Ga naar inhoud

Hijackthis logje


Aanbevolen berichten

Op de laptop van mijn vrouw kan ik google niet meer instellen als startpagina? Telkens verschijnt de site www.trvigo.com als startpagina, en zoeken gaat via ASK inplaats van google.

Via extra/internet opties lukt het niet, ook niet via de link van google zelf 'stel google als startpagina in.

Hier het logje.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:31:58, on 23/02/2014

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.16518)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe

C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe

C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe

C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

C:\Program Files\Sony\VAIO Care\listener.exe

C:\Program Files (x86)\Internet Explorer\IELowutil.exe

C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe

C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Zoeken=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: CrossriderApp0013370 - {11111111-1111-1111-1111-110111331170} - C:\Program Files (x86)\PhotoMania\PhotoMania.dll

O2 - BHO: CrossriderApp0044160 - {11111111-1111-1111-1111-110411411160} - C:\Program Files (x86)\BobyLyrics-16\BobyLyrics-16-bho.dll

O2 - BHO: CrossriderApp0049074 - {11111111-1111-1111-1111-110411901174} - C:\Program Files (x86)\The weDownload Manager\The weDownload Manager-bho.dll

O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

O4 - HKLM\..\Run: [iSBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"

O4 - HKLM\..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"

O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

O4 - HKCU\..\Run: [EPSON BX620FWD Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBU.EXE /FU "C:\Windows\TEMP\E_SEB3C.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\christel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Search Protect by Conduit Service (CltMngSvc) - Conduit - C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe

O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: Online Games Manager (ogmservice) - RealNetworks, Inc. - C:\Program Files (x86)\Online Games Manager\ogmservice.exe

O23 - Service: PMBDeviceInfoProvider - Sony Corporation - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe

O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe

O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe

O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe

O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe

O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe

O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 15048 bytes

Link naar reactie
Delen op andere sites

Hoi Odil,

1.

Ik zie nergens de aanwezigheid van een actieve antivirus scanner?

Kijk eens op DEZE site en download + installeer een gratis scanner naar keuze.

2.

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie).


  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

C:\PROGRA~2\SearchProtect;fs
{11111111-1111-1111-1111-110111331170};c
C:\Program Files (x86)\PhotoMania;fs
{11111111-1111-1111-1111-110411411160};c
C:\Program Files (x86)\BobyLyrics-16;fs
{11111111-1111-1111-1111-110411901174};c
C:\Program Files (x86)\The weDownload Manager;fs
C:\Program Files (x86)\Mobogenie;fs
C:\Users\christel\AppData\Roaming\newnext.me;fs
CltMngSvc;s
autoclean;
emptyclsid;
emptyfolderscheck;delete 
startupall; 
filesrcm;


  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

3.

Je Java software is verouderd.

Oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem.

Ga naar Java en download daar de correcte Java versie.

  • Klik op "Gratis Java-download".
  • Ga akkoord met de licentiebepalingen en klik op de button voor de gratis download.
  • Het bestand JavaSetup wordt aangeboden - kies hier voor "bestand opslaan".
  • Sluit alle programma's die eventueel open zijn - zeker je web browser!
  • Ga dan naar Start > Configuratiescherm > Software en verwijder alle oudere versies van Java uit de Softwarelijst.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE of JAVA) in de naam.
  • Klik dan op Verwijderen of op de Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart je pc.
  • Klik vervolgens op JavaSetup om de nieuwste versie van Java te installeren.
  • Vink de installatie van de Ask toolbar uit en ga dan verder met de installatie.

aangepast door Jion
Link naar reactie
Delen op andere sites

Hmm na het herstarten van de pc staat opeens google als startpagina terug.

Hier het logje zoals gevraagd.

Zoek.exe v5.0.0.0 Updated 19-February-2014

Tool run by christel on zo 23/02/2014 at 17:59:29,67.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\christel\Desktop\zoek.exe [scan all users] [Quick Scan] [Auto Clean]

==== System Restore Info ======================

23/02/2014 18:01:27 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\Users\christel\AppData\Roaming\WinRAR deleted successfully

C:\Users\christel\AppData\Local\cache deleted successfully

C:\Users\christel\AppData\Local\LogMeIn Rescue Applet deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CltMngSvc deleted successfully

==== Deleting Files \ Folders ======================

C:\PROGRA~3\eSellerate deleted

C:\Users\christel\AppData\Local\genienext deleted

C:\Users\christel\.android deleted

C:\PROGRA~2\SearchProtect deleted

C:\PROGRA~2\FromDocToPDF_65 deleted

C:\Users\christel\AppData\Roaming\newnext.me deleted

C:\PROGRA~3\Trymedia deleted

C:\Users\christel\AppData\Local\SearchProtect deleted

C:\Users\christel\AppData\Local\Mobogenie deleted

C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie deleted

C:\Users\christel\AppData\LocalLow\IAC deleted

C:\Users\christel\AppData\LocalLow\BobyLyrics-16 deleted

C:\Users\christel\AppData\LocalLow\FromDocToPDF_65 deleted

C:\windows\SysNative\tasks\BobyLyrics-16-chromeinstaller deleted

C:\windows\SysNative\tasks\BobyLyrics-16-codedownloader deleted

C:\windows\SysNative\tasks\BobyLyrics-16-enabler deleted

C:\windows\SysNative\tasks\BobyLyrics-16-updater deleted

C:\Windows\tasks\BobyLyrics-16-chromeinstaller.job deleted

C:\Windows\tasks\BobyLyrics-16-codedownloader.job deleted

C:\Windows\tasks\BobyLyrics-16-enabler.job deleted

C:\Windows\tasks\BobyLyrics-16-updater.job deleted

C:\windows\SysNative\tasks\The weDownload Manager-codedownloader deleted

C:\windows\SysNative\tasks\The weDownload Manager-enabler deleted

C:\windows\SysNative\tasks\The weDownload Manager-firefoxinstaller deleted

C:\windows\SysNative\tasks\The weDownload Manager-updater deleted

C:\Windows\tasks\The weDownload Manager-codedownloader.job deleted

C:\Windows\tasks\The weDownload Manager-enabler.job deleted

C:\Windows\tasks\The weDownload Manager-firefoxinstaller.job deleted

C:\Windows\tasks\The weDownload Manager-updater.job deleted

C:\Windows\Syswow64\SearchProtect deleted

C:\Users\christel\Documents\Mobogenie deleted

"C:\Users\christel\daemonprocess.txt" deleted

"C:\PROGRA~2\Mobogenie\DaemonProcess.exe" deleted

"C:\PROGRA~2\Mobogenie\DCR.dll" deleted

"C:\PROGRA~2\Mobogenie\Device.dll" deleted

"C:\PROGRA~2\Mobogenie\libeay32.dll" deleted

"C:\PROGRA~2\Mobogenie\msvcp100.dll" deleted

"C:\PROGRA~2\Mobogenie\msvcr100.dll" deleted

"C:\PROGRA~2\Mobogenie\QtCore4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtGui4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtNetwork4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtSql4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtWebKit4.dll" deleted

"C:\PROGRA~2\Mobogenie\ssleay32.dll" deleted

"C:\PROGRA~2\The weDownload Manager\The weDownload Manager-bg.exe" deleted

"C:\PROGRA~2\The weDownload Manager\The weDownload Manager-bho.dll" deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho.dll" deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho64.dll" not deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-buttonutil64.dll" not deleted

"C:\PROGRA~2\Mobogenie" deleted

"C:\PROGRA~2\The weDownload Manager" not deleted

"C:\PROGRA~2\BobyLyrics-16" not deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

====== C:\Users\christel\AppData\Local\Temp ====

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Temp\nsaB24F\SpSetup.exe

2014-02-23 13:24:50 D09FB396FF34603B5ECA5A2DF3D0544B 497664 ----a-w- C:\Users\christel\AppData\Local\Temp\LollipopInstaller_14888.exe

2014-02-23 13:24:50 9FB9D49C2DB7EDD1084AB765D619F5C6 66368 ----a-w- C:\Users\christel\AppData\Local\Temp\sp_downloader.exe

2014-02-23 13:24:50 1DF7D011EA59663A8C37CBBBC6A8019C 6772048 ----a-w- C:\Users\christel\AppData\Local\Temp\1392371628_the_wedownload_manager.exe

2014-02-23 13:24:50 0FBD402D906E3E6DF14C6CC064D9050E 52771576 ----a-w- C:\Users\christel\AppData\Local\Temp\pal_install_a5082_r132020.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvF8E6.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvF5D9.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvD3B6.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsqD0D8.exe

