Options

Free space on C is disapearing

Heya there, since a while i have been creating free space on my C\ harddisk because i only had 800 kb left, so i made 200 mb free and got back to what i was doing, now a couple days after that, i noticed i had again 2 mb 0.o i created 200 mb got back in couple hours 50 mb and so on. here is my hijack report:

Logfile of HijackThis v1.99.1
Scan saved at 22:33:47, on 25-3-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
D:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Skype.exe
D:\Program Files\Plugin Manager\SkypePM.exe
D:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Documenten en Settings\jurre\Bureaublad\Corné\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = file:///C:/Program%20Files/MStart2Page/Portal/portal.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTP00688 - {355DF66B-CDED-470F-A87F-F4B29D2D573A} - C:\PROGRA~1\POKERN~1\untitled.dll (file missing)
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: XBTP00764 - {5D901040-C9C9-4162-8A60-2BECCD98B5A9} - C:\PROGRA~1\POKERT~1\PokerTB.dll (file missing)
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: PokerNEWS Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [CleanRegPath] C:\Program Files\ADSLModemUtility(AnnexA)\CleanReg.exe
O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunServices: [MS] adwareremover.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "D:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunServices: [MS] adwareremover.exe
O4 - HKCU\..\RunOnce: [__GSCAdditionalInstallation__] "M:\Setup.exe" -AdditionalInstall
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Poker Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
O9 - Extra 'Tools' menuitem: Poker Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - AutorunsDisabled - (no file) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {031B6D43-CBC4-46A5-8E46-CF8B407C1A33} - http://qck.cc/x/ipreg32.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-nl/nl/games4.cab?fgiocv=1
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: MsgPlusLoader.d
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

Comments

  • edited March 2007
    Hello there and welcome, you have a nasty worm running there, I would like to see another log please

    Download ComboScan to your Desktop.
    • Close all applications and windows.
    • Double-click on comboscan.exe to run it, and follow the prompts.
    • The scan may take a minute. When the scan is complete, a text file will open - ComboScan.txt
    Extra Note: When running Comboscan, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags Comboscan as suspicious. Please allow the Comboscan to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)
    Post the Comboscan.txt from the Comboscan into your next reply
  • edited March 2007
    Ty, i ran it and now i have my 1.7 gb back ^^ here is the log

    ComboScan v20070306.20 run by jurre on 2007-03-29 at 08:36:53
    Computer is in Normal Mode.
    -- System Restore
    Failed to create restore point; disk is full.

    Performed disk cleanup.

    -- HijackThis (run as jurre.exe)
    Logfile of HijackThis v1.99.1
    Scan saved at 8:37:06, on 29-3-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
    D:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\svchost.exe
    D:\Documenten en Settings\jurre\Bureaublad\Corné\comboscan.exe
    D:\DOCUME~1\jurre\BUREAU~1\CORN~1\jurre.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = [URL]file:///C:/Program%20Files/MStart2Page/Portal/portal.html[/URL]
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    R3 - URLSearchHook: (no name) - - (no file)
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: XBTP00688 - {355DF66B-CDED-470F-A87F-F4B29D2D573A} - C:\PROGRA~1\POKERN~1\untitled.dll (file missing)
    O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O2 - BHO: XBTP00764 - {5D901040-C9C9-4162-8A60-2BECCD98B5A9} - C:\PROGRA~1\POKERT~1\PokerTB.dll (file missing)
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O3 - Toolbar: PokerNEWS Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
    O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
    O4 - HKLM\..\Run: [CleanRegPath] C:\Program Files\ADSLModemUtility(AnnexA)\CleanReg.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\RunServices: [MS] adwareremover.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MessengerPlus3] "D:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\RunServices: [MS] adwareremover.exe
    O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
    O9 - Extra button: Poker Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
    O9 - Extra 'Tools' menuitem: Poker Toolbar - {C49DD894-C6DE-4910-8C41-BA20F852D8BC} - C:\Program Files\PokerNEWS Toolbar\untitled.dll (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - AutorunsDisabled - (no file) (HKCU)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {031B6D43-CBC4-46A5-8E46-CF8B407C1A33} - http://qck.cc/x/ipreg32.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
    O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-nl/nl/games4.cab?fgiocv=1
    O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: CRKKUBHO - Unknown owner - D:\DOCUME~1\jurre\LOCALS~1\Temp\CRKKUBHO.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
    O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

    -- File Associations
    .bat - batfile - "%1" %*
    .chm - chm.file - "C:\WINDOWS\hh.exe" %1
    .cmd - cmdfile - "%1" %*
    .com - comfile - "%1" %*
    .exe - exefile - "%1" %*
    .hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1
    .inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1
    .ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1
    .js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %*
    .lnk - lnkfile - {00021401-0000-0000-C000-000000000046}
    .pif - piffile - "%1" %*
    .reg - regfile - regedit.exe "%1"
    .scr - scrfile - "%1" /S
    .txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1
    .vbs - VBSFile - %SystemRoot%\System32\WScript.exe "%1" %*

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    2S 713xTVCard (SAA7135 TV Card) - C:\WINDOWS\system32\drivers\SAA713x.sys
    3R aeaudio - C:\WINDOWS\system32\drivers\aeaudio.sys
    3S alcan5wn (Alcatel SpeedTouch(tm) USB ADSL PPPoA Networking Driver (NDIS)) - C:\WINDOWS\system32\drivers\alcan5wn.sys
    3S alcaudsl (Alcatel Speed Touch ADSL Modem ATM Transport) - C:\WINDOWS\system32\drivers\alcaudsl.sys
    2R Aspi32 - C:\WINDOWS\system32\drivers\aspi32.sys
    3R ati2mtag - C:\WINDOWS\system32\drivers\ati2mtag.sys
    1R Avg7Core (AVG7 Kernel) - C:\WINDOWS\system32\drivers\avg7core.sys
    1R Avg7RsW (AVG7 Wrap Driver) - C:\WINDOWS\system32\drivers\avg7rsw.sys
    1R Avg7RsXP (AVG7 Resident Driver XP) - C:\WINDOWS\system32\drivers\avg7rsxp.sys
    1R AvgClean (AVG7 Clean Driver) - C:\WINDOWS\system32\drivers\avgclean.sys
    3R bcm4sbxp (ASUSTeK/Broadcom 440x 10/100 Integrated Controller XP Driver) - C:\WINDOWS\system32\drivers\bcm4sbxp.sys
    3S BthEnum (Stuurprogramma voor Bluetooth-aanvraagblok) - C:\WINDOWS\system32\drivers\bthenum.sys
    3S BTHMODEM (Bluetooth-stuurprogramma voor seriële communicatie) - C:\WINDOWS\system32\drivers\bthmodem.sys
    3S BthPan (Bluetooth-apparaat (PAN - Personal Area Network)) - C:\WINDOWS\system32\drivers\bthpan.sys
    3S BTHPORT (Poortstuurprogramma voor Bluetooth) - C:\WINDOWS\system32\drivers\bthport.sys
    3S BTHUSB (USB-stuurprogramma voor Bluetooth-radio's) - C:\WINDOWS\system32\drivers\bthusb.sys
    3R Cap7134 (Philips Cap7133 Capture) - C:\WINDOWS\system32\drivers\Cap7134.sys
    3S CCDECODE (Closed Caption Decoder) - C:\WINDOWS\system32\drivers\ccdecode.sys
    0S d347bus - C:\WINDOWS\system32\drivers\d347bus.sys
    0S d347prt - C:\WINDOWS\system32\drivers\d347prt.sys
    3S dtscsi - C:\WINDOWS\system32\Drivers\dtscsi.sys (not found)
    2R EIO - C:\WINDOWS\system32\drivers\EIO.sys
    3R GEARAspiWDM - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
    3S hamachi (Hamachi Network Interface) - C:\WINDOWS\system32\drivers\hamachi.sys
    3S HidBth (Microsoft HID-minipoort voor Bluetooth) - C:\WINDOWS\system32\drivers\hidbth.sys
    3S hidgame (Microsoft Hid-naar-joystickpoort-enabler) - C:\WINDOWS\system32\drivers\hidgame.sys
    3S hidusb (Microsoft HID Class-stuurprogramma) - C:\WINDOWS\system32\drivers\hidusb.sys
    3S hitmanpro2 (Hitman Pro 2 Driver) - D:\Program Files\Hitman Pro\hitmanpro2.sys (not found)
    3S HPZid412 (IEEE-1284.4 Driver HPZid412) - C:\WINDOWS\system32\drivers\HPZid412.sys
    3S HPZipr12 (Print Class Driver for IEEE-1284.4 HPZipr12) - C:\WINDOWS\system32\drivers\HPZipr12.sys
    3S HPZius12 (USB to IEEE-1284.4 Translation Driver HPZius12) - C:\WINDOWS\system32\drivers\HPZius12.sys
    0R IdeBusDr - C:\WINDOWS\system32\drivers\IdeBusDr.sys
    0R IdeChnDr (Intel(R) Ultra ATA Controller) - C:\WINDOWS\system32\drivers\IdeChnDr.sys
    1R ikhfile (File Security Kernel Anti-Spyware Driver) - C:\WINDOWS\system32\drivers\ikhfile.sys
    1R ikhlayer (Kernel Anti-Spyware Driver) - C:\WINDOWS\system32\drivers\ikhlayer.sys
    1R intelppm (Intel GV3-processorstuurprogramma) - C:\WINDOWS\system32\drivers\intelppm.sys
    3S k750bus (Sony Ericsson 750 driver (WDM)) - C:\WINDOWS\system32\drivers\k750bus.sys
    3S k750mdfl (Sony Ericsson 750 USB WMC Modem Filter) - C:\WINDOWS\system32\drivers\k750mdfl.sys
    3S k750mdm (Sony Ericsson 750 USB WMC Modem Drivers) - C:\WINDOWS\system32\drivers\k750mdm.sys
    3S k750obex (Sony Ericsson 750 USB WMC OBEX Interface Drivers) - C:\WINDOWS\system32\drivers\k750obex.sys
    1R kbdhid (Stuurprogramma voor toetsenbord-HID) - C:\WINDOWS\system32\drivers\kbdhid.sys
    3R mouhid (Stuurprogramma voor muis-HID) - C:\WINDOWS\system32\drivers\mouhid.sys
    3S msgame (Poort inschakelen voor Sidewinder HID naar joystick) - C:\WINDOWS\system32\drivers\msgame.sys
    3S MSTEE (Microsoft Streaming Tee/Sink-to-Sink Converter) - C:\WINDOWS\system32\drivers\mstee.sys
    2R MXBULK (Smartcam Still, KNBulk3.Sys) - C:\WINDOWS\system32\drivers\KNBulk3.sys
    2R MXCap (Smartcam 350 Video V101) - C:\WINDOWS\system32\drivers\KNCap3.sys
    3S NABTSFEC (NABTS/FEC VBI Codec) - C:\WINDOWS\system32\drivers\nabtsfec.sys
    3S NdisIP (Microsoft TV/Video Connection) - C:\WINDOWS\system32\drivers\ndisip.sys
    3S nm (Stuurprogramma voor Netwerkcontrole) - C:\WINDOWS\system32\drivers\nmnt.sys
    3R PhTVTune (Philips WDM TVTuner) - C:\WINDOWS\system32\drivers\PhTVTune.sys
    1R prodrv06 (StarForce Protection Environment Driver v6) - C:\WINDOWS\system32\drivers\prodrv06.sys
    0R prohlp02 (StarForce Protection Helper Driver v2) - C:\WINDOWS\system32\drivers\prohlp02.sys
    0R prosync1 (StarForce Protection Synchronization Driver v1) - C:\WINDOWS\system32\drivers\prosync1.sys
    0R PxHelp20 - C:\WINDOWS\system32\drivers\pxhelp20.sys
    3S RFCOMM (Bluetooth-apparaat (RFCOMM Protocol TDI)) - C:\WINDOWS\system32\drivers\rfcomm.sys
    3S rtl8139 (NT-stuurprogramma voor Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter) - C:\WINDOWS\system32\drivers\rtl8139.sys
    3S SaiH0109 - C:\WINDOWS\system32\drivers\SaiH0109.sys
    3R SaiMini - C:\WINDOWS\system32\drivers\SaiMini.sys
    3R SaiNtBus - C:\WINDOWS\system32\drivers\SaiNtBus.sys
    3S SaiU0109 - C:\WINDOWS\system32\drivers\SaiU0109.sys
    0R sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - C:\WINDOWS\system32\drivers\sfdrv01.sys
    0R sfhlp01 (StarForce Protection Helper Driver) - C:\WINDOWS\system32\drivers\sfhlp01.sys
    0R sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - C:\WINDOWS\system32\drivers\sfhlp02.sys
    0R sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - C:\WINDOWS\system32\drivers\sfsync02.sys
    0R sfsync04 (StarForce Protection Synchronization Driver (version 4.x)) - C:\WINDOWS\system32\drivers\sfsync04.sys
    0R sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - C:\WINDOWS\system32\drivers\sfvfs02.sys
    3S SLIP (BDA Slip De-Framer) - C:\WINDOWS\system32\drivers\slip.sys
    3R smwdm - C:\WINDOWS\system32\drivers\smwdm.sys
    0R sptd - C:\WINDOWS\system32\drivers\sptd.sys
    3S STEAMDVR - D:\Steam\bin\x86\SteamDvr.sys (not found)
    3S streamip (BDA IPSink) - C:\WINDOWS\system32\drivers\streamip.sys
    3S TIEHDUSB - C:\WINDOWS\system32\drivers\tiehdusb.sys
    3R usbccgp (Microsoft generiek hoofd-USB-stuurprogramma) - C:\WINDOWS\system32\drivers\usbccgp.sys
    3R usbehci (Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) - C:\WINDOWS\system32\drivers\usbehci.sys
    3S usbprint (Microsoft USB PRINTER Class) - C:\WINDOWS\system32\drivers\usbprint.sys
    3S usbscan (Stuurprogramma voor USB-scanner) - C:\WINDOWS\system32\drivers\usbscan.sys
    3R USBSTOR (Stuurprogramma voor USB-massaopslag) - C:\WINDOWS\system32\drivers\usbstor.sys
    0R Vax347b - C:\WINDOWS\system32\drivers\Vax347b.sys
    0R Vax347s - C:\WINDOWS\system32\drivers\Vax347s.sys
    3R WmBEnum (Logitech Virtual Bus Enumerator Driver) - C:\WINDOWS\system32\drivers\WmBEnum.sys
    3S WmFilter (Logitech WingMan HID Filter Driver) - C:\WINDOWS\system32\drivers\WmFilter.sys
    3S WmHidLo (Logitech WingMan USB Filter Driver) - C:\WINDOWS\system32\drivers\WmHidLo.sys
    3S WmVirHid (Logitech Virtual Hid Device Driver) - C:\WINDOWS\system32\drivers\WmVirHid.sys
    3R WmXlCore (Logitech WingMan Translation Layer Driver) - C:\WINDOWS\system32\drivers\WmXlCore.sys
    1R WS2IFSL (Windows Socket 2.0 Non-IFS-omgeving voor serviceproviderondersteuning) - C:\WINDOWS\system32\drivers\ws2ifsl.sys
    3S WSTCODEC (World Standard Teletext Codec) - C:\WINDOWS\system32\drivers\wstcodec.sys
    3S WudfPf (Windows Driver Foundation - User-mode Driver Framework Platform Driver) - C:\WINDOWS\system32\drivers\WudfPf.sys
    3S WudfRd (Windows Driver Foundation - User-mode Driver Framework Reflector) - C:\WINDOWS\system32\drivers\WudfRd.sys

