Ga naar inhoud

Internet loopt regelmatig vast door een script dat bezig is.


Aanbevolen berichten

Hallo,

Dit is mijn eerste bericht in dit forum, en ik hoop dat iemand mij kan helpen.

Tijdens het bezoeken van verschillende internet sites krijg ik zeer regelmatig een bericht waardoor internet geblokkeerd wordt.

Meestal krijg ik het volgende bericht:

"Script: chrome://bbrs_002.tb/content/witapi.js:529"

Soms ook deze:

"Een script op deze pagina is bezig, of het reageert niet meer. U kunt het script nu stoppen, of u kunt verdergaan om te zien of het script zal worden voltooid."

Weet iemand wat hier het probleem is en hoe ik dit kan oplossen?

InternetMarketer

Link naar reactie
Delen op andere sites

  • Reacties 83
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Welke browser gebruik je?

We zullen ook eens nagaan of malware of virussen de oorzaak zijn van je probleem.

1. Download HijackThis. (klik er op)

Klik op HijackThis.msi en de download start automatisch na 5 seconden.

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere pc en het bestand met een usb stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable (HijackThis.exe) downloaden.

Sla deze op in een nieuwe map op de C schijf (bvb C:\hijackthis) en start hijackthis dan vanaf deze map.

De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)


3. Na het plaatsen van je logje wordt dit door een expert (Kape of Kweezie Wabbit) nagekeken en begeleidt hij jou verder door het ganse proces.

Tip!

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.

Link naar reactie
Delen op andere sites

Ik gebruik Firefox en hieronder vind je de inhoud van de log:

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 18:37:52, on 23-10-2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16450)

Boot mode: Normal

Running processes:

C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe

C:\Program Files (x86)\SoMud\somud.exe

C:\Program Files (x86)\TechSmith\Jing\Jing.exe

C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Program Files (x86)\Sitecom\Common\RaUI.exe

C:\Program Files (x86)\WinZip\WZQKPICK.EXE

C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe

C:\Program Files (x86)\Google\Google Talk\googletalk.exe

C:\Program Files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe

C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe

C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe

C:\Program Files (x86)\Feed Notifier\notifier.exe

C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

C:\Program Files (x86)\BrowserCompanion\BCHelper.exe

C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Ask.com\Updater\Updater.exe

C:\Windows\SysWOW64\conime.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe

C:\Program Files (x86)\Internet Explorer\IELowutil.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=2&barid={4B45C800-58B1-11E1-A7DE-002421827688}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

R3 - URLSearchHook: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

R3 - URLSearchHook: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\SoMud Toolbar\tbhelper.dll

R3 - URLSearchHook: PHPNukeDU Toolbar - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

R3 - URLSearchHook: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

R3 - URLSearchHook: Serif WebPlus Toolbar - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

F2 - REG:system.ini: UserInit=userinit.exe

O1 - Hosts: ::1 localhost

O2 - BHO: script helper for ie - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Serif WebPlus - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

O2 - BHO: CrossriderApp0005060 - {11111111-1111-1111-1111-110011501160} - C:\Program Files (x86)\Savings Sidekick\Savings Sidekick.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Updater For Spam Free Search Bar - {20a0be68-8fd9-4539-8712-ce3d1c1fdfc6} - C:\Program Files (x86)\blekkotb\auxi\blekkoAu.dll

O2 - BHO: Ironsource LTD Helper Object - {25927741-5E5B-4D27-8D8B-9188FE64373F} - C:\Program Files (x86)\Ironsource\searchya\1.5.11.13\bh\searchya.dll

O2 - BHO: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll

O2 - BHO: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll

O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

O2 - BHO: PHPNukeDU - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

O2 - BHO: BrotherSoft Extreme - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

O2 - BHO: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\ToolBar\searchqudtx.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - C:\Program Files (x86)\Logia\eSnipsDownloader\eSnipsBHO.dll

O2 - BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O2 - BHO: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll

O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\SoMud Toolbar\tbcore3.dll

O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll

O3 - Toolbar: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

O3 - Toolbar: SoMud Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\SoMud Toolbar\tbcore3.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll

O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\ToolBar\searchqudtx.dll

O3 - Toolbar: PHPNukeDU Toolbar - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

O3 - Toolbar: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

O3 - Toolbar: Serif WebPlus Toolbar - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

O3 - Toolbar: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

O3 - Toolbar: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O3 - Toolbar: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll

O3 - Toolbar: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll

O3 - Toolbar: SearchYa Toolbar - {33AA308B-B565-4376-AC66-59EE9B6AD13E} - C:\Program Files (x86)\Ironsource\searchya\1.5.11.13\searchyaTlbr.dll

O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (file missing)

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"

O4 - HKLM\..\Run: [siteAdvisor] "C:\Program Files (x86)\SiteAdvisor\6172\SiteAdv.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe

O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"

O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart

O4 - HKLM\..\Run: [eSnips_Downloader] "C:\Program Files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe" -startup

O4 - HKLM\..\Run: [babylonToolbar] "C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I

O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE

O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [searchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

O4 - HKLM\..\Run: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [sweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

O4 - HKLM\..\Run: [browser companion helper] "C:\Program Files (x86)\BrowserCompanion\BCHelper.exe" /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej

O4 - HKLM\..\Run: [azontop100analyzer] "C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [soMud] "C:\Program Files (x86)\SoMud\somud.exe" /bