447F . 2193408 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe [-] 2003-04-08 . ED3086CF7C835D8A3FD0E6FBD95C0F53 . 2046464 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe . [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll [-] 2008-04-14 . 81CBF363C414620CAA61BD6843D8FDB9 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll [-] 2003-04-08 . 323020B1DF45D8B80886C1806AF35595 . 158720 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\srsvc.dll . [-] 2008-04-14 . 390D8E65F362327AD510B08971478301 . 176128 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\w32time.dll [-] 2008-04-14 . 390D8E65F362327AD510B08971478301 . 176128 . . [5.1.2600.5512] . . c:\windows\system32\w32time.dll [-] 2003-04-08 . 910C770BBEB488B2163924988FB6B07A . 166400 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\w32time.dll . [-] 2008-04-14 . 5AE996186D2DC694FEF88F14A3FC9242 . 334336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wiaservc.dll [-] 2008-04-14 . 5AE996186D2DC694FEF88F14A3FC9242 . 334336 . . [5.1.2600.5512] . . c:\windows\system32\wiaservc.dll [-] 2003-04-08 . 415531BDA25C2F8D1D342CD47A3BBC8C . 316928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\wiaservc.dll . [-] 2008-04-14 . 5203C84A11E39CBB1408F5E2767B04ED . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\midimap.dll [-] 2008-04-14 . 5203C84A11E39CBB1408F5E2767B04ED . 18944 . . [5.1.2600.5512] . . c:\windows\system32\midimap.dll [-] 2003-04-08 . 96DF0DD74F5BB1A16CCCF707793875FB . 17920 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\midimap.dll . [-] 2008-04-14 . 3D5CC4BFF926A0ABD4F5A117825629A3 . 7680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rasadhlp.dll [-] 2008-04-14 . 3D5CC4BFF926A0ABD4F5A117825629A3 . 7680 . . [5.1.2600.5512] . . c:\windows\system32\rasadhlp.dll [-] 2003-04-08 . 8B36031EB26860D00D12C87941D27471 . 6144 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\rasadhlp.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\thera-johan\Menu Start\Programma's\Opstarten\ OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Joke en Geert^Menu Start^Programma's^Opstarten^OneNote 2007 Schermopname en Snel starten.lnk] path=c:\documents and settings\Joke en Geert\Menu Start\Programma's\Opstarten\OneNote 2007 Schermopname en Snel starten.lnk backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-02 09:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-11-01 22:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY] 2012-01-24 15:24 2416480 ----a-w- c:\program files\AVG\AVG2012\avgtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116] 1998-11-30 16:04 497376 ----a-w- c:\windows\p_981116.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2003-06-25 10:24 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-12-08 00:36 421736 ----a-w- d:\itunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 21:33 1695232 ------w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2010-02-10 21:32 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.EXE"= "c:\\Program Files\\Call of Duty\\CoDMP.exe"= "c:\\Documents and Settings\\Ro-elle\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Call of Duty\\CoDUOMP.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "d:\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"= "c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56872:TCP"= 56872:TCP:Pando Media Booster "56872:UDP"= 56872:UDP:Pando Media Booster . R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8-5-2012 21:10 654408] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8-5-2012 21:10 22344] S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [16-11-2009 17:58 135664] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 9:16 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7-4-2012 14:13 257696] S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:37 24448] S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [16-11-2009 17:58 135664] S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [29-7-2010 0:25 25112] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [20-5-2012 18:32 40776] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [28-4-2012 20:47 129976] S3 XDva343;XDva343;\??\c:\windows\system32\XDva343.sys --> c:\windows\system32\XDva343.sys [?] . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - WS2IFSL . Inhoud van de 'Gedeelde Taken' map . 2012-05-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 19:05] . 2012-05-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:57] . 2012-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc705a23128c8c.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-16 15:58] . 2012-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc705a2319b39a.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-16 15:58] . 2012-05-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-261478967-725345543-1006Core.job - c:\documents and settings\Ro-elle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-20 15:19] . 2012-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-261478967-725345543-1006UA.job - c:\documents and settings\Ro-elle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-20 15:19] . 2012-05-21 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . 2012-05-21 c:\windows\Tasks\MpIdleTask.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . 2012-05-21 c:\windows\Tasks\User_Feed_Synchronization-{7F81D862-2402-4401-B041-45603D31C752}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31] . . ------- Bijkomende Scan ------- . mSearch Bar = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\documents and settings\thera-johan\Application Data\Mozilla\Firefox\Profiles\goggo5vg.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3196716&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3196716&SearchSource=13 . - - - - ORPHANS VERWIJDERD - - - - . HKLM-Run-Soltek - c:\windows\system32\autorun.exe MSConfigStartUp-BitTorrent DNA - c:\program files\DNA\btdna.exe MSConfigStartUp-GabPath - c:\documents and settings\kinderen\Application Data\GabPath\gabpath.exe MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\mwsoemon.exe MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL MSConfigStartUp-SfKg6wIPuSp - c:\documents and settings\kinderen\Application Data\Microsoft\Windows\jnipmo.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-05-21 21:18 Windows 5.1.2600 Service Pack 3 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . --------------------- DLLs Geladen Onder Lopende Processen --------------------- . - - - - - - - > 'winlogon.exe'(632) c:\windows\system32\Ati2evxx.dll . - - - - - - - > 'explorer.exe'(152) c:\windows\system32\webcheck.dll . ------------------------ Andere Aktieve Processen ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Microsoft Security Client\MsMpEng.exe c:\windows\system32\Ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\rundll32.exe c:\windows\system32\PnkBstrB.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Voltooingstijd: 2012-05-21 21:24:00 - machine werd herstart ComboFix-quarantined-files.txt 2012-05-21 19:23 . Pre-Run: 30.778.441.728 bytes beschikbaar Post-Run: 32.104.529.920 bytes beschikbaar . WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn . - - End Of File - - 9188C371A7D0587BEF10A5DC2407BFF7
  7. dan zal ik kape wel weer gaan lastigvallen met een andere 2e (en laaste) pc... bedankt alvast in ieder geval.
  8. Beste, Mijn pc is op het moment ontzettend traag. Ik weet niet wat de beste/handigste manier is om dat op te lossen? terugbrengen naar fabrieksinstellingen zal waarschijnlijk de beste manier zijn maar dat kost nogal wat tijd dus ligt dat jullie een andere manier weten. heb vast een logje gemaakt en ook de malwarebytes- anti malware scan een snelle scan laten doen. Die scan kwam o.a. trojaan tegen dus er is blijkbaar niet alleen wat ontbrekende snelheid.... Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:20:28, on 20-5-2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Pando Networks\Media Booster\PMB.exe C:\Program Files\Call of Duty\League of Legends\RADS\system\rads_user_kernel.exe C:\Program Files\Call of Duty\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.54\deploy\LoLLauncher.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\thera-johan\Mijn documenten\Downloads\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [soltek] C:\WINDOWS\system32\autorun.exe O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.marktplaats.nl/js/widgets/imageUploader/aurigma/5_7_24_0/ImageUploader5.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe -- End of file - 7527 bytes ------------------------------------------------------------------------------------------ Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Databaseversie: v2012.05.08.08 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 thera-johan :: R02 [administrator] 8-5-2012 21:12:07 mbam-log-2012-05-08 (21-12-07).txt Scantype: Snelle scan Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scanopties: P2P Objecten gescand: 320787 Verstreken tijd: 43 minuut/minuten, 21 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 123 HKCR\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearchToolBar.SettingsPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearchToolBar.SettingsPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.IECookiesManager.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.IECookiesManager (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.DataControl.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.DataControl (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HTMLMenu.2 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HTMLMenu (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.HTMLPanel.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.HTMLPanel (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearchToolBar.ToolbarPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearchToolBar.ToolbarPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.PopSwatterSettingsControl.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.PopSwatterSettingsControl (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{7473D290-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.PseudoTransparentPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.PseudoTransparentPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.PopSwatterBarButton.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.PopSwatterBarButton (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HTMLMenu.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\ScreenSaverControl.ScreenSaverInstaller.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\ScreenSaverControl.ScreenSaverInstaller (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.OutlookAddin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.KillerObjManager.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.KillerObjManager (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HistoryKillerScheduler.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HistoryKillerScheduler (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HistorySwatterControlBar.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\FunWebProducts.HistorySwatterControlBar (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{E79DFBC0-5697-4fbd-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.ChatSessionPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\MyWebSearch.ChatSessionPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\FocusInteractive (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\FunWebProducts (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\ESENT\Process\Adparatus (Adware.Adparatus) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd. Registerwaarden gedetecteerd: 4 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources|f3PopularScreensavers (PUP.MyWebSearch) -> Data: C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform|FunWebProducts (PUP.MyWebSearch) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd. Registerdata gedetecteerd: 1 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Slecht: (http://www.mirarsearch.com/?useie5=1&q=) Goed: (http://www.google.com) -> Succesvol in quarantaine geplaatst en gerepareerd. Mappen gedetecteerd: 2 C:\Documents and Settings\Joke en Geert\Local Settings\Application Data\I Want This (Adware.GamePlayLab) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Joke en Geert\Local Settings\Application Data\I Want This\Chrome (Adware.GamePlayLab) -> Succesvol in quarantaine geplaatst en verwijderd. Bestanden gedetecteerd: 8 C:\Documents and Settings\jarco\Mijn documenten\Downloads\PDFCreatorSetup.exe (PUP.Adware.InstallCore) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Joke en Geert\Mijn documenten\Downloads\ADLSoft_UnCompressor.exe (PUP.Adware.InstallCore) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Joke en Geert\Mijn documenten\Downloads\PCPerformerSetup.exe (PUP.BundleInstaller.IB) -> Succesvol in quarantaine geplaatst en verwijderd. C:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Joke en Geert\Local Settings\Temp\is1590112554\IWantThis_ROW.exe (Adware.GamePlayLabs) -> Succesvol in quarantaine geplaatst en verwijderd. C:\WINDOWS\system32\f3PSSavr.scr (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\thera-johan\Local Settings\Temp\Oprdacht Organiseren van een Toernooi.doc (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Joke en Geert\Local Settings\Application Data\I Want This\Chrome\I Want This.crx (Adware.GamePlayLab) -> Succesvol in quarantaine geplaatst en verwijderd. (einde)
  9. het probleem is denk ik verholpen. Heb er op het moment in ieder geval geen last meer van. Mocht ik er weer last van krijgen dan zal ik het wel even melden. Hartelijk bedankt voor de hulp! Groet, Johan
  10. ik zie het al. heb enkel bij plug-ins gekeken. Ik kan echter ook bij extensies dingen uitschakelen... Voel me een beste stumper op het moment die kan ik wel volledig weggooien dus zal daar alles wat ik niet ken eerst eens weggooien in de hoop dat het probleem over zal zijn. Als dat niet het geval is gooi ik gewoon alles eruit.