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    3S Adobe LM Service - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
    3S aspnet_state (ASP.NET State Service) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    2R Ati HotKey Poller - C:\WINDOWS\system32\Ati2evxx.exe
    2S ATI Smart - C:\WINDOWS\system32\ati2sgag.exe
    2R Avg7Alrt (AVG7 Alert Manager Server) - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    2R Avg7UpdSvc (AVG7 Update Service) - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    2R BthServ (Bluetooth Support Service) - C:\WINDOWS\system32\svchost.exe -k bthsvcs
    3S clr_optimization_v2.0.50727_32 (.NET Runtime Optimization Service v2.0.50727_X86) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    3S CRKKUBHO - D:\DOCUME~1\jurre\LOCALS~1\Temp\CRKKUBHO.exe
    2S Fax - C:\WINDOWS\system32\fxssvc.exe
    3S IDriverT (InstallDriver Table Manager) - "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"
    3S iPod Service - "C:\Program Files\iPod\bin\iPodService.exe"
    2R LightScribeService (LightScribeService Direct Disc Labeling Service) - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
    2R Pml Driver HPZ12 - C:\WINDOWS\system32\HPZipm12.exe
    3S SandraDataSrv (Sandra Data Service) - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
    3S SandraTheSrv (Sandra Service) - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
    3S SDhelper (PC Tools Spyware Doctor) - D:\Program Files\Spyware Doctor\sdhelp.exe
    2R SoundMAX Agent Service (default) (SoundMAX Agent Service) - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    2R StarWindService (StarWind iSCSI Service) - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    3S svcWRSSSDK (Webroot Spy Sweeper Engine) - D:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    2R UserAccess7 (SecuROM User Access Service (V7)) - C:\WINDOWS\system32\UAService7.exe
    3R usnsvc (Messenger Sharing USN Journal Reader service) - C:\WINDOWS\system32\svchost.exe -k usnsvc
    3S usprserv (User Privilege Service) - C:\WINDOWS\System32\svchost.exe -k netsvcs

    -- Scheduled Tasks
    2007-02-19 21:40:29 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job<APPLES~1.JOB>

    -- Files created between 2007-02-28 and 2007-03-29
    2007-03-29 08:36:53 0 d
    D:\ComboScan<COMBOS~1>
    2007-03-27 18:37:22 0 dr-h
    D:\Documenten en Settings\LocalService\Onlangs geopend<ONLANG~1>
    2007-03-26 11:41:13 0 d
    C:\Program Files\Common Files\Adobe
    2007-03-25 21:00:35 0 d
    C:\WINDOWS\ie7updates<IE7UPD~1>
    2007-03-24 23:38:36 2916352
    n--- C:\WINDOWS\UNNMP.exe
    2007-03-24 23:35:41 0 d
    C:\Program Files\Common Files\Nero
    2007-03-24 23:34:48 2969600
    n--- C:\WINDOWS\UNNeroVision.exe<UNNERO~1.EXE>
    2007-03-24 23:21:29 0 d
    C:\Program Files\nero
    2007-03-24 23:21:28 0 d
    D:\Documenten en Settings\All Users\Application Data\Ahead
    2007-03-24 23:21:28 364544
    n--- C:\WINDOWS\system32\TwnLib4.dll
    2007-03-24 23:21:26 38912
    n--- C:\WINDOWS\system32\picn20.dll
    2007-03-19 18:53:28 0 d
    D:\ATI
    2007-03-19 17:14:15 0 d
    D:\Documenten en Settings\All Users\Application Data\POP3Profiles<POP3PR~1>
    2007-03-19 16:49:27 0 d
    D:\Documenten en Settings\All Users\Application Data\POPWWPROFILES<POPWWP~1>
    2007-03-18 20:40:04 0 d
    C:\WINDOWS\WBEM
    2007-03-18 20:39:57 0 d
    C:\WINDOWS\system32\nl-nl
    2007-03-18 20:38:47 0 d--h---c- C:\WINDOWS\ie7
    2007-03-18 20:35:33 121856
    n--- C:\WINDOWS\system32\xmllite.dll
    2007-03-18 20:34:19 0 d
    C:\WINDOWS\network diagnostic<NETWOR~1>
    2007-03-18 20:14:26 0 d
    D:\Documenten en Settings\jurre\Application Data\InstallShield Installation Information<INSTAL~2>
    2007-03-18 17:35:01 0 d
    D:\Documenten en Settings\aafke\Application Data\AVG7
    2007-03-18 15:09:46 0 d
    D:\Documenten en Settings\jurre\Application Data\AVG7
    2007-03-18 15:09:17 0 d
    D:\Documenten en Settings\LocalService\Application Data\AVG7
    2007-03-18 15:09:14 19392 --a
    C:\WINDOWS\system32\drivers\avgmfx86.sys
    2007-03-18 15:09:14 3968 --a
    C:\WINDOWS\system32\drivers\avgclean.sys
    2007-03-18 15:09:13 27776 --a
    C:\WINDOWS\system32\drivers\avg7rsxp.sys
    2007-03-18 15:09:13 4224 --a
    C:\WINDOWS\system32\drivers\avg7rsw.sys
    2007-03-18 15:09:12 775680 --a
    C:\WINDOWS\system32\drivers\avg7core.sys
    2007-03-18 15:09:07 0 d
    D:\Documenten en Settings\All Users\Application Data\Grisoft
    2007-03-18 14:19:49 0 d
    D:\Documenten en Settings\All Users\Application Data\Avg7
    2007-03-09 00:26:52 12 --a
    C:\WINDOWS\bthservsdp.dat<BTHSER~1.DAT>
    2007-03-08 16:47:17 8192 --a
    C:\WINDOWS\system32\wshirda.dll
    2007-03-08 16:47:17 28160 --a
    C:\WINDOWS\system32\irmon.dll
    2007-03-08 16:47:17 154112 --a
    C:\WINDOWS\system32\irftp.exe
    2007-03-02 14:37:14 5248 --a
    C:\WINDOWS\system32\drivers\Vax347s.sys
    2007-03-02 14:37:14 159616 --a
    C:\WINDOWS\system32\drivers\Vax347b.sys

