J-P staat IDD versteld en gaat nu het log aan Pieter laten zien die hoofdpijn krijgt
DiamondCS Autostart Viewer (
www.diamondcs.com.au) - Report for Jean-Paul@UW-TPLFS1IVZS0U, 06-14-2003
c:\windows\system32\autoexec.nt
C:\WINDOWS\system32\mscdexnt.exe
C:\WINDOWS\system32\redir.exe
C:\WINDOWS\system32\dosx.exe
c:\windows\system32\config.nt
C:\WINDOWS\system32\himem.sys
c:\windows\system.ini [boot]\shell
C:\WINDOWS\Explorer.exe
c:\windows\system.ini [boot]\scrnsave.exe
C:\WINDOWS\system32\ssstars.scr
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
C:\WINDOWS\Explorer.exe
HKCU\Control Panel\Desktop\scrnsave.exe
C:\WINDOWS\system32\ssstars.scr
HKCR\vbsfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\vbefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\jsfile\shell\open\command\
C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1
HKCR\jsefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wshfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wsffile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\CPQEASYACC
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\srmclean
C:\Cpqs\Scom\srmclean.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\nwiz
nwiz.exe /install
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ZoneAlarm Pro
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ccApp
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ccRegVfy
C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TC Monitor
C:\Program Files\The Cleaner\tcm.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MessengerPlus2
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LWBMOUSE
C:\Program Files\Muis drivers\1.0\lwbwheel.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DU Meter
C:\Program Files\DU Meter\DUMeter.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Tweak UI
RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SpeedFan
C:\Program Files\SpeedFan\speedfan.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MessengerPlus2
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\msnmsgr
C:\Program Files\MSN Messenger\msnmsgr.exe
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
C:\WINDOWS\System32\CTFMON.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\System32\webcheck.dll
C:\WINDOWS\System32\stobject.dll
C:\WINDOWS\Tasks\Message.job
C:\Message.txt
C:\WINDOWS\Tasks\Norton AntiVirus - Mijn computer scannen.job
C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exe
C:\WINDOWS\Tasks\Norton System Doctor.job
C:\PROGRA~1\NORTON~1\NORTON~4\SYSDOC32.EXE
C:\WINDOWS\Tasks\One Button Checkup van Norton SystemWorks.job
C:\Program Files\Norton SystemWorks\OBC.exe
C:\WINDOWS\Tasks\Symantec NetDetect.job
C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
C:\WINDOWS\Tasks\{C93A8701-E9F2-4844-B219-FFD87360AFBF}_UW-TPLFS1IVZS0U_Jean-Paul.job
C:\WINDOWS\system32\mobsync.exe
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Microsoft Office.lnk
C:\Program Files\Microsoft Office\Office10\OSA.EXE
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\ZoneAlarm Pro.lnk
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
HKLM\System\CurrentControlSet\Control\WOW\cmdline
C:\WINDOWS\system32\ntvdm.exe
HKLM\System\CurrentControlSet\Control\WOW\wowcmdline
C:\WINDOWS\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rsvpsp.dll
HKLM\System\CurrentControlSet\Services\VxD\JAVASUP\
C:\WINDOWS\system32\JAVASUP.VXD