  11. ok. Heb je daar een handleiding voor want ik kan wel uitschakelen maar verwijderen lukt mij niet..
  12. nog altijd problemen met Text Enhance. weet niet of je in deze link ook de afbeelding kan zien http://postimage.org/image/ahpi1lkuj/ dit is namelijk hoe mijn site er uit ziet..
  13. c:\program files\Video Codec c:\documents and settings\All Users\Application Data\Premium heb ik kunnen verwijderen. ik blijk echter niet bij de map application data te kunnen. Kan zijn dat m'n vader die voor mij heeft geblokkeerd al zie ik geen reden waarom... c:\documents and settings\All Users\Application Data\Premium kon de zoekmachine vinden maar die andere 2 werden niet gevonden... zal de malwarebytes scanner er nog eens over laten lopen en nieuw hijack this logje maken vanavond. weet niet of je daar wat mee kunt?
  14. Is in ieder geval niet door mij bewust gedownload. Eventueel kan het door mijn broertje zijn gebeurd. Het is een lege bestandmap eigenschappen: type: Bestandsmap Locatie: C:\Program Files Grootte: 0 bytes Grootte op schijf: 0 bytes Bevat: 0 bestanden, 0 mappen Gemaakt: dinsdag 24 april 2012 Dit is volgens mij exact de dag waarop het probleem voor het eerst voorkwam.
  15. elke keer na het herstarten van de pc laat de text enhance zich gewoon weer zien. nog verdere opties (addons zijn enkel uitgeschakeld, misschien kunnen die ook volledig verwijderd worden en ligt het daar aan?)
  16. ComboFix 12-05-10.02 - Kinderen 10-05-2012 16:16:27.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1023.505 [GMT 2:00] Gestart vanuit: c:\documents and settings\Kinderen\Mijn documenten\Downloads\ComboFix.exe gebruikte Opdracht switches :: c:\kinderen bestanden\jarco\vrijetijd\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . FILE :: "C:\user.js" . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\Babylon c:\documents and settings\All Users\Application Data\Premium c:\documents and settings\Kinderen\Application Data\Babylon c:\documents and settings\Kinderen\Application Data\Babylon\log_file.txt c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\bab033.tbinst.dat c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\bab091.norecovericon.dat c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Babylon.dat c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\BExternal.dll c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\blueStar.png c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\eula.html c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\globe.png c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\options.js c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page0.html c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2.css c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2.html c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page2Lrg.css c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3.css c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3.html c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\page3Lrg.css c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\pBar.gif c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\progress.png c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\setup.js c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\title.png c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\HtmlScreens\toolBar.jpg c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\IECookieLow.dll c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Setup-tbmntr903.zpb c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\Setup.exe c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\SetupStrings.dat c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\sign c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon\Setup\sqlite3.dll C:\found.001 c:\found.001\dir0000.chk\resume.dat.old c:\found.001\dir0000.chk\rss.dat.old C:\found.002 c:\found.002\dir0000.chk\Age of Empires II\00000409.016 c:\found.002\dir0000.chk\Age of Empires II\00000409.256 c:\found.002\dir0000.chk\Age of Empires II\AI\AI.txt c:\found.002\dir0000.chk\Age of Empires II\AVI\AGE2.AVI c:\found.002\dir0000.chk\Age of Empires II\AVI\AVI.TXT c:\found.002\dir0000.chk\Age of Empires II\AVI\ESLOGO.AVI c:\found.002\dir0000.chk\Age of Empires II\AVI\MSLOGO.AVI c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam1.cpn c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam2.cpn c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam3.cpn c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam4.cpn c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\cam8.cpn c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD1.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD2.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD3.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD4.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\BACKGRD8.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S1_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S2_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S3_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S4_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S5_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C1S6_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S1_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S2_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S3_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S4_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S5_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C2S6_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S1_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S2_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S3_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S4_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S5_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C3S6_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S1_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S2_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S3_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S4_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S5_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C4S6_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S1_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S2_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S3_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S4_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S5_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S6_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_BEG.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_BEG.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_END.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\C8S7_END.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM1.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM2.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM3.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM4.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\CAM8.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.BLN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.MM c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.PAL c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.SIN c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTRO.SLP c:\found.002\dir0000.chk\Age of Empires II\CAMPAIGN\MEDIA\INTROBKG.SLP c:\found.002\dir0000.chk\Age of Empires II\clcd16.dll c:\found.002\dir0000.chk\Age of Empires II\clcd32.dll c:\found.002\dir0000.chk\Age of Empires II\clokspl.exe c:\found.002\dir0000.chk\Age of Empires II\DATA\blendomatic.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\BlkEdge.Dat c:\found.002\dir0000.chk\Age of Empires II\DATA\closedpw.exe c:\found.002\dir0000.chk\Age of Empires II\DATA\EMPIRES2.DAT c:\found.002\dir0000.chk\Age of Empires II\DATA\FilterMaps.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\gamedata.drs c:\found.002\dir0000.chk\Age of Empires II\DATA\graphics.drs c:\found.002\dir0000.chk\Age of Empires II\DATA\interfac.drs c:\found.002\dir0000.chk\Age of Empires II\DATA\lightMaps.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\list.cr c:\found.002\dir0000.chk\Age of Empires II\DATA\Load\Load.txt c:\found.002\dir0000.chk\Age of Empires II\DATA\LoQMaps.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\PatternMasks.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\shadow.col c:\found.002\dir0000.chk\Age of Empires II\DATA\sounds.drs c:\found.002\dir0000.chk\Age of Empires II\DATA\STemplet.dat c:\found.002\dir0000.chk\Age of Empires II\DATA\terrain.drs c:\found.002\dir0000.chk\Age of Empires II\DATA\TileEdge.Dat c:\found.002\dir0000.chk\Age of Empires II\DATA\view_icm.dat c:\found.002\dir0000.chk\Age of Empires II\DPLAY61A.EXE c:\found.002\dir0000.chk\Age of Empires II\dplayerx.dll c:\found.002\dir0000.chk\Age of Empires II\drvmgt.dll c:\found.002\dir0000.chk\Age of Empires II\EBUEula.dll c:\found.002\dir0000.chk\Age of Empires II\EMPIRES2.EXE c:\found.002\dir0000.chk\Age of Empires II\EMPIRES2.ICD c:\found.002\dir0000.chk\Age of Empires II\EULA.RTF c:\found.002\dir0000.chk\Age of Empires II\HA312W32.DLL c:\found.002\dir0000.chk\Age of Empires II\History\Armies.txt c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesMongols.txt c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesOrg.txt c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesStrat.txt c:\found.002\dir0000.chk\Age of Empires II\History\ArmiesTactics.txt c:\found.002\dir0000.chk\Age of Empires II\History\barbarianinvaders.txt c:\found.002\dir0000.chk\Age of Empires II\History\British original.txt c:\found.002\dir0000.chk\Age of Empires II\History\british regular.txt c:\found.002\dir0000.chk\Age of Empires II\History\british test.txt c:\found.002\dir0000.chk\Age of Empires II\History\british.txt c:\found.002\dir0000.chk\Age of Empires II\History\Byzantines.txt c:\found.002\dir0000.chk\Age of Empires II\History\CastleDefenses.txt c:\found.002\dir0000.chk\Age of Empires II\History\CastleEvolution.txt c:\found.002\dir0000.chk\Age of Empires II\History\Castles.txt c:\found.002\dir0000.chk\Age of Empires II\History\CastleSiege.txt c:\found.002\dir0000.chk\Age of Empires II\History\Celts.txt c:\found.002\dir0000.chk\Age of Empires II\History\charlemagne.txt c:\found.002\dir0000.chk\Age of Empires II\History\Chinese.txt c:\found.002\dir0000.chk\Age of Empires II\History\darkagereligion.txt c:\found.002\dir0000.chk\Age of Empires II\History\darkages.txt c:\found.002\dir0000.chk\Age of Empires II\History\DarkArmies.txt c:\found.002\dir0000.chk\Age of Empires II\History\economy.txt c:\found.002\dir0000.chk\Age of Empires II\History\feudalcontract.txt c:\found.002\dir0000.chk\Age of Empires II\History\feudalism.txt c:\found.002\dir0000.chk\Age of Empires II\History\feudalismdecline.txt c:\found.002\dir0000.chk\Age of Empires II\History\Franks.txt c:\found.002\dir0000.chk\Age of Empires II\History\Goths.txt c:\found.002\dir0000.chk\Age of Empires II\History\Gunpowder.txt c:\found.002\dir0000.chk\Age of Empires II\History\history.txt c:\found.002\dir0000.chk\Age of Empires II\History\Japanese.txt c:\found.002\dir0000.chk\Age of Empires II\History\Knights.txt c:\found.002\dir0000.chk\Age of Empires II\History\latemiddleages.txt c:\found.002\dir0000.chk\Age of Empires II\History\middleages.txt c:\found.002\dir0000.chk\Age of Empires II\History\Mongols.txt c:\found.002\dir0000.chk\Age of Empires II\History\Naval.txt c:\found.002\dir0000.chk\Age of Empires II\History\Persians.txt c:\found.002\dir0000.chk\Age of Empires II\History\politics.txt c:\found.002\dir0000.chk\Age of Empires II\History\religion.txt c:\found.002\dir0000.chk\Age of Empires II\History\renaissance.txt c:\found.002\dir0000.chk\Age of Empires II\History\Saracens.txt c:\found.002\dir0000.chk\Age of Empires II\History\technology.txt c:\found.002\dir0000.chk\Age of Empires II\History\Teutons.txt c:\found.002\dir0000.chk\Age of Empires II\History\thecrusades.txt c:\found.002\dir0000.chk\Age of Empires II\History\thefallofrome.txt c:\found.002\dir0000.chk\Age of Empires II\History\themanor.txt c:\found.002\dir0000.chk\Age of Empires II\History\thevikings.txt c:\found.002\dir0000.chk\Age of Empires II\History\Turks.txt c:\found.002\dir0000.chk\Age of Empires II\History\Vikings.txt c:\found.002\dir0000.chk\Age of Empires II\History\Warfare.txt c:\found.002\dir0000.chk\Age of Empires II\History\Weapons.txt c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsCav.txt c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsHand.txt c:\found.002\dir0000.chk\Age of Empires II\History\WeaponsMissile.txt c:\found.002\dir0000.chk\Age of Empires II\LANGUAGE.DLL c:\found.002\dir0000.chk\Age of Empires II\Learn\Default.uh c:\found.002\dir0000.chk\Age of Empires II\Learn\GanGstaNL.uh c:\found.002\dir0000.chk\Age of Empires II\Learn\kingjarco.uh c:\found.002\dir0000.chk\Age of Empires II\Learn\Learn.txt c:\found.002\dir0000.chk\Age of Empires II\mcp.dll c:\found.002\dir0000.chk\Age of Empires II\player.nfo c:\found.002\dir0000.chk\Age of Empires II\Readme.rtf c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco III.