Author Topic: It's that time again  (Read 1934 times)

Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« on: June 04, 2009, 11:56:21 AM »
Hi guys,

I think I have a virus, but I can't be sure; I downloaded a "movie" and didn't check the file before I opened it (stupid I know). Now everything's working slower and my avg antivirus gets my computer frozen whenever I try to remove threats. So anyway, hope you can help, thanks in advance and here's my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20:46, on 4-6-2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Media\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://games.asobrain.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

--
End of file - 11426 bytes

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #1 on: June 05, 2009, 12:10:34 AM »
Can you do the following please

download Malwarebytes' Anti-Malware from Here or Here
Save the installer to desktop

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to [color=\"#006400\"]Update Malwarebytes' Anti-Malware[/color] and [color=\"#006400\"]Launch Malwarebytes' Anti-Malware[/color], then click Finish.
       
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
       
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
       
  • Make sure that everything is checked, and click Remove Selected.
        * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
       
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

With the MBAM log, run a fresh Scan and Save logfile with Hijackthis and post the new log

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« Reply #2 on: June 05, 2009, 01:34:06 PM »
It didn't find anything:

Malwarebytes' Anti-Malware 1.37
Database version: 2234
Windows 6.0.6001 Service Pack 1

5-6-2009 20:08:28
mbam-log-2009-06-05 (20-08-28).txt

Scan type: Quick Scan
Objects scanned: 73776
Time elapsed: 1 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



But  I ran the hjt-log again just in case:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:30:54, on 5-6-2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Media\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://games.asobrain.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

--
End of file - 11637 bytes


Thanks Again!

Nia

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #3 on: June 05, 2009, 02:37:43 PM »
That didn't find anything, can you do the following
Download and Save to your desktop
[color=\"#FF0000\"]OTS.exe[/color] by OldTimer

Right click on OTS.exe and choose to "Run as Administrator"
Under Additional Scans click the button labelled "Extras"
Also, put a tick beside>> Reg - Disabled MS Config Items
So now all the following will be ticked
    Reg - Disabled MS Config Items
    Reg - File Associations
    Reg - Protocol Filters
    Reg - Protocol Handlers
    Reg - Security Center Settings
    Reg - Winsock2 Catalogs
    Reg - Uninstall List
    Evnt - EventViewer Logs (Last 10 Errors)

Afterwards: Click the button [color=\"#0000FF\"]Run Scan[/color]

Let this scan finish, when done, it will open a log
Can you copy and paste that log back here please
A copy of the log will also be on your desktop>>OTS.txt

NOTE: IF you do get an error posting this log, please Upload it in a reply
Simply using the Browse..>> UPLOAD buttons on the bottom right of the reply box

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« Reply #4 on: June 05, 2009, 04:02:50 PM »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #5 on: June 05, 2009, 04:16:50 PM »
Is there a problem?
I don't see the log
« Last Edit: June 05, 2009, 04:17:08 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« Reply #6 on: June 05, 2009, 04:39:35 PM »
OTS logfile created on: 5-6-2009 22:55:18 - Run 1
OTS by OldTimer - Version 3.0.3.0     Folder = C:\Users\Media\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
 
