okay, here we go. I did the scans as requested. One remark however, I had to limit the Kaspersky-scan to the 2 hard discs on my computer, when I choose "my computer" it scans the network drives as well...
Report 1: dss notepad "Main.txt"
Deckard's System Scanner v20071014.68
Run by 306 on 2008-08-06 12:01:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
51: 2008-08-06 10:01:35 UTC - RP209 - Deckard's System Scanner Restore Point
50: 2008-08-06 08:14:28 UTC - RP208 - System Checkpoint
49: 2008-08-04 15:47:52 UTC - RP207 - Software Distribution Service 3.0
48: 2008-08-04 10:11:30 UTC - RP206 - System Checkpoint
47: 2008-07-11 06:07:25 UTC - RP205 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-07-04 12:47:23 UTC - RP159 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as 306.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:18, on 6/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
D:\Downloaded software\Deckards system scanner\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\306.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.be...html?channel=beR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.be...html?channel=beR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft....k/?LinkId=74005O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [EFI Job Monitor] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\efjm.dll,run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.t...ivex/hcImpl.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = FrisomatGroep.Lan
O17 - HKLM\Software\..\Telephony: DomainName = FrisomatGroep.Lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = FrisomatGroep.Lan
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 5462 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080707-095858-165 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.defaulthomepage.infobackup-20080707-095858-175 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896backup-20080707-095858-282 O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
backup-20080707-095858-307 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
backup-20080707-095858-353 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896backup-20080707-095858-442 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157backup-20080707-095858-488 O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
backup-20080707-095858-553 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080707-095858-559 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.be/ig/dell?hl=en&client=dell-row-rel&channel=be&ibd=1071023
backup-20080707-095858-567 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
backup-20080707-095858-617 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
backup-20080707-095858-639 O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
backup-20080707-095858-645 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.be...html?channel=bebackup-20080707-095858-720 O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
backup-20080707-095858-799 O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
backup-20080707-095858-865 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.be...html?channel=bebackup-20080707-095858-935 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
backup-20080707-095858-948 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.be/ig/dell?hl=en&client=dell-row-rel&channel=be&ibd=1071023
backup-20080707-095858-953 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.be...html?channel=bebackup-20080707-095859-112 O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
backup-20080707-095859-144 O8 - Extra context menu item: Geselecteerde koppelingen converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
backup-20080707-095859-157 O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
backup-20080707-095859-163 O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
backup-20080707-095859-230 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
backup-20080707-095859-250 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080707-095859-251 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20080707-095859-258 O4 - HKLM\..\RunOnce: [SpybotDeletingA3868] command /c del "C:\WINDOWS\system32\tuvsSIaA.dll_old"
backup-20080707-095859-335 O8 - Extra context menu item: Geselecteerde koppelingen converteren naar Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
backup-20080707-095859-341 O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
backup-20080707-095859-465 O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
backup-20080707-095859-497 O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
backup-20080707-095859-534 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20080707-095859-570 O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
backup-20080707-095859-577 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
backup-20080707-095859-630 O8 - Extra context menu item: Selectie converteren naar Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
backup-20080707-095859-658 O8 - Extra context menu item: Koppelingdoel converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
backup-20080707-095859-660 O4 - HKLM\..\RunOnce: [SpybotDeletingC1432] cmd /c del "C:\WINDOWS\system32\tuvsSIaA.dll_old"
backup-20080707-095859-719 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