====== Java Cache =====

====== C:\Windows\SysWOW64 =====

2014-02-13 02:01:37 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll

2014-02-13 02:00:47 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll

2014-02-13 02:00:47 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

2014-02-13 02:00:47 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll

2014-02-13 02:00:45 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

2014-02-13 02:00:45 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe

2014-02-13 02:00:45 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

2014-02-13 02:00:44 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll

2014-02-13 02:00:44 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll

2014-02-13 02:00:44 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll

2014-02-13 02:00:43 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll

2014-02-13 02:00:43 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll

2014-02-13 02:00:42 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll

2014-02-13 02:00:42 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll

2014-02-13 02:00:42 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll

2014-02-13 02:00:41 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl

2014-02-13 02:00:40 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll

2014-02-13 02:00:39 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll

2014-02-13 02:00:39 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll

2014-02-12 02:08:21 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls

2014-02-12 02:08:19 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll

2014-02-12 02:08:19 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll

2014-02-12 02:08:07 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

2014-02-12 02:08:07 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe

2014-02-12 02:08:07 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

2014-02-12 02:08:06 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll

2014-02-12 02:08:06 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll

2014-02-12 02:08:06 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll

2014-02-12 02:08:06 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll

2014-02-12 02:08:06 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll

2014-02-12 02:08:06 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

2014-02-12 02:08:04 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll

2014-02-12 02:08:03 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2014-02-13 02:01:37 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll

2014-02-13 02:00:48 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb

2014-02-13 02:00:47 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll

2014-02-13 02:00:47 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll

2014-02-13 02:00:46 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll

2014-02-13 02:00:46 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll

2014-02-13 02:00:46 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe

2014-02-13 02:00:45 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll

2014-02-13 02:00:45 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll

2014-02-13 02:00:44 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll

2014-02-13 02:00:44 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe

2014-02-13 02:00:44 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll

2014-02-13 02:00:44 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll

2014-02-13 02:00:44 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe

2014-02-13 02:00:43 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll

2014-02-13 02:00:43 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll

2014-02-13 02:00:42 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll

2014-02-13 02:00:42 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll

2014-02-13 02:00:42 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll

2014-02-13 02:00:41 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll

2014-02-13 02:00:41 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl

2014-02-13 02:00:38 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll

2014-02-12 02:08:21 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls

2014-02-12 02:08:19 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll

2014-02-12 02:08:19 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll

2014-02-12 02:08:07 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe

2014-02-12 02:08:07 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe

2014-02-12 02:08:07 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe

2014-02-12 02:08:06 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll

2014-02-12 02:08:06 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll

2014-02-12 02:08:06 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll

2014-02-12 02:08:06 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll

2014-02-12 02:08:06 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll

2014-02-12 02:08:06 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe

2014-02-12 02:08:04 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll

2014-02-12 02:08:04 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll

====== C:\Windows\Sysnative\drivers =====

====== C:\Windows\Tasks ======

2014-02-07 14:18:42 -------- d-----w- C:\Windows\Sysnative\Tasks\NCH Software

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\PROGRA~2 =====

2014-02-23 13:26:20 -------- d-----w- C:\PROGRA~2\Trend Micro

2014-02-23 13:25:25 -------- d-----w- C:\PROGRA~2\The weDownload Manager

======= C: =====

====== C:\Users\christel\AppData\Roaming ======

2014-02-23 17:12:53 -------- d-----w- C:\Users\christel\AppData\Locallow\BobyLyrics-16

2014-02-23 13:48:39 -------- d-----r- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices

2014-02-07 14:18:47 -------- d-----w- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite

2014-02-07 14:18:47 -------- d-----w- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audio Related Programs

2014-02-07 14:18:31 -------- d-----w- C:\Users\christel\AppData\Roaming\NCH Software

====== C:\Users\christel ======

2014-02-08 17:20:20 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe

2014-02-07 14:18:42 -------- d-----w- C:\ProgramData\NCH Software

2014-02-07 14:18:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite

2014-02-07 14:18:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs

====== C: exe-files ==

2014-02-23 13:53:27 6DF65147D868ED42F400B4A2C02BDF96 272880 ----a-w- C:\Windows\Temp\ogmtmp\ogmservice-setup.exe

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Temp\nsaB24F\SpSetup.exe

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7ECZN2W3\SPSetup[1].exe

2014-02-23 13:25:00 DE24D470B32B657EADF336232963E9EC 123896 ----a-w- C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUQAWDUG\spstub[1].exe

2014-02-23 13:24:50 D09FB396FF34603B5ECA5A2DF3D0544B 497664 ----a-w- C:\Users\christel\AppData\Local\Temp\LollipopInstaller_14888.exe

2014-02-23 13:24:50 9FB9D49C2DB7EDD1084AB765D619F5C6 66368 ----a-w- C:\Users\christel\AppData\Local\Temp\sp_downloader.exe

2014-02-23 13:24:50 1DF7D011EA59663A8C37CBBBC6A8019C 6772048 ----a-w- C:\Users\christel\AppData\Local\Temp\1392371628_the_wedownload_manager.exe

2014-02-23 13:24:50 0FBD402D906E3E6DF14C6CC064D9050E 52771576 ----a-w- C:\Users\christel\AppData\Local\Temp\pal_install_a5082_r132020.exe

2014-02-21 20:39:36 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe

=== C: other files ==

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"EPSON BX620FWD Series"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBU.EXE /FU C:\Windows\TEMP\E_SEB3C.tmp /EF HKCU"

"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"

"Facebook Update"="C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"NextLive"="C:\Windows\SysWOW64\rundll32.exe C:\Users\christel\AppData\Roaming\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe"

"ISBMgr.exe"="C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"

"PMBVolumeWatcher"="c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe"

"EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"

"APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

"mobilegeni daemon"="C:\Program Files (x86)\Mobogenie\DaemonProcess.exe"

"FUFAXSTM"=""C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"EPSON BX620FWD Series"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBU.EXE /FU C:\Windows\TEMP\E_SEB3C.tmp /EF HKCU"

"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"

"Facebook Update"="C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"NextLive"="C:\Windows\SysWOW64\rundll32.exe C:\Users\christel\AppData\Roaming\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe"

"AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

"AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

"Apoint"="%ProgramFiles%\Apoint\Apoint.exe "

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll"

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe ARM"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe Reader Speed Launcher"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\""

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [20/02/2014 21:06]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000Core.job --a------ C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/01/2013 18:27]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000UA.job --a------ C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/01/2013 18:27]

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/08/2013 09:13]

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/08/2013 09:13]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]

"C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000Core" [C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000UA" [C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

"C:\Windows\SysNative\tasks\User_Feed_Synchronization-{951B3D99-C232-4ADF-9557-C514437DC03B}" [C:\Windows\system32\msfeedssync.exe]

"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

"C:\Windows\SysNative\tasks\NCH Software\WavePadSevenDays" [C:\Program Files (x86)\NCH Software\WavePad\WavePad.exe]

"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

"C:\Windows\SysNative\tasks\SONY\VAIO Gate\StartExecuteProxy" ["%programfiles%\Sony\VAIO Gate\ExecutionProxy.exe"]

"C:\Windows\SysNative\tasks\SONY\VAIO Gate\VAIO Gate" [C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VAIO Care" ["%ProgramFiles%\Sony\VAIO Care\VCsystray.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VCOneClick" ["%ProgramFiles%\Sony\VAIO Care\VCOneClick.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader" [C:\Program Files\Sony\VAIO Improvement\viuploader.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation" [C:\Program Files\Sony\VAIO Improvement Validation\viv.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start" [C:\Program Files\Sony\VAIO Smart Network\VSNClient]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update" ["C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair" [C:\Program Files\Sony\VAIO Update\VUSR.exe]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

hmjdlbnelihabmidedpddnfhamfbcdpm - C:\Users\christel\AppData\Local\PhotoMania\Chrome\PhotoMania.crx[01/01/2013 15:10]

YouTube - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

Google Search - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

PhotoMania - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm

BobyLyrics-16 - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iffnmffcnjgdnckipooehcgglcfaheeb

Google Wallet - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

Gmail - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Chrome Fix ======================

C:\Users\christel\AppData\Local\PhotoMania\Chrome\PhotoMania.crx deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iffnmffcnjgdnckipooehcgglcfaheeb deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0.localstorage deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0.localstorage-journal deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\databases\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0 deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Extension Settings\iffnmffcnjgdnckipooehcgglcfaheeb deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0.localstorage deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0.localstorage-journal deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0 deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\databases\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0 deleted successfully

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Zoeken="

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}"

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Conduit Search Url="{searchTerms} - Ask.com Search="

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

{B8DDA9AC-9549-4CA3-B801-5C53E73B44E0} eBay Url="Elektronica, auto's, kleding, verzamelobjecten, cadeaubons en meer | eBay}"

