DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Gebruiker at 20:00:30 on 2012-06-11
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.31.1043.18.1791.1122
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.nl
uStart Page = hxxp://startpagina.nl/
uDefault_Page_URL = www.google.nl
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {0734D757-FEA6-4637-A7E4-2BD40A7FD8DA} - No File
uRun: c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: “c:\program files\windows live\messenger\msnmsgr.exe” /background
mRun: “c:\program files\avast software\avast\avastUI.exe” /nogui
mRun: “c:\program files\common files\java\java update\jusched.exe”
mRun: “c:\program files\microsoft office\office14\BCSSync.exe” /DelayServices
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Verzenden naar OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 212.54.35.25 212.54.40.25
TCP: Interfaces\{9BF62FCF-BB50-467D-8405-825B68BA4DEA} : DhcpNameServer = 212.54.35.25 212.54.40.25
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys
S3 c2wts;Claims voor Windows Token Service;c:\program files\windows identity foundation\v3.5\c2wtshost.exe
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe
.
=============== Created Last 30 ================
.
2012-06-11 15:20:03 388096 —-a-r- c:\users\gebruiker\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-06-11 15:20:03 ——– d—–w- c:\program files\Trend Micro
2012-06-11 10:21:13 ——– d—–w- c:\users\gebruiker\appdata\local\{3AF78FC3-661D-40CF-A1FD-1F3BEC091B66}
2012-06-11 10:21:01 ——– d—–w- c:\users\gebruiker\appdata\local\{6D1FBD3A-AB31-416D-8EBD-1780A4030AC5}
2012-06-11 10:14:25 39272 —-a-w- c:\windows\system32\drivers\fssfltr.sys
2012-06-11 10:09:20 ——– d—–w- c:\program files\Microsoft
2012-06-11 10:06:14 7450888 —-a-w- c:\program files\common files\windows live\.cache\d3da10d01cd47b901\bingbarsetup.exe
2012-06-11 07:04:10 ——– d—–w- c:\users\gebruiker\appdata\local\{4B7F3EB8-CB55-400B-82EC-F22A2C2B83E4}
2012-06-11 07:03:56 ——– d—–w- c:\users\gebruiker\appdata\local\{4944C893-C79C-4F2E-B1A4-67E6C5DD099D}
2012-06-11 06:52:31 ——– d—–w- c:\users\gebruiker\appdata\roaming\GlarySoft
2012-06-11 06:34:30 ——– d—–w- c:\users\gebruiker\appdata\local\{4E21EB6D-7380-4DB7-96B0-650FCA82858F}
2012-06-11 06:00:12 ——– d—–w- c:\users\gebruiker\appdata\local\{E1533ED4-4B22-41E2-8D51-A1C911AEC1BB}
2012-06-11 05:59:34 ——– d—–w- c:\users\gebruiker\appdata\local\{6D3B6E0D-8065-45E3-88F5-8F0708672D0A}
2012-06-10 19:30:46 ——– d—–w- c:\users\gebruiker\appdata\roaming\BSplayer Pro
2012-06-10 19:30:46 ——– d—–w- c:\users\gebruiker\appdata\roaming\BSplayer
2012-06-10 19:30:45 ——– d—–w- c:\program files\Webteh
2012-06-10 19:01:32 ——– d—–w- c:\users\gebruiker\appdata\roaming\Ashampoo
2012-06-10 19:01:32 ——– d—–w- c:\program files\Conduit
2012-06-10 19:01:29 ——– d—–w- c:\users\gebruiker\appdata\local\Conduit
2012-06-10 19:00:35 ——– d—–w- c:\users\gebruiker\appdata\local\ashampoo
2012-06-10 19:00:35 ——– d—–w- c:\programdata\ashampoo
2012-06-10 18:59:19 ——– d—–w- c:\program files\Ashampoo
2012-06-10 17:30:37 ——– d—–w- c:\windows\AutoKMS
2012-06-10 17:23:28 ——– d—–w- c:\windows\system32\appmgmt
2012-06-10 17:12:57 ——– d—–w- c:\program files\Microsoft Synchronization Services
2012-06-10 17:11:29 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2012-06-10 17:10:19 ——– d—–w- c:\program files\Microsoft Analysis Services
2012-06-10 17:09:22 ——– d—–w- c:\users\gebruiker\appdata\local\Microsoft Help
2012-06-10 16:58:23 ——– d—–w- c:\windows\pss
2012-06-10 16:57:28 476960 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-06-10 14:17:36 ——– d—–w- c:\users\gebruiker\appdata\local\ElevatedDiagnostics
2012-06-10 13:46:52 ——– d—–w- c:\program files\NewsLeecher
2012-06-10 13:13:36 21888 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-06-10 13:11:13 ——– d—–w- c:\users\gebruiker\appdata\roaming\OpenOffice.org
2012-06-10 12:59:34 ——– d—–w- c:\program files\OpenOffice.org 3
2012-06-10 12:58:22 472864 —-a-w- c:\windows\system32\deployJava1.dll
2012-06-10 12:29:18 ——– d—–w- c:\users\gebruiker\appdata\roaming\Malwarebytes
2012-06-10 12:29:09 ——– d—–w- c:\programdata\Malwarebytes
2012-06-10 12:29:07 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-10 12:29:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-06-10 12:28:33 ——– d—–w- c:\programdata\IObit
2012-06-10 12:28:13 ——– d—–w- c:\users\gebruiker\appdata\roaming\IObit
2012-06-10 12:27:58 ——– d—–w- c:\program files\IObit
2012-06-10 12:25:17 ——– d—–w- c:\program files\VideoLAN
2012-06-10 11:47:36 ——– d—–w- c:\users\gebruiker\appdata\roaming\NewsLeecher
2012-06-10 11:31:31 ——– d—–w- c:\users\gebruiker\appdata\local\SpotLite
2012-06-10 11:30:34 ——– d—–w- c:\program files\SpotLite
2012-06-10 10:16:15 ——– dc-h–w- c:\programdata\{27B0A538-DF16-44D6-820D-D0B042C42C20}
2012-06-10 10:16:14 ——– d—–w- c:\program files\UPC Fiber Power Optimizer
2012-06-10 10:15:57 ——– d—–w- c:\users\gebruiker\appdata\local\PackageAware
2012-06-10 10:08:09 89600 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
2012-06-10 09:54:40 ——– d—–w- c:\users\gebruiker\appdata\local\{5FB90B87-A628-4538-AA7F-52CCE8E13954}
2012-06-10 09:54:18 ——– d—–w- c:\users\gebruiker\appdata\local\{16443ED7-995A-47A3-8508-28435B0FD63D}
2012-06-10 09:49:49 ——– d—–w- c:\program files\CCleaner
2012-06-10 09:17:42 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-10 09:17:42 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-09 10:31:51 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-06-09 10:31:51 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-09 10:03:17 ——– d—–w- c:\windows\system32\SPReview
2012-06-09 10:01:04 ——– d—–w- c:\windows\system32\EventProviders
2012-06-09 09:51:59 988160 —-a-w- c:\windows\system32\propsys.dll
2012-06-09 09:50:59 750080 —-a-w- c:\windows\system32\sdcpl.dll
2012-06-09 09:49:35 189952 —-a-w- c:\windows\system32\wdscore.dll
2012-06-09 09:49:22 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2012-06-09 09:49:22 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2012-06-09 09:49:22 189952 —-a-w- c:\program files\windows portable devices\sqmapi.dll
2012-06-09 09:49:15 189952 —-a-w- c:\windows\system32\sqmapi.dll
2012-06-09 09:07:46 ——– d—–w- c:\users\gebruiker\appdata\local\{4273CFB7-D653-4C94-B9DA-34E42D0064A4}
2012-06-09 09:07:33 ——– d—–w- c:\users\gebruiker\appdata\local\{78A24301-35D8-4517-AB28-C50CD8640076}
2012-06-09 09:07:22 ——– d—–w- c:\users\gebruiker\appdata\roaming\Windows Live Writer
2012-06-09 09:07:22 ——– d—–w- c:\users\gebruiker\appdata\local\Windows Live Writer
2012-06-09 09:07:06 ——– d—–w- c:\users\gebruiker\Tracing
2012-06-09 09:05:06 ——– d—–w- c:\windows\nl
2012-06-09 09:02:06 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2012-06-09 08:59:35 ——– d—–w- c:\windows\PCHEALTH
2012-06-09 08:58:46 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll
2012-06-09 08:58:46 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2012-06-09 08:58:46 453456 —-a-w- c:\windows\system32\d3dx10_42.dll
2012-06-09 08:58:43 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2012-06-09 08:58:39 15712 —-a-w- c:\program files\common files\windows live\.cache\fb402981cd461e09\MeshBetaRemover.exe
2012-06-09 08:58:34 89944 —-a-w- c:\program files\common files\windows live\.cache\c4f2cb81cd461e08\DSETUP.dll
2012-06-09 08:58:34 537432 —-a-w- c:\program files\common files\windows live\.cache\c4f2cb81cd461e08\DXSETUP.exe
2012-06-09 08:58:34 1801048 —-a-w- c:\program files\common files\windows live\.cache\c4f2cb81cd461e08\dsetup32.dll
2012-06-09 08:58:28 94040 —-a-w- c:\program files\common files\windows live\.cache\856c1981cd461e07\DSETUP.dll
2012-06-09 08:58:28 525656 —-a-w- c:\program files\common files\windows live\.cache\856c1981cd461e07\DXSETUP.exe
2012-06-09 08:58:28 1691480 —-a-w- c:\program files\common files\windows live\.cache\856c1981cd461e07\dsetup32.dll
2012-06-09 08:57:22 ——– d—–w- c:\users\gebruiker\appdata\local\Windows Live
2012-06-09 08:57:20 ——– d—–w- c:\program files\common files\Windows Live
2012-06-09 08:50:33 805376 —-a-w- c:\windows\system32\FntCache.dll
2012-06-09 08:50:32 739840 —-a-w- c:\windows\system32\d2d1.dll
2012-06-09 08:40:26 ——– d—–w- c:\windows\system32\Wat
2012-06-08 21:25:16 ——– d—–w- c:\windows\system32\wbem\en-US
2012-06-08 20:55:36 6737808 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{eb719180-232e-4cd0-bcc5-3d202963dc55}\mpengine.dll
2012-06-08 20:55:35 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-06-08 20:34:09 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-08 20:34:09 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-08 20:34:08 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-06-08 20:34:08 159232 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-08 20:33:33 293376 —-a-w- c:\windows\system32\browserchoice.exe
2012-06-08 20:26:48 ——– d—–w- c:\programdata\NVIDIA Corporation
2012-06-08 20:26:39 ——– d—–w- c:\program files\NVIDIA Corporation
2012-06-08 20:22:39 571904 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-08 20:22:39 233472 —-a-w- c:\windows\system32\oleacc.dll
2012-06-08 20:22:33 1328128 —-a-w- c:\windows\system32\quartz.dll
2012-06-08 20:22:32 514560 —-a-w- c:\windows\system32\qdvd.dll
2012-06-08 20:22:29 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2012-06-08 20:19:59 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-06-08 20:18:58 1288472 —-a-w- c:\windows\system32\ntdll.dll
2012-06-08 20:18:25 2048 —-a-w- c:\windows\system32\tzres.dll
2012-06-08 20:16:57 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2012-06-08 20:16:57 145920 —-a-w- c:\windows\system32\cfgmgr32.dll
2012-06-08 20:16:48 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2012-06-08 20:16:47 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2012-06-08 20:16:39 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2012-06-08 20:16:21 56176 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-08 20:16:03 708608 —-a-w- c:\program files\common files\system\wab32.dll
2012-06-08 20:14:30 802304 —-a-w- c:\windows\system32\WFS.exe
2012-06-08 20:14:30 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2012-06-08 20:14:20 870912 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-08 20:14:07 690688 —-a-w- c:\windows\system32\msvcrt.dll
2012-06-08 20:13:58 123904 —-a-w- c:\windows\system32\poqexec.exe
2012-06-08 20:13:41 1077248 —-a-w- c:\windows\system32\DWrite.dll
2012-06-08 20:13:37 67072 —-a-w- c:\windows\system32\packager.dll
2012-06-08 20:13:29 1137664 —-a-w- c:\windows\system32\mfc42.dll
2012-06-08 20:13:27 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2012-06-08 20:03:41 ——– d—–w- c:\windows\Panther
2012-06-08 19:55:28 ——– d—–w- C:\Windows.old
2012-06-08 19:52:43 728448 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-06-08 19:52:42 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-06-08 19:52:42 107520 —-a-w- c:\windows\system32\cdd.dll
2012-06-08 19:47:03 ——– d—–w- C:\oud
2012-06-08 19:39:02 ——– d—–w- c:\windows\system32\wbem\Performance
2012-06-08 19:38:56 44376 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-06-08 19:38:55 612184 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-06-08 19:38:54 57688 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-06-08 19:38:00 41184 —-a-w- c:\windows\avastSS.scr
2012-06-08 19:37:45 ——– d—–w- c:\programdata\AVAST Software
2012-06-08 19:37:45 ——– d—–w- c:\program files\AVAST Software
2012-06-08 19:36:46 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-08 19:36:41 919040 —-a-w- c:\windows\system32\rdpcorets.dll
2012-06-08 19:36:41 826880 —-a-w- c:\windows\system32\rdpcore.dll
2012-06-08 19:36:41 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-08 19:36:41 15872 —-a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2012-06-08 19:36:41 134656 —-a-w- c:\windows\system32\rdpudd.dll
2012-06-08 19:36:40 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-06-08 19:36:40 18432 —-a-w- c:\windows\system32\drivers\tdpipe.sys
2012-06-08 19:34:36 441633 —-a-w- c:\windows\EMPTYRB.EXE
2012-06-08 19:34:36 441423 —-a-w- c:\windows\OPENRB.EXE
2012-06-08 19:34:31 ——– d—–w- c:\windows\GodMode Windows7.{ED7BA470-8E54-465E-825C-99712043E01C}
2012-06-08 19:30:46 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-06-08 19:30:33 ——– d—–w- c:\program files\PlayReady
2012-06-08 19:30:26 ——– d-sh–w- c:\windows\Installer
2012-06-08 19:30:08 ——– d—–w- c:\program files\MCE
2012-06-08 19:29:55 ——– d-sh–w- C:\Recovery
2012-06-08 19:29:54 ——– d-sh–we c:\programdata\Sjablonen
2012-06-08 19:29:54 ——– d-sh–we c:\programdata\Menu Start
2012-06-08 19:29:54 ——– d-sh–we c:\programdata\Favorieten
2012-06-08 19:29:54 ——– d-sh–we c:\programdata\Documenten
2012-06-08 19:29:54 ——– d-sh–we c:\programdata\Bureaublad
.
==================== Find3M ====================
.
2012-06-09 10:17:14 152576 —-a-w- c:\windows\system32\msclmd.dll
2012-03-31 04:39:37 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 02:36:11 2343424 —-a-w- c:\windows\system32\win32k.sys
2012-03-30 10:23:11 1291632 —-a-w- c:\windows\system32\drivers\tcpip.sys
.
============= FINISH: 20:01:16,74 ===============