backup-20080707-095859-720 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
backup-20080707-095859-726 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
backup-20080707-095859-793 O8 - Extra context menu item: Converteren naar Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
backup-20080707-095859-799 O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
backup-20080707-095859-842 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
backup-20080707-095859-855 O8 - Extra context menu item: Koppelingdoel converteren naar Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
backup-20080707-095859-865 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
backup-20080707-095859-879 O8 - Extra context menu item: Selectie converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
backup-20080707-095859-929 O8 - Extra context menu item: Converteren naar bestaand PDF-bestand - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
backup-20080707-095859-931 O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Downloaded software\Spybot\Spybot - Search & Destroy\TeaTimer.exe
backup-20080707-095903-845 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
backup-20080707-095905-897 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
backup-20080707-095906-199 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\DOWNLO~1\Spybot\SPYBOT~1\SDHelper.dll
backup-20080707-095908-957 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\DOWNLO~1\Spybot\SPYBOT~1\SDHelper.dll
backup-20080707-095909-571 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080707-095912-237 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080707-095913-269 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080707-095913-286 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080707-095913-540 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.m...ash/swflash.cabbackup-20080707-095915-191 O17 - HKLM\Software\..\Telephony: DomainName = FrisomatGroep.Lan
backup-20080707-095915-290 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = FrisomatGroep.Lan
backup-20080707-095915-319 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
backup-20080707-095915-363 O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
backup-20080707-095915-385 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
backup-20080707-095915-450 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20080707-095915-458 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = FrisomatGroep.Lan
backup-20080707-095915-485 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
backup-20080707-095915-487 O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
backup-20080707-095915-496 O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
backup-20080707-095915-657 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
backup-20080707-095915-758 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
backup-20080707-095915-842 O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
backup-20080707-095915-877 O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
backup-20080707-095916-279 O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
backup-20080707-095916-495 O23 - Service: NTRU TSS v1.2.1.12 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
backup-20080707-095916-773 O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 PBADRV - c:\windows\system32\drivers\pbadrv.sys <Not Verified; Dell Inc; Application Driver>
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.6.0.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.6.0.0>
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R3 DXEC01 - c:\windows\system32\drivers\dxec01.sys <Not Verified; Knowles Acoustics; DXEC.01 Speech Enhancement>
S4 vsdatant - a (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 RegSrvc (Intel® PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel® PROSet/Wireless Registry Service>
R2 STacSV (SigmaTel Audio Service) - c:\program files\sigmatel\c-major audio\wdm\stacsv.exe <Not Verified; SigmaTel, Inc.; C-Major Audio>
R2 WLANKEEPER (Intel® PROSet/Wireless SSO Service) - c:\program files\intel\wireless\bin\wlkeeper.exe <Not Verified; Intel® Corporation; SSO Service>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 NICCONFIGSVC - c:\program files\dell\quickset\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
S4 SecureStorageService - "c:\program files\wave systems corp\secure storage manager\securestorageservice.exe" <Not Verified; Wave Systems Corp.; Secure Storage Manager>
S4 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>
S4 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>
S4 tcsd_win32.exe (NTRU TSS v1.2.1.12 TCS) - "c:\program files\ntru cryptosystems\ntru tcg software stack\bin\tcsd_win32.exe"
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6234
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
-- Files created between 2008-07-06 and 2008-08-06 -----------------------------
2008-08-06 09:30:57 0 d-------- C:\Documents and Settings\306\Application Data\Malwarebytes
2008-08-06 09:30:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-06 09:30:18 0 d-------- C:\Program Files\Common Files\Download Manager
2008-08-05 16:18:01 0 d-------- C:\Documents and Settings\306\Application Data\Lavasoft
2008-08-05 15:34:31 0 d-------- C:\Documents and Settings\306\Application Data\Apple Computer