    -- Find3M Report
    2007-03-29 08:25:10 0 d
    C:\Program Files\Mozilla Firefox<MOZILL~1>
    2007-03-27 22:34:15 0 d
    D:\Documenten en Settings\jurre\Application Data\Skype
    2007-03-27 22:26:45 0 d
    D:\Documenten en Settings\jurre\Application Data\Hamachi
    2007-03-27 21:05:25 0 d
    C:\Program Files\HP
    2007-03-27 20:20:06 47600 --a
    D:\Documenten en Settings\jurre\Application Data\GDIPFONTCACHEV1.DAT<GDIPFO~1.DAT>
    2007-03-25 21:16:33 468186 --a
    C:\WINDOWS\system32\perfh013.dat
    2007-03-25 21:16:33 82706 --a
    C:\WINDOWS\system32\perfc013.dat
    2007-03-25 14:50:21 0 d
    D:\Documenten en Settings\jurre\Application Data\Xfire
    2007-03-23 16:16:16 0 d
    C:\Program Files\Common Files\svchostsys<SVCHOS~1>
    2007-03-19 19:33:50 7804 --a
    C:\WINDOWS\system32\d3d9caps.dat
    2007-03-19 17:08:12 0 d--h
    C:\Program Files\InstallShield Installation Information<INSTAL~1>
    2007-03-18 21:29:53 0 d
    D:\Documenten en Settings\jurre\Application Data\My Games<MYGAME~1>
    2007-03-18 14:28:44 0 d
    D:\Documenten en Settings\jurre\Application Data\Azureus
    2007-03-18 14:24:09 0 d
    C:\Program Files\Hitman Pro<HITMAN~1>
    2007-03-18 14:23:17 0 d
    C:\Program Files\McAfee
    2007-03-04 20:56:58 0 d
    C:\Program Files\Windows Live Safety Center<WIE5D0~1>
    2007-02-23 17:45:31 0 d
    D:\Documenten en Settings\jurre\Application Data\Real
    2007-02-11 15:40:53 3733 --a----c- C:\WINDOWS\eReg.dat
    2007-02-11 15:38:45 737280 --a
    C:\WINDOWS\iun6002.exe
    2007-02-02 22:17:00 307200 --a
    C:\WINDOWS\system32\atiiiexx.dll
    2007-02-02 22:04:44 307200 --a
    C:\WINDOWS\system32\ATIDEMGX.dll
    2007-02-02 22:03:43 264704 --a
    C:\WINDOWS\system32\ati2dvag.dll
    2007-02-02 21:57:08 118784 --a
    C:\WINDOWS\system32\atipdlxx.dll
    2007-02-02 21:56:56 110592 --a
    C:\WINDOWS\system32\Oemdspif.dll
    2007-02-02 21:56:48 26112 --a
    C:\WINDOWS\system32\Ati2mdxx.exe
    2007-02-02 21:56:41 42496 --a
    C:\WINDOWS\system32\ati2edxx.dll
    2007-02-02 21:56:29 110592 --a
    C:\WINDOWS\system32\ati2evxx.dll
    2007-02-02 21:55:08 446464 --a
    C:\WINDOWS\system32\ati2evxx.exe
    2007-02-02 21:54:20 53248 --a
    C:\WINDOWS\system32\ATIDDC.DLL
    2007-02-02 21:46:45 2827968 --a
    C:\WINDOWS\system32\ati3duag.dll
    2007-02-02 21:40:29 1272960 --a
    C:\WINDOWS\system32\ativvaxx.dll
    2007-02-02 21:40:11 3107788 --a
    C:\WINDOWS\system32\ativvaxx.dat
    2007-02-02 21:27:17 241664 --a
    C:\WINDOWS\system32\atikvmag.dll
    2007-02-02 21:25:54 17408 --a
    C:\WINDOWS\system32\atitvo32.dll
    2007-02-02 21:20:28 348160 --a
    C:\WINDOWS\system32\ati2cqag.dll
    2007-02-02 21:19:49 5312512 --a
    C:\WINDOWS\system32\atioglxx.dll
    2007-02-02 19:34:00 520192
    n--- C:\WINDOWS\system32\ati2sgag.exe
    2007-01-30 18:21:34 128813 --a
    C:\WINDOWS\system32\atiicdxx.dat
    2007-01-29 10:58:06 60416
    n--- C:\WINDOWS\system32\tzchange.exe
    2007-01-12 10:27:42 232960 --a
    C:\WINDOWS\system32\webcheck.dll
    2007-01-12 10:27:42 51712
    n--- C:\WINDOWS\system32\msfeedsbs.dll<MSFEED~1.DLL>
    2007-01-12 10:27:42 458752
    n--- C:\WINDOWS\system32\msfeeds.dll
    2007-01-12 10:27:42 6054400 --a
    C:\WINDOWS\system32\ieframe.dll
    2007-01-08 20:04:54 105984 --a
    C:\WINDOWS\system32\url.dll
    2007-01-08 20:04:08 102400 --a
    C:\WINDOWS\system32\occache.dll
    2007-01-08 20:02:04 266752 --a
    C:\WINDOWS\system32\iertutil.dll
    2007-01-08 20:02:04 44544 --a
    C:\WINDOWS\system32\iernonce.dll
    2007-01-08 20:02:02 384000 --a
    C:\WINDOWS\system32\iedkcs32.dll
    2007-01-08 20:02:02 383488
    n--- C:\WINDOWS\system32\ieapfltr.dll
    2007-01-08 20:02:02 161792 --a
    C:\WINDOWS\system32\ieakui.dll
    2007-01-08 20:02:02 230400 --a
    C:\WINDOWS\system32\ieaksie.dll
    2007-01-08 20:02:02 153088 --a
    C:\WINDOWS\system32\ieakeng.dll
    2007-01-08 20:01:14 17408 --a
    C:\WINDOWS\system32\corpol.dll
    2007-01-08 20:00:48 124928 --a
    C:\WINDOWS\system32\advpack.dll
    2007-01-08 19:08:14 56832 --a
    C:\WINDOWS\system32\ie4uinit.exe
    2007-01-08 19:08:10 13824 --a
    C:\WINDOWS\system32\ieudinit.exe

    -- Registry Dump

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "Steam"=""
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "MessengerPlus3"="\"D:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AutorunsDisabled]
    "Skype"="\"D:\\Program Files\\Skype\\Skype.exe\" /nosplash /minimized"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
    "MS"="adwareremover.exe"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smtray.exe"
    "CleanRegPath"="C:\\Program Files\\ADSLModemUtility(AnnexA)\\CleanReg.exe"
    "MessengerPlus3"="\"D:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
    "BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
    "AVG7_CC"="D:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
    "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\AutorunsDisabled]
    "HotKey"="C:\\WINDOWS\\Twain_32\\FlatBed\\HotKey.exe"
    "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
    "PE2CKFNT SE"="C:\\Program Files\\Ulead Systems\\Ulead Photo Express 2 SE\\ChkFont.exe"
    "QuickTime Task"="\"D:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "SaiSmart"="C:\\Program Files\\Saitek\\Software\\SaiSmart.exe"
    "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
    "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
    "HP Software Update"="D:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
    "PVR Agent"="D:\\Program Files\\ZOLID Multimedia\\PVR Plus\\TVR\\Scheduled.exe"
    "Profiler"="C:\\Program Files\\Saitek\\Software\\Profiler.exe"
    "DAEMON Tools"="\"D:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
    "Installed"="1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
    "Installed"="1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
    "MS"="adwareremover.exe"

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "wuwr"="C:\\PROGRA~1\\COMMON~1\\wuwr\\wuwrm.exe"
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
    "Spyware Doctor"=""
    "AVG7_Run"="D:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
    [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "wuwr"="C:\\PROGRA~1\\COMMON~1\\wuwr\\wuwrm.exe"
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
    "Spyware Doctor"=""
    "AVG7_Run"="D:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=dword:00000000
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "AllowLegacyWebView"=dword:00000001
    "AllowUnhashedWebView"=dword:00000001
    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
    Source REG_SZ
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
    Usnsvc REG_MULTI_SZ usnsvc\0\0
    bthsvcs REG_MULTI_SZ BthServ\0\0

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
    Shell\AutoRun\command E:\autorun.exe
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{13ebb77a-9563-11d9-82cb-000c6e0ae70e}]
    Shell\AutoRun\command F:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6cb971b7-c8bb-11db-9dbd-000c6e0ae70e}]
    Shell\AutoRun\command F:\Setup\rsrc\Autorun.exe
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6cb971b8-c8bb-11db-9dbd-000c6e0ae70e}]
    Shell\AutoRun\command G:\Setup\rsrc\Autorun.exe

    -- End of ComboScan: finished at 2007-03-29 at 08:37:36
  • edited March 2007
    And Supplementary

    ComboScan v20070306.20 run by jurre on 2007-03-29 at 08:36:53
    Supplementary logfile - please post this as an attachment with your post.
    -- System Information
    Microsoft Windows XP Home Edition (build 2600) SP 2.0
    Architecture: X86; Language: Dutch
    CPU 0: Intel(R) Pentium(R) 4 CPU 2.40GHz
    Percentage of Memory in Use: 43%
    Physical Memory (total/avail): 1023.47 MiB / 579.47 MiB
    Pagefile Memory (total/avail): 1696.14 MiB / 1457.81 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1994.28 MiB
    A: is Removable (No Media)
    C: is Fixed (NTFS) - 9.28 GiB total, 1.74 GiB free.
    D: is Fixed (NTFS) - 103.74 GiB total, 26.14 GiB free.
    E: is CDROM (No Media)
    K: is Fixed (FAT32) - 372.52 GiB total, 126.15 GiB free.
    L: is CDROM (CDFS)
    M: is CDROM (No Media)
    N: is CDROM (No Media)
    O: is CDROM (No Media)
    P: is CDROM (No Media)
    Q: is CDROM (No Media)

    -- Security Center
    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is enabled.
    AV: AVG 7.5.446 v7.5.446 (GRISOFT)
    AV: NOD32 antivirus systeem 2.51 v2.51 (Eset) Disabled Outdated

    -- Environment Variables
    ALLUSERSPROFILE=D:\Documenten en Settings\All Users
    APPDATA=D:\Documenten en Settings\jurre\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=KRAMER
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=D:
    HOMEPATH=\Documenten en Settings\jurre
    LOGONSERVER=\\KRAMER
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adobe\AGL;D:\Program Files\QuickTime\QTSystem\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 7, GenuineIntel
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=0207
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=D:\DOCUME~1\jurre\LOCALS~1\Temp
    TMP=D:\DOCUME~1\jurre\LOCALS~1\Temp
    USERDOMAIN=KRAMER
    USERNAME=jurre
    USERPROFILE=D:\Documenten en Settings\jurre
    windir=C:\WINDOWS
    __COMPAT_LAYER=EnableNXShowUI

    -- User Profiles
    aafke (admin)
    jurre (admin)
    Gast (guest)

    -- Add/Remove Programs
    --> C:\Program Files\nero\nero\nero\uninstall\UNNERO.exe /UNINSTALL
    --> C:\WINDOWS\IsUn0413.exe -fC:\WINDOWS\orun32.isu
    --> C:\WINDOWS\IsUninst.exe -f"d:\program files\games\Battlezone 2\BZII.isu"
    --> C:\WINDOWS\IsUninst.exe -f"D:\Program Files\Vampire The Masquerade - Redemption\Vampire.isu"
    --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    --> C:\WINDOWS\UNNMP.exe /UNINSTALL
    --> MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    3ivx D4 4.5.1 (remove only) --> "C:\Program Files\3ivx\3ivx D4 4.5.1\uninstall.exe"
    ABBYY FineReader 5.0 Sprint --> MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
    AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
    ACD/Labs Software 5 (D:\ACDFREE5) --> D:\ACDFREE5\UN_INFO\1\_setup.exe
    Ad-Aware SE Personal --> D:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE D:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
    Adobe Bridge 1.0 --> MsiExec.exe /I{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}
    Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}
    Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
    Adobe Help Center 2.0 --> MsiExec.exe /I{8FFC924C-ED06-44CB-8867-3CA778ECE903}
    Adobe Illustrator CS2 --> msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}
    Adobe InDesign CS2 --> msiexec /I{7F4C8163-F259-49A0-A018-2857A90578BC}
    Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
    Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
    Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1437-443D-B06E-79A00FE45110}
    Adobe SVG Viewer 3.0 --> C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
    ADSL Modem Utility (Annex A) --> C:\WINDOWS\uninst.exe -f"C:\Program Files\ADSLModemUtility(AnnexA)\DeIsL1.isu" -c"C:\Program Files\ADSLModemUtility(AnnexA)\_ISREG32.DLL"
    Age of Empires III --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}
    Alexander --> K:\Games\Ubisoft\GSC Game World\Alexander\uninstall.exe
    Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
    ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Atomic Clock Sync --> D:\PROGRA~1\ATOMIC~1\UNWISE.EXE D:\PROGRA~1\ATOMIC~1\INSTALL.LOG
    AVG 7.5 --> D:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
    Battlefield 2142 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ED50ECE9-EC54-4C05-B5ED-EE4741A9F2EC}\setup.exe" -l0x13 -removeonly
    Battlefield Vietnam(TM) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E35B3C63-E958-4E31-A178-95D22024109A}\setup.exe" -l0x9
    Beveiligingsupdate voor Windows XP (KB883939) --> "C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB890046) --> "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB893756) --> "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896358) --> "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896422) --> "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896423) --> "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896424) --> "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896428) --> "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB896688) --> "C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB899587) --> "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB899588) --> "C:\WINDOWS\$NtUninstallKB899588$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB899591) --> "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB900725) --> "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB901017) --> "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB901214) --> "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB902400) --> "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB903235) --> "C:\WINDOWS\$NtUninstallKB903235$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB904706) --> "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB905414) --> "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB905749) --> "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB905915) --> "C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB908519) --> "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB908531) --> "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB911280) --> "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB911562) --> "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB911567) --> "C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB911927) --> "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB912812) --> "C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB912919) --> "C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB913446) --> "C:\WINDOWS\$NtUninstallKB913446$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB913580) --> "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB914388) --> "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB914389) --> "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB916281) --> "C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB917159) --> "C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB917344) --> "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB917422) --> "C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB917953) --> "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB918118) --> "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB918439) --> "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB918899) --> "C:\WINDOWS\$NtUninstallKB918899$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB919007) --> "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB920213) --> "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB920214) --> "C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB920670) --> "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB920683) --> "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB920685) --> "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB921398) --> "C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB921883) --> "C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB922616) --> "C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB922760) --> "C:\WINDOWS\$NtUninstallKB922760$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB922819) --> "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB923191) --> "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB923414) --> "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB923694) --> "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB923980) --> "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB924191) --> "C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB924270) --> "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB924496) --> "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB924667) --> "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB925454) --> "C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB925486) --> "C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB926255) --> "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB926436) --> "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB927779) --> "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB927802) --> "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB928090) --> "C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB928255) --> "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
    Beveiligingsupdate voor Windows XP (KB928843) --> "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
    BFVCC Server Manager --> C:\WINDOWS\iun6002.exe "K:\Games\BF\irunin.ini"
    Cabri-géomètre II --> MsiExec.exe /X{8DB1FFAC-6F84-4616-A46D-F0D244D67257}
    CDBurnerXP Pro 3 --> MsiExec.exe /I{896D642C-7125-44F0-AC49-A23ABF82209C}
    CEP - Color Enable Package --> "C:\WINDOWS\unins000.exe"
    Coach 5 Thuis --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{FC6A7512-8D70-4385-AB76-0DA49A08217A}
    Command & Conquer 3 Tiberium Wars™ Demo --> MsiExec.exe /I{39F7653F-3E82-4FED-9EE5-6B9253EA57E3}
    Company of Heroes --> MsiExec.exe /X{66F78C51-D108-4F0C-A93C-1CBE74CE338F}
    Counter-Strike: Source --> MsiExec.exe /I{9580813D-94B1-4C28-9426-A441E2BB29A5}
    Dark Messiah --> C:\Program Files\InstallShield Installation Information\{A8E2EF8F-73EF-4DD8-BB38-31FCCAF50103}\setup.exe -runfromtemp -l0x0009 -removeonly
    De Geo 2 havo/vwo --> D:\PROGRA~1\THIEME~1\DeGeo\vmbo-hv\UNWISE.EXE D:\PROGRA~1\THIEME~1\DeGeo\vmbo-hv\INSTALL.LOG
    De Sims 2 --> D:\Program Files\Games\Sims2\EAUninstall.exe
    De Sims 2 Gaan het Maken --> D:\Program Files\Games\Sims2 ghm\EAUninstall.exe
    De Sims 2 HomeCrafter Plus --> D:\Program Files\EA GAMES\De Sims 2 HomeCrafter Plus\EAUninstall.exe
    De Sims 2 Nachtleven --> D:\Program Files\Games\Sims2 nl\EAUninstall.exe
    De Sims 2 Studentenleven --> D:\Program Files\Games\Sims2 stl\EAUninstall.exe
    DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    DivX Player --> D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    Doorzien --> C:\WINDOWS\uninst.exe -f"D:\Program Files\EPN\Doorzien\DeIsL1.isu"
    Dungeon Siege --> "K:\Games\Dungeon Siege\UNINSTAL.EXE" /runtemp /addremove
    DVD Shrink 3.2 --> "D:\Program Files\DVD Shrink\unins000.exe"
    EA SPORTS online 2007 --> D:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
    EA.com Matchup --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F173C40-563E-11D4-89C5-0010ADDAAC33}\setup.exe" -l0x0 Uninstall
    EA.com Update --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB97F52-512B-43EF-AAEC-4825C17B32ED}\setup.exe" -l0x0 Uninstall
    Easy CD and DVD Cover Creator 4.11 --> D:\Program Files\Easy CD & DVD Cover Creator\uninst.exe
    EasyDvd --> C:\WINDOWS\st6unst.exe -n "D:\ST6UNST.LOG"
    EasyDvd (D:\) --> C:\WINDOWS\st6unst.exe -n "D:\ST6UNST.000"
    Eminem --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E0009377-9F59-40FB-83E0-0F74E83039F4}\Setup.exe" -l0x9
    EPN werkboek-i Getal en Ruimte/3 vwo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6911A8D8-E249-45AB-BF06-D894F2DC783C}\setup.exe" -l0x13 UNINSTALL
    EPN werkboek-i Getal en Ruimte/vwo B1,2 deel 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{81BD019E-833C-4DE0-B124-EB8E29018F1B}\setup.exe" -l0x13 UNINSTALL
    Eragon --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{322F75E0-71A3-4125-8EB3-761834EDC166}\setup.exe" -l0x9 -removeonly
    FIFA 07 --> D:\Program Files\EA SPORTS\FIFA 07\EAUninstall.exe
    File Recover 6.1 --> "D:\Program Files\File Recover\unins000.exe"
    Francesco's leveled creatures-items mod 4.1 --> "K:\Games\Oblivion\data\Francesco's mod\Unistall data\Main files\unins000.exe"
    Freecom Backup Software 1.15 --> "D:\Program Files\Freecom Backup Software\unins000.exe"
    GameShadow --> MsiExec.exe /I{F7C1C17E-70E3-475F-BD52-EA554391F15D}
    GameSpy 3D --> C:\Program Files\GameSpy\uninstall.exe
    GameSpy Arcade --> D:\GAMESP~1\UNWISE.EXE D:\GAMESP~1\INSTALL.LOG
    GdiplusUpgrade --> MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}
    Getal en Grafiek XP --> MsiExec.exe /I{FDD6791E-9D46-40F5-A2FD-6A3C2CF70C84}
    Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
    GrabIt 1.6.2 Beta (build 940) --> "D:\Program Files\GrabIt\unins000.exe"
    GSpot Codec Information Appliance --> D:\Program Files\GSpot\Uninstall.exe
    GTA San Andreas --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
    GtkRadiant-1.3.8-ET --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{36BC3F0C-8777-4DB2-B2F4-7FA5250F34BA}\Setup.exe"
    Guild Wars --> "D:\Program Files\Guild Wars\Gw.exe" -uninstall
    GUN (TM) --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{2DFF2906-52BB-4222-8062-1509259FC013} /l2057
    Half-Life(R) 2 --> MsiExec.exe /I{D45EC259-4A19-4656-B588-C2C360DD18EA}
    Half-Life: Counter-Strike --> D:\Sierra\COUNTE~1\UNWISE.EXE D:\Sierra\COUNTE~1\INSTALL.LOG
    HijackThis 1.99.1 --> D:\Documenten en Settings\jurre\Bureaublad\Corné\HijackThis.exe /uninstall
    Hitman Blood Money --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}\setup.exe" -l0x9 -removeonly
    Hitman Pro --> "D:\Program Files\Hitman Pro\unins000.exe"
    Hotfix voor Windows XP (KB914440) --> "C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
    HP Document Viewer 5.3 --> D:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
    HP Extended Capabilities 5.3 --> D:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
    HP Image Zone 5.3 --> D:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
    HP Imaging Device Functions 5.3 --> D:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
    HP PSC & OfficeJet 5.3.B --> "D:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
    HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
    HP Solution Center & Imaging Support Tools 5.3 --> D:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
    HydraVision --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
    ijji - Gunz --> K:\Games\Gunz\Uninstall.exe
    ImageForge version 3.60 --> "D:\Program Files\ImageForge3\unins000.exe"
    Intel Application Accelerator --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9984DF60-1C5B-11D3-ACA1-908A4FC10801}\Setup.exe" -INTELUNINST
    InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
    IpWins --> C:\Program Files\ipwins\Uninst.exe
    iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
    J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
    JAM KT v3 --> C:\WINDOWS\system32\JAMktSetup_uninstall.exe uninstall
    Jasc Paint Shop Pro 9 --> MsiExec.exe /I{F843C6A3-224D-4615-94F8-3C461BD9AEA0}
    Java 2 Runtime Environment, SE v1.4.2_01 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142010}
    KB898458: Beveiligingsupdate voor Step by Step Interactive Training --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
    KB923723: Beveiligingsupdate voor Step by Step Interactive Training --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
    Kumiko Manor 2.15 --> K:\Games\Oblivion\Data\UninstalKumikoManor.exe
    Light Alloy 3.0 --> C:\Program Files\Light Alloy\Uninstall.exe
    Logitech Gaming Software --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9242864-2841-4ADE-86E0-8F90F91B04DD}\setup.exe" -l0x13
    Maatschappijleer 2005-2006 --> MsiExec.exe /X{5157CDD3-D836-41D9-8AB2-A8307CFFF4E0}
    Macromedia Flash Player 8 --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe
    Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
    MeMo Leerlingen-cd-rom deel 1 --> D:\PROGRA~1\Malmberg\MeMo1\UNWISE32.EXE D:\PROGRA~1\Malmberg\MeMo1\install.log "Verwijderen MeMo Leerlingen-cd-rom deel 1"
    Messenger Plus! 3 --> "D:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
    Microsoft Chat 2.5 --> RunDll32 advpack.dll,LaunchINFSection CChat25.inf, CChatUninstall.NT
    Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
    Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
    Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
    Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348) --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
    Monopoly --> C:\WINDOWS\IsUn0413.exe -f"C:\Program Files\Hasbro Interactive\Monopoly\Uninst.isu"
    Mozilla (1.7.12) --> C:\WINDOWS\MozillaUninstall.exe /ua "1.7.12 (en)"
    Mozilla Firefox (1.5.0.10) --> C:\Program Files\Mozilla Firefox\uninstall\uninstall.exe /ua "1.5.0.10 (nl)"
    MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
    My Global Search Bar --> rundll32 C:\PROGRA~1\MYGLOB~1\bar\1.bin\mgsBar.dll,O
    MyPhoneExplorer --> D:\Program Files\MyPhoneExplorer\uninstall.exe
    Nero Suite --> C:\Program Files\Common Files\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
    NVIDIA Photoshop Plug-ins --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{23F79416-CAD1-41BF-99A3-040F6C814AAA}\Setup.exe" -l0x9
    Oblivion --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
    Oblivion - Construction Set --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{23D683DD-93C6-48E6-B84E-78B57778F126}\setup.exe" -l0x9 -removeonly
    Oblivion - Horse Armor Pack --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3ABEBD00-299D-4DCA-967F-B912163AB5EA}\setup.exe" -l0x9 -removeonly
    Oblivion - Knights of the Nine --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14C87AA7-08E6-419F-A165-998EBE5023D7}\setup.exe" -l0x9 -removeonly
    Oblivion - Orrery --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EC425CFC-EE78-4A91-AA25-3BFA65B75364}\setup.exe" -l0x9 -removeonly
    Oblivion - Thieves Den --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FFFFFD17-B460-41EB-93F1-C48ABAD63828}\setup.exe" -l0x9 -removeonly
    Oblivion - Wizard's Tower --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F2E3D62-8B8C-448F-8900-451325E50948}\setup.exe" -l0x9 -removeonly
    Oblivion mod manager 0.9.14 --> "K:\Games\Oblivion\obmm\uninstall\unins000.exe"
    Ots CD Scratch 1200 1.0.14 --> "C:\WINDOWS\OTS_UI.EXE" "C:\OtsLabs\OTSCDS.osi"
    PCFriendly --> D:\Program Files\PCFriendly\inuninst.exe
    Pivot Stickfigure Animator --> MsiExec.exe /I{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}
    PKR --> "D:\Program Files\PKR\uninstall-pkr.exe"
    Planet Poker --> K:\GAMES\PLANET~1\UNWISE.EXE K:\GAMES\PLANET~1\INSTALL.LOG
    PlayLinc --> MsiExec.exe /I{2158685C-E2B3-4026-B0A1-0FFE31837AFD}
    POD-Bot 2.5 --> C:\WINDOWS\unvise32.exe D:\Sierra\Half-Life\cstrike\poduninst.log
    Poker Toolbar --> regsvr32 /u /s "C:\Program Files\Poker Toolbar\PokerTB.dll"
    PokerNEWS Toolbar --> regsvr32 /u /s "C:\Program Files\PokerNEWS Toolbar\untitled.dll"
    PopCap Browser Plugin --> C:\Program Files\PopCap Games\PopCap Browser Plugin\Uninstall.exe
    Populous: The Beginning --> C:\WINDOWS\IsUn0413.exe -f"D:\Program Files\Bullfrog\Populous\Uninst.isu" -c"D:\Program Files\Bullfrog\Populous\uninst.dll"
    PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
    Praetorians --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAC8AF92-DAEC-45D2-B77D-36699E3751A9}\Setup.exe"
    Prince of Persia T2T --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}\setup.exe" -l0x9 -removeonly
    Prince of Persia The Sands of Time --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8C453F13-6877-4D34-8816-009ABDE306DB}\setup.exe" -l0x9