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco IIII.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarco1.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\jarcoII.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan 3 opgeslagen door thera!!hipperdehipperdehoihoihoi!!!hoeraaaaajjaaajjaa.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan 3.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan2!!.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan2.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan4.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan5.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johan6.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\johannes.gam c:\found.002\dir0000.chk\Age of Empires II\SaveGame\Multi\Multi.txt c:\found.002\dir0000.chk\Age of Empires II\SaveGame\SaveGame.txt c:\found.002\dir0000.chk\Age of Empires II\Scenario\default0.scn c:\found.002\dir0000.chk\Age of Empires II\Scenario\jarco1.scn c:\found.002\dir0000.chk\Age of Empires II\Scenario\jarco2.scn c:\found.002\dir0000.chk\Age of Empires II\Scenario\scenario.inf c:\found.002\dir0000.chk\Age of Empires II\scenariobkg.bmp c:\found.002\dir0000.chk\Age of Empires II\SETUPENU.DLL c:\found.002\dir0000.chk\Age of Empires II\SHW32.DLL c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S1END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S2END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S3.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S3END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S4.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S4END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S5.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S5END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S6.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C1S6END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S1END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S2END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S3.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S3END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S4.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S4END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S5.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S5END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S6.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C2S6END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S1END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S2END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S3.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S3END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S4.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S4END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S5.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S5END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S6.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C3S6END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S1END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S2END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S3.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S3END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S4.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S4END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S5.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S5END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S6.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C4S6END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S1END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S2END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S3.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S3END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S4.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S4END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S5.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S5END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S6.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S6END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S7.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\C8S7END.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\CAMPAIGN\INTRO.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b1d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b2c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3aa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b3e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b4f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b5q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\b6n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\d1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1lold.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g1m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g2h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g3e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g4j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g5j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\g6i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1r.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1t.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1u.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1v.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1w.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1x.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1y.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j1z.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j2o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j3p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4c2.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j4j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j5l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6a2.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\j6q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\S1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s1j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s2l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s3f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s4m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s5d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\s6i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1r.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1s.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1t.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wb.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w1wc.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2aa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w2wa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3e2.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w3wa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wb.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w4wc.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5a2.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5r.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5s.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5t.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5u.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5v.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5w.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wa.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wd.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5we.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wf.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wg.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5wh.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5x.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5y.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z2.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z3.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w5z4.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6r.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6s.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6t.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6u.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6v.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w6w.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7a.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7b.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7c.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7d.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7e.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7f.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7g.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7h.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7i.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7j.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7k.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7l.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7m.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7n.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7o.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7p.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\scenario\w7q.mp3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\BRITISH.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\BYZANTIN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CELT.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CHINESE.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\COUNTDWN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\CREDITS.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\FRENCH.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\GOTH.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\JAPANESE.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\LOST.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\MONGOL.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\OPEN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\PERSIAN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\RANDOM.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\SARACEN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TEUTON.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TOWN.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\TURK.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\VIKING.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\WON1.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\STREAM\WON2.MP3 c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Cricket.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf1.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf2.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf3.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf4.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf6.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf7.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\tf8.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave1.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave2.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave3.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave4.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wave5.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind1.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind2.wav c:\found.002\dir0000.chk\Age of Empires II\SOUND\terrain\Wind3.wav c:\found.002\dir0000.chk\Age of Empires II\Taunt\01 Yes.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\02 No.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\03 Food, please.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\04 Wood, please.