2008-07-11 14:40:42 0 d-------- C:\Documents and Settings\306\Application Data\Real
2008-07-09 10:12:22 0 d-------- C:\Program Files\Palm
2008-07-09 09:12:21 0 d-------- C:\Documents and Settings\306\Application Data\WinRAR
2008-07-08 19:49:03 0 d-------- C:\Documents and Settings\306\Application Data\Leadertech
2008-07-08 19:36:46 0 d-------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data\Intel
2008-07-08 19:36:46 0 d-------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data\InstallShield
2008-07-08 19:36:46 0 d-------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data\Identities
2008-07-08 19:36:45 0 d--h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\Templates
2008-07-08 19:36:45 0 dr------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Start Menu
2008-07-08 19:36:45 0 dr-h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\SendTo
2008-07-08 19:36:45 0 dr-h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\Recent
2008-07-08 19:36:45 0 d--h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\PrintHood
2008-07-08 19:36:45 786432 --ah----- C:\Documents and Settings\TEMP.FRISOMATGROEP\NTUSER.DAT
2008-07-08 19:36:45 0 d--h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\NetHood
2008-07-08 19:36:45 0 dr------- C:\Documents and Settings\TEMP.FRISOMATGROEP\My Documents
2008-07-08 19:36:45 0 d--h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\Local Settings
2008-07-08 19:36:45 0 dr------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Favorites
2008-07-08 19:36:45 0 d-------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Desktop
2008-07-08 19:36:45 0 d--hs---- C:\Documents and Settings\TEMP.FRISOMATGROEP\Cookies
2008-07-08 19:36:45 0 dr-h----- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data
2008-07-08 19:36:45 0 d-------- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data\Wave Systems Corp
2008-07-08 19:36:45 0 d---s---- C:\Documents and Settings\TEMP.FRISOMATGROEP\Application Data\Microsoft
2008-07-08 11:56:18 0 d-------- C:\Documents and Settings\306\Application Data\Mozilla
2008-07-08 11:47:56 0 d-------- C:\Documents and Settings\306\Application Data\VanDale
2008-07-08 09:16:45 0 d-------- C:\Documents and Settings\306\Application Data\Google
2008-07-07 15:24:05 0 d-------- C:\Documents and Settings\381\Application Data\Logitech
2008-07-07 15:23:11 0 d--h----- C:\Documents and Settings\381\NetHood
2008-07-07 15:23:11 0 dr------- C:\Documents and Settings\381\My Documents
2008-07-07 15:23:11 0 d--h----- C:\Documents and Settings\381\Local Settings
2008-07-07 15:23:11 0 dr------- C:\Documents and Settings\381\Favorites
2008-07-07 15:23:11 0 d-------- C:\Documents and Settings\381\Desktop
2008-07-07 15:23:11 0 d--hs---- C:\Documents and Settings\381\Cookies
2008-07-07 15:23:11 0 dr-h----- C:\Documents and Settings\381\Application Data
2008-07-07 15:23:11 0 d-------- C:\Documents and Settings\381\Application Data\Wave Systems Corp
2008-07-07 15:23:11 0 d---s---- C:\Documents and Settings\381\Application Data\Microsoft
2008-07-07 15:23:11 0 d-------- C:\Documents and Settings\381\Application Data\Intel
2008-07-07 15:23:11 0 d-------- C:\Documents and Settings\381\Application Data\InstallShield
2008-07-07 15:23:11 0 d-------- C:\Documents and Settings\381\Application Data\Identities
2008-07-07 15:23:10 0 d--h----- C:\Documents and Settings\381\Templates
2008-07-07 15:23:10 0 dr------- C:\Documents and Settings\381\Start Menu
2008-07-07 15:23:10 0 dr-h----- C:\Documents and Settings\381\SendTo
2008-07-07 15:23:10 0 dr-h----- C:\Documents and Settings\381\Recent
2008-07-07 15:23:10 0 d--h----- C:\Documents and Settings\381\PrintHood
2008-07-07 15:23:10 1048576 --ah----- C:\Documents and Settings\381\NTUSER.DAT
2008-07-07 13:38:08 0 d-------- C:\Documents and Settings\306\Application Data\Sun
2008-07-07 13:30:21 0 d-------- C:\Documents and Settings\306\Application Data\AdobeUM
2008-07-07 12:56:57 0 d-------- C:\Documents and Settings\306\Application Data\Logitech
2008-07-07 11:43:45 0 d-------- C:\Documents and Settings\306\Application Data\Macromedia
2008-07-07 11:43:45 0 d-------- C:\Documents and Settings\306\Application Data\Adobe
2008-07-07 11:19:49 0 d-------- C:\Program Files\Acro Software
2008-07-07 11:18:26 0 d-------- C:\Program Files\GPLGS
2008-07-07 11:07:20 0 dr------- C:\Documents and Settings\306\Favorites
2008-07-07 11:07:20 0 d-------- C:\Documents and Settings\306\Desktop
2008-07-07 11:07:20 0 d--hs---- C:\Documents and Settings\306\Cookies
2008-07-07 11:07:20 0 dr-h----- C:\Documents and Settings\306\Application Data
2008-07-07 11:07:20 0 d-------- C:\Documents and Settings\306\Application Data\Wave Systems Corp
2008-07-07 11:07:20 0 d-------- C:\Documents and Settings\306\Application Data\Intel
2008-07-07 11:07:20 0 d-------- C:\Documents and Settings\306\Application Data\InstallShield
2008-07-07 11:07:20 0 d-------- C:\Documents and Settings\306\Application Data\Identities
2008-07-07 11:07:19 0 d--h----- C:\Documents and Settings\306\Templates
2008-07-07 11:07:19 0 dr------- C:\Documents and Settings\306\Start Menu
2008-07-07 11:07:19 0 dr-h----- C:\Documents and Settings\306\SendTo
2008-07-07 11:07:19 0 dr-h----- C:\Documents and Settings\306\Recent
2008-07-07 11:07:19 0 d--h----- C:\Documents and Settings\306\PrintHood