    Prince of Persia Warrior Within --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE5BC0BB-9EDA-423C-8276-48857B735D68}\Setup.exe" -l0x13
    Pringles Football Screen Saver --> C:\WINDOWS\system32\Pringles Football.scr /u
    Pro Evolution Soccer 6 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1033
    PunkBuster for Battlefield Vietnam --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D07643A3-CE41-4286-8C78-EB9C83E76DDB}\setup.exe" -l0x9
    PVR Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B893587-00A8-4A4E-83F0-8AFA7BFC7C1A}\Setup.exe" -l0x13
    QuickPar 0.9 --> D:\Program Files\QuickPar\uninst.exe
    QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
    Rise and Fall --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D078226E-83F2-45FD-9CDE-5DA66E5ADB51}\Setup.exe" -l0x9 -removeonly
    Rome Total War - patch 1.3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5D65411-8E73-4C85-AD80-9FE8B7391CF9}\Setup.exe" -l0x9
    RPM --> "D:\Program Files\Games\Soldier of Fortune II - Double Helix\RPM\uninstall_RPM.exe"
    RuneScape SideKick --> MsiExec.exe /I{FD84C4CE-A2B0-4C94-B0BB-9F81BB65D626}
    Shareaza versie 2.2.3.0 --> "D:\Program Files\Shareaza\Uninstall\unins000.exe"
    Shockwave --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    Sid Meier's Civilization 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "D:\Documenten en Settings\jurre\Application Data\InstallShield Installation Information\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}\setup.exe" -l0x9 -removeonly
    Sierra Utilities --> C:\Program Files\Sierra On-Line\sutil32.exe uninstall
    SimPE 0.58 (alpha) --> "D:\Program Files\SimPE\unins000.exe"
    SiSoftware Sandra Lite 2005.SR3 (Win64/32/CE) --> "C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\unins000.exe"
    Skype 3.0 --> "D:\Program Files\unins000.exe"
    Skype Plugin Manager --> MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
    Smartcam 350 Drivers --> C:\WINDOWS\ISUnMX.exe -fC:\UnKN0851.isu
    SmartCamera Ver 2.1 --> MsiExec.exe /X{9527450C-64B3-11D5-9B31-000021116B62}
    SmartFTP Client --> MsiExec.exe /I{11C762F9-95EA-486A-A8E7-683A50C231C1}
    Snowball Wars by OIN --> C:\Program Files\Snowball Wars\uninstaller.exe
    Sony Ericsson Bluetooth Remote Control 1.00 --> D:\Program Files\Sony Ericsson\Bluetooth Remote Control\Uninstall.exe
    Sony Ericsson Image Editor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05E9F134-07C9-4249-9B80-EE5D975F201B}\setup.exe" -l0x13 -l0013 --remove=y
    Sony Ericsson MMS Home Studio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9462C4AD-D6C4-4365-B4AD-BFE0B1E216C3}\setup.exe" -l0x13 -l0013 --remove=y
    Sony Ericsson PC Suite --> MsiExec.exe /I{C037D08B-4883-491D-9329-DC5ACA90F797}
    SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
    SpeechRedist --> MsiExec.exe /X{8795CBED-55E2-4693-9F14-84EC446935BE}
    Spy Sweeper --> "D:\Program Files\Webroot\Spy Sweeper\unins000.exe"
    Spyware Doctor 3.8 --> "D:\Program Files\Spyware Doctor\unins000.exe"
    SST Programming Software --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{03ADCA1C-BCF0-4B12-AFCF-8EBF2CB3AB07}\setup.exe" AddRem
    Star Wars JK II Jedi Outcast --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{576E71DA-3000-48F6-9B21-B9A70D47DFCF}\Setup.exe"
    Steam --> D:\Steam\UNWISE.EXE D:\Steam\INSTALL.LOG
    Sudoku --> "C:\Program Files\Common Files\MimarSinan\Installation Information\{FB5055E4-9BE1-425F-B40A-33E43E9460DA}\{C8A522A9-9CBA-4AD3-80E9-EE3DD9BCA3A2}\SudokuSetup.exe" REMOVE=TRUE MODIFY=FALSE
    Supreme Commander Demo --> C:\Program Files\InstallShield Installation Information\{25A1E6A4-2DBD-4AC0-8650-8EA9A45B1848}\setup.exe -runfromtemp -l0x0009 -removeonly
    Teach2000 8.11 --> "D:\Program Files\Teach2000\Uninstall\unins000.exe"
    Text Express Deluxe --> "C:\Program Files\Zylom Games\Text Express Deluxe\GameInstaller.exe" --uninstall UnInstall.log
    The Battle for Middle-earth(tm) --> K:\spellen\EAUninstall.exe
    The Sims Makin' Magic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A00D1BA-D03A-44E5-AF28-86A1F377DF61}\setup.exe" -l0009
    Theme Hospital --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Bullfrog\Hospital\DeIsL1.isu"
    Ulead COOL 360 1.0 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead COOL 360\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead COOL 360\IS32Inst.dll"
    Ulead Photo Explorer 6.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0194539-8118-4FD7-8ABA-912B2D479B48}\setup.exe"
    Ulead Photo Express 2.0 SE --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\IS32Inst.dll"
    Ulead Photo Express 4.0 SE --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBC0D330-C37B-4472-BFB9-AA217CF0C95F}\setup.exe"
    Unofficial Oblivion Patch v1.7.1 --> "K:\Games\Oblivion\Unofficial Oblivion Patch\unins000.exe"
    Unreal --> C:\WINDOWS\IsUninst.exe -fC:\Unreal\System\Uninst.isu
    Unreal Tournament 2004 --> L:\games\UT2004\System\Setup.exe uninstall "UT2004"
    Update voor Windows XP (KB894391) --> "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
    Update voor Windows XP (KB896727) --> "C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe"
    Update voor Windows XP (KB898461) --> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    Update voor Windows XP (KB900485) --> "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
    Update voor Windows XP (KB904942) --> "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
    Update voor Windows XP (KB910437) --> "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
    Update voor Windows XP (KB916595) --> "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
    Update voor Windows XP (KB920872) --> "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
    Update voor Windows XP (KB922582) --> "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
    Update voor Windows XP (KB929338) --> "C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
    Update voor Windows XP (KB931836) --> "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
    USB Scanner --> C:\WINDOWS\RunUnDrv.exe C:\WINDOWS\Twain_32\FlatBed\PmxScan.INF DefaultUnInstall.USB.NTX86
    Vampire - The Masquerade Bloodlines --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{08F8FD7C-44A5-4423-B87C-EBD3D94C9F87} /l1033 /x
    VobSub v2.23 (Remove Only) --> "D:\Program Files\Gabest\VobSub\uninstall.exe"
    VoroGlide --> MsiExec.exe /I{5BB15733-4B94-4B1D-9F65-B7DF18B8F9AC}
    VU Leerling Bovenbouw EPN --> MsiExec.exe /I{97A80FD4-8EEC-402F-ABFE-8D8A3ACDBE4E}
    VU Leerling Onderbouw EPN --> MsiExec.exe /I{D6E8FF6E-67A3-4A0C-AC48-BFCECFBF3D08}
    War of the Ring(tm) --> D:\Program Files\Games\Wotr\Setup.exe -u
    Winamp (remove only) --> "D:\Program Files\Winamp5\UninstWA.exe"
    Windows Defender Signatures --> MsiExec.exe /I{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}
    Windows Live Messenger --> MsiExec.exe /I{707EAB85-551E-4494-B4A5-DD99F5B6F369}
    Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    Wolters-Noordhoff digiTaal thuis --> C:\WINDOWS\IsUninst.exe -f"D:\Program Files\Wolters Noordhoff\Wolters-Noordhoff digiTaal thuis\Uninst.isu"
    WONswap --> C:\Program Files\WON\WONswap\WONswapUninstall.exe
    WordUp --> C:\WINDOWS\unvise32.exe d:\Program Files\Skunk Studios\WordUp\uninstal.log
    Xfire (remove only) --> "D:\Program Files\Xfire\uninst.exe"
    XviD Video Codec 04102002-1 (Koepi's build with EPSZ ME) --> "D:\Program Files\XviD\UninstXviD.exe"
    Yazzle by OIN --> "C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe"
    Zodiac Tower 1.01 --> C:\Program Files\Zodiac Tower\Uninstall.exe
    ZOLID TV713X WDM Drivers --> C:\WINDOWS\p3xunist.exe
    ZOLID VS-TV7134RF Teletext --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{70FDCCEE-E169-47DB-9D2A-2EF70377910E}\Setup.exe" -l0x9 -uninst
    ZOLID VS-TV7134RF Utilities --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{477AB148-138C-46D2-820B-0DBFA744CEE8}\Setup.exe" -l0x13 -uninst

    -- End of ComboScan: finished at 2007-03-29 at 08:37:36
  • edited March 2007
    Click on start, then control panel, and then double-click on add/remove programs. From within add/remove program uninstall the following if they exist by double-clicking on the following entries:

    My Global Search Bar
    Planet Poker ß unless you installed this knowingly
    PokerNEWS Toolbar ß unless you installed this knowingly
    Yazzle by OIN
    Messenger Plus! 3 ß It will ask you if you only want to un install the sponser programs choose yes if you want to keep messenger plus otherwise un install the whole program


    Restart your computer and post back a fresh HJT log and an uninstall list



    • Start HijackThis
    • Click on the Config button
    • Click on the Misc Tools button
    • Click on the Open Uninstall Manager button.
    • You can click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad into this topic please,



Sign In or Register to comment.