2,00 Gb Total Physical Memory | 1,55 Gb Available Physical Memory | 77,54% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,44 Gb Total Space | 24,62 Gb Free Space | 22,09% Space Free | Partition Type: NTFS
Drive D: | 104,90 Gb Total Space | 83,13 Gb Free Space | 79,25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PC_VAN_MEDIA
Current User Name: Media
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
acervcm.exe -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe -> [2009-01-07 17:41:42 | 01,216,512 | ---- | M] (Acer Incorporated)
acp2hid.exe -> C:\Program Files\Acer\Acer VCM\acp2HID.exe -> [2007-03-27 12:00:32 | 00,196,608 | ---- | M] (Acer Inc.)
agentsvc.exe -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -> [2008-03-03 14:11:14 | 00,016,384 | ---- | M] (NewTech Infosystems, Inc.)
agrsmsvc.exe -> C:\Windows\System32\agrsmsvc.exe -> [2007-12-11 05:15:04 | 00,012,800 | ---- | M] (Agere Systems)
arcadedeluxeagent.exe -> C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe -> [2008-07-24 15:54:10 | 00,147,456 | ---- | M] (CyberLink Corp.)
avgcsrvx.exe -> C:\Program Files\AVG\AVG8\avgcsrvx.exe -> [2009-05-24 11:19:00 | 00,692,504 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgemc.exe -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009-05-24 11:18:59 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgnsx.exe -> C:\Program Files\AVG\AVG8\avgnsx.exe -> [2009-05-24 11:19:00 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> C:\Program Files\AVG\AVG8\avgrsx.exe -> [2009-05-24 11:19:00 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgtray.exe -> C:\Program Files\AVG\AVG8\avgtray.exe -> [2009-05-24 11:18:59 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009-05-24 11:18:58 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.)
backupsvc.exe -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -> [2008-04-25 22:36:20 | 00,045,056 | ---- | M] (NewTech InfoSystems, Inc.)
basvc.exe -> C:\Program Files\Acer\Acer Bio Protection\BASVC.exe -> [2009-05-12 02:45:04 | 03,520,512 | ---- | M] ()
bkuptray.exe -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe -> [2008-04-25 22:36:20 | 00,028,672 | ---- | M] ()
clhnservice.exe -> C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -> [2008-01-16 18:35:02 | 00,081,504 | ---- | M] ()
clmlsvc.exe -> C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe -> [2008-07-24 15:54:18 | 00,167,936 | ---- | M] (CyberLink)
compptcvui.exe -> C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe -> [2009-05-12 02:45:13 | 03,485,696 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
eaudio.exe -> C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe -> [2008-05-30 13:24:30 | 00,544,768 | ---- | M] (Acer Incorporated)
edsloader.exe -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe -> [2008-07-29 18:52:50 | 00,526,896 | ---- | M] (Egis Incorporated)
edsservice.exe -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008-07-29 18:53:00 | 00,500,784 | ---- | M] (Egis Incorporated)
epower_dmc.exe -> C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe -> [2008-08-01 10:51:42 | 00,405,504 | ---- | M] (Acer Inc.)
etservice.exe -> C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -> [2008-06-02 10:25:40 | 00,024,576 | ---- | M] ()
evteng.exe -> C:\Program Files\Intel\WiFi\bin\EvtEng.exe -> [2008-04-30 20:41:12 | 00,815,104 | ---- | M] (Intel® Corporation)
explorer.exe -> C:\Windows\Explorer.EXE -> [2008-10-29 08:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation)
firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2009-04-24 11:27:03 | 00,307,704 | ---- | M] (Mozilla Corporation)
framework.launcher.exe -> C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe -> [2008-06-02 10:26:22 | 00,319,488 | ---- | M] ()
googletoolbarnotifier.exe -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009-05-12 02:41:12 | 00,068,856 | ---- | M] (Google Inc.)
iaanotif.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe -> [2008-07-20 18:45:06 | 00,182,808 | ---- | M] (Intel Corporation)
iaantmon.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2008-07-20 18:45:06 | 00,354,840 | ---- | M] (Intel Corporation)
jusched.exe -> C:\Program Files\Java\jre6\bin\jusched.exe -> [2009-03-09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.)
lmanager.exe -> C:\Program Files\Launch Manager\LManager.exe -> [2008-06-16 11:58:38 | 00,809,480 | ---- | M] (Dritek System Inc.)
lssrvc.exe -> C:\Program Files\Common Files\LightScribe\LSSrvc.exe -> [2007-01-17 12:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
mdm.exe -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe -> [2006-10-26 13:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation)
mobilityservice.exe -> C:\Acer\Mobility Center\MobilityService.exe -> [2007-12-06 17:15:28 | 00,110,592 | ---- | M] ()
msascui.exe -> C:\Program Files\Windows Defender\MSASCui.exe -> [2008-01-21 04:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation)
nvvsvc.exe -> C:\Windows\System32\nvvsvc.exe -> [2008-12-05 12:24:00 | 00,203,296 | ---- | M] (NVIDIA Corporation)
ots.exe -> C:\Users\Media\Downloads\OTS.exe -> [2009-06-05 22:46:27 | 00,505,344 | ---- | M] (OldTimer Tools)
pdtwzd.exe -> C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe -> [2009-05-12 02:44:55 | 03,719,680 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
plfseti.exe -> C:\Windows\PLFSetI.exe -> [2008-06-30 17:56:32 | 00,200,704 | ---- | M] ()
pmvservice.exe -> C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe -> [2008-07-18 16:04:36 | 00,167,936 | ---- | M] (Acer Corp.)
popcfde.tmp -> C:\Users\Media\Documents\Games\bejeweled 2 deluxe\popCFDE.tmp -> [2009-06-05 21:18:36 | 01,675,264 | -H-- | M] ()
pwdbank.exe -> C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe -> [2009-05-12 02:45:18 | 03,833,640 | ---- | M] ()
regsrvc.exe -> C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -> [2008-04-30 20:10:10 | 00,466,944 | ---- | M] (Intel® Corporation)
richvideo.exe -> C:\Program Files\Cyberlink\Shared files\RichVideo.exe -> [2007-01-09 19:25:30 | 00,272,024 | ---- | M] ()
rs_service.exe -> C:\Program Files\Acer\Acer VCM\RS_Service.exe -> [2008-07-19 15:13:44 | 00,233,472 | ---- | M] (Acer Incorporated)
rthdvcpl.exe -> C:\Windows\RtHDVCpl.exe -> [2008-05-07 10:19:26 | 06,139,904 | ---- | M] (Realtek Semiconductor)
rtkbtmnt.exe -> C:\Users\Media\AppData\Local\Temp\RtkBtMnt.exe -> [2009-05-12 02:44:02 | 00,204,800 | ---- | M] (Realtek Semiconductor Corp.)
schedulersvc.exe -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -> [2008-04-25 22:36:02 | 00,131,072 | ---- | M] ()
syntpenh.exe -> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe -> [2008-04-04 11:26:54 | 01,037,608 | ---- | M] (Synaptics, Inc.)
syntphelper.exe -> C:\Program Files\Synaptics\SynTP\SynTPHelper.exe -> [2008-04-04 11:27:02 | 00,095,528 | ---- | M] (Synaptics, Inc.)
unsecapp.exe -> C:\Windows\System32\wbem\unsecapp.exe -> [2008-01-21 04:23:52 | 00,037,888 | ---- | M] (Microsoft Corporation)
vfsfpservice.exe -> C:\Windows\System32\vfsFPService.exe -> [2008-05-26 05:43:58 | 00,599,344 | ---- | M] (Validity Sensors, Inc.)
winbej2.exe -> C:\Users\Media\Documents\Games\bejeweled 2 deluxe\WinBej2.exe -> [2007-12-04 05:56:28 | 02,040,226 | ---- | M] ()
wmiprvse.exe -> C:\Windows\System32\wbem\wmiprvse.exe -> [2009-03-03 04:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation)
wmiprvse.exe -> C:\Windows\System32\wbem\wmiprvse.exe -> [2009-03-03 04:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(AgereModemAudio) Agere Modem Call Progress Audio [Win32_Own | Auto | Running] -> C:\Windows\System32\agrsmsvc.exe -> [2007-12-11 05:15:04 | 00,012,800 | ---- | M] (Agere Systems)
(avg8emc) AVG Free8 E-mail Scanner [Win32_Own | Auto | Running] -> C:\Program Files\AVG\AVG8\avgemc.exe -> [2009-05-24 11:18:59 | 00,908,568 | ---- | M] (AVG Technologies CZ, s.r.o.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> C:\Program Files\AVG\AVG8\avgwdsvc.exe -> [2009-05-24 11:18:58 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.)
(BUNAgentSvc) NTI Backup Now 5 Agent Service [Win32_Own | Auto | Running] -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -> [2008-03-03 14:11:14 | 00,016,384 | ---- | M] (NewTech Infosystems, Inc.)
(CLHNService) CLHNService [Win32_Own | Auto | Running] -> C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -> [2008-01-16 18:35:02 | 00,081,504 | ---- | M] ()
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008-01-21 04:24:55 | 00,070,144 | ---- | M] (Microsoft Corporation)
(eDataSecurity Service) eDataSecurity Service [Win32_Own | Auto | Running] -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008-07-29 18:53:00 | 00,500,784 | ---- | M] (Egis Incorporated)
(ehRecvr) Windows Media Center Receiver-service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehRecvr.exe -> [2008-01-21 04:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler-service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehsched.exe -> [2006-11-02 14:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> C:\Windows\ehome\ehstart.dll -> [2006-11-02 14:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation)
(ETService) Empowering Technology Service [Win32_Own | Auto | Running] -> C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -> [2008-06-02 10:25:40 | 00,024,576 | ---- | M] ()
(Eventlog) Windows Event Log [Win32_Shared | Auto | Running] -> C:\Windows\System32\wevtsvc.dll -> [2008-01-21 04:23:49 | 01,013,760 | ---- | M] (Microsoft Corporation)
(EvtEng) Intel® PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> C:\Program Files\Intel\WiFi\bin\EvtEng.exe -> [2008-04-30 20:41:12 | 00,815,104 | ---- | M] (Intel® Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008-01-21 04:25:20 | 00,036,864 | ---- | M] (Microsoft Corporation)
(GoogleDesktopManager-092308-165331) Google Desktop Manager 5.8.809.23506 [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -> [2009-01-12 21:23:52 | 00,030,192 | ---- | M] (Google)
(gusvc) Google Software Updater [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009-05-23 23:00:30 | 00,182,768 | ---- | M] (Google)
(IAANTMON) Intel® Matrix Storage Event Monitor [Win32_Own | Auto | Running] -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2008-07-20 18:45:06 | 00,354,840 | ---- | M] (Intel Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008-01-21 04:25:20 | 00,864,256 | ---- | M] (Microsoft Corporation)
(IGBASVC) iGroupTec Service [Win32_Own | Auto | Running] -> C:\Program Files\Acer\Acer Bio Protection\BASVC.exe -> [2009-05-12 02:45:04 | 03,520,512 | ---- | M] ()
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\LightScribe\LSSrvc.exe -> [2007-01-17 12:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe -> [2006-10-26 13:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation)
(MobilityService) MobilityService [Win32_Own | Auto | Running] -> C:\Acer\Mobility Center\MobilityService.exe -> [2007-12-06 17:15:28 | 00,110,592 | ---- | M] ()
(NetTcpPortSharing) Net.Tcp-service voor het delen van poorten [Win32_Shared | Disabled | Stopped] -> C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008-01-21 04:25:21 | 00,122,880 | ---- | M] (Microsoft Corporation)
(NTIBackupSvc) NTI Backup Now 5 Backup Service [Win32_Own | Auto | Running] -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -> [2008-04-25 22:36:20 | 00,045,056 | ---- | M] (NewTech InfoSystems, Inc.)
(NTISchedulerSvc) NTI Backup Now 5 Scheduler Service [Win32_Own | Auto | Running] -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -> [2008-04-25 22:36:02 | 00,131,072 | ---- | M] ()
(nvsvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> C:\Windows\System32\nvvsvc.exe -> [2008-12-05 12:24:00 | 00,203,296 | ---- | M] (NVIDIA Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007-08-24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation)
(RegSrvc) Intel® PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -> [2008-04-30 20:10:10 | 00,466,944 | ---- | M] (Intel® Corporation)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files\Cyberlink\Shared files\RichVideo.exe -> [2007-01-09 19:25:30 | 00,272,024 | ---- | M] ()
(RS_Service) Raw Socket Service [Win32_Own | Auto | Running] -> C:\Program Files\Acer\Acer VCM\RS_Service.exe -> [2008-07-19 15:13:44 | 00,233,472 | ---- | M] (Acer Incorporated)
(vfsFPService) Validity Fingerprint Service [Win32_Own | Auto | Running] -> C:\Windows\System32\vfsFPService.exe -> [2008-05-26 05:43:58 | 00,599,344 | ---- | M] (Validity Sensors, Inc.)
(WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2008-01-21 04:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing-service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008-01-21 04:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(adp94xx) adp94xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adp94xx.sys -> [2008-01-21 04:23:21 | 00,422,968 | ---- | M] (Adaptec, Inc.)
(adpahci) adpahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpahci.sys -> [2008-01-21 04:23:25 | 00,300,600 | ---- | M] (Adaptec, Inc.)
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu160m.sys -> [2008-01-21 04:23:26 | 00,101,432 | ---- | M] (Adaptec, Inc.)
(adpu320) adpu320 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu320.sys -> [2008-01-21 04:23:27 | 00,149,560 | ---- | M] (Adaptec, Inc.)
(AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\AGRSM.sys -> [2008-02-29 09:13:38 | 01,202,560 | ---- | M] (Agere Systems)
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\djsvs.sys -> [2006-11-02 11:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.)
(AlfaFF) AlfaFF File System mini-filter [File_System | Boot | Running] -> C:\Windows\system32\Drivers\AlfaFF.sys -> [2009-05-12 02:44:59 | 00,043,184 | ---- | M] (Alfa Corporation)
(aliide) aliide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\aliide.sys -> [2008-01-21 04:23:00 | 00,017,464 | ---- | M] (Acer Laboratories Inc.)
(arc) arc [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arc.sys -> [2008-01-21 04:23:23 | 00,079,416 | ---- | M] (Adaptec, Inc.)
(arcsas) arcsas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arcsas.sys -> [2008-01-21 04:23:24 | 00,079,928 | ---- | M] (Adaptec, Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgldx86.sys -> [2009-05-24 11:19:08 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\Windows\System32\Drivers\avgmfx86.sys -> [2009-05-24 11:19:06 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | System | Running] -> C:\Windows\System32\Drivers\avgtdix.sys -> [2009-05-24 11:19:12 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
(BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltlo.sys -> [2006-11-02 10:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.)
(BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltup.sys -> [2006-11-02 10:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.)
(Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserid.sys -> [2006-11-02 10:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.)
(BrSerWdm) Brother WDM Serial driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserwdm.sys -> [2006-11-02 10:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brusbmdm.sys -> [2006-11-02 10:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.)
(BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brusbser.sys -> [2006-11-02 10:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.)
(cmdide) cmdide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\cmdide.sys -> [2008-01-21 04:23:00 | 00,019,000 | ---- | M] (CMD Technology, Inc.)
(DKbFltr) Dritek Keyboard Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\DKbFltr.sys -> [2006-11-02 15:29:36 | 00,021,264 | ---- | M] (Dritek System Inc.)
(DritekPortIO) Dritek General Port I/O [Kernel | System | Running] -> C:\Program Files\Launch Manager\DPortIO.sys -> [2006-11-02 15:27:34 | 00,020,112 | ---- | M] (Dritek System Inc.)
(E1G60) Intel® PRO/1000 NDIS 6 Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\DRIVERS\E1G60I32.sys -> [2008-01-21 04:23:24 | 00,118,784 | ---- | M] (Intel Corporation)
(elxstor) elxstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\elxstor.sys -> [2008-01-21 04:23:22 | 00,342,584 | ---- | M] (Emulex)
(HpCISSs) HpCISSs [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\hpcisss.sys -> [2008-01-21 04:23:26 | 00,040,504 | ---- | M] (Hewlett-Packard Company)
(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\iaStor.sys -> [2008-07-20 18:44:44 | 00,324,120 | ---- | M] (Intel Corporation)
(iaStorV) Intel RAID Controller Vista [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iastorv.sys -> [2008-01-21 04:23:23 | 00,235,064 | ---- | M] (Intel Corporation)
(iirsp) iirsp [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iirsp.sys -> [2006-11-02 11:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH)
(int15) int15 [Kernel | Auto | Running] -> C:\Windows\System32\drivers\int15.sys -> [2007-01-26 08:32:18 | 00,069,632 | ---- | M] ()
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\RTKVHDA.sys -> [2008-05-07 13:22:50 | 02,134,424 | ---- | M] (Realtek Semiconductor Corp.)
(iteatapi) ITEATAPI_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteatapi.sys -> [2006-11-02 11:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(itecir) ITECIR Infrared Receiver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\itecir.sys -> [2007-12-18 17:12:12 | 00,054,784 | ---- | M] (ITE Tech. Inc. )
(iteraid) ITERAID_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteraid.sys -> [2006-11-02 11:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.)