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\05 Gold, PLease.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\06 Stone, please.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\07 Ahh.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\08 All hail.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\09 Oooh.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\10 Back to Age 1.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\11 Herb laugh.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\12 Being rushed.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\13 Blame your isp.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\14 Start the game.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\15 Don't Point That Thing.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\16 Enemy Sighted.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\17 It Is Good.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\18 I Need a Monk.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\19 Long Time No Siege.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\20 My granny.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\21 Nice Town I'll Take It.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\22 Quit Touchin.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\23 Raiding Party.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\24 Dadgum.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\25 Smite Me.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\26 The wonder.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\27 You play 2 hours.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\28 You Should See the Other Guy.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\29 Roggan.mp3 c:\found.002\dir0000.chk\Age of Empires II\Taunt\30 Wololo.mp3 c:\found.002\dir0000.chk\Age of Empires II\UNINSTAL.EXE c:\found.002\dir0000.chk\Age of Empires II\WARRANTY.RTF c:\found.002\dir0000.chk\Age of Empires III\art\ui\random_map\large_maps.ddt c:\found.002\dir0000.chk\Age of Empires III\privacy.rtf c:\found.002\dir0000.chk\Age of Empires III\SetupENU2.dll C:\found.003 c:\found.003\file0000.chk c:\program files\Optimizer Pro C:\user.js . . (((((((((((((((((((( Bestanden Gemaakt van 2012-04-10 to 2012-05-10 )))))))))))))))))))))))))))))) . . 2012-05-10 14:13 . 2012-05-10 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\offreg.dll 2012-05-10 11:14 . 2012-05-10 11:14 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsl47eb3b3e.sys 2012-05-09 18:33 . 2012-05-09 18:33 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsle44fdd8b.sys 2012-05-09 16:18 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\mpengine.dll 2012-05-08 16:38 . 2012-05-08 16:38 -------- d-----w- c:\program files\CodeStuff 2012-05-08 13:08 . 2012-05-08 13:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-05-08 13:08 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-05-08 12:11 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-02 13:32 . 2012-05-08 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ADDICT-THING 2012-05-02 12:14 . 2012-05-02 12:29 -------- d-----w- c:\program files\Maxis 2012-04-27 17:11 . 2012-04-27 17:11 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Malwarebytes 2012-04-27 17:10 . 2012-04-27 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-04-27 15:58 . 2012-04-27 15:58 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG2012 2012-04-27 15:48 . 2012-04-27 15:48 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG Secure Search 2012-04-27 15:42 . 2012-04-27 15:42 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files 2012-04-27 15:42 . 2012-04-28 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData 2012-04-26 17:57 . 2012-04-26 17:57 388096 ----a-r- c:\documents and settings\Kinderen\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-04-26 17:57 . 2012-04-26 17:57 -------- d-----w- c:\program files\Trend Micro 2012-04-25 16:52 . 2012-04-25 16:52 -------- d-----w- c:\program files\Mozilla Maintenance Service 2012-04-25 16:52 . 2012-04-25 16:52 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-04-25 16:52 . 2012-04-25 16:52 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-25 13:26 . 2012-04-25 13:26 -------- d-----w- c:\program files\Common Files\Skype 2012-04-24 16:42 . 2012-04-24 16:42 -------- d-----w- c:\program files\Video Codec 2012-04-24 16:31 . 2012-04-27 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Bcool 2012-04-24 16:30 . 2012-05-02 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate 2012-04-22 06:10 . 2012-04-22 06:10 -------- d-----w- c:\documents and settings\Kinderen\Application Data\LolClient 2012-04-21 19:11 . 2012-04-21 19:11 -------- d-----w- C:\Riot Games 2012-04-12 05:16 . 2012-04-12 05:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple 2012-04-11 10:04 . 2012-04-11 10:04 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-08 16:42 . 2012-04-09 20:17 1409 ----a-w- c:\windows\QTFont.for 2012-04-17 15:39 . 2010-03-14 11:26 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.exe 2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.ex0 2012-04-11 13:55 . 2004-08-04 00:58 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-11 13:55 . 2004-09-02 12:00 2152960 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 13:55 . 2004-09-02 12:00 1862400 ----a-w- c:\windows\system32\win32k.sys 2012-04-03 18:19 . 2012-04-03 18:20 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-04-03 18:19 . 2011-07-22 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-20 18:44 . 2009-12-02 13:23 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-01 14:43 . 2012-03-01 14:42 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr 2012-03-01 11:00 . 2004-09-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-03-01 11:00 . 2004-09-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2012-03-01 11:00 . 2004-09-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-02-29 20:30 . 2010-03-14 11:26 75136 ----a-w- c:\windows\system32\PnkBstrA.exe 2012-02-29 20:17 . 2012-02-29 20:17 138056 ----a-w- c:\documents and settings\Kinderen\Application Data\PnkBstrK.sys 2012-02-29 14:10 . 2004-09-02 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10 . 2004-09-02 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17 . 2004-09-02 12:00 385024 ----a-w- c:\windows\system32\html.iec 2012-02-16 20:52 . 2012-02-07 20:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-15 09:01 . 2012-04-09 09:25 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll 2012-02-15 09:01 . 2012-04-09 09:25 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2012-04-25 16:52 . 2012-02-07 20:09 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll [-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll . ((((((((((((((((((((((((((((( SnapShot@2012-05-09_16.05.54 ))))))))))))))))))))))))))))))))))))))))) . + 2012-05-10 11:13 . 2012-05-10 11:13 16384 c:\windows\Temp\Perflib_Perfdata_1a4.dat - 2004-09-02 12:00 . 2012-04-11 20:50 91150 c:\windows\system32\perfc013.dat + 2004-09-02 12:00 . 2012-05-09 21:06 91150 c:\windows\system32\perfc013.dat - 2004-09-02 12:00 . 2012-04-11 20:50 71624 c:\windows\system32\perfc009.dat + 2004-09-02 12:00 . 2012-05-09 21:06 71624 c:\windows\system32\perfc009.dat - 2009-03-17 16:59 . 2011-07-05 13:46 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll + 2009-03-17 16:59 . 2012-01-13 15:03 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll + 2009-03-17 16:59 . 2012-01-13 15:03 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll - 2009-03-17 16:59 . 2011-07-05 13:46 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll - 2009-03-17 16:59 . 2011-07-06 07:57 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe + 2009-03-17 16:59 . 2012-01-13 15:54 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe - 2009-03-17 16:59 . 2011-07-06 07:57 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe + 2009-03-17 16:59 . 2012-01-13 15:54 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe + 2009-03-24 18:28 . 2012-05-09 21:13 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe - 2009-03-24 18:28 . 2012-04-11 20:52 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe + 2009-03-24 18:28 . 2012-05-09 21:13 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe - 2009-03-24 18:28 . 2012-04-11 20:52 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe - 2009-03-24 18:28 . 2012-04-11 20:52 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe + 2009-03-24 18:28 . 2012-05-09 21:13 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe - 2010-06-04 07:22 . 2012-02-08 14:56 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll + 2010-06-04 07:22 . 2012-05-09 21:01 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll + 2012-05-10 11:14 . 2012-05-10 11:14 90112 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_08e40963\System.Drawing.Design.dll + 2012-05-09 21:14 . 2012-05-09 21:14 61440 c:\windows\assembly\NativeImages1_v1.0.3705\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a_33e6d197\CustomMarshalers.dll + 2012-05-09 21:11 . 2012-05-09 21:11 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\ff0e98a47a1aaa29100976e9e2cc430a\WindowsLiveWriter.ni.exe + 2012-05-10 12:02 . 2012-05-10 12:02 99840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5d4d60e3cb7f6b19d1dc6452e735a360\WindowsLive.Writer.Api.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\f121ccced1aa14badb316d8d9be5154d\UIAutomationProvider.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\316e223f2ab8c69cd6a5a06de21650ec\System.Windows.Presentation.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\7aac1fe67890463655aeeb3b8e4f2884\System.Web.DynamicData.Design.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\34c988dea48c291b4e648941207e83fb\System.ComponentModel.DataAnnotations.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\7bb7e51275fa19f8b4894c772bdb1e10\System.AddIn.Contract.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\f0c4a4528f130ef2ff1ae63dd7b39075\PresentationFontCache.ni.exe + 2012-05-09 21:07 . 2012-05-09 21:07 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\53931181e5a5e194da82605613cda6af\PresentationCFFRasterizer.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2be3ad4cda6853d7959a84cec0414c5\Microsoft.Vsa.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\f00a18225430e7531135589688d650a1\Microsoft.VisualC.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\8fab9cd28bbc860a34feec119512664d\Microsoft.Build.Framework.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\0eac132c7c36f1c100ae23c956b379e7\Microsoft.Build.Framework.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\d66bc03eb7eae89b4dde2d09eda1414f\dfsvc.ni.exe + 2012-05-09 21:11 . 2012-05-09 21:11 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll - 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2012-05-09 21:05 . 2012-05-09 21:05 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2012-04-11 20:50 . 2012-04-11 20:50 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2012-05-09 21:05 . 2012-05-09 21:05 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2012-05-09 21:06 . 2012-05-09 21:06 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2012-04-11 20:50 . 2012-04-11 20:50 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2012-04-11 20:50 . 2012-04-11 20:50 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2012-05-09 21:06 . 2012-05-09 21:06 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2012-04-11 20:50 . 2012-04-11 20:50 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2012-05-09 21:06 . 2012-05-09 21:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll - 2012-04-11 20:50 . 2012-04-11 20:50 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2012-05-09 21:06 . 2012-05-09 21:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2012-05-09 21:06 . 2012-05-09 21:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2012-05-09 21:06 . 2012-05-09 21:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2012-04-11 20:50 . 2012-04-11 20:50 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2012-05-09 21:06 . 2012-05-09 21:06 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2012-04-11 20:50 . 2012-04-11 20:50 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2012-04-11 20:50 . 2012-04-11 20:50 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2012-05-09 21:06 . 2012-05-09 21:06 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2012-04-11 20:50 . 