{DEC0E36E-AC34-44BD-91D6-4B53B96B8C8B} Zinio Url="Page Not Found"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411160} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm deleted successfully

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie deleted successfully

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2629 folders=272 246587619 bytes)

==== Empty Temp Folders ======================

C:\Users\christel\AppData\Local\Temp will be emptied at reboot

C:\Users\Default\AppData\Local\Temp emptied successfully

C:\Users\Default User\AppData\Local\Temp emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\christel\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho64.dll" not found

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-buttonutil64.dll" not found

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

"C:\PROGRA~2\The weDownload Manager" not found

"C:\PROGRA~2\BobyLyrics-16" not found

==== EOF on zo 23/02/2014 at 18:58:26,60 ======================

- - - Updated - - -

Hmm na het herstarten van de pc staat opeens google als startpagina terug.

Hier het logje zoals gevraagd.

Zoek.exe v5.0.0.0 Updated 19-February-2014

Tool run by christel on zo 23/02/2014 at 17:59:29,67.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\christel\Desktop\zoek.exe [scan all users] [Quick Scan] [Auto Clean]

==== System Restore Info ======================

23/02/2014 18:01:27 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\Users\christel\AppData\Roaming\WinRAR deleted successfully

C:\Users\christel\AppData\Local\cache deleted successfully

C:\Users\christel\AppData\Local\LogMeIn Rescue Applet deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CltMngSvc deleted successfully

==== Deleting Files \ Folders ======================

C:\PROGRA~3\eSellerate deleted

C:\Users\christel\AppData\Local\genienext deleted

C:\Users\christel\.android deleted

C:\PROGRA~2\SearchProtect deleted

C:\PROGRA~2\FromDocToPDF_65 deleted

C:\Users\christel\AppData\Roaming\newnext.me deleted

C:\PROGRA~3\Trymedia deleted

C:\Users\christel\AppData\Local\SearchProtect deleted

C:\Users\christel\AppData\Local\Mobogenie deleted

C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie deleted

C:\Users\christel\AppData\LocalLow\IAC deleted

C:\Users\christel\AppData\LocalLow\BobyLyrics-16 deleted

C:\Users\christel\AppData\LocalLow\FromDocToPDF_65 deleted

C:\windows\SysNative\tasks\BobyLyrics-16-chromeinstaller deleted

C:\windows\SysNative\tasks\BobyLyrics-16-codedownloader deleted

C:\windows\SysNative\tasks\BobyLyrics-16-enabler deleted

C:\windows\SysNative\tasks\BobyLyrics-16-updater deleted

C:\Windows\tasks\BobyLyrics-16-chromeinstaller.job deleted

C:\Windows\tasks\BobyLyrics-16-codedownloader.job deleted

C:\Windows\tasks\BobyLyrics-16-enabler.job deleted

C:\Windows\tasks\BobyLyrics-16-updater.job deleted

C:\windows\SysNative\tasks\The weDownload Manager-codedownloader deleted

C:\windows\SysNative\tasks\The weDownload Manager-enabler deleted

C:\windows\SysNative\tasks\The weDownload Manager-firefoxinstaller deleted

C:\windows\SysNative\tasks\The weDownload Manager-updater deleted

C:\Windows\tasks\The weDownload Manager-codedownloader.job deleted

C:\Windows\tasks\The weDownload Manager-enabler.job deleted

C:\Windows\tasks\The weDownload Manager-firefoxinstaller.job deleted

C:\Windows\tasks\The weDownload Manager-updater.job deleted

C:\Windows\Syswow64\SearchProtect deleted

C:\Users\christel\Documents\Mobogenie deleted

"C:\Users\christel\daemonprocess.txt" deleted

"C:\PROGRA~2\Mobogenie\DaemonProcess.exe" deleted

"C:\PROGRA~2\Mobogenie\DCR.dll" deleted

"C:\PROGRA~2\Mobogenie\Device.dll" deleted

"C:\PROGRA~2\Mobogenie\libeay32.dll" deleted

"C:\PROGRA~2\Mobogenie\msvcp100.dll" deleted

"C:\PROGRA~2\Mobogenie\msvcr100.dll" deleted

"C:\PROGRA~2\Mobogenie\QtCore4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtGui4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtNetwork4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtSql4.dll" deleted

"C:\PROGRA~2\Mobogenie\QtWebKit4.dll" deleted

"C:\PROGRA~2\Mobogenie\ssleay32.dll" deleted

"C:\PROGRA~2\The weDownload Manager\The weDownload Manager-bg.exe" deleted

"C:\PROGRA~2\The weDownload Manager\The weDownload Manager-bho.dll" deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho.dll" deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho64.dll" not deleted