(L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\L1E60x86.sys -> [2008-05-19 18:23:00 | 00,047,104 | ---- | M] (Atheros Communications, Inc.)
(LSI_FC) LSI_FC [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_fc.sys -> [2008-01-21 04:23:23 | 00,096,312 | ---- | M] (LSI Logic)
(LSI_SAS) LSI_SAS [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_sas.sys -> [2008-01-21 04:23:25 | 00,089,656 | ---- | M] (LSI Logic)
(LSI_SCSI) LSI_SCSI [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_scsi.sys -> [2008-01-21 04:23:23 | 00,096,312 | ---- | M] (LSI Logic)
(megasas) megasas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasas.sys -> [2008-01-21 04:23:27 | 00,031,288 | ---- | M] (LSI Corporation)
(MegaSR) MegaSR [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasr.sys -> [2008-01-21 04:23:27 | 00,386,616 | ---- | M] (LSI Corporation, Inc.)
(Mraid35x) Mraid35x [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\mraid35x.sys -> [2006-11-02 11:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation)
(NETw5v32) Stuurprogramma voor Intel® Wireless WiFi Link Adapter onder Windows Vista 32 Bit [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\NETw5v32.sys -> [2008-04-28 00:29:26 | 03,658,752 | ---- | M] (Intel Corporation)
(nfrd960) nfrd960 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nfrd960.sys -> [2006-11-02 11:50:19 | 00,045,160 | ---- | M] (IBM Corporation)
(NTIDrvr) Upper Class Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\NTIDrvr.sys -> [2008-01-30 11:52:06 | 00,014,848 | ---- | M] (NewTech Infosystems, Inc.)
(NTIPPKernel) NTIPPKernel [Kernel | Auto | Running] -> C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys -> [2008-01-16 18:35:08 | 00,122,368 | ---- | M] (Cyberlink Corp.)
(ntrigdigi) N-trig HID Tablet Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ntrigdigi.sys -> [2006-11-02 09:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies)
(NVHDA) Service for NVIDIA High Definition Audio Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\nvhda32v.sys -> [2008-09-24 23:39:48 | 00,045,600 | ---- | M] (NVIDIA Corporation)
(nvlddmkm) nvlddmkm [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\nvlddmkm.sys -> [2008-12-05 12:24:00 | 07,538,560 | ---- | M] (NVIDIA Corporation)
(nvraid) NVIDIA nForce RAID Driver    [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvraid.sys -> [2008-01-21 04:23:21 | 00,102,968 | ---- | M] (NVIDIA Corporation)
(nvstor) nvstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvstor.sys -> [2008-01-21 04:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation)
(PSDFilter) PSDFilter [File_System | Boot | Running] -> C:\Windows\system32\DRIVERS\psdfilter.sys -> [2008-07-29 18:53:10 | 00,018,992 | ---- | M] (Egis Incorporated)
(PSDNServ) PSDNServ [Kernel | Auto | Running] -> C:\Windows\System32\DRIVERS\PSDNServ.sys -> [2008-07-29 18:53:10 | 00,016,944 | ---- | M] (Egis Incorporated)
(psdvdisk) psdvdisk [Kernel | Auto | Running] -> C:\Windows\System32\DRIVERS\PSDVdisk.sys -> [2008-07-29 18:53:12 | 00,060,464 | ---- | M] (Egis Incorporated)
(ql2300) QLogic Fibre Channel Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql2300.sys -> [2008-01-21 04:23:24 | 01,122,360 | ---- | M] (QLogic Corporation)
(ql40xx) QLogic iSCSI Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql40xx.sys -> [2006-11-02 11:50:35 | 00,106,088 | ---- | M] (QLogic Corporation)
(secdrv) Security Driver [Kernel | Auto | Running] -> C:\Windows\System32\drivers\secdrv.sys -> [2006-11-02 08:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SiSRaid4) SiSRaid4 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sisraid4.sys -> [2008-01-21 04:23:26 | 00,074,808 | ---- | M] (Silicon Integrated Systems)
(Symc8xx) Symc8xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\symc8xx.sys -> [2006-11-02 11:50:05 | 00,035,944 | ---- | M] (LSI Logic)
(Sym_hi) Sym_hi [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_hi.sys -> [2006-11-02 11:49:56 | 00,031,848 | ---- | M] (LSI Logic)
(Sym_u3) Sym_u3 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_u3.sys -> [2006-11-02 11:50:03 | 00,034,920 | ---- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\DRIVERS\SynTP.sys -> [2008-04-04 11:26:56 | 00,196,784 | ---- | M] (Synaptics, Inc.)
(UBHelper) UBHelper [Kernel | Boot | Running] -> C:\Windows\System32\drivers\UBHelper.sys -> [2008-01-30 11:51:50 | 00,013,824 | ---- | M] (NewTech Infosystems Corporation)
(uliahci) uliahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\uliahci.sys -> [2008-01-21 04:23:20 | 00,238,648 | ---- | M] (ULi Electronics Inc.)
(UlSata) UlSata [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata.sys -> [2006-11-02 11:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.)
(ulsata2) ulsata2 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata2.sys -> [2008-01-21 04:23:23 | 00,115,816 | ---- | M] (Promise Technology, Inc.)
(vfs101x) vfs101x [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\vfs101x.sys -> [2008-05-26 05:44:14 | 00,040,752 | ---- | M] (Validity Sensors, Inc.)
(viaide) viaide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\viaide.sys -> [2008-01-21 04:23:00 | 00,020,024 | ---- | M] (VIA Technologies, Inc.)
(vsmraid) vsmraid [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\vsmraid.sys -> [2008-01-21 04:23:23 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd)
({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} [Kernel | Auto | Running] -> C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl -> [2008-07-18 16:05:10 | 00,061,424 | ---- | M] (Cyberlink Corp.)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935 ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_6935 ->
HKEY_CURRENT_USER\: Main\\"Default_Secondary_Page_URL" -> http://global.acer.com [binary data] ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\Windows\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com ->
HKEY_CURRENT_USER\: Main\\"SearchDefaultBranded" -> 1 ->
HKEY_CURRENT_USER\: Main\\"Secondary Start Pages" -> http://www.woningnet.nl/ [binary data] ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://games.asobrain.com/ ->
HKEY_CURRENT_USER\: Main\\"StartPageCache" -> 1 ->
HKEY_CURRENT_USER\: SearchURL\\"" -> http://www.google.com/search/?q=%s ->
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\prefs.js ->
browser.search.selectedEngine -> "Ask.com" ->
browser.search.useDBForOrder -> true ->
browser.startup.homepage -> "http://jeannie81.livejournal.com/friends | mail.yahoo.com" ->
extensions.enabledItems -> {3f963a5b-e555-4543-90e2-c3908898db71}:8.5 ->
extensions.enabledItems -> {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.1.0.7 ->
extensions.enabledItems -> [email protected]:1.19 ->
extensions.enabledItems -> {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.1.041 ->
extensions.enabledItems -> {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 ->
extensions.enabledItems -> {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.3 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 ->
extensions.enabledItems -> {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.3.9 ->
extensions.enabledItems -> {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.5 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 ->
extensions.enabledItems -> {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.08 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  ->
HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\PROGRAM FILES\AVG\AVG8\FIREFOX [C:\PROGRAM FILES\AVG\AVG8\FIREFOX] -> [2009-06-03 04:43:09 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8} -> C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF] -> [2009-06-03 04:43:09 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions ->  ->
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009-05-23 23:00:08 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009-05-26 21:25:25 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
 -> C:\Users\Media\AppData\Roaming\mozilla\Extensions -> [2009-05-23 23:00:21 | 00,000,000 | ---D | M]
 -> C:\Users\Media\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009-05-23 23:00:21 | 00,000,000 | ---D | M]
 -> C:\Users\Media\AppData\Roaming\mozilla\Extensions\[email protected] -> [2009-05-23 23:00:21 | 00,000,000 | ---D | M]
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions -> [2009-06-05 22:53:26 | 00,989,870 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\[email protected] -> [2009-06-05 22:55:19 | 00,991,869 | ---- | M] ()
 -> C:\Users\Media\AppData\Roaming\mozilla\Firefox\Profiles\vetpoexf.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}\chrome\mozapps\extensions -> [2009-05-23 23:39:46 | 00,000,000 | ---D | M]
< FireFox SearchPlugins [User Folders] > ->
C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\searchplugins\ -> C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\searchplugins -> [2009-05-30 01:13:09 | 00,000,000 | ---D | M]
askcom.xml -> C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\searchplugins\askcom.xml -> [2009-05-24 11:08:26 | 00,002,207 | ---- | M] ()
imdb.xml -> C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\searchplugins\imdb.xml -> [2009-05-30 01:13:09 | 00,001,504 | ---- | M] ()
youtube.xml -> C:\Users\Media\AppData\Roaming\Mozilla\FireFox\Profiles\vetpoexf.default\searchplugins\youtube.xml -> [2009-05-23 23:34:24 | 00,004,140 | ---- | M] ()
< FireFox Extensions [Program Folders] > ->
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009-04-24 11:27:04 | 09,756,664 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009-04-24 11:27:04 | 09,756,664 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -> [2009-04-24 11:27:04 | 09,756,664 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -> [2009-04-24 11:27:04 | 09,756,664 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009-05-23 23:00:08 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009-04-24 11:27:05 | 00,023,032 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009-04-24 11:27:05 | 00,134,648 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009-05-26 21:25:25 | 00,000,000 | ---D | M]
npdeploytk.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npdeploytk.dll -> [2009-03-09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.)
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009-04-24 11:27:05 | 00,065,528 | ---- | M] (mozilla.org)
NPOFF12.DLL -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPOFF12.DLL -> [2006-10-26 21:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation)
< FireFox SearchPlugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009-05-24 11:16:00 | 00,000,000 | ---D | M]
bolcom-nl.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\bolcom-nl.xml -> [2008-02-08 11:12:30 | 00,001,890 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2008-04-16 06:08:20 | 00,001,706 | ---- | M] ()
marktplaats-nl.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\marktplaats-nl.xml -> [2008-02-11 23:02:16 | 00,004,558 | ---- | M] ()
vandale-nl.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\vandale-nl.xml -> [2007-11-09 11:17:02 | 00,001,111 | ---- | M] ()
wikipedia-nl.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia-nl.xml -> [2008-03-18 13:19:22 | 00,001,049 | ---- | M] ()
yahoo-nl.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo-nl.xml -> [2007-11-09 11:17:02 | 00,000,802 | ---- | M] ()
< HOSTS File > (761 bytes and 20 lines) -> C:\Windows\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1       localhost
::1             localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2008-06-11 23:33:16 | 00,075,128 | ---- | M] (Adobe Systems Incorporated)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009-05-24 11:19:00 | 01,107,224 | ---- | M] (AVG Technologies CZ, s.r.o.)
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} [HKLM] -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [ShowBarObj Class] -> [2008-07-29 18:51:50 | 00,312,880 | ---- | M] (Egis)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2008-11-18 14:47:06 | 00,408,952 | ---- | M] (Microsoft Corporation)
{A057A204-BACC-4D26-9990-79A187E2698E} [HKLM] -> C:\Program Files\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2009-05-24 11:19:05 | 02,223,872 | ---- | M] (AVG Technologies CZ, s.r.o.)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009-05-23 22:57:34 | 00,259,696 | ---- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [Google Toolbar Notifier BHO] -> [2009-05-23 23:00:31 | 00,668,656 | ---- | M] (Google Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [Google Dictionary Compression sdch] -> [2009-05-23 22:57:34 | 00,470,512 | ---- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009-03-09 05:18:50 | 00,035,840 | ---- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009-05-23 22:57:34 | 00,259,696 | ---- | M] (Google Inc.)
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008-07-29 18:52:08 | 00,142,896 | ---- | M] (Egis Incorporated.)
"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> C:\Program Files\AVG\AVG8\avgtoolbar.dll [AVG Security Toolbar] -> [2009-05-24 11:19:05 | 02,223,872 | ---- | M] (AVG Technologies CZ, s.r.o.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008-07-29 18:52:08 | 00,142,896 | ---- | M] (Egis Incorporated.)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar] -> [2009-05-23 22:57:34 | 00,259,696 | ---- | M] (Google Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"] -> [2008-06-12 03:38:00 | 00,034,672 | ---- | M] (Adobe Systems Incorporated)
"ArcadeDeluxeAgent" -> C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe ["C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"] -> [2008-07-24 15:54:10 | 00,147,456 | ---- | M] (CyberLink Corp.)
"AVG8_TRAY" -> C:\Program Files\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009-05-24 11:18:59 | 01,947,928 | ---- | M] (AVG Technologies CZ, s.r.o.)
"BkupTray" -> C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ["C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"] -> [2008-04-25 22:36:20 | 00,028,672 | ---- | M] ()
"CLMLServer" -> C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe ["C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"] -> [2008-07-24 15:54:18 | 00,167,936 | ---- | M] (CyberLink)
"eAudio" -> C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe ["C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"] -> [2008-05-30 13:24:30 | 00,544,768 | ---- | M] (Acer Incorporated)
"eDataSecurity Loader" -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe] -> [2008-07-29 18:52:50 | 00,526,896 | ---- | M] (Egis Incorporated)
"ePower_DMC" -> C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe] -> [2008-08-01 10:51:42 | 00,405,504 | ---- | M] (Acer Inc.)
"eRecoveryService" ->  [] -> File not found
"Google Desktop Search" ->  ["C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup] -> File not found
"IAAnotif" -> C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe] -> [2008-07-20 18:45:06 | 00,182,808 | ---- | M] (Intel Corporation)
"LManager" -> C:\Program Files\Launch Manager\LManager.exe [C:\PROGRA~1\LAUNCH~1\LManager.exe] -> [2008-06-16 11:58:38 | 00,809,480 | ---- | M] (Dritek System Inc.)
"NvCplDaemon" -> C:\Windows\System32\NvCpl.DLL [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2008-12-05 12:24:00 | 13,601,312 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\Windows\System32\NvMcTray.DLL [RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit] -> [2008-12-05 12:24:00 | 00,092,704 | ---- | M] (NVIDIA Corporation)
"PlayMovie" -> C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe ["C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"] -> [2008-07-18 16:04:36 | 00,167,936 | ---- | M] (Acer Corp.)
"PLFSetI" -> C:\Windows\PLFSetI.exe [C:\Windows\PLFSetI.exe] -> [2008-06-30 17:56:32 | 00,200,704 | ---- | M] ()
"RtHDVCpl" -> C:\Windows\RtHDVCpl.exe [RtHDVCpl.exe] -> [2008-05-07 10:19:26 | 06,139,904 | ---- | M] (Realtek Semiconductor)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009-03-09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.)
"SynTPEnh" -> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2008-04-04 11:26:54 | 01,037,608 | ---- | M] (Synaptics, Inc.)
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008-01-21 04:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation)
"ZPdtWzdVitaKey MC3000" -> C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe ["C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show] -> [2009-05-12 02:44:55 | 03,719,680 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
< RunOnce [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"Malwarebytes' Anti-Malware" ->  [C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent] -> File not found
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Eraser" -> C:\Program Files\Eraser\Eraser.exe [C:\Program Files\Eraser\Eraser.exe -hide] -> [2007-12-23 01:03:28 | 00,916,240 | ---- | M] (The Eraser Project)
"ProductReg" -> C:\Program Files\Acer\WR_PopUp\ProductReg.exe ["C:\Program Files\Acer\WR_PopUp\ProductReg.exe"] -> [2008-11-17 09:47:56 | 00,135,168 | ---- | M] (Acer)
"swg" -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2009-05-12 02:41:12 | 00,068,856 | ---- | M] (Google Inc.)
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [2] -> File not found
\\"ConsentPromptBehaviorUser" ->  [1] -> File not found
\\"EnableInstallerDetection" ->  [1] -> File not found
\\"EnableLUA" ->  [1] -> File not found
\\"EnableSecureUIAPaths" ->  [1] -> File not found
\\"EnableVirtualization" ->  [1] -> File not found
\\"PromptOnSecureDesktop" ->  [1] -> File not found
\\"ValidateAdminCodeSignatures" ->  
  • -> File not found