2012-04-11 20:50 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2012-05-09 21:06 . 2012-05-09 21:06 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2012-05-09 21:06 . 2012-05-09 21:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2012-04-11 20:50 . 2012-04-11 20:50 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2012-04-11 20:50 . 2012-04-11 20:50 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2012-05-09 21:06 . 2012-05-09 21:06 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll - 2012-04-11 20:50 . 2012-04-11 20:50 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2012-05-09 21:06 . 2012-05-09 21:06 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll - 2009-03-17 16:59 . 2011-07-12 16:05 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe + 2009-03-17 16:59 . 2012-01-16 23:19 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe + 2012-05-09 21:06 . 2012-05-09 21:06 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll - 2012-04-11 20:50 . 2012-04-11 20:50 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2012-05-09 21:06 . 2012-05-09 21:06 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2012-04-11 20:50 . 2012-04-11 20:50 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2012-04-11 20:50 . 2012-04-11 20:50 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2012-05-09 21:06 . 2012-05-09 21:06 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2012-05-09 21:06 . 2012-05-09 21:06 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2012-04-11 20:50 . 2012-04-11 20:50 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2012-04-11 20:50 . 2012-04-11 20:50 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2012-05-09 21:06 . 2012-05-09 21:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll - 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2012-04-05 21:13 . 2012-04-05 21:13 299080 c:\windows\system32\XPSViewer\XPSViewer.exe - 2004-09-02 12:00 . 2012-04-11 20:50 509474 c:\windows\system32\perfh013.dat + 2004-09-02 12:00 . 2012-05-09 21:06 509474 c:\windows\system32\perfh013.dat - 2004-09-02 12:00 . 2012-04-11 20:50 441688 c:\windows\system32\perfh009.dat + 2004-09-02 12:00 . 2012-05-09 21:06 441688 c:\windows\system32\perfh009.dat + 2009-03-17 17:42 . 2012-05-10 11:13 158752 c:\windows\system32\FNTCACHE.DAT - 2009-03-17 17:42 . 2012-03-15 06:52 158752 c:\windows\system32\FNTCACHE.DAT + 2012-04-05 21:52 . 2012-04-05 21:52 131168 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll + 2011-12-25 01:50 . 2011-12-25 01:50 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll + 2011-12-25 01:50 . 2011-12-25 01:50 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2011-12-25 01:50 . 2011-12-25 01:50 989968 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2009-03-17 16:59 . 2012-01-13 14:59 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll - 2009-03-17 16:59 . 2011-07-05 13:44 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll + 2009-03-17 16:59 . 2012-01-13 15:54 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll - 2009-03-17 16:59 . 2011-07-06 07:57 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll + 2011-12-22 14:50 . 2011-12-22 14:50 256000 c:\windows\Installer\870f71.msp + 2009-03-24 18:28 . 2012-05-09 21:13 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe - 2009-03-24 18:28 . 2012-04-11 20:52 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe - 2009-03-24 18:28 . 2012-04-11 20:52 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe + 2009-03-24 18:28 . 2012-05-09 21:13 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe - 2009-03-24 18:28 . 2012-04-11 20:52 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe + 2009-03-24 18:28 . 2012-05-09 21:13 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe + 2009-03-24 18:28 . 2012-05-09 21:13 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe - 2009-03-24 18:28 . 2012-04-11 20:52 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe + 2011-09-15 19:41 . 2011-09-15 19:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WINWORD.EXE + 2012-05-10 11:14 . 2012-05-10 11:14 851968 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_7a8e096d\System.Drawing.dll + 2012-05-09 21:11 . 2012-05-09 21:11 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\ac4fc3032c19946f9b2729468888206d\WsatConfig.ni.exe + 2012-05-10 12:02 . 2012-05-10 12:02 626688 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\218b4362202a2f432bb3714221ff2aa4\WindowsLiveLocal.WriterPlugin.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\fb438f62f426ff28b4a9949d699051b8\WindowsLive.Writer.Extensibility.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ccc14b04d082666155d2c355ef1f6563\WindowsLive.Writer.FileDestinations.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c954ba830b50bd4a6cf0ee094e2ea928\WindowsLive.Writer.Mshtml.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c627e81fcd97ecd7c70b7eedf7928713\WindowsLive.Writer.Localization.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bdeb63577afc142cf5b377b9e2565660\WindowsLive.Writer.Controls.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\baacfa565b2f46f4501cd89b067a8a47\WindowsLive.Writer.HtmlParser.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 334848 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ab181ae110294c0c572059dea0a4332c\WindowsLive.Writer.Interop.Mshtml.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\809bd32a5211d9cd4115fba88f370a74\WindowsLive.Writer.BrowserControl.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6d9c4d236bacb711597c5aca6c04200e\WindowsLive.Writer.Interop.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\678f35b523dbb63a4f247c1ffdf359cd\WindowsLive.Writer.Instrumentation.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\313958002b6415baf438056e452f23c3\WindowsLive.Writer.Passport.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\29e8f27943707613416f76a0357c8f41\WindowsLive.Writer.Interop.SHDocVw.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\228e3d0a57dc24f37a2b2259104749c1\WindowsLive.Writer.BlogClient.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1b316a40898d5a62af81ed70a3b708d0\WindowsLive.Writer.HtmlEditor.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\130bc8fe5ff6eb69e4c7f0ba24fba59a\WindowsLive.Writer.SpellChecker.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\d74a2a15b12d1d7c33eb64df4879cf7e\WindowsLive.Client.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\6198de2c5b8f7d89404c2ba39d69ae56\WindowsFormsIntegration.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\be27ab5913cec2b292a019c2a13ec701\UIAutomationTypes.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\04e5e2be34a70ee7f4c87550238095a0\UIAutomationClient.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP474.tmp\WindowsLive.Writer.Passport.dll + 2012-05-10 12:04 . 2012-05-10 12:04 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\1c13b08593e99d6f5bef49ae7939c78b\System.Xml.Linq.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\8bffbaa5d5abe40674d0bc124dfe8622\System.Web.Routing.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6c7765c10516d375e9ddedad2dbab848\System.Web.RegularExpressions.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\a7908debe80c209b599529685a159fa0\System.Web.Extensions.Design.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\44ecb9f7be54a2ba46e6102d343e2e7e\System.Web.Entity.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\fee8237aa2daa36e48aec379ee642422\System.Web.Entity.Design.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\40d90d2c1484164b786067320ce778f4\System.Web.DynamicData.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\6b4ce8cf2c3307b75ea7ebe77258bb26\System.Web.Abstractions.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\41f6f6dd0c8427d4a8e6fd3915505a6b\System.Transactions.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8dc4a28c456f81ee7399da21bd9d55aa\System.ServiceProcess.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\129b15861e200613ff78ae15581f9093\System.Security.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a644ec04e18202b60f9d828bc207972b\System.Runtime.Serialization.Formatters.Soap.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\4a9eb43005a041959ddc5c7e586ab746\System.Net.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\3182a049ba953010dec649cf290a9e90\System.Management.Instrumentation.ni.dll + 2012-05-09 21:10 . 2012-05-09 21:10 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\8991f21d4b3676bf6f779110db8d4ac9\System.IO.Log.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cd9c60a35d4958e94d2e3dd2f778e2e9\System.IdentityModel.Selectors.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\29bce0113d611084a9329349e33528ac\System.EnterpriseServices.Wrapper.dll + 2012-05-09 21:14 . 2012-05-09 21:14 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\29bce0113d611084a9329349e33528ac\System.EnterpriseServices.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\88aa4f80c7e5ac25f06f8950e42a1678\System.Drawing.Design.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ca484772955bc4db03b5dcb611c09423\System.DirectoryServices.Protocols.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8ba5e68dddfd3279a8469d39eded48f3\System.DirectoryServices.AccountManagement.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a0109fce606a3110a5e7f9a4773f517e\System.Data.Services.Design.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3a68d0441f509ffa6f8f0fb9cfcc5780\System.Data.Services.Client.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\04440b3dd5d822da4973a525ee04b05d\System.Data.Entity.Design.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\7bbb5d9e3b161b4d4b968e590442d3ae\System.Data.DataSetExtensions.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\bf7d6af03e1230ccad546a8659245ae9\System.Configuration.Install.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\931a2bece4668863db4f852401c828cf\System.AddIn.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6762f1ee780fa9c0b4ef66b285c64844\SMSvcHost.ni.exe + 2012-05-09 21:11 . 2012-05-09 21:11 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\47ed5bc9f42ea0054ce9acfde5e640b8\ServiceModelReg.ni.exe + 2012-05-09 21:08 . 2012-05-09 21:08 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a4706b850df9a3483f2fc439b6abe616\PresentationFramework.Royale.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8b873631a0855fb6aa0ad25f1d9de7fe\PresentationFramework.Luna.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7416fe825e6e49a87fa8ff60c8971813\PresentationFramework.Classic.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\186c27fbd7b38b5551889274f6fa2ccd\PresentationFramework.Aero.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5a121969a115d11b6256eb960c145686\MSBuild.ni.exe + 2012-05-09 21:11 . 2012-05-09 21:11 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\97c613d3899b320a6765793bdf490272\Microsoft.Transactions.Bridge.Dtc.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\dec22fb7d6b8929a41380e5359741a07\Microsoft.Build.Utilities.v3.5.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\1009b31c86a1b798fffa9e0127cec29c\Microsoft.Build.Utilities.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\21d88631ef629715d3eecdd08e62e0b8\Microsoft.Build.Engine.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a0f38c6478cca8297fb160291346c1c9\Microsoft.Build.Conversion.v3.5.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bb26dd100d656605c576881a1a823667\CustomMarshalers.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\9869c02d18825fdd32e64135a3e7246b\ComSvcConfig.ni.exe + 2012-05-09 21:11 . 2012-05-09 21:11 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e414683ec4cff1cac0c77aaefd67144e\AspNetMMCExt.ni.dll - 2012-04-11 20:50 . 2012-04-11 20:50 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2012-05-09 21:05 . 2012-05-09 21:05 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2012-05-09 21:05 . 2012-05-09 21:05 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2012-04-11 20:50 . 2012-04-11 20:50 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll + 2012-05-09 21:06 . 2012-05-09 21:06 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll - 2012-04-11 20:50 . 2012-04-11 20:50 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll - 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2012-05-09 21:06 . 2012-05-09 21:06 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2012-04-11 20:50 . 