2008-07-07 11:07:19 3670016 --ah----- C:\Documents and Settings\306\NTUSER.DAT
2008-07-07 11:07:19 0 d--h----- C:\Documents and Settings\306\NetHood
2008-07-07 11:07:19 0 dr------- C:\Documents and Settings\306\My Documents
2008-07-07 11:07:19 0 d--h----- C:\Documents and Settings\306\Local Settings
2008-07-07 10:47:07 110602 --a------ C:\WINDOWS\system32\xcdsfx32.bin
2008-07-07 10:47:04 0 d-------- C:\Program Files\Driver Magician
2008-07-07 10:44:47 0 dr------- C:\Documents and Settings\Administrator.frisomatgroep\Favorites
2008-07-07 10:44:47 0 d-------- C:\Documents and Settings\Administrator.frisomatgroep\Desktop
2008-07-07 10:44:47 0 d--hs---- C:\Documents and Settings\Administrator.frisomatgroep\Cookies
2008-07-07 10:44:47 0 dr-h----- C:\Documents and Settings\Administrator.frisomatgroep\Application Data
2008-07-07 10:44:47 0 d-------- C:\Documents and Settings\Administrator.frisomatgroep\Application Data\Wave Systems Corp
2008-07-07 10:44:47 0 d---s---- C:\Documents and Settings\Administrator.frisomatgroep\Application Data\Microsoft
2008-07-07 10:44:47 0 d-------- C:\Documents and Settings\Administrator.frisomatgroep\Application Data\Intel
2008-07-07 10:44:47 0 d-------- C:\Documents and Settings\Administrator.frisomatgroep\Application Data\InstallShield
2008-07-07 10:44:47 0 d-------- C:\Documents and Settings\Administrator.frisomatgroep\Application Data\Identities
2008-07-07 10:44:46 0 d--h----- C:\Documents and Settings\Administrator.frisomatgroep\Templates
2008-07-07 10:44:46 0 dr------- C:\Documents and Settings\Administrator.frisomatgroep\Start Menu
2008-07-07 10:44:46 0 dr-h----- C:\Documents and Settings\Administrator.frisomatgroep\SendTo
2008-07-07 10:44:46 0 dr-h----- C:\Documents and Settings\Administrator.frisomatgroep\Recent
2008-07-07 10:44:46 0 d--h----- C:\Documents and Settings\Administrator.frisomatgroep\PrintHood
2008-07-07 10:44:46 1048576 --ah----- C:\Documents and Settings\Administrator.frisomatgroep\NTUSER.DAT
2008-07-07 10:44:46 0 d--h----- C:\Documents and Settings\Administrator.frisomatgroep\NetHood
2008-07-07 10:44:46 0 dr------- C:\Documents and Settings\Administrator.frisomatgroep\My Documents
2008-07-07 10:44:46 0 d--h----- C:\Documents and Settings\Administrator.frisomatgroep\Local Settings
2008-07-07 10:14:49 0 d-------- C:\Documents and Settings\306old\.housecall6.6
2008-07-07 09:52:29 0 d-------- C:\Documents and Settings\306old\DoctorWeb
2008-07-07 09:52:15 0 d-------- C:\Program Files\Trend Micro
2008-07-07 08:23:29 345 --ahs---- C:\WINDOWS\system32\ehNoVELm.ini2
-- Find3M Report ---------------------------------------------------------------
2008-08-06 09:30:18 0 d-------- C:\Program Files\Common Files
2008-08-05 14:57:38 0 d-------- C:\Program Files\Kinoma
2008-08-05 08:20:47 140973 --a------ C:\WINDOWS\system32\nvModes.dat
2008-07-09 09:12:58 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-08 11:43:18 0 d-------- C:\Program Files\Google
2008-07-07 10:48:23 0 d-------- C:\Program Files\Symantec
2008-07-07 10:48:12 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-07 10:27:36 0 d-------- C:\Program Files\MSECACHE
2008-07-07 10:26:30 0 d-------- C:\Program Files\Dell
2008-07-04 16:04:42 16879 --ahs---- C:\WINDOWS\system32\AaISsvut.ini2
2008-07-01 14:00:34 0 d-------- C:\Program Files\IrfanView
2008-06-24 09:18:54 0 d-------- C:\Program Files\Nokia
2008-06-24 09:18:54 0 d-------- C:\Program Files\Common Files\Nokia
2008-05-30 12:44:31 0 --a------ C:\WINDOWS\system32\Infob.dat
2008-05-30 12:44:31 0 --a------ C:\WINDOWS\system32\Infoa.dat
2008-05-30 12:41:14 305 --a------ C:\WINDOWS\system32\treeinfo.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [31/10/2007 10:36]
"NvMediaCenter"="NvMCTray.dll" [31/05/2007 16:50 C:\WINDOWS\system32\nvmctray.dll]
"nwiz"="nwiz.exe" [31/05/2007 16:50 C:\WINDOWS\system32\nwiz.exe]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [04/08/2004 06:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [31/05/2007 16:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EFI Job Monitor"=" C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\efjm.dll,run" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [13/10/2004 18:24]
C:\Documents and Settings\306\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [25/09/2003 10:47:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [05/02/2007 15:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 15/11/2007 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wxvault.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 wvauth C:\WINDOWS\system32\mLEVoNhe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3693744080-3800500109-2892053873-1123\Scripts\Logon\0\0]
"Script"=\\friso2008\netlogon\logonscript.vbs
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Snelle start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Snelle start.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Snelle start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP4 Player]
"C:\Program Files\MP4 Player\mp4Player.exe" hmw
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
"C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LBTServ"=3 (0x3)
"Fax"=2 (0x2)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
-- End of Deckard's System Scanner: finished at 2008-08-06 12:03:53 ------------
report 2: dss notepad "extra.txt" + kaspersky-log in seperate reply...