\\"dontdisplaylastusername" ->  
  • -> File not found

\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"scforceoption" ->  
  • -> File not found

\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"FilterAdministratorToken" ->  
  • -> File not found

\\"EnableUIADesktopToggle" ->  
  • -> File not found

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" ->  [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" ->  [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" ->  [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" ->  [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" ->  [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" ->  [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" ->  [17] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xporteren naar Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000] -> [2007-10-05 21:37:38 | 17,927,192 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{10954C80-4F0F-11d3-B17C-00C0DFE39736}:Exec [HKLM] -> C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe [Button: Quick-Launching Area] -> [2009-05-12 02:45:18 | 03,833,640 | ---- | M] ()
{10954C80-4F0F-11d3-B17C-00C0DFE39736}:Exec [HKLM] -> C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe [Menu: Quick-Launching Area] -> [2009-05-12 02:45:18 | 03,833,640 | ---- | M] ()
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [Button: In weblog opnemen] -> [2008-12-02 23:27:36 | 00,187,224 | ---- | M] (Microsoft Corporation)
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [Menu: &In weblog opnemen met Windows Live Writer] -> [2008-12-02 23:27:36 | 00,187,224 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Button: Verzenden naar OneNote] -> [2007-08-29 01:49:28 | 00,606,120 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Menu: Verz&enden naar OneNote] -> [2007-08-29 01:49:28 | 00,606,120 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006-10-26 21:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find...=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 1 range(s) found. ->
GD [:Range = 127.0.0.1] -> http = Local intranet |  ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_13] ->
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_13] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_13] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.254 195.241.77.55 195.241.77.58 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{57309779-A609-451C-A2E5-AE5C56B5A605}\\DhcpNameServer -> 192.168.1.254 195.241.77.55 195.241.77.58   (Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller) ->
{6F022C26-00AF-4888-9482-EE95D3124458}\\DhcpNameServer -> 192.168.1.254 195.241.77.55 195.241.77.58   (Intel® Wireless WiFi Link 5100) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2009-01-12 21:23:53 | 00,119,296 | ---- | M] (Google)
avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009-05-24 11:19:13 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2008-10-29 08:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
AWinNotifyVitaKey MC3000 -> C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll -> [2009-05-12 02:45:17 | 03,162,624 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHIN
« Last Edit: June 05, 2009, 08:03:25 PM by guestolo »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #7 on: June 05, 2009, 07:52:40 PM »
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{047F790A-7A2A-4B6A-AD02-38092BA63DAC} -> Acer VCM
{11316260-6666-467B-AC34-183FCB5D4335} -> Acer Mobility Center Plug-In
{12EFA1A4-AC3B-443C-8143-237EDE760403} -> NTI Backup Now Standard
{13D85C14-2B85-419F-AC41-C7F21E68B25D} -> Acer eSettings Management
{15D967B5-A4BE-42AE-9E84-64CD062B25AA} -> eSobi v2
{18455581-E099-4BA8-BC6B-F34B2F06600C} -> Google Toolbar for Internet Explorer
{1A38EBE5-08BD-4E0D-AAB9-0DFECACE108B} -> Windows Live Messenger
{205C6BDD-7B73-42DE-8505-9A093F35A238} -> Windows Live - Hulpprogramma voor uploaden
{22B63288-28E5-4F8C-9BA4-5BD7F6A027E0} -> Windows Live Photo Gallery
{22B775E7-6C42-4FC5-8E10-9A5E3257BD94} -> MSVCRT
{2318C2B1-4965-11d4-9B18-009027A5CD4F} -> Google Toolbar for Internet Explorer
{2413930C-8309-47A6-BC61-5EF27A4222BC} -> NTI Media Maker 8
{2637C347-9DAD-11D6-9EA2-00055D0CA761} -> Acer Arcade Deluxe
{26604C7E-A313-4D12-867F-7C6E7820BE4C} -> JMicron JMB38X Flash Media Controller
{26921B2E-3E62-47F9-A514-1FC4A83BD738} -> Software van Intel® PROSet/Wireless WiFi
{26A24AE4-039D-4CA4-87B4-2F83216011FF} -> Java(tm) 6 Update 13
{3108C217-BE83-42E4-AE9E-A56A2A92E549} -> Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
{362F80B4-9628-4100-B074-5A1BB6FCBBF3} -> Windows Live Call
{40580068-9B10-40B5-9548-536CE88AB23C} -> ITECIR
{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A} -> Junk Mail filter update
{567E8236-C414-4888-8211-3D61608D57AE} -> Validity Sensors software
{57265292-228A-41FA-9AEC-4620CBCC2739} -> Acer eAudio Management
{58E5844B-7CE2-413D-83D1-99294BF6C74F} -> Acer ePower Management
{5B63A470-9334-44D1-AF61-6CE2DB565AE9} -> Orion
{6FAA5F2A-5C2D-4BB5-B611-EFAE018B0234} -> Windows Live aanmeldhulp
{71C2828F-2678-4675-BDEC-895424861262}_is1 -> C:\Program Files\Acer GameZone\GameConsole
{7299052b-02a4-4627-81f2-1818da5d550d} -> Microsoft Visual C++ 2005 Redistributable
{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC} -> Acer ScreenSaver
{7F811A54-5A09-4579-90E1-C93498E230D9} -> Acer eRecovery Management
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110082360} -> Alien Shooter
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593} -> Chicken Invaders 2
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110422467} -> Tiks Texas Hold em
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750} -> Cake Mania
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457} -> Galapago
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363} -> Mystery Solitaire - Secret Island
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111940693} -> Bookworm Adventures
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112028410} -> Putt Mania
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112548397} -> The Rise of Atlantis
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767} -> Alice Greenfingers
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380} -> Heroes of Hellas
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110} -> Dream Day First Home
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113848220} -> Agatha Christie Peril at End House
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113919217} -> Mythic Mahjong
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114072167} -> Go-Go Gourmet
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11408540} -> Magic Match Adventures
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114086870} -> Womens Murder Club
{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114717227} -> Magic Farm
{8F1B6239-FEA0-450A-A950-B05276CE177C} -> Acer Empowering Technology
{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E} -> Choice Guard
{90120000-0015-0413-0000-0000000FF1CE} -> Microsoft Office Access MUI (Dutch) 2007
{90120000-0016-0413-0000-0000000FF1CE} -> Microsoft Office Excel MUI (Dutch) 2007
{90120000-0016-0413-0000-0000000FF1CE}_ENTERPRISE_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-0016-0413-0000-0000000FF1CE}_HOMESTUDENTR_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-0018-0413-0000-0000000FF1CE} -> Microsoft Office PowerPoint MUI (Dutch) 2007
{90120000-0018-0413-0000-0000000FF1CE}_ENTERPRISE_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-0018-0413-0000-0000000FF1CE}_HOMESTUDENTR_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-0019-0413-0000-0000000FF1CE} -> Microsoft Office Publisher MUI (Dutch) 2007
{90120000-001A-0413-0000-0000000FF1CE} -> Microsoft Office Outlook MUI (Dutch) 2007
{90120000-001B-0413-0000-0000000FF1CE} -> Microsoft Office Word MUI (Dutch) 2007
{90120000-001B-0413-0000-0000000FF1CE}_ENTERPRISE_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-001B-0413-0000-0000000FF1CE}_HOMESTUDENTR_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-001F-0407-0000-0000000FF1CE} -> Microsoft Office Proof (German) 2007
{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-001F-0409-0000-0000000FF1CE} -> Microsoft Office Proof (English) 2007
{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-001F-040C-0000-0000000FF1CE} -> Microsoft Office Proof (French) 2007
{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-001F-0413-0000-0000000FF1CE} -> Microsoft Office Proof (Dutch) 2007
{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{B3F4DC34-7F60-4B7C-A79F-1C13012D99D4} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-002C-0413-0000-0000000FF1CE} -> Microsoft Office Proofing (Dutch) 2007
{90120000-0030-0000-0000-0000000FF1CE} -> Microsoft Office Enterprise 2007
{90120000-0044-0413-0000-0000000FF1CE} -> Microsoft Office InfoPath MUI (Dutch) 2007
{90120000-006E-0413-0000-0000000FF1CE} -> Microsoft Office Shared MUI (Dutch) 2007
{90120000-006E-0413-0000-0000000FF1CE}_HOMESTUDENTR_{1120A001-69F4-43D2-83CE-716B2DC4366F} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-00A1-0413-0000-0000000FF1CE} -> Microsoft Office OneNote MUI (Dutch) 2007
{90120000-00A1-0413-0000-0000000FF1CE}_HOMESTUDENTR_{4059772C-68BA-4FE4-9B6E-3EC37C0C4624} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{90120000-00BA-0413-0000-0000000FF1CE} -> Microsoft Office Groove MUI (Dutch) 2007
{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} -> Intel® Matrix Storage Manager
{91120000-002F-0000-0000-0000000FF1CE} -> Microsoft Office Home and Student 2007
{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419} -> 2007 Microsoft Office Suite Service Pack 1 (SP1)
{95120000-00B9-0409-0000-0000000FF1CE} -> Microsoft Application Error Reporting
{A2A0A82F-025F-458d-A0CD-9BB2320804B5} -> Microsoft Works
{A5633652-3795-4829-BB0B-644F0279E279} -> Acer eDataSecurity Management
{A5F3E8C0-E949-40D0-B529-D34A4BCDA43C} -> Windows Live Sync
{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E} -> Acer Crystal Eye Webcam 3.0.6.3
{AC76BA86-7AD7-1043-7B44-A90000000001} -> Adobe Reader 9 - Nederlands
{B38B1F86-8202-482F-A289-A4806DFA498D} -> Windows Live Mail
{B3B4E65B-F8B9-46E8-9B30-4DE339DB3F1E} -> Windows Live Essentials
{C8114985-F9C5-4A4A-885D-C6BA4AE8F231} -> Windows Live Writer
{CB099890-1D5F-11D5-9EA9-0050BAE317E1} -> CyberLink PowerDirector
{CE386A4E-D0DA-4208-8235-BCE43275C694} -> LightScribe  1.4.142.1
{D36DD326-7280-11D8-97C8-000129760CBE} -> PhotoNow!
{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E} -> Acer Product Registration
{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E} -> Microsoft Office Suite Activation Assistant
{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} -> Microsoft SQL Server 2005 Compact Edition [ENU]
{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} -> Realtek High Definition Audio Driver
{F69E83CF-B440-43F8-89E6-6EA80712109B} -> Windows Live Communications Platform
{F850707C-B6A0-4B56-8709-F89CF8F9AC6D} -> Eraser
Acer Acer Bio Protection 6.0.00.15 -> Acer Bio Protection

AAV 6.0.00.15
Adobe Flash Player ActiveX -> Adobe Flash Player ActiveX
Adobe Flash Player Plugin -> Adobe Flash Player 10 Plugin
Adobe Shockwave Player -> Adobe Shockwave Player 11.5
Agere Systems Soft Modem -> Agere Systems HDA Modem
AVG8Uninstall -> AVG Free 8.5
CleanUp! -> CleanUp!
ENTERPRISE -> Microsoft Office Enterprise 2007
Google Desktop -> Google Desktop
GridVista -> Acer GridVista
HijackThis -> HijackThis 2.0.2
HOMESTUDENTR -> Microsoft Office Home and Student 2007
InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403} -> NTI Backup Now 5
InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA} -> eSobi v2
InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC} -> NTI Media Maker 8
InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761} -> Acer Arcade Deluxe
InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} -> CyberLink PowerDirector
LimeWire -> LimeWire 5.1.3
LManager -> Launch Manager
Malwarebytes' Anti-Malware_is1 -> Malwarebytes' Anti-Malware
Mozilla Firefox (3.0.10) -> Mozilla Firefox (3.0.10)
NVIDIA Drivers -> NVIDIA Drivers
ProInst -> Intel PROSet Wireless
Ranch Rush1.0 -> Ranch Rush
SynTPDeinstKey -> Synaptics Pointing Device Driver
VLC media player -> VLC media player 0.9.9
WinLiveSuite_Wave3 -> Windows Live Essentials
WinRAR archiver -> WinRAR archiver
< Uninstall List [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
Eraser -> Eraser
uTorrent -> µTorrent
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 20-5-2009 21:36:45 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 21-5-2009 11:57:52 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 21-5-2009 17:55:20 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 21-5-2009 18:57:13 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 22-5-2009 10:55:02 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 22-5-2009 20:06:02 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 23-5-2009 10:59:31 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 23-5-2009 15:22:15 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 23-5-2009 19:09:23 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
Application [ Error ] 23-5-2009 17:27:04 Computer Name = PC_van_Media | Source = WinMgmt | ID = 10 -> Description =
System [ Error ] 16-5-2009 11:01:05 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
System [ Error ] 17-5-2009 11:59:30 Computer Name = PC_van_Media | Source = EventLog | ID = 6008 -> Description = De vorige afsluiting van het systeem om 2:48:30 op 17-5-2009 is onverwacht gebeurd.
System [ Error ] 17-5-2009 11:59:32 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
System [ Error ] 17-5-2009 14:31:19 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
System [ Error ] 18-5-2009 11:04:42 Computer Name = PC_van_Media | Source = EventLog | ID = 6008 -> Description = De vorige afsluiting van het systeem om 1:01:34 op 18-5-2009 is onverwacht gebeurd.
System [ Error ] 18-5-2009 11:04:43 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
System [ Error ] 19-5-2009 10:52:26 Computer Name = PC_van_Media | Source = EventLog | ID = 6008 -> Description = De vorige afsluiting van het systeem om 4:45:30 op 19-5-2009 is onverwacht gebeurd.
System [ Error ] 19-5-2009 10:52:28 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
System [ Error ] 20-5-2009 10:56:34 Computer Name = PC_van_Media | Source = EventLog | ID = 6008 -> Description = De vorige afsluiting van het systeem om 4:37:06 op 20-5-2009 is onverwacht gebeurd.
System [ Error ] 20-5-2009 10:56:36 Computer Name = PC_van_Media | Source = HTTP | ID = 15016 -> Description =
 