2012-04-11 20:50 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll + 2012-05-09 21:06 . 2012-05-09 21:06 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2012-04-11 20:50 . 2012-04-11 20:50 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll - 2012-04-11 20:50 . 2012-04-11 20:50 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2012-05-09 21:06 . 2012-05-09 21:06 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll - 2012-04-11 20:50 . 2012-04-11 20:50 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll + 2012-05-09 21:06 . 2012-05-09 21:06 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2012-04-11 20:50 . 2012-04-11 20:50 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2012-05-09 21:06 . 2012-05-09 21:06 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll - 2012-04-11 20:50 . 2012-04-11 20:50 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2012-05-09 21:05 . 2012-05-09 21:05 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2012-05-09 21:06 . 2012-05-09 21:06 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll - 2012-04-11 20:50 . 2012-04-11 20:50 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2012-05-09 21:06 . 2012-05-09 21:06 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll - 2012-04-11 20:50 . 2012-04-11 20:50 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2012-05-09 21:06 . 2012-05-09 21:06 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll - 2012-04-11 20:50 . 2012-04-11 20:50 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2012-05-09 21:11 . 2012-05-09 21:11 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll - 2009-08-15 20:30 . 2009-08-15 20:30 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll - 2012-04-11 20:50 . 2012-04-11 20:50 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2012-05-09 21:06 . 2012-05-09 21:06 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2012-05-09 21:02 . 2012-05-09 21:02 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll + 2012-05-09 21:06 . 2012-05-09 21:06 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2012-04-11 20:50 . 2012-04-11 20:50 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2012-04-11 20:50 . 2012-04-11 20:50 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2012-05-09 21:06 . 2012-05-09 21:06 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2012-05-09 21:06 . 2012-05-09 21:06 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll - 2012-04-11 20:50 . 2012-04-11 20:50 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2012-05-09 21:06 . 2012-05-09 21:06 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2012-04-11 20:50 . 2012-04-11 20:50 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2012-04-11 20:50 . 2012-04-11 20:50 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll + 2012-05-09 21:06 . 2012-05-09 21:06 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2012-04-11 20:50 . 2012-04-11 20:50 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2012-05-09 21:06 . 2012-05-09 21:06 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll - 2012-04-11 20:50 . 2012-04-11 20:50 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2012-05-09 21:05 . 2012-05-09 21:05 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll - 2012-04-11 20:50 . 2012-04-11 20:50 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2012-05-09 21:06 . 2012-05-09 21:06 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2012-05-09 21:02 . 2012-05-09 21:02 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll - 2009-08-15 20:29 . 2009-08-15 20:29 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll - 2012-04-11 20:50 . 2012-04-11 20:50 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2012-05-09 21:06 . 2012-05-09 21:06 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2012-05-09 21:06 . 2012-05-09 21:06 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2012-04-11 20:50 . 2012-04-11 20:50 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2012-04-11 20:50 . 2012-04-11 20:50 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2012-05-09 21:06 . 2012-05-09 21:06 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2012-05-09 16:27 . 2012-02-09 15:43 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll + 2010-05-02 08:10 . 2012-04-11 13:55 1862400 c:\windows\system32\dllcache\win32k.sys + 2010-06-11 14:23 . 2012-04-11 13:55 2196992 c:\windows\system32\dllcache\ntoskrnl.exe + 2010-06-11 14:23 . 2012-04-11 13:55 2031104 c:\windows\system32\dllcache\ntkrpamp.exe + 2009-02-10 17:10 . 2012-04-11 13:55 2073472 c:\windows\system32\dllcache\ntkrnlpa.exe + 2010-06-11 14:23 . 2012-04-11 13:55 2152960 c:\windows\system32\dllcache\ntkrnlmp.exe + 2011-12-25 01:50 . 2011-12-25 01:50 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll - 2011-03-25 04:15 . 2011-03-25 04:15 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll + 2011-12-25 01:50 . 2011-12-25 01:50 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll - 2011-10-26 02:39 . 2011-10-26 02:39 3186688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll + 2011-12-25 01:50 . 2011-12-25 01:50 5913360 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - 2011-07-07 03:18 . 2011-07-07 03:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2011-12-25 01:50 . 2011-12-25 01:50 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll - 2009-03-17 16:59 . 2004-07-19 17:54 2002944 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.dll + 2009-03-17 16:59 . 2012-01-16 23:19 2002944 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.dll + 2009-03-17 16:59 . 2012-01-16 23:20 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll - 2009-03-17 16:59 . 2011-07-12 16:04 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll - 2009-03-17 16:59 . 2007-12-17 15:29 1179648 c:\windows\Microsoft.NET\Framework\v1.0.3705\system.dll + 2009-03-17 16:59 . 2012-01-16 23:19 1179648 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.dll + 2009-03-17 16:59 . 2012-01-13 14:59 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll - 2009-03-17 16:59 . 2011-07-05 13:45 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll + 2009-03-17 16:59 . 2012-01-13 14:59 2273280 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll + 2009-03-17 16:59 . 2012-01-16 23:19 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll - 2009-03-17 16:59 . 2011-07-12 16:05 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll + 2012-04-04 20:38 . 2012-04-04 20:38 2831360 c:\windows\Installer\870f9a.msp + 2012-04-28 19:44 . 2012-04-28 19:44 9101824 c:\windows\Installer\870f89.msp + 2012-04-28 19:44 . 2012-04-28 19:44 9586176 c:\windows\Installer\870f5d.msp + 2012-04-04 20:38 . 2012-04-04 20:38 3620864 c:\windows\Installer\870f4b.msp + 2012-03-15 00:24 . 2012-03-15 00:24 1795584 c:\windows\Installer\870f2e.msp + 2012-04-28 19:43 . 2012-04-28 19:43 8459264 c:\windows\Installer\870f1d.msp + 2012-02-17 06:45 . 2012-02-17 06:45 2299392 c:\windows\Installer\870f01.msp - 2009-03-24 18:28 . 2012-04-11 20:52 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe + 2009-03-24 18:28 . 2012-05-09 21:13 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe + 2011-08-17 08:49 . 2011-08-17 08:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CNV.DLL + 2011-07-07 01:58 . 2011-07-07 01:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGL.DLL + 2010-06-11 14:23 . 2012-04-11 13:55 2196992 c:\windows\Driver Cache\i386\ntoskrnl.exe + 2010-06-11 14:23 . 2012-04-11 13:55 2031104 c:\windows\Driver Cache\i386\ntkrpamp.exe + 2009-02-10 17:10 . 2012-04-11 13:55 2073472 c:\windows\Driver Cache\i386\ntkrnlpa.exe + 2010-06-11 14:23 . 2012-04-11 13:55 2152960 c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2012-05-09 21:14 . 2012-05-09 21:14 1855488 c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_b3fe6eb5\System.dll + 2012-05-10 11:14 . 2012-05-10 11:14 2027520 c:\windows\assembly\NativeImages1_v1.0.3705\System.Xml\1.0.3300.0__b77a5c561934e089_6cd9d84c\System.Xml.dll + 2012-05-10 11:14 . 2012-05-10 11:14 2953216 c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_41b2cdaf\System.Windows.Forms.dll + 2012-05-10 11:14 . 2012-05-10 11:14 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_49478551\System.Design.dll + 2012-05-09 21:14 . 2012-05-09 21:14 3301376 c:\windows\assembly\NativeImages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_f3325456\mscorlib.dll + 2012-05-09 21:13 . 2012-05-09 21:13 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ed14765fc0f1a92b9211a088455799fc\WindowsLive.Writer.PostEditor.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\724479ec2aae6cebefd965ac1bacdce6\WindowsLive.Writer.ApplicationFramework.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 2018816 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5b93d79ffd230432a9448c110a76d6b6\WindowsLive.Writer.CoreServices.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\41a81b97625c113b591ed082c95276e2\UIAutomationClientsideProviders.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 7953408 c:\windows\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll + 2012-05-09 21:09 . 2012-05-09 21:09 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\33fa6a2055bf857bff2e31020279b5e9\System.WorkflowServices.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5eccf6fef6bee8a2f93bc65ff33699bb\System.Workflow.Runtime.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\62bd2e1bf98b04ceca2102c8f54aab9d\System.Workflow.ComponentModel.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\8215548b3d4aabbaa0557ab747700778\System.Workflow.Activities.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\3e11aea7d742b5eddbd0b6bd1012f7df\System.Web.Services.ni.dll + 2012-05-10 12:04 . 2012-05-10 12:04 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\ff995dde9cd34ff1e8ac7ab55fc92d32\System.Web.Mobile.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\8899d1091e64a4d0b6ae69060197091a\System.Web.Extensions.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\5efb50c91f3c5e49be2079f625d933b7\System.Speech.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll + 2012-05-09 21:10 . 2012-05-09 21:10 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\1d6707a5a9da16c1d1b88529837884d6\System.Printing.ni.dll + 2012-05-09 21:10 . 2012-05-09 21:10 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\e09496ddb2bf6f3b69707924f2e6b5ff\System.IdentityModel.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 1591808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8ca00132a08c69697adf1cda32ebd835\System.Drawing.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\b55887436d2cfbe1fb32dd18d554185b\System.DirectoryServices.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\832196527f0497078f085eaf9189265f\System.Deployment.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\12c6fe8d4dd78f9bddf847d3b2821c03\System.Data.ni.dll + 2012-05-09 21:13 . 2012-05-09 21:13 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\982b508698278c6ffb3d143bbe1e8bb8\System.Data.SqlXml.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\2de7666b1cd0a1bc363726c9553dc39c\System.Data.Services.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\7afb1abdbb8ba32cf578ff8ea4e45d99\System.Data.OracleClient.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\44a5fc9e7c71b1fe1e2c79b03ecc3bc7\System.Data.Linq.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\772c94f595cd87b7fa187d592ef46fcf\System.Data.Entity.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\38d07a5ac34b99d94fd14f42e779f625\System.Core.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 2146304 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\2ecefd16184a78f19aaf0f02cc0a7e1f\ReachFramework.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\51204805c71113e0db2103faa064b313\PresentationUI.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\8c509044eea2ab22689ea43926b30108\PresentationBuildTasks.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\b49dd780ba8e3501b0adcf108b431e7b\Microsoft.VisualBasic.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\42145ebf75f77cabad442f0801a81c64\Microsoft.Transactions.Bridge.ni.dll + 2012-05-10 12:03 . 2012-05-10 12:03 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\cfe15312373b4668398404b5822bab7d\Microsoft.JScript.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\f3fcd65eca42d13b746cf3f5bd993ee0\Microsoft.Build.Tasks.v3.5.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\2091903cd9b359e96f05ac2d6d25ef4e\Microsoft.Build.Tasks.ni.dll + 2012-05-10 12:02 . 2012-05-10 12:02 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5aa63a1cb41e3a5e1e8ed17072e60ec3\Microsoft.Build.Engine.ni.dll + 2012-05-09 21:02 . 2012-05-09 21:02 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll - 2010-06-23 20:27 . 2010-06-23 20:27 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll - 2012-04-11 20:50 . 2012-04-11 20:50 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2012-05-09 21:06 . 2012-05-09 21:06 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll - 2012-04-11 20:50 . 2012-04-11 20:50 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2012-05-09 21:06 . 2012-05-09 21:06 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2012-05-09 21:05 . 2012-05-09 21:05 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2012-04-11 20:50 . 2012-04-11 20:50 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2012-05-09 21:05 . 2012-05-09 21:05 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll - 2012-04-11 20:50 . 2012-04-11 20:50 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2012-05-09 21:02 . 2012-05-09 21:02 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll - 2012-04-11 20:50 . 2012-04-11 20:50 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll + 2012-05-09 21:05 . 2012-05-09 21:05 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2012-04-11 20:50 . 2012-04-11 20:50 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2012-05-09 21:06 . 2012-05-09 21:06 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2012-05-09 21:02 . 2012-05-09 21:02 4214784 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll + 2012-05-09 21:06 . 2012-05-09 21:06 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll - 2012-04-11 20:50 . 2012-04-11 20:50 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2012-05-09 21:14 . 2012-05-09 21:14 1179648 c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll - 2010-06-11 13:23 . 2010-06-11 13:23 1179648 c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll + 2012-05-09 21:14 . 2012-05-09 21:14 2002944 c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll - 2010-06-11 13:23 . 2010-06-11 13:23 2002944 c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll + 2012-05-09 21:14 . 2012-05-09 21:14 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll - 2011-10-13 05:08 . 2011-10-13 05:08 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll + 2009-09-05 11:42 . 2012-05-09 21:06 55656824 c:\windows\system32\MRT.exe + 2012-04-06 00:12 . 2012-04-06 00:12 15709696 c:\windows\Installer\870f78.msp + 2012-01-04 00:25 . 2012-01-04 00:25 17751552 c:\windows\Installer\870f6a.msp + 2012-04-06 01:13 . 2012-04-06 01:13 16527872 c:\windows\Installer\870f3a.msp + 2012-05-09 21:00 . 2012-05-09 21:00 23771136 c:\windows\Installer\870f0d.msp + 2011-09-15 19:42 . 2011-09-15 19:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WWLIB.DLL + 2012-05-09 21:09 . 2012-05-09 21:09 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\995fcf39ead2c2a53e084505c2c67d49\System.Windows.Forms.ni.dll + 2012-05-09 21:14 . 2012-05-09 21:14 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\7861cd979ea5db3fb7d30ed94fb0edd2\System.Web.ni.dll + 2012-05-09 21:11 . 2012-05-09 21:11 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\a9256d2ad7e4be2bbb4e9b18c3997b84\System.Design.ni.dll + 2012-05-09 21:08 . 2012-05-09 21:08 14329856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5b8ff47c1db373a2a4c638ca31988bd2\PresentationFramework.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 12218368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\4eb3cd1f1d5a83617524a9dfb96a657d\PresentationCore.ni.dll + 2012-05-09 21:07 . 2012-05-09 21:07 11492352 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll . -- Snapshot teruggezet naar huidige datum -- . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392] "SkyTel"="SkyTel.EXE" [2009-03-17 2879488] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848] . c:\documents and settings\Kinderen\Menu Start\Programma's\Opstarten\ OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\ InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-3-17 303104] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /r \??\I:\0autocheck autochk * . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Call of Duty\\CoDMP.exe"= "c:\\BitTorrent\\bittorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56388:TCP"= 56388:TCP:Pando Media Booster "56388:UDP"= 56388:UDP:Pando Media Booster . R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;c:\windows\system32\drivers\hcw88aud.sys [17-3-2009 21:57 12928] R1 MpKsl47eb3b3e;MpKsl47eb3b3e;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2ED6D2C9-25DC-40CD-B85B-A7195A78E1E3}\MpKsl47eb3b3e.sys [10-5-2012 13:14 29904] R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 18:21 249648] R2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [17-3-2009 22:00 434176] R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys [17-3-2009 21:57 182400] R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys [17-3-2009 21:57 320256] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [17-3-2009 21:57 74624] R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [17-3-2009 21:57 394880] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [17-3-2009 21:57 17280] S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 16:23 196176] S2 gupdate1ca0ddb241ef2ef;Google Updateservice (gupdate1ca0ddb241ef2ef);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 8:50 158856] S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:25 24448] S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25-4-2012 18:52 129976] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - MPKSL47EB3B3E . Inhoud van de 'Gedeelde Taken' map . 2012-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57] . 2012-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23] . 2012-05-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23] . 2012-05-10 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . . ------- Bijkomende Scan ------- . uInternet Connection Wizard,ShellNext = iexplore IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Free YouTube Download - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to Mp3 Converter - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.0.1 DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab FF - ProfilePath - c:\documents and settings\Kinderen\Application Data\Mozilla\Firefox\Profiles\0g756rsy.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.startpagina.nl/ FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false FF - user.js: extensions.incredibar_i.ms_url_id - FF - user.js: extensions.incredibar_i.upn2 - 6OyzRaMCX2 FF - user.js: extensions.incredibar_i.upn2n - 92261296176075556 FF - user.js: extensions.incredibar_i.productid - 26 FF - user.js: extensions.incredibar_i.installerproductid - 26 FF - user.js: extensions.incredibar_i.did - 10595 FF - user.js: extensions.incredibar_i.ppd - . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-05-10 16:31 Windows 5.1.2600 Service Pack 3 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-1606980848-1770027372-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C4684E37-EFF7-CB9C-94C3-06BB7F8AD9EA}*] "hahhphpbcigacdml"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61, 70,6b,00,ff "iajhnihobokimciimd"=hex:63,61,6f,62,6f,70,00,7c "iangnhnhodclokigco"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61, 70,6b,00,ff "dbpbddiedeakjooomdajkjkdmhbhgogjacffnkac"=hex:68,61,63,66,6f,67,6b,68,62,65, 6e,70,6d,67,6a,66,00,00 "jbpbddiedeakjooomdajjggcjcdpijjdgkcaldonlgeaajmnfoel"=hex:68,61,63,66,6f,67, 6b,68,62,65,6e,70,6d,67,6a,66,00,00 "dbpbddiedeakjooomdajhgjdgmghloofnnlicolf"=hex:62,61,68,62,00,00 . --------------------- DLLs Geladen Onder Lopende Processen --------------------- . - - - - - - - > 'winlogon.exe'(728) c:\windows\system32\SensApi.dll . Voltooingstijd: 2012-05-10 16:35:33 ComboFix-quarantined-files.txt 2012-05-10 14:35 ComboFix2.txt 2012-05-09 16:10 . Pre-Run: 85.176.938.496 bytes beschikbaar Post-Run: 85.176.934.400 bytes beschikbaar . - - End Of File - - 568B19D566C1F9C966FA4255E55694B9
  17. ComboFix 12-05-09.01 - Kinderen 09-05-2012 17:38:37.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1023.315 [GMT 2:00] Gestart vanuit: c:\documents and settings\Kinderen\Mijn documenten\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Kinderen\Application Data\facemoods.com c:\documents and settings\Kinderen\Bureaublad\Internet Explorer.lnk c:\documents and settings\Kinderen\Onlangs geopend\Thumbs.db C:\Thumbs.db c:\windows\EventSystem.log c:\windows\system32\asycfilt.dll.tmp c:\windows\system32\OLD20.tmp c:\windows\system32\PowerToyReadme.htm . . (((((((((((((((((((( Bestanden Gemaakt van 2012-04-09 to 2012-05-09 )))))))))))))))))))))))))))))) . . 2012-05-09 15:22 . 2012-05-09 15:22 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\offreg.dll 2012-05-09 13:29 . 2012-05-09 13:29 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\MpKsl3eb90a35.sys 2012-05-09 13:03 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\mpengine.dll 2012-05-08 16:38 . 2012-05-08 16:38 -------- d-----w- c:\program files\CodeStuff 2012-05-08 13:08 . 2012-05-08 13:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-05-08 13:08 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-05-08 12:11 . 2012-04-13 07:36 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-02 13:33 . 2012-05-04 06:02 -------- d-----w- c:\program files\Optimizer Pro 2012-05-02 13:32 . 2012-05-08 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ADDICT-THING 2012-05-02 12:14 . 2012-05-02 12:29 -------- d-----w- c:\program files\Maxis 2012-05-01 06:54 . 2012-05-01 06:54 -------- d-----w- C:\found.003 2012-04-27 17:11 . 2012-04-27 17:11 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Malwarebytes 2012-04-27 17:10 . 2012-04-27 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-04-27 15:58 . 2012-04-27 15:58 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG2012 2012-04-27 15:48 . 2012-04-27 15:48 -------- d-----w- c:\documents and settings\Kinderen\Application Data\AVG Secure Search 2012-04-27 15:42 . 2012-04-27 15:42 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files 2012-04-27 15:42 . 2012-04-28 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData 2012-04-26 17:57 . 2012-04-26 17:57 388096 ----a-r- c:\documents and settings\Kinderen\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-04-26 17:57 . 2012-04-26 17:57 -------- d-----w- c:\program files\Trend Micro 2012-04-25 16:52 . 2012-04-25 16:52 -------- d-----w- c:\program files\Mozilla Maintenance Service 2012-04-25 16:52 . 2012-04-25 16:52 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-04-25 16:52 . 2012-04-25 16:52 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-25 13:26 . 2012-04-25 13:26 -------- d-----w- c:\program files\Common Files\Skype 2012-04-24 16:42 . 2012-04-24 16:42 -------- d-----w- c:\program files\Video Codec 2012-04-24 16:32 . 2012-04-24 16:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Premium 2012-04-24 16:31 . 2012-04-24 16:42 684 ----a-w- C:\user.js 2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\Kinderen\Local Settings\Application Data\Babylon 2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon 2012-04-24 16:31 . 2012-04-24 16:31 -------- d-----w- c:\documents and settings\Kinderen\Application Data\Babylon 2012-04-24 16:31 . 2012-04-27 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Bcool 2012-04-24 16:30 . 2012-05-02 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate 2012-04-22 06:10 . 2012-04-22 06:10 -------- d-----w- c:\documents and settings\Kinderen\Application Data\LolClient 2012-04-21 19:11 . 2012-04-21 19:11 -------- d-----w- C:\Riot Games 2012-04-20 19:09 . 2012-04-20 19:09 -------- d-----w- C:\found.002 2012-04-12 05:16 . 2012-04-12 05:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple 2012-04-11 10:04 . 2012-04-11 10:04 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles 2012-04-09 20:17 . 2012-05-08 16:42 1409 ----a-w- c:\windows\QTFont.for . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-17 15:39 . 2010-03-14 11:26 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.exe 2012-04-17 15:38 . 2010-03-14 11:26 202448 ----a-w- c:\windows\system32\PnkBstrB.ex0 2012-04-03 18:19 . 2012-04-03 18:20 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-04-03 18:19 . 2011-07-22 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-20 18:44 . 2009-12-02 13:23 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-01 14:43 . 2012-03-01 14:42 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr 2012-03-01 11:00 . 2004-09-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-03-01 11:00 . 2004-09-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2012-03-01 11:00 . 2004-09-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-02-29 20:30 . 2010-03-14 11:26 75136 ----a-w- c:\windows\system32\PnkBstrA.exe 2012-02-29 20:17 . 2012-02-29 20:17 138056 ----a-w- c:\documents and settings\Kinderen\Application Data\PnkBstrK.sys 2012-02-29 14:10 . 2004-09-02 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10 . 2004-09-02 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17 . 2004-09-02 12:00 385024 ----a-w- c:\windows\system32\html.iec 2012-02-16 20:52 . 2012-02-07 20:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-15 09:01 . 2012-04-09 09:25 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll 2012-02-15 09:01 . 2012-04-09 09:25 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2012-04-25 16:52 . 2012-02-07 20:09 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll [-] 2004-09-02 12:00 . 61A79E8D4A440095EA2EB9FD694CD1AE . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392] "SkyTel"="SkyTel.EXE" [2009-03-17 2879488] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848] . c:\documents and settings\Kinderen\Menu Start\Programma's\Opstarten\ OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\ InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-3-17 303104] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /r \??\I:\0autocheck autochk * . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Call of Duty\\CoDMP.exe"= "c:\\BitTorrent\\bittorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56388:TCP"= 56388:TCP:Pando Media Booster "56388:UDP"= 56388:UDP:Pando Media Booster . R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;c:\windows\system32\drivers\hcw88aud.sys [17-3-2009 21:57 12928] R1 MpKsl3eb90a35;MpKsl3eb90a35;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D093E5C-A68E-428E-9868-B79C08371003}\MpKsl3eb90a35.sys [9-5-2012 15:29 29904] R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [13-10-2011 18:21 249648] R2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [17-3-2009 22:00 434176] R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys [17-3-2009 21:57 182400] R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys [17-3-2009 21:57 320256] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [17-3-2009 21:57 74624] R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [17-3-2009 21:57 394880] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [17-3-2009 21:57 17280] S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [21-10-2011 16:23 196176] S2 gupdate1ca0ddb241ef2ef;Google Updateservice (gupdate1ca0ddb241ef2ef);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29-2-2012 8:50 158856] S3 FNETTHJM_152D;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm_152D.sys [9-2-2011 22:25 24448] S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26-7-2009 12:23 133104] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25-4-2012 18:52 129976] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - MPKSL3EB90A35 . Inhoud van de 'Gedeelde Taken' map . 2012-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57] . 2012-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23] . 2012-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-26 10:23] . 2012-05-09 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job - c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 15:03] . . ------- Bijkomende Scan ------- . uInternet Connection Wizard,ShellNext = iexplore IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Free YouTube Download - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to Mp3 Converter - c:\documents and settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.0.1 DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab FF - ProfilePath - c:\documents and settings\Kinderen\Application Data\Mozilla\Firefox\Profiles\0g756rsy.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.startpagina.nl/ FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111252 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - 68b81f39000000000000001d6060f95b FF - user.js: extensions.BabylonToolbar_i.hardId - 68b81f39000000000000001d6060f95b FF - user.js: extensions.BabylonToolbar_i.instlDay - 15454 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1718:31 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: extensions.incredibar_i.newTab - false FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyzRaMCX2&loc=IB_TB&i=26&search= FF - user.js: extensions.incredibar_i.id - 68b81f39000000000000001d6060f95b FF - user.js: extensions.incredibar_i.instlDay - 15454 FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14 FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1418:42 FF - user.js: extensions.incredibar_i.prtnrId - Incredibar FF - user.js: extensions.incredibar_i.prdct - incredibar FF - user.js: extensions.incredibar_i.aflt - orgnl FF - user.js: extensions.incredibar_i.smplGrp - none FF - user.js: extensions.incredibar_i.tlbrId - base FF - user.js: extensions.incredibar_i.instlRef - FF - user.js: extensions.incredibar_i.dfltLng - FF - user.js: extensions.incredibar_i.excTlbr - false FF - user.js: extensions.incredibar_i.ms_url_id - FF - user.js: extensions.incredibar_i.upn2 - 6OyzRaMCX2 FF - user.js: extensions.incredibar_i.upn2n - 92261296176075556 FF - user.js: extensions.incredibar_i.productid - 26 FF - user.js: extensions.incredibar_i.installerproductid - 26 FF - user.js: extensions.incredibar_i.did - 10595 FF - user.js: extensions.incredibar_i.ppd - . - - - - ORPHANS VERWIJDERD - - - - . WebBrowser-{3AD798D0-4642-4C55-BC14-CFE7DD19E0D1} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) AddRemove-Free Studio_is1 - c:\kinderen bestanden\Free Studio\unins000.exe AddRemove-PunkBusterSvc - c:\program files\EA Games\Battlefield Heroes\pbsvc_heroes.exe AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}\bm_installer.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-05-09 18:05 Windows 5.1.2600 Service Pack 3 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-1606980848-1770027372-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C4684E37-EFF7-CB9C-94C3-06BB7F8AD9EA}*] "hahhphpbcigacdml"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61, 70,6b,00,ff "iajhnihobokimciimd"=hex:63,61,6f,62,6f,70,00,7c "iangnhnhodclokigco"=hex:6a,61,6a,62,67,64,6a,66,63,6a,6d,67,6f,6b,67,64,62,61, 70,6b,00,ff "dbpbddiedeakjooomdajkjkdmhbhgogjacffnkac"=hex:68,61,63,66,6f,67,6b,68,62,65, 6e,70,6d,67,6a,66,00,00 "jbpbddiedeakjooomdajjggcjcdpijjdgkcaldonlgeaajmnfoel"=hex:68,61,63,66,6f,67, 6b,68,62,65,6e,70,6d,67,6a,66,00,00 "dbpbddiedeakjooomdajhgjdgmghloofnnlicolf"=hex:62,61,68,62,00,00 . Voltooingstijd: 2012-05-09 18:10:00 ComboFix-quarantined-files.txt 2012-05-09 16:09 . Pre-Run: 80.180.736.000 bytes beschikbaar Post-Run: 86.134.370.304 bytes beschikbaar . WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer . - - End Of File - - 6DDD4AFE7FC078AE9CF070795C4AD1DB de text enhance komt elke keer als de pc opnieuw opgestart wordt weer terug. Weet niet of dat hierdoor opgelost zal zijn. De plug-ins heb ik enkel uitgeschakeld en niet verwijderd. Als ik de plugins allemaal uitschakel en vervolgens weer inschakel is de text enhance totdat ik de pc opnieuw opstart wel verdwenen.
  18. Ik heb alle addOns uitgeschakeld. Heb er geen 1 verwijderd omdat ik niet kon vinden hoe dat moest. Heb vervolgens even op google gezocht naar het handmatig verwijderen van die add ons. dit was het resultaat en heb ik uitgevoerd: Problemen met plug-ins oplossen | Probleemoplossing | Firefox Help misschien is dat de reden dat alles verwijderd is? bij extra-> addOns -> Plug-ins staan de volgende ingeschakeld: Adobe acrobat 9.5.1.283 Google Earth Plugin 6.1.0.5001 Google update 1.3.21.111 Shockwave Flash 11.1.102.55 Silverlight Plug-In 5.0.61118.0 Unity Player 2.6.1.31223 uitgeschakeld staan: 3DVIA player 5.0.0.12 DNA Plug-in 1.0.0.1 EA Battlefield Heroes 5.0.134.0 (deze weet ik zeker dat hij verwijderd kan worden) Jave Deployment Toolkiet 6.0.310.5 Java Platform SE 6 U31 6.0.310.5 Microsoft Office Live Plug-in for Firefox 2.0.2313.0 Microsoft® Windows Media Player Firefox Plugin 1.0.0.8 Pando Web Plugin 1.0.0.1 Quicktime Plug-in 6.0 6.0.0.75 Shockwave for Director 11.5.6.606 SOE Web Installer 1.0.3.151 Windows Live® Photo Gallery 14.0.8117.416 Windows Presentation Foundation 3.5.30729.1 dacht nog redelijk verstand van computers te hebben maar dat blijkt wat tegen te vallen De verdere aangegeven stappen zijn zojuist uitgevoerd. nadat ik de computer nogmaals heb opgestart merk ik dat het probleem zich weer voordoet. Ook wel: de text enhance was weer terug. na de plugins aan en uit gezet te hebben is het probleem (waarschijnlijk tot de volgende keer herstarten) opgelost
  19. Heb alle AddOns uitgeschakeld. Het probleem zelf was daarna verholpen. Kreeg wel een nieuw probleem: de youtubefilmpjes wilden niet meer laden. Heb dit inmiddels opgelost door een aantal AddOns weer aan te zetten. Hoe moet ik de AddOns volledig verwijderen? Ik heb ze nu enkel uitgeschakeld. Malware log: Malwarebytes Anti-Malware 1.61.0.1400 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Databaseversie: v2012.05.08.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Kinderen :: R01 [administrator] 8-5-2012 15:09:44 mbam-log-2012-05-08 (15-09-44).txt Scantype: Snelle scan Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scanopties: P2P Objecten gescand: 367643 Verstreken tijd: 1 uur/uren, 58 minuut/minuten, 52 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Bestanden gedetecteerd: 2 C:\Documents and Settings\Kinderen\Mijn documenten\Downloads\DownloadSetup.exe (Affiliate.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Documents and Settings\Kinderen\Mijn documenten\Downloads\SoftonicDownloader_voor_virtual-dj.exe (PUP.ToolbarDownloader) -> Succesvol in quarantaine geplaatst en verwijderd. (einde) Nieuwe HiJackThis scan: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:33:11, on 8-5-2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Your Home Page Has Been Changed R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.marktplaats.nl/js/widgets/imageUploader/aurigma/5_7_24_0/ImageUploader5.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: Google Updateservice (gupdate1ca0ddb241ef2ef) (gupdate1ca0ddb241ef2ef) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe -- End of file - 10124 bytes Is het misschien mogelijk het aantal running processes te verlagen om zo mijn pc sneller te maken?
  20. Beste, Ook ik heb last van text enhance sinds enige tijd. Op nagenoeg elke pagina kom ik het wel weer tegen. Zelf heb ik al alles geprobeerd was ik kan bedenken om dit probleem op te lossen. Krijg het echter niet weg. hoop dat jullie me verder kunnen helpen. Het vast wat voorwerk gedaan door een hijackthis scan te doen. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 19:40:16, on 7-5-2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\Microsoft\BingBar\BBSvc.EXE C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\DNA\btdna.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MyStart by IncrediBar.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Your Home Page Has Been Changed R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=68b81f39000000000000001d6060f95b&tlver=1.4.19.19&affID=19405 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file) R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) R3 - URLSearchHook: (no name) - {3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: ADDICT-THING - {9024DD4E-5BBF-4612-B2DF-256B5E594B33} - C:\Documents and Settings\All Users\Application Data\ADDICT-THING\bhoclass.dll O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing) O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Kinderen\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://verkopen.marktplaats.nl/js/widgets/imageUploader/aurigma/5_7_24_0/ImageUploader5.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: Google Updateservice (gupdate1ca0ddb241ef2ef) (gupdate1ca0ddb241ef2ef) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe -- End of file - 11963 bytes
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.