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-buttonutil64.dll" not deleted

"C:\PROGRA~2\Mobogenie" deleted

"C:\PROGRA~2\The weDownload Manager" not deleted

"C:\PROGRA~2\BobyLyrics-16" not deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

====== C:\Users\christel\AppData\Local\Temp ====

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Temp\nsaB24F\SpSetup.exe

2014-02-23 13:24:50 D09FB396FF34603B5ECA5A2DF3D0544B 497664 ----a-w- C:\Users\christel\AppData\Local\Temp\LollipopInstaller_14888.exe

2014-02-23 13:24:50 9FB9D49C2DB7EDD1084AB765D619F5C6 66368 ----a-w- C:\Users\christel\AppData\Local\Temp\sp_downloader.exe

2014-02-23 13:24:50 1DF7D011EA59663A8C37CBBBC6A8019C 6772048 ----a-w- C:\Users\christel\AppData\Local\Temp\1392371628_the_wedownload_manager.exe

2014-02-23 13:24:50 0FBD402D906E3E6DF14C6CC064D9050E 52771576 ----a-w- C:\Users\christel\AppData\Local\Temp\pal_install_a5082_r132020.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvF8E6.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvF5D9.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsvD3B6.exe

2014-02-12 11:54:14 C67BCF6441E378371F0D6EEFB7EF0861 167812 ----a-w- C:\Users\christel\AppData\Local\Temp\nsqD0D8.exe

====== Java Cache =====

====== C:\Windows\SysWOW64 =====

2014-02-13 02:01:37 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll

2014-02-13 02:00:47 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll

2014-02-13 02:00:47 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

2014-02-13 02:00:47 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll

2014-02-13 02:00:45 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

2014-02-13 02:00:45 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe

2014-02-13 02:00:45 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

2014-02-13 02:00:44 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll

2014-02-13 02:00:44 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll

2014-02-13 02:00:44 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll

2014-02-13 02:00:43 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll

2014-02-13 02:00:43 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll

2014-02-13 02:00:42 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll

2014-02-13 02:00:42 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll

2014-02-13 02:00:42 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll

2014-02-13 02:00:41 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl

2014-02-13 02:00:40 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll

2014-02-13 02:00:39 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll

2014-02-13 02:00:39 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll

2014-02-12 02:08:21 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls

2014-02-12 02:08:19 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll

2014-02-12 02:08:19 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll

2014-02-12 02:08:07 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

2014-02-12 02:08:07 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe

2014-02-12 02:08:07 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

2014-02-12 02:08:06 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll

2014-02-12 02:08:06 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll

2014-02-12 02:08:06 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll

2014-02-12 02:08:06 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll

2014-02-12 02:08:06 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll

2014-02-12 02:08:06 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

2014-02-12 02:08:04 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll

2014-02-12 02:08:03 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2014-02-13 02:01:37 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll

2014-02-13 02:00:48 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb

2014-02-13 02:00:47 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll

2014-02-13 02:00:47 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll

2014-02-13 02:00:46 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll

2014-02-13 02:00:46 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll

2014-02-13 02:00:46 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe

2014-02-13 02:00:45 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll

2014-02-13 02:00:45 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll

2014-02-13 02:00:44 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll

2014-02-13 02:00:44 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe

2014-02-13 02:00:44 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll

2014-02-13 02:00:44 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll

2014-02-13 02:00:44 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe

2014-02-13 02:00:43 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll

2014-02-13 02:00:43 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll

2014-02-13 02:00:42 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll

2014-02-13 02:00:42 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll

2014-02-13 02:00:42 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll

2014-02-13 02:00:41 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll

2014-02-13 02:00:41 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl

2014-02-13 02:00:38 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll

2014-02-12 02:08:21 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls

2014-02-12 02:08:19 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll

2014-02-12 02:08:19 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll

2014-02-12 02:08:07 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe

2014-02-12 02:08:07 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe

2014-02-12 02:08:07 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe

2014-02-12 02:08:06 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll

2014-02-12 02:08:06 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll

2014-02-12 02:08:06 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll

2014-02-12 02:08:06 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll

2014-02-12 02:08:06 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll

2014-02-12 02:08:06 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe

2014-02-12 02:08:04 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll

2014-02-12 02:08:04 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll

====== C:\Windows\Sysnative\drivers =====

====== C:\Windows\Tasks ======

2014-02-07 14:18:42 -------- d-----w- C:\Windows\Sysnative\Tasks\NCH Software

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\PROGRA~2 =====

2014-02-23 13:26:20 -------- d-----w- C:\PROGRA~2\Trend Micro

2014-02-23 13:25:25 -------- d-----w- C:\PROGRA~2\The weDownload Manager

======= C: =====

====== C:\Users\christel\AppData\Roaming ======

2014-02-23 17:12:53 -------- d-----w- C:\Users\christel\AppData\Locallow\BobyLyrics-16

2014-02-23 13:48:39 -------- d-----r- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices

2014-02-07 14:18:47 -------- d-----w- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite

2014-02-07 14:18:47 -------- d-----w- C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audio Related Programs

2014-02-07 14:18:31 -------- d-----w- C:\Users\christel\AppData\Roaming\NCH Software

====== C:\Users\christel ======

2014-02-08 17:20:20 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe

2014-02-07 14:18:42 -------- d-----w- C:\ProgramData\NCH Software

2014-02-07 14:18:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite

2014-02-07 14:18:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs

====== C: exe-files ==

2014-02-23 13:53:27 6DF65147D868ED42F400B4A2C02BDF96 272880 ----a-w- C:\Windows\Temp\ogmtmp\ogmservice-setup.exe

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Temp\nsaB24F\SpSetup.exe

2014-02-23 13:25:02 C016C4C32857DAFFE6E3EAEB24939592 6177744 ----a-w- C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7ECZN2W3\SPSetup[1].exe

2014-02-23 13:25:00 DE24D470B32B657EADF336232963E9EC 123896 ----a-w- C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUQAWDUG\spstub[1].exe

2014-02-23 13:24:50 D09FB396FF34603B5ECA5A2DF3D0544B 497664 ----a-w- C:\Users\christel\AppData\Local\Temp\LollipopInstaller_14888.exe

2014-02-23 13:24:50 9FB9D49C2DB7EDD1084AB765D619F5C6 66368 ----a-w- C:\Users\christel\AppData\Local\Temp\sp_downloader.exe

2014-02-23 13:24:50 1DF7D011EA59663A8C37CBBBC6A8019C 6772048 ----a-w- C:\Users\christel\AppData\Local\Temp\1392371628_the_wedownload_manager.exe

2014-02-23 13:24:50 0FBD402D906E3E6DF14C6CC064D9050E 52771576 ----a-w- C:\Users\christel\AppData\Local\Temp\pal_install_a5082_r132020.exe

2014-02-21 20:39:36 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe

=== C: other files ==

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"EPSON BX620FWD Series"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBU.EXE /FU C:\Windows\TEMP\E_SEB3C.tmp /EF HKCU"

"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"

"Facebook Update"="C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"NextLive"="C:\Windows\SysWOW64\rundll32.exe C:\Users\christel\AppData\Roaming\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe"

"ISBMgr.exe"="C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"

"PMBVolumeWatcher"="c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe"

"EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"

"APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

"mobilegeni daemon"="C:\Program Files (x86)\Mobogenie\DaemonProcess.exe"

"FUFAXSTM"=""C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"EPSON BX620FWD Series"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBU.EXE /FU C:\Windows\TEMP\E_SEB3C.tmp /EF HKCU"

"RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe"

"Facebook Update"="C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"

"NextLive"="C:\Windows\SysWOW64\rundll32.exe C:\Users\christel\AppData\Roaming\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe"

"AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

"AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

"Apoint"="%ProgramFiles%\Apoint\Apoint.exe "

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll"

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe ARM"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe Reader Speed Launcher"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\""

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [20/02/2014 21:06]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000Core.job --a------ C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/01/2013 18:27]

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000UA.job --a------ C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/01/2013 18:27]

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/08/2013 09:13]

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/08/2013 09:13]

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]

"C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000Core" [C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2824171206-2023740141-987856411-1000UA" [C:\Users\christel\AppData\Local\Facebook\Update\FacebookUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

"C:\Windows\SysNative\tasks\User_Feed_Synchronization-{951B3D99-C232-4ADF-9557-C514437DC03B}" [C:\Windows\system32\msfeedssync.exe]

"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

"C:\Windows\SysNative\tasks\NCH Software\WavePadSevenDays" [C:\Program Files (x86)\NCH Software\WavePad\WavePad.exe]

"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]

"C:\Windows\SysNative\tasks\SONY\VAIO Gate\StartExecuteProxy" ["%programfiles%\Sony\VAIO Gate\ExecutionProxy.exe"]

"C:\Windows\SysNative\tasks\SONY\VAIO Gate\VAIO Gate" [C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VAIO Care" ["%ProgramFiles%\Sony\VAIO Care\VCsystray.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VCOneClick" ["%ProgramFiles%\Sony\VAIO Care\VCOneClick.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader" [C:\Program Files\Sony\VAIO Improvement\viuploader.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation" [C:\Program Files\Sony\VAIO Improvement Validation\viv.exe]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start" [C:\Program Files\Sony\VAIO Smart Network\VSNClient]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update" ["C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe"]

"C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair" [C:\Program Files\Sony\VAIO Update\VUSR.exe]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

hmjdlbnelihabmidedpddnfhamfbcdpm - C:\Users\christel\AppData\Local\PhotoMania\Chrome\PhotoMania.crx[01/01/2013 15:10]

YouTube - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

Google Search - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

PhotoMania - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm

BobyLyrics-16 - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iffnmffcnjgdnckipooehcgglcfaheeb

Google Wallet - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

Gmail - christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Chrome Fix ======================

C:\Users\christel\AppData\Local\PhotoMania\Chrome\PhotoMania.crx deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iffnmffcnjgdnckipooehcgglcfaheeb deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0.localstorage deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0.localstorage-journal deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\databases\chrome-extension_iffnmffcnjgdnckipooehcgglcfaheeb_0 deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Extension Settings\iffnmffcnjgdnckipooehcgglcfaheeb deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0.localstorage deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0.localstorage-journal deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0 deleted successfully

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\databases\chrome-extension_hmjdlbnelihabmidedpddnfhamfbcdpm_0 deleted successfully

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://search.conduit.com/?ctid=CT3322168&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPB3DB389D-5C9A-451A-AF8F-2AD0259F2174&SSPV="

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}"

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.google.com"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Conduit Search Url="http://search.conduit.com/Results.aspx?ctid=CT3322168&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB3DB389D-5C9A-451A-AF8F-2AD0259F2174&q={searchTerms}&SSPV="

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

{B8DDA9AC-9549-4CA3-B801-5C53E73B44E0} eBay Url="http://rover.ebay.com/rover/1/1553-42507-16445-53/4?satitle={searchTerms}"

{DEC0E36E-AC34-44BD-91D6-4B53B96B8C8B} Zinio Url="http://services.zinio.com/search?s={searchTerms}&rf=sonyslices"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174} deleted successfully

HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411160} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411160} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\hmjdlbnelihabmidedpddnfhamfbcdpm deleted successfully

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie deleted successfully

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\christel\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\christel\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2629 folders=272 246587619 bytes)

==== Empty Temp Folders ======================

C:\Users\christel\AppData\Local\Temp will be emptied at reboot

C:\Users\Default\AppData\Local\Temp emptied successfully

C:\Users\Default User\AppData\Local\Temp emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\christel\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-bho64.dll" not found

"C:\PROGRA~2\BobyLyrics-16\BobyLyrics-16-buttonutil64.dll" not found

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

"C:\PROGRA~2\The weDownload Manager" not found

"C:\PROGRA~2\BobyLyrics-16" not found

==== EOF on zo 23/02/2014 at 18:58:26,60 ======================

Link naar reactie
Delen op andere sites

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Start 51a612a8b27e2-Zoek.pngZoek.exe nogmaals met het onderstaande script.


  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
     
    C:\Windows\Sysnative\Tasks\NCH Software;f
    C:\Users\christel\AppData\Locallow\BobyLyrics-16;fs
    C:\Users\christel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite;fs
    C:\Users\christel\AppData\Roaming\NCH Software;fs
    C:\ProgramData\NCH Software;fs
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite;fs
    [HKEY_USERS\S-1-5-21-2824171206-2023740141-987856411-1000\Software\Microsoft\Windows\CurrentVersion\Run];r64
    "NextLive"=-;r64
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
    "mobilegeni daemon"=-;r
    C:\Program Files (x86)\Mobogenie;fs
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]r64
    "NextLive"=-;r64
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
    "AppInit_DLLs"=-;r
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]r64
    "AppInit_DLLs"=-;r64
    autoclean; 
    


  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.