[Files/Folders - Created Within 30 Days]
Malwarebytes -> C:\Users\Media\AppData\Roaming\Malwarebytes -> [2009-06-05 19:58:35 | 00,000,000 | ---D | C]
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009-06-05 19:58:34 | 00,000,822 | ---- | C] ()
mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2009-06-05 19:58:31 | 00,040,160 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2009-06-05 19:58:30 | 00,019,096 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009-06-05 19:58:30 | 00,000,000 | ---D | C]
Malwarebytes -> C:\ProgramData\Malwarebytes -> [2009-06-05 19:58:30 | 00,000,000 | ---D | C]
Adobe -> C:\Windows\System32\Adobe -> [2009-06-05 19:36:15 | 00,000,000 | ---D | C]
popcinfo.dat -> C:\Windows\popcinfo.dat -> [2009-06-04 23:33:31 | 00,000,016 | ---- | C] ()
CleanUp! -> C:\Program Files\CleanUp! -> [2009-06-04 19:13:27 | 00,000,000 | ---D | C]
HijackThis.lnk -> C:\Users\Media\Desktop\HijackThis.lnk -> [2009-06-04 18:20:23 | 00,001,878 | ---- | C] ()
Trend Micro -> C:\Program Files\Trend Micro -> [2009-06-04 18:20:22 | 00,000,000 | ---D | C]
IconCache.db -> C:\Users\Media\AppData\Local\IconCache.db -> [2009-06-04 08:13:03 | 01,918,093 | -H-- | C] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009-06-02 21:12:07 | 32,159,90784 | -HS- | C] ()
Minidump -> C:\Windows\Minidump -> [2009-06-02 18:46:21 | 00,000,000 | ---D | C]
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2009-06-02 18:46:02 | 19,692,6064 | ---- | C] ()
Steam -> C:\ProgramData\Steam -> [2009-06-01 15:07:36 | 00,000,000 | ---D | C]
Games -> C:\Users\Media\Documents\Games -> [2009-06-01 15:07:12 | 00,000,000 | ---D | C]
WinRAR -> C:\Users\Media\AppData\Roaming\WinRAR -> [2009-06-01 15:05:15 | 00,000,000 | ---D | C]
WinRAR -> C:\Program Files\WinRAR -> [2009-06-01 15:05:01 | 00,000,000 | ---D | C]
Tracing -> C:\Users\Media\Tracing -> [2009-05-31 16:34:29 | 00,000,000 | ---D | C]
Eraser -> C:\Users\Media\AppData\Local\Eraser -> [2009-05-30 23:26:44 | 00,000,000 | ---D | C]
{A25FEDC1-F6D7-440C-BCE2-B71F595F6646} -> C:\Users\Media\AppData\Local\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646} -> [2009-05-30 23:19:12 | 00,000,000 | -H-D | C]
Eraser -> C:\Program Files\Eraser -> [2009-05-30 23:19:03 | 00,000,000 | ---D | C]
$AVG8.VAULT$ -> C:\$AVG8.VAULT$ -> [2009-05-30 21:43:56 | 00,000,000 | -H-D | C]
~$irefox.docx -> C:\Users\Media\Documents\~$irefox.docx -> [2009-05-30 10:46:47 | 00,000,162 | -H-- | C] ()
Sun -> C:\Windows\Sun -> [2009-05-29 18:49:36 | 00,000,000 | ---D | C]
Incomplete -> C:\Users\Media\Documents\Incomplete -> [2009-05-26 22:52:00 | 00,000,000 | ---D | C]
LimeWire -> C:\Users\Media\Documents\LimeWire -> [2009-05-26 21:34:26 | 00,000,000 | ---D | C]
LimeWire -> C:\Users\Media\AppData\Roaming\LimeWire -> [2009-05-26 21:33:56 | 00,000,000 | ---D | C]
LimeWire 5.1.3.lnk -> C:\Users\Media\Desktop\LimeWire 5.1.3.lnk -> [2009-05-26 21:25:44 | 00,001,704 | ---- | C] ()
Java -> C:\Program Files\Java -> [2009-05-26 21:25:16 | 00,000,000 | ---D | C]
LimeWire -> C:\Program Files\LimeWire -> [2009-05-26 21:24:49 | 00,000,000 | ---D | C]
FreshGames -> C:\ProgramData\FreshGames -> [2009-05-24 23:07:23 | 00,000,000 | ---D | C]
Ranch Rush.lnk -> C:\Users\Media\Desktop\Ranch Rush.lnk -> [2009-05-24 23:00:52 | 00,001,699 | ---- | C] ()
Ranch Rush -> C:\Windows\Ranch Rush -> [2009-05-24 22:59:10 | 00,000,000 | ---D | C]
Ranch Rush -> C:\Program Files\Ranch Rush -> [2009-05-24 22:59:10 | 00,000,000 | ---D | C]
~$bdayfic.docx -> C:\Users\Media\Documents\~$bdayfic.docx -> [2009-05-24 20:40:18 | 00,000,162 | -H-- | C] ()
PopCap Games -> C:\ProgramData\PopCap Games -> [2009-05-24 13:33:52 | 00,000,000 | ---D | C]
playblue -> C:\Users\Media\Documents\playblue -> [2009-05-24 13:32:13 | 00,000,000 | -H-D | C]
mdimon.dll -> C:\Windows\System32\mdimon.dll -> [2009-05-24 12:09:48 | 00,030,512 | ---- | C] (Microsoft Corporation)
Microsoft Visual Studio -> C:\Program Files\Microsoft Visual Studio -> [2009-05-24 12:08:02 | 00,000,000 | ---D | C]
Microsoft Help -> C:\Users\Media\AppData\Local\Microsoft Help -> [2009-05-24 12:05:47 | 00,000,000 | ---D | C]
AVG Free 8.5.lnk -> C:\Users\Public\Desktop\AVG Free 8.5.lnk -> [2009-05-24 11:19:15 | 00,001,651 | ---- | C] ()
avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009-05-24 11:19:13 | 00,011,952 | ---- | C] (AVG Technologies CZ, s.r.o.)
avgtdix.sys -> C:\Windows\System32\drivers\avgtdix.sys -> [2009-05-24 11:19:12 | 00,108,552 | ---- | C] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> C:\Windows\System32\drivers\avgldx86.sys -> [2009-05-24 11:19:08 | 00,325,896 | ---- | C] (AVG Technologies CZ, s.r.o.)
incavi.avm -> C:\Windows\System32\drivers\Avg\incavi.avm -> [2009-05-24 11:19:06 | 36,828,130 | ---- | C] ()
avi7.avg -> C:\Windows\System32\drivers\Avg\avi7.avg -> [2009-05-24 11:19:06 | 06,061,540 | ---- | C] ()
miniavi.avg -> C:\Windows\System32\drivers\Avg\miniavi.avg -> [2009-05-24 11:19:06 | 00,434,673 | ---- | C] ()
microavi.avg -> C:\Windows\System32\drivers\Avg\microavi.avg -> [2009-05-24 11:19:06 | 00,064,911 | ---- | C] ()
avgmfx86.sys -> C:\Windows\System32\drivers\avgmfx86.sys -> [2009-05-24 11:19:06 | 00,027,784 | ---- | C] (AVG Technologies CZ, s.r.o.)
Avg -> C:\Windows\System32\drivers\Avg -> [2009-05-24 11:19:06 | 00,000,000 | ---D | C]
avg8 -> C:\ProgramData\avg8 -> [2009-05-24 11:18:58 | 00,000,000 | ---D | C]
AVG -> C:\Program Files\AVG -> [2009-05-24 11:18:58 | 00,000,000 | ---D | C]
Go Go Gourmet -> C:\ProgramData\Go Go Gourmet -> [2009-05-24 01:32:22 | 00,000,000 | ---D | C]
EncDec.dll -> C:\Windows\System32\EncDec.dll -> [2009-05-24 01:19:00 | 00,428,544 | ---- | C] (Microsoft Corporation)
psisrndr.ax -> C:\Windows\System32\psisrndr.ax -> [2009-05-24 01:18:59 | 00,217,088 | ---- | C] (Microsoft Corporation)
psisdecd.dll -> C:\Windows\System32\psisdecd.dll -> [2009-05-24 01:18:54 | 00,293,376 | ---- | C] (Microsoft Corporation)
mpg2splt.ax -> C:\Windows\System32\mpg2splt.ax -> [2009-05-24 01:18:53 | 00,177,664 | ---- | C] (Microsoft Corporation)
MSNP.ax -> C:\Windows\System32\MSNP.ax -> [2009-05-24 01:18:53 | 00,080,896 | ---- | C] (Microsoft Corporation)
winhttp.dll -> C:\Windows\System32\winhttp.dll -> [2009-05-24 01:17:34 | 00,376,832 | ---- | C] (Microsoft Corporation)
msdtcprx.dll -> C:\Windows\System32\msdtcprx.dll -> [2009-05-24 01:17:32 | 00,562,176 | ---- | C] (Microsoft Corporation)
xolehlp.dll -> C:\Windows\System32\xolehlp.dll -> [2009-05-24 01:17:32 | 00,038,912 | ---- | C] (Microsoft Corporation)
wmp.dll -> C:\Windows\System32\wmp.dll -> [2009-05-24 01:17:28 | 10,622,976 | ---- | C] (Microsoft Corporation)
spwmp.dll -> C:\Windows\System32\spwmp.dll -> [2009-05-24 01:17:26 | 00,007,680 | ---- | C] (Microsoft Corporation)
msdxm.ocx -> C:\Windows\System32\msdxm.ocx -> [2009-05-24 01:17:26 | 00,004,096 | ---- | C] (Microsoft Corporation)
dxmasf.dll -> C:\Windows\System32\dxmasf.dll -> [2009-05-24 01:17:26 | 00,004,096 | ---- | C] (Microsoft Corporation)
wmploc.DLL -> C:\Windows\System32\wmploc.DLL -> [2009-05-24 01:17:25 | 08,147,456 | ---- | C] (Microsoft Corporation)
explorer.exe -> C:\Windows\explorer.exe -> [2009-05-24 01:17:23 | 02,927,104 | ---- | C] (Microsoft Corporation)
rpcss.dll -> C:\Windows\System32\rpcss.dll -> [2009-05-24 01:17:19 | 00,551,424 | ---- | C] (Microsoft Corporation)
ntkrnlpa.exe -> C:\Windows\System32\ntkrnlpa.exe -> [2009-05-24 01:17:18 | 03,599,328 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\System32\ntoskrnl.exe -> [2009-05-24 01:17:18 | 03,547,632 | ---- | C] (Microsoft Corporation)
printfilterpipelinesvc.exe -> C:\Windows\System32\printfilterpipelinesvc.exe -> [2009-05-24 01:17:16 | 00,666,624 | ---- | C] (Microsoft Corporation)
sdohlp.dll -> C:\Windows\System32\sdohlp.dll -> [2009-05-24 01:17:16 | 00,183,296 | ---- | C] (Microsoft Corporation)
iasrecst.dll -> C:\Windows\System32\iasrecst.dll -> [2009-05-24 01:17:16 | 00,098,304 | ---- | C] (Microsoft Corporation)
iasads.dll -> C:\Windows\System32\iasads.dll -> [2009-05-24 01:17:16 | 00,054,784 | ---- | C] (Microsoft Corporation)
iasdatastore.dll -> C:\Windows\System32\iasdatastore.dll -> [2009-05-24 01:17:16 | 00,044,032 | ---- | C] (Microsoft Corporation)
printfilterpipelineprxy.dll -> C:\Windows\System32\printfilterpipelineprxy.dll -> [2009-05-24 01:17:16 | 00,026,112 | ---- | C] (Microsoft Corporation)
iashost.exe -> C:\Windows\System32\iashost.exe -> [2009-05-24 01:17:16 | 00,017,408 | ---- | C] (Microsoft Corporation)
lsasrv.dll -> C:\Windows\System32\lsasrv.dll -> [2009-05-24 01:17:11 | 01,255,936 | ---- | C] (Microsoft Corporation)
kernel32.dll -> C:\Windows\System32\kernel32.dll -> [2009-05-24 01:17:11 | 00,888,832 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\System32\secur32.dll -> [2009-05-24 01:17:10 | 00,072,704 | ---- | C] (Microsoft Corporation)
amxread.dll -> C:\Windows\System32\amxread.dll -> [2009-05-24 01:17:10 | 00,024,064 | ---- | C] (Microsoft Corporation)
apilogen.dll -> C:\Windows\System32\apilogen.dll -> [2009-05-24 01:17:10 | 00,013,824 | ---- | C] (Microsoft Corporation)
win32k.sys -> C:\Windows\System32\win32k.sys -> [2009-05-24 01:17:08 | 02,033,152 | ---- | C] (Microsoft Corporation)
schannel.dll -> C:\Windows\System32\schannel.dll -> [2009-05-24 01:17:06 | 00,268,288 | ---- | C] (Microsoft Corporation)
srv.sys -> C:\Windows\System32\drivers\srv.sys -> [2009-05-24 01:17:05 | 00,288,768 | ---- | C] (Microsoft Corporation)
mshtml.dll -> C:\Windows\System32\mshtml.dll -> [2009-05-24 01:17:01 | 03,580,928 | ---- | C] (Microsoft Corporation)
ieframe.dll -> C:\Windows\System32\ieframe.dll -> [2009-05-24 01:16:59 | 06,068,736 | ---- | C] (Microsoft Corporation)
urlmon.dll -> C:\Windows\System32\urlmon.dll -> [2009-05-24 01:16:58 | 01,166,336 | ---- | C] (Microsoft Corporation)
iedkcs32.dll -> C:\Windows\System32\iedkcs32.dll -> [2009-05-24 01:16:58 | 00,389,120 | ---- | C] (Microsoft Corporation)
iertutil.dll -> C:\Windows\System32\iertutil.dll -> [2009-05-24 01:16:58 | 00,270,336 | ---- | C] (Microsoft Corporation)
wininet.dll -> C:\Windows\System32\wininet.dll -> [2009-05-24 01:16:57 | 00,827,392 | ---- | C] (Microsoft Corporation)
msfeeds.dll -> C:\Windows\System32\msfeeds.dll -> [2009-05-24 01:16:57 | 00,458,240 | ---- | C] (Microsoft Corporation)
html.iec -> C:\Windows\System32\html.iec -> [2009-05-24 01:16:57 | 00,389,632 | ---- | C] (Microsoft Corporation)
ieaksie.dll -> C:\Windows\System32\ieaksie.dll -> [2009-05-24 01:16:57 | 00,230,400 | ---- | C] (Microsoft Corporation)
occache.dll -> C:\Windows\System32\occache.dll -> [2009-05-24 01:16:57 | 00,102,912 | ---- | C] (Microsoft Corporation)
ieencode.dll -> C:\Windows\System32\ieencode.dll -> [2009-05-24 01:16:57 | 00,078,336 | ---- | C] (Microsoft Corporation)
ieUnatt.exe -> C:\Windows\System32\ieUnatt.exe -> [2009-05-24 01:16:57 | 00,026,624 | ---- | C] (Microsoft Corporation)
mstime.dll -> C:\Windows\System32\mstime.dll -> [2009-05-24 01:16:56 | 00,671,232 | ---- | C] (Microsoft Corporation)
jsproxy.dll -> C:\Windows\System32\jsproxy.dll -> [2009-05-24 01:16:56 | 00,028,160 | ---- | C] (Microsoft Corporation)
mshtml.tlb -> C:\Windows\System32\mshtml.tlb -> [2009-05-24 01:16:55 | 01,383,424 | ---- | C] (Microsoft Corporation)
µTorrent.lnk -> C:\Users\Media\Desktop\µTorrent.lnk -> [2009-05-24 01:04:49 | 00,000,756 | ---- | C] ()
uTorrent -> C:\Program Files\uTorrent -> [2009-05-24 01:04:48 | 00,000,000 | ---D | C]
uTorrent -> C:\Users\Media\AppData\Roaming\uTorrent -> [2009-05-24 01:03:56 | 00,000,000 | ---D | C]
vlc -> C:\Users\Media\AppData\Roaming\vlc -> [2009-05-23 23:59:01 | 00,000,000 | ---D | C]
Adobe -> C:\Users\Media\AppData\Local\Adobe -> [2009-05-23 23:57:04 | 00,000,000 | ---D | C]
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2009-05-23 23:56:45 | 00,000,863 | ---- | C] ()
VideoLAN -> C:\Program Files\VideoLAN -> [2009-05-23 23:56:34 | 00,000,000 | ---D | C]
branden -> C:\Users\Media\Documents\branden -> [2009-05-23 23:47:02 | 00,000,000 | ---D | C]
vlc-0.9.9-win32.exe -> C:\Users\Media\Documents\vlc-0.9.9-win32.exe -> [2009-05-23 23:46:58 | 16,742,799 | ---- | C] ()
3342_-_SimAnimals_(E) -> C:\Users\Media\Documents\3342_-_SimAnimals_(E) -> [2009-05-23 23:46:58 | 00,000,000 | ---D | C]
firefox.docx -> C:\Users\Media\Documents\firefox.docx -> [2009-05-23 23:46:57 | 00,326,774 | ---- | C] ()
lucky day.one -> C:\Users\Media\Documents\lucky day.one -> [2009-05-23 23:46:57 | 00,151,952 | ---- | C] ()
Gegevensschijf.cdm -> C:\Users\Media\Documents\Gegevensschijf.cdm -> [2009-05-23 23:46:57 | 00,063,068 | ---- | C] ()
junnaCV.doc -> C:\Users\Media\Documents\junnaCV.doc -> [2009-05-23 23:46:57 | 00,038,400 | ---- | C] ()
BWDM fic.doc -> C:\Users\Media\Documents\BWDM fic.doc -> [2009-05-23 23:46:57 | 00,035,328 | ---- | C] ()
dmbdayfic.docx -> C:\Users\Media\Documents\dmbdayfic.docx -> [2009-05-23 23:46:57 | 00,029,775 | ---- | C] ()
drabbleforcentopiedi.doc -> C:\Users\Media\Documents\drabbleforcentopiedi.doc -> [2009-05-23 23:46:57 | 00,024,064 | ---- | C] ()
Fairy tales and Make-believe.doc -> C:\Users\Media\Documents\Fairy tales and Make-believe.doc -> [2009-05-23 23:46:57 | 00,022,528 | ---- | C] ()
suicidefic.docx -> C:\Users\Media\Documents\suicidefic.docx -> [2009-05-23 23:46:57 | 00,013,397 | ---- | C] ()
dmhpnov08.doc -> C:\Users\Media\Documents\dmhpnov08.doc -> [2009-05-23 23:46:57 | 00,001,312 | ---- | C] ()
photoshop -> C:\Users\Media\Documents\photoshop -> [2009-05-23 23:46:56 | 00,000,000 | ---D | C]
OneNote-notitieblokken -> C:\Users\Media\Documents\OneNote-notitieblokken -> [2009-05-23 23:46:56 | 00,000,000 | ---D | C]
movies -> C:\Users\Media\Documents\movies -> [2009-05-23 23:33:17 | 00,000,000 | ---D | C]
Mijn ontvangen bestanden -> C:\Users\Media\Documents\Mijn ontvangen bestanden -> [2009-05-23 23:33:17 | 00,000,000 | ---D | C]
fic -> C:\Users\Media\Documents\fic -> [2009-05-23 23:32:40 | 00,000,000 | ---D | C]
downloads -> C:\Users\Media\Documents\downloads -> [2009-05-23 23:30:15 | 00,000,000 | ---D | C]
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\Media\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009-05-23 23:30:13 | 00,012,800 | ---- | C] ()
nsreg.dat -> C:\Windows\nsreg.dat -> [2009-05-23 23:00:25 | 00,000,000 | ---- | C] ()
Mozilla -> C:\Users\Media\AppData\Roaming\Mozilla -> [2009-05-23 23:00:12 | 00,000,000 | ---D | C]
Mozilla -> C:\Users\Media\AppData\Local\Mozilla -> [2009-05-23 23:00:12 | 00,000,000 | ---D | C]
Mozilla Firefox.lnk -> C:\Users\Public\Desktop\Mozilla Firefox.lnk -> [2009-05-23 23:00:09 | 00,001,728 | ---- | C] ()
Mozilla Firefox -> C:\Program Files\Mozilla Firefox -> [2009-05-23 23:00:05 | 00,000,000 | ---D | C]
Adobe -> C:\Users\Media\AppData\Roaming\Adobe -> [2009-05-23 22:49:36 | 00,000,000 | ---D | C]
wuaueng.dll -> C:\Windows\System32\wuaueng.dll -> [2009-05-23 22:43:24 | 01,809,944 | ---- | C] (Microsoft Corporation)
wucltux.dll -> C:\Windows\System32\wucltux.dll -> [2009-05-23 22:43:24 | 01,524,736 | ---- | C] (Microsoft Corporation)
wuauclt.exe -> C:\Windows\System32\wuauclt.exe -> [2009-05-23 22:43:24 | 00,051,224 | ---- | C] (Microsoft Corporation)
wups2.dll -> C:\Windows\System32\wups2.dll -> [2009-05-23 22:43:24 | 00,043,544 | ---- | C] (Microsoft Corporation)
wuapi.dll -> C:\Windows\System32\wuapi.dll -> [2009-05-23 22:43:12 | 00,561,688 | ---- | C] (Microsoft Corporation)
wudriver.dll -> C:\Windows\System32\wudriver.dll -> [2009-05-23 22:43:12 | 00,083,456 | ---- | C] (Microsoft Corporation)
wups.dll -> C:\Windows\System32\wups.dll -> [2009-05-23 22:43:12 | 00,034,328 | ---- | C] (Microsoft Corporation)
wuwebv.dll -> C:\Windows\System32\wuwebv.dll -> [2009-05-23 22:43:06 | 00,162,064 | ---- | C] (Microsoft Corporation)
wuapp.exe -> C:\Windows\System32\wuapp.exe -> [2009-05-23 22:43:06 | 00,031,232 | ---- | C] (Microsoft Corporation)
d3d9caps.dat -> C:\Users\Media\AppData\Local\d3d9caps.dat -> [2009-05-13 00:29:13 | 00,001,356 | ---- | C] ()
CyberLink -> C:\Users\Media\AppData\Local\CyberLink -> [2009-05-13 00:29:12 | 00,000,000 | ---D | C]
PlayMovie -> C:\Users\Media\AppData\Local\PlayMovie -> [2009-05-13 00:29:03 | 00,000,000 | ---D | C]
SoftDMA -> C:\Users\Media\AppData\Local\SoftDMA -> [2009-05-13 00:29:02 | 00,000,000 | ---D | C]
Acer Arcade Deluxe -> C:\Users\Media\AppData\Local\Acer Arcade Deluxe -> [2009-05-13 00:28:59 | 00,000,000 | ---D | C]
CyberLink -> C:\Users\Media\AppData\Roaming\CyberLink -> [2009-05-13 00:28:58 | 00,000,000 | ---D | C]
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009-05-12 03:08:01 | 00,031,871 | ---- | C] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009-05-12 03:06:23 | 00,031,871 | ---- | C] ()
acer.exe -> C:\Windows\System32\acer.exe -> [2009-05-12 03:05:45 | 20,619,563 | ---- | C] (Macromedia, Inc.)
acer.scr -> C:\Windows\System32\acer.scr -> [2009-05-12 03:05:44 | 83,554,304 | ---- | C] ()
Macromedia -> C:\Users\Media\AppData\Roaming\Macromedia -> [2009-05-12 03:05:43 | 00,000,000 | ---D | C]
ACER -> C:\Windows\ACER -> [2009-05-12 03:05:38 | 00,000,000 | ---D | C]
Acer -> C:\Users\Media\AppData\Roaming\Acer -> [2009-05-12 03:05:03 | 00,000,000 | ---D | C]
Acer VCM.lnk -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk -> [2009-05-12 03:04:56 | 00,000,627 | ---- | C] ()
msxml4a.dll -> C:\Windows\System32\msxml4a.dll -> [2009-05-12 03:03:44 | 00,044,544 | ---- | C] (Microsoft Corporation)
Google -> C:\Users\Media\AppData\Roaming\Google -> [2009-05-12 03:02:57 | 00,000,000 | ---D | C]
PowerCinema -> C:\Users\Media\AppData\Local\PowerCinema -> [2009-05-12 03:01:17 | 00,000,000 | ---D | C]
Acer Arcade Deluxe.lnk -> C:\Users\Public\Desktop\Acer Arcade Deluxe.lnk -> [2009-05-12 03:01:16 | 00,002,069 | ---- | C] ()
Acer Arcade Deluxe -> C:\Program Files\Acer Arcade Deluxe -> [2009-05-12 02:58:58 | 00,000,000 | ---D | C]
Temp -> C:\ProgramData\Temp -> [2009-05-12 02:58:55 | 00,000,000 | ---D | C]
CyberLink -> C:\ProgramData\CyberLink -> [2009-05-12 02:58:55 | 00,000,000 | ---D | C]
Medion.ini -> C:\Medion.ini -> [2009-05-12 02:58:20 | 00,000,020 | ---- | C] ()
CLSetup -> C:\CLSetup -> [2009-05-12 02:58:20 | 00,000,000 | ---D | C]
LogConfigTemp.xml -> C:\Windows\System32\LogConfigTemp.xml -> [2009-05-12 02:49:10 | 00,000,000 | ---- | C] ()
GridV.UNI -> C:\Windows\GridV.UNI -> [2009-05-12 02:48:18 | 00,000,092 | ---- | C] ()
Acer Inc -> C:\Program Files\Acer Inc -> [2009-05-12 02:48:15 | 00,000,000 | ---D | C]
itecir.sys -> C:\Windows\System32\drivers\itecir.sys -> [2009-05-12 02:47:54 | 00,054,784 | ---- | C] (ITE Tech. Inc. )
CIRCoInst.dll -> C:\Windows\System32\CIRCoInst.dll -> [2009-05-12 02:47:54 | 00,007,680 | ---- | C] (Microsoft Corporation)
ITECIR -> C:\Windows\ITECIR -> [2009-05-12 02:47:54 | 00,000,000 | ---D | C]
LManager.UNI -> C:\Windows\LManager.UNI -> [2009-05-12 02:47:26 | 00,000,083 | ---- | C] ()
Launch Manager -> C:\Program Files\Launch Manager -> [2009-05-12 02:47:24 | 00,000,000 | ---D | C]
Image.dll -> C:\Windows\Image.dll -> [2009-05-12 02:46:43 | 00,626,688 | ---- | C] ()
Acer Crystal Eye webcam.EXE -> C:\Windows\Acer Crystal Eye webcam.EXE -> [2009-05-12 02:46:43 | 00,352,256 | ---- | C] (SuYin)
Acer Crystal Eye webcam.ico -> C:\Windows\Acer Crystal Eye webcam.ico -> [2009-05-12 02:46:43 | 00,222,382 | ---- | C] ()
PLFSetI.exe -> C:\Windows\PLFSetI.exe -> [2009-05-12 02:46:43 | 00,200,704 | ---- | C] ()
usbvideo_reg.exe -> C:\Windows\usbvideo_reg.exe -> [2009-05-12 02:46:43 | 00,009,216 | ---- | C] ()
Suyin.reg -> C:\Windows\Suyin.reg -> [2009-05-12 02:46:43 | 00,004,838 | ---- | C] ()
PidList.ini -> C:\Windows\PidList.ini -> [2009-05-12 02:46:43 | 00,000,036 | ---- | C] ()
InstallShield -> C:\Users\Media\AppData\Roaming\InstallShield -> [2009-05-12 02:46:32 | 00,000,000 | ---D | C]
VMC3KAPI.dll -> C:\Windows\System32\VMC3KAPI.dll -> [2009-05-12 02:45:26 | 00,118,784 | ---- | C] ()
VCryptAPI.dll -> C:\Windows\System32\VCryptAPI.dll -> [2009-05-12 02:45:26 | 00,114,688 | ---- | C] (Arachnoid Biometrics Identification Group Corp.)
ShlCmd.exe -> C:\Windows\System32\ShlCmd.exe -> [2009-05-12 02:45:14 | 00,023,040 | ---- | C] (Arachnoid Biometrics Identification Group Corp.)
biologon.dll -> C:\Windows\System32\biologon.dll -> [2009-05-12 02:45:12 | 00,005,632 | ---- | C] (Microsoft Corporation)
AlfaFF.sys -> C:\Windows\System32\drivers\AlfaFF.sys -> [2009-05-12 02:44:59 | 00,043,184 | ---- | C] (Alfa Corporation)
AlfaFF.dll -> C:\Windows\System32\AlfaFF.dll -> [2009-05-12 02:44:59 | 00,016,384 | ---- | C] (Alfa Corporation)
DrvCrypt.dll -> C:\Windows\System32\DrvCrypt.dll -> [2009-05-12 02:44:58 | 00,331,776 | ---- | C] (Alfa Corporation)
BioOne.dll -> C:\Windows\System32\BioOne.dll -> [2009-05-12 02:44:54 | 00,192,512 | ---- | C] (Arachnoid Biometric Identification Group.)
PBAGUI.dll -> C:\Windows\System32\PBAGUI.dll -> [2009-05-12 02:44:53 | 00,189,952 | ---- | C] (AuthenTec, Inc.)
Validity -> C:\Users\Media\AppData\Roaming\Validity -> [2009-05-12 02:44:52 | 00,000,000 | ---D | C]
Mijn Google Gadgets -> C:\Users\Media\Documents\Mijn Google Gadgets -> [2009-05-12 02:44:50 | 00,000,000 | ---D | C]
Google -> C:\Users\Media\AppData\Local\Google -> [2009-05-12 02:44:36 | 00,000,000 | ---D | C]
Validity Sensors, Inc -> C:\Program Files\Validity Sensors, Inc -> [2009-05-12 02:44:15 | 00,000,000 | ---D | C]
Acer -> C:\Users\Public\Documents\Acer -> [2009-05-12 02:44:02 | 00,000,000 | ---D | C]
$RECYCLE.BIN -> C:\$RECYCLE.BIN -> [2009-05-12 02:43:54 | 00,000,000 | -HSD | C]
desktop.ini -> C:\Users\Media\Documents\desktop.ini -> [2009-05-12 02:43:48 | 00,000,402 | -HS- | C] ()
desktop.ini -> C:\Users\Media\Desktop\desktop.ini -> [2009-05-12 02:43:48 | 00,000,282 | -HS- | C] ()
desktop.ini -> C:\Users\Media\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -> [2009-05-12 02:43:48 | 00,000,174 | -HS- | C] ()
Searches -> C:\Users\Media\Searches -> [2009-05-12 02:43:48 | 00,000,000 | R--D | C]
Identities -> C:\Users\Media\AppData\Roaming\Identities -> [2009-05-12 02:43:40 | 00,000,000 | ---D | C]
Contacts -> C:\Users\Media\Contacts -> [2009-05-12 02:43:38 | 00,000,000 | R--D | C]
GDIPFONTCACHEV1.DAT -> C:\Users\Media\AppData\Local\GDIPFONTCACHEV1.DAT -> [2009-05-12 02:42:58 | 00,102,960 | ---- | C] ()
Acer Store.lnk -> C:\Users\Public\Desktop\Acer Store.lnk -> [2009-05-12 02:42:54 | 00,000,594 | ---- | C] ()
Google -> C:\ProgramData\Google -> [2009-05-12 02:41:12 | 00,000,000 | ---D | C]
VirtualStore -> C:\Users\Media\AppData\Local\VirtualStore -> [2009-05-12 02:40:55 | 00,000,000 | ---D | C]
NVIDIA -> C:\ProgramData\NVIDIA -> [2009-05-12 02:40:55 | 00,000,000 | ---D | C]
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms -> [2009-05-12 02:40:53 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> [2009-05-12 02:40:53 | 00,524,288 | -HS- | C] ()
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> [2009-05-12 02:40:53 | 00,065,536 | -HS- | C] ()
Cyberlink PowerDirector.lnk -> C:\Users\Media\Desktop\Cyberlink PowerDirector.lnk -> [2009-05-12 02:40:53 | 00,001,850 | ---- | C] ()
ntuser.ini -> C:\Users\Media\ntuser.ini -> [2009-05-12 02:40:53 | 00,000,020 | -HS- | C] ()
Temporary Internet Files -> C:\Users\Media\AppData\Local\Temporary Internet Files -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Sjablonen -> C:\Users\Media\Sjablonen -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
SendTo -> C:\Users\Media\SendTo -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Recent -> C:\Users\Media\Recent -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Netwerkprinteromgeving -> C:\Users\Media\Netwerkprinteromgeving -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
NetHood -> C:\Users\Media\NetHood -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Mijn video's -> C:\Users\Media\Documents\Mijn video's -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Mijn muziek -> C:\Users\Media\Documents\Mijn muziek -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Mijn documenten -> C:\Users\Media\Mijn documenten -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Mijn afbeeldingen -> C:\Users\Media\Documents\Mijn afbeeldingen -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Menu Start -> C:\Users\Media\Menu Start -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Local Settings -> C:\Users\Media\Local Settings -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Geschiedenis -> C:\Users\Media\AppData\Local\Geschiedenis -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Cookies -> C:\Users\Media\Cookies -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Application Data -> C:\Users\Media\Application Data -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Application Data -> C:\Users\Media\AppData\Local\Application Data -> [2009-05-12 02:40:53 | 00,000,000 | -HSD | C]
Temp -> C:\Users\Media\AppData\Local\Temp -> [2009-05-12 02:40:53 | 00,000,000 | ---D | C]
Microsoft -> C:\Users\Media\AppData\Local\Microsoft -> [2009-05-12 02:40:53 | 00,000,000 | ---D | C]
Media Center Programs -> C:\Users\Media\AppData\Roaming\Media Center Programs -> [2009-05-12 02:40:53 | 00,000,000 | ---D | C]
Acer GameZone Console -> C:\Users\Media\AppData\Roaming\Acer GameZone Console -> [2009-05-12 02:40:53 | 00,000,000 | ---D | C]
ntuser.dat -> C:\Users\Media\ntuser.dat -> [2009-05-12 02:40:52 | 01,310,720 | -HS- | C] ()
Microsoft -> C:\Users\Media\AppData\Roaming\Microsoft -> [2009-05-12 02:40:52 | 00,000,000 | --SD | C]
Videos -> C:\Users\Media\Videos -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Saved Games -> C:\Users\Media\Saved Games -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Pictures -> C:\Users\Media\Pictures -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Music -> C:\Users\Media\Music -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Links -> C:\Users\Media\Links -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Favorites -> C:\Users\Media\Favorites -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Downloads -> C:\Users\Media\Downloads -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Documents -> C:\Users\Media\Documents -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
Desktop -> C:\Users\Media\Desktop -> [2009-05-12 02:40:52 | 00,000,000 | R--D | C]
AppData -> C:\Users\Media\AppData -> [2009-05-12 02:40:52 | 00,000,000 | -H-D | C]
Roaming -> C:\Users\Media\Roaming -> [2009-05-12 02:40:52 | 00,000,000 | ---D | C]
Sjablonen -> C:\ProgramData\Sjablonen -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Mijn video's -> C:\Users\Public\Documents\Mijn video's -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Mijn muziek -> C:\Users\Public\Documents\Mijn muziek -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Mijn afbeeldingen -> C:\Users\Public\Documents\Mijn afbeeldingen -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Menu Start -> C:\ProgramData\Menu Start -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Favorieten -> C:\ProgramData\Favorieten -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Documenten -> C:\ProgramData\Documenten -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
Bureaublad -> C:\ProgramData\Bureaublad -> [2009-05-12 00:26:16 | 00,000,000 | -HSD | C]
agrsmdel.exe -> C:\Windows\System32\agrsmdel.exe -> [2009-05-12 00:13:20 | 00,054,824 | ---- | C] (Agere Systems)
Options -> C:\Windows\Options -> [2009-05-12 00:13:10 | 00,000,000 | ---D | C]
SoftwareDistribution -> C:\Windows\SoftwareDistribution -> [2009-05-12 00:10:56 | 00,000,000 | ---D | C]
Interop.IWshRuntimeLibrary.dll -> C:\Windows\Interop.IWshRuntimeLibrary.dll -> [2009-01-13 04:09:57 | 00,049,152 | ---- | C] ( )
WdfCoInstaller01000.dll -> C:\Windows\System32\WdfCoInstaller01000.dll -> [2009-01-13 04:06:37 | 01,060,424 | ---- | C] ()
NTIOFM4.dll -> C:\Windows\System32\NTIOFM4.dll -> [2009-01-12 21:49:10 | 00,001,024 | RH-- | C] ()
NTIBUN5.dll -> C:\Windows\System32\NTIBUN5.dll -> [2009-01-12 21:49:10 | 00,001,024 | RH-- | C] ()
INT15.dll -> C:\Windows\System32\INT15.dll -> [2009-01-12 21:18:40 | 00,487,424 | ---- | C] ()
RtDefLvl.ini -> C:\Windows\RtDefLvl.ini -> [2009-01-12 20:59:21 | 00,001,694 | ---- | C] ()
CogentBioSDK.dll -> C:\Windows\System32\CogentBioSDK.dll -> [2007-11-14 16:17:34 | 00,204,800 | ---- | C] ()
int15.sys -> C:\Windows\System32\drivers\int15.sys -> [2007-01-26 08:32:18 | 00,069,632 | ---- | C] ()
sysprepMCE.dll -> C:\Windows\System32\sysprepMCE.dll -> [2006-11-02 14:35:32 | 00,005,632 | ---- | C] ()
win.ini -> C:\Windows\win.ini -> [2006-11-02 12:23:31 | 00,000,219 | ---- | C] ()
system.ini -> C:\Windows\system.ini -> [2006-11-02 12:23:31 | 00,000,219 | ---- | C] ()
pacerprf.ini -> C:\Windows\System32\pacerprf.ini -> [2006-11-02 09:40:29 | 00,013,750 | ---- | C] ()
multiplex_vcd.dll -> C:\Windows\System32\multiplex_vcd.dll -> [2001-12-26 17:12:30 | 00,065,536 | ---- | C] ()
Hmpg12.dll -> C:\Windows\System32\Hmpg12.dll -> [2001-09-04 00:46:38 | 00,110,592 | ---- | C] ()
HMPV2_ENC.dll -> C:\Windows\System32\HMPV2_ENC.dll -> [2001-07-30 17:33:56 | 00,118,784 | ---- | C] ()
HMPV2_ENC_MMX.dll -> C:\Windows\System32\HMPV2_ENC_MMX.dll -> [2001-07-23 23:04:36 | 00,118,784 | ---- | C] ()
 
[Files/Folders - Modified Within 30 Days]
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009-06-05 22:57:11 | 00,003,216 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009-06-05 22:57:11 | 00,003,216 | -H-- | M] ()
ntuser.dat -> C:\Users\Media\ntuser.dat -> [2009-06-05 22:53:29 | 01,310,720 | -HS- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009-06-05 19:58:34 | 00,000,822 | ---- | M] ()
PublishedRacMonSWITable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonSWITable.DAT -> [2009-06-05 19:12:17 | 00,043,452 | ---- | M] ()
PublishedRacMonOSFTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonOSFTable.DAT -> [2009-06-05 19:12:17 | 00,005,796 | ---- | M] ()
PublishedRacMonIndex.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonIndex.DAT -> [2009-06-05 19:12:17 | 00,000,576 | ---- | M] ()
PublishedRacMonAFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonAFLTable.DAT -> [2009-06-05 19:12:17 | 00,000,276 | ---- | M] ()
PublishedRacMonHFLTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonHFLTable.DAT -> [2009-06-05 19:12:17 | 00,000,000 | ---- | M] ()
PublishedRacMonCLKTable.DAT -> C:\ProgramData\Microsoft\RAC\PublishedData\PublishedRacMonCLKTable.DAT -> [2009-06-05 19:12:17 | 00,000,000 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2009-06-05 19:03:31 | 01,471,570 | ---- | M] ()
perfh013.dat -> C:\Windows\System32\perfh013.dat -> [2009-06-05 19:03:31 | 00,667,352 | ---- | M] ()
perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2009-06-05 19:03:31 | 00,587,178 | ---- | M] ()
perfc013.dat -> C:\Windows\System32\perfc013.dat -> [2009-06-05 19:03:31 | 00,126,854 | ---- | M] ()
perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2009-06-05 19:03:31 | 00,101,250 | ---- | M] ()
qmgr1.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat -> [2009-06-05 19:01:58 | 04,194,304 | ---- | M] ()
qmgr0.dat -> C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat -> [2009-06-05 19:01:58 | 04,194,304 | ---- | M] ()
incavi.avm -> C:\Windows\System32\drivers\Avg\incavi.avm -> [2009-06-05 18:59:26 | 36,828,130 | ---- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2009-06-05 18:58:10 | 00,031,871 | ---- | M] ()
LogConfigTemp.xml -> C:\Windows\System32\LogConfigTemp.xml -> [2009-06-05 18:57:37 | 00,000,000 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009-06-05 18:57:15 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009-06-05 18:57:09 | 00,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009-06-05 18:57:05 | 32,159,90784 | -HS- | M] ()
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> [2009-06-04 23:37:39 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> [2009-06-04 23:37:39 | 00,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\Media\AppData\Local\IconCache.db -> [2009-06-04 23:37:25 | 01,918,093 | -H-- | M] ()
popcinfo.dat -> C:\Windows\popcinfo.dat -> [2009-06-04 23:33:32 | 00,000,016 | ---- | M] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2009-06-04 19:36:31 | 00,031,871 | ---- | M] ()
HijackThis.lnk -> C:\Users\Media\Desktop\HijackThis.lnk -> [2009-06-04 18:20:23 | 00,001,878 | ---- | M] ()
microavi.avg -> C:\Windows\System32\drivers\Avg\microavi.avg -> [2009-06-04 18:05:48 | 00,064,911 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\Media\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009-06-02 23:39:14 | 00,012,800 | ---- | M] ()
d3d9caps.dat -> C:\Users\Media\AppData\Local\d3d9caps.dat -> [2009-06-02 20:18:07 | 00,001,356 | ---- | M] ()
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2009-06-02 18:46:21 | 19,692,6064 | ---- | M] ()
~$irefox.docx -> C:\Users\Media\Documents\~$irefox.docx -> [2009-05-30 10:46:47 | 00,000,162 | -H-- | M] ()
LimeWire 5.1.3.lnk -> C:\Users\Media\Desktop\LimeWire 5.1.3.lnk -> [2009-05-26 21:25:44 | 00,001,704 | ---- | M] ()
mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2009-05-26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2009-05-26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation)
Ranch Rush.lnk -> C:\Users\Media\Desktop\Ranch Rush.lnk -> [2009-05-24 23:00:52 | 00,001,699 | ---- | M] ()
~$bdayfic.docx -> C:\Users\Media\Documents\~$bdayfic.docx -> [2009-05-24 20:40:18 | 00,000,162 | -H-- | M] ()
FNTCACHE.DAT -> C:\Windows\System32\FNTCACHE.DAT -> [2009-05-24 15:41:17 | 00,382,392 | ---- | M] ()
GDIPFONTCACHEV1.DAT -> C:\Users\Media\AppData\Local\GDIPFONTCACHEV1.DAT -> [2009-05-24 12:22:51 | 00,102,960 | ---- | M] ()
win.ini -> C:\Windows\win.ini -> [2009-05-24 12:06:03 | 00,000,219 | ---- | M] ()
AVG Free 8.5.lnk -> C:\Users\Public\Desktop\AVG Free 8.5.lnk -> [2009-05-24 11:19:15 | 00,001,651 | ---- | M] ()
avgrsstx.dll -> C:\Windows\System32\avgrsstx.dll -> [2009-05-24 11:19:13 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgtdix.sys -> C:\Windows\System32\drivers\avgtdix.sys -> [2009-05-24 11:19:12 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> C:\Windows\System32\drivers\avgldx86.sys -> [2009-05-24 11:19:08 | 00,325,896 | ---- | M] (AVG Technologies CZ, s.r.o.)
avi7.avg -> C:\Windows\System32\drivers\Avg\avi7.avg -> [2009-05-24 11:19:06 | 06,061,540 | ---- | M] ()
miniavi.avg -> C:\Windows\System32\drivers\Avg\miniavi.avg -> [2009-05-24 11:19:06 | 00,434,673 | ---- | M] ()
avgmfx86.sys -> C:\Windows\System32\drivers\avgmfx86.sys -> [2009-05-24 11:19:06 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.)
µTorrent.lnk -> C:\Users\Media\Desktop\µTorrent.lnk -> [2009-05-24 01:04:49 | 00,000,756 | ---- | M] ()
opa12.dat -> C:\ProgramData\Microsoft\OFFICE\DATA\opa12.dat -> [2009-05-24 00:24:18 | 00,008,292 | ---- | M] ()
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2009-05-23 23:56:45 | 00,000,863 | ---- | M] ()
index.dat -> C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009-05-23 23:55:25 | 00,032,768 | -HS- | M] ()
index.dat -> C:\Windows\Temp\History\History.IE5\index.dat -> [2009-05-23 23:55:25 | 00,016,384 | -HS- | M] ()
index.dat -> C:\Windows\Temp\Cookies\index.dat -> [2009-05-23 23:55:25 | 00,016,384 | -HS- | M] ()
nsreg.dat -> C:\Windows\nsreg.dat -> [2009-05-23 23:00:25 | 00,000,000 | ---- | M] ()
Mozilla Firefox.lnk -> C:\Users\Public\Desktop\Mozilla Firefox.lnk -> [2009-05-23 23:00:09 | 00,001,728 | ---- | M] ()
firefox.docx -> C:\Users\Media\Documents\firefox.docx -> [2009-05-23 21:26:56 | 00,326,774 | ---- | M] ()
vlc-0.9.9-win32.exe -> C:\Users\Media\Documents\vlc-0.9.9-win32.exe -> [2009-05-13 00:28:45 | 16,742,799 | ---- | M] ()
NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Media\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms -> [2009-05-12 03:07:14 | 00,524,288 | -HS- | M] ()
Acer VCM.lnk -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk -> [2009-05-12 03:04:56 | 00,000,627 | ---- | M] ()
Acer Arcade Deluxe.lnk -> C:\Users\Public\Desktop\Acer Arcade Deluxe.lnk -> [2009-05-12 03:01:16 | 00,002,069 | ---- | M] ()
Medion.ini -> C:\Medion.ini -> [2009-05-12 02:58:20 | 00,000,020 | ---- | M] ()
GridV.UNI -> C:\Windows\GridV.UNI -> [2009-05-12 02:48:18 | 00,000,092 | ---- | M] ()
LManager.UNI -> C:\Windows\LManager.UNI -> [2009-05-12 02:47:26 | 00,000,083 | ---- | M] ()
VMC3KAPI.dll -> C:\Windows\System32\VMC3KAPI.dll -> [2009-05-12 02:45:26 | 00,118,784 | ---- | M] ()
VCryptAPI.dll -> C:\Windows\System32\VCryptAPI.dll -> [2009-05-12 02:45:26 | 00,114,688 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
ShlCmd.exe -> C:\Windows\System32\ShlCmd.exe -> [2009-05-12 02:45:14 | 00,023,040 | ---- | M] (Arachnoid Biometrics Identification Group Corp.)
biologon.dll -> C:\Windows\System32\biologon.dll -> [2009-05-12 02:45:12 | 00,005,632 | ---- | M] (Microsoft Corporation)
AlfaFF.sys -> C:\Windows\System32\drivers\AlfaFF.sys -> [2009-05-12 02:44:59 | 00,043,184 | ---- | M] (Alfa Corporation)
AlfaFF.dll -> C:\Windows\System32\AlfaFF.dll -> [2009-05-12 02:44:59 | 00,016,384 | ---- | M] (Alfa Corporation)
DrvCrypt.dll -> C:\Windows\System32\DrvCrypt.dll -> [2009-05-12 02:44:58 | 00,331,776 | ---- | M] (Alfa Corporation)
BioOne.dll -> C:\Windows\System32\BioOne.dll -> [2009-05-12 02:44:54 | 00,192,512 | ---- | M] (Arachnoid Biometric Identification Group.)
PBAGUI.dll -> C:\Windows\System32\PBAGUI.dll -> [2009-05-12 02:44:53 | 00,189,952 | ---- | M] (AuthenTec, Inc.)
desktop.ini -> C:\Users\Media\Documents\desktop.ini -> [2009-05-12 02:43:48 | 00,000,402 | -HS- | M] ()
desktop.ini -> C:\Users\Media\Desktop\desktop.ini -> [2009-05-12 02:43:48 | 00,000,282 | -HS- | M] ()
desktop.ini -> C:\Users\Media\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini -> [2009-05-12 02:43:48 | 00,000,174 | -HS- | M] ()
Acer Store.lnk -> C:\Users\Public\Desktop\Acer Store.lnk -> [2009-05-12 02:42:54 | 00,000,594 | ---- | M] ()
ntuser.ini -> C:\Users\Media\ntuser.ini -> [2009-05-12 02:40:53 | 00,000,020 | -HS- | M] ()
Media.dat -> C:\ProgramData\Microsoft\User Account Pictures\Media.dat -> [2009-05-12 02:40:53 | 00,000,000 | ---- | M] ()
license.rtf -> C:\Windows\System32\license.rtf -> [2009-05-12 00:24:55 | 00,054,101 | ---- | M] ()
 
[Alternate Data Streams]
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:A42A9F39
< End of report >
« Last Edit: June 05, 2009, 08:02:47 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #8 on: June 05, 2009, 08:58:51 PM »
Still not finding anything

Why don't you try a Scan at Kaspersky's
I suggest that you first temporarily disable AVG resident protection:
open the AVG 8.5 Control Center, by right clicking on the AVG icon on task bar.

    * Click on Open AVG Interface.
    * Double click on Resident Shield
    * Deselect the option to "Enable Resident Shield."
    * Save changes, and exit the application.
Then do the following:
Close Internet Explorer>>I need you to reopen your Browser in this manner
Right click the icon to your Browser and choose to "Run as Administrator"

Go to the following link
[color=\"blue\"]Kaspersky Online Scanner[/color]

Note: If you have used this particular scanner before, you MAY HAVE TO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Click Yes, when/if prompted to install its ActiveX component.
(Note.. for Internet [color=\"#3333FF\"]Explorer 7[/color] users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%[/i].)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the [color=\"Navy\"]Scan is completed [/color]window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the [color=\"Navy\"]Save as [/color]prompt, [color=\"navy\"]Save in[/color] area, select: Desktop
In the [color=\"navy\"]File name[/color] area, use KScan, or something similar
In [color=\"navy\"]Save as type[/color], click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the [color=\"Navy\"]Kaspersky Online Scanner Report [/color]in your reply.

Don't forget to reenable your protection with AVG resident shield
« Last Edit: June 05, 2009, 09:02:05 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« Reply #9 on: June 06, 2009, 04:24:44 PM »
Nothing here either. I remembered, I think ran the Cleanup! program before I posted. Could the virus have been erased? Here's the log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
 Saturday, June 6, 2009
 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
 Kaspersky Online Scanner  version: 7.0.26.13
 Program database last update: Saturday, June 06, 2009 11:11:06
 Records in database: 2318019
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   F:\

Scan statistics:
   Files scanned: 129245
   Threat name: 0
   Infected objects: 0
   Suspicious objects: 0
   Duration of the scan: 03:18:36

No malware has been detected. The scan area is clean.

The selected area was scanned.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
It's that time again
« Reply #10 on: June 07, 2009, 07:57:01 AM »
Are you still experiencing any of the problems from your first post?
Quote
Now everything's working slower and my avg antivirus gets my computer frozen whenever I try to remove threats.

Why not run CleanUp! again, this will remove Kaspersky from Temp directory
Then run a scan with AVG and see if it finds anything, or freezes on removing anything
Take note of what AVG finds and post it back here
« Last Edit: June 07, 2009, 08:04:39 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Nia

  • Newbie
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
It's that time again
« Reply #11 on: June 08, 2009, 01:27:23 PM »
I tried it again and selected 'remove unhealed items to vault' that worked fine and today I tried it with "remove selected infections" and it froze again. Here's what it found the first time:

"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite";"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\247realmedia.com.855b46d";"Found Tracking cookie.247realmedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\247realmedia.com.d90d45cf";"Found Tracking cookie.247realmedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\2o7.net.29c43642";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\2o7.net.b368833d";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\ad.yieldmanager.com.557bf2b0";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\ad.yieldmanager.com.830b6f08";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\ad.yieldmanager.com.539b0606";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\ad.yieldmanager.com.b68f2b7b";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\ad.yieldmanager.com.ff92306";"Found Tracking cookie.Yieldmanager";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adbrite.com.44f92a69";"Found Tracking cookie.Adbrite";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adbrite.com.71beeff9";"Found Tracking cookie.Adbrite";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adbrite.com.d5e309c2";"Found Tracking cookie.Adbrite";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adrevolver.com.9b9d670a";"Found Tracking cookie.Adrevolver";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adrevolver.com.f6cfcad4";"Found Tracking cookie.Adrevolver";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\adtech.de.a9245469";"Found Tracking cookie.Adtech";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\advertising.com.1820df7a";"Found Tracking cookie.Advertising";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\advertising.com.203aa218";"Found Tracking cookie.Advertising";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\advertising.com.525a5fb9";"Found Tracking cookie.Advertising";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\advertising.com.b624fa46";"Found Tracking cookie.Advertising";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\advertising.com.f62113d5";"Found Tracking cookie.Advertising";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\atdmt.com.7247c262";"Found Tracking cookie.Atdmt";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\atdmt.com.b3e33b5f";"Found Tracking cookie.Atdmt";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\bluestreak.com.bf396750";"Found Tracking cookie.Bluestreak";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\bs.serving-sys.com.5bf1f00f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\burstnet.com.a3218a37";"Found Tracking cookie.Burstnet";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\burstnet.com.c4fe2ebb";"Found Tracking cookie.Burstnet";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.12e6c053";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.1773afc";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.80ad4799";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.987e6b46";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.8a6435e9";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.8dd1284a";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.94ca190b";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.9b41aa53";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.156cbc67";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\casalemedia.com.3a28db8d";"Found Tracking cookie.Casalemedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\doubleclick.net.bf396750";"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.57e8da10";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\fastclick.net.fac3d6f0";"Found Tracking cookie.Fastclick";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\hitbox.com.bbf2a6e8";"Found Tracking cookie.Hitbox";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\hitbox.com.2b95f8a3";"Found Tracking cookie.Hitbox";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\media.adrevolver.com.7fd89687";"Found Tracking cookie.Adrevolver";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\overture.com.52ca467a";"Found Tracking cookie.Overture";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\mediaplex.com.f652b123";"Found Tracking cookie.Mediaplex";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\overture.com.e626e6be";"Found Tracking cookie.Overture";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\realmedia.com.125a868c";"Found Tracking cookie.Realmedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\realmedia.com.855b46d";"Found Tracking cookie.Realmedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\realmedia.com.e14be39e";"Found Tracking cookie.Realmedia";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revenue.net.bcf44ea1";"Found Tracking cookie.Revenue";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.2df99d79";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.44927ec";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.50e13b1b";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.55564293";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.b8d48360";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\revsci.net.e9dbeb91";"Found Tracking cookie.Revsci";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\searchportal.information.com.44e78b2";"Found Tracking cookie.Information";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\searchportal.information.com.3a8d7204";"Found Tracking cookie.Information";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\searchportal.information.com.4a4cae2d";"Found Tracking cookie.Information";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.255d6f2f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.400f83f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.4b416ef8";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.606c3d3b";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.6a1cf9e8";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\serving-sys.com.c9034af6";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\statse.webtrendslive.com.b4ca7df0";"Found Tracking cookie.Webtrendslive";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\tradedoubler.com.ba12c0e9";"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\tradedoubler.com.dc3c9994";"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\tradedoubler.com.eab0972e";"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\tradedoubler.com.ef90aa95";"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\trafficmp.com.a00e30b4";"Found Tracking cookie.Trafficmp";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\weborama.fr.30104bcb";"Found Tracking cookie.Weborama";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\yadroWebsite removed for spamming.c77afad5";"Found Tracking cookie.Yadro";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\zedo.com.14a38114";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\zedo.com.27f1639b";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\zedo.com.a5b6a132";"Found Tracking cookie.Zedo";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\trafficmp.com.f3e5803e";"Found Tracking cookie.Trafficmp";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\tribalfusion.com.dcc03271";"Found Tracking cookie.Tribalfusion";"Potentially dangerous object"
"C:\Users\Media\AppData\Roaming\Mozilla\Firefox\Profiles\vetpoexf.default\cookies.sqlite:\zedo.com.c1dd09f2";"Found Tracking cookie.Zedo";"Potentially dangerous object"


I was a bit too opimistic after that so I didn't save the second report, but they were all cookies as well. Is it probably that my avg just doesn't work properly? The programs aren't all that slow anymore, but it does take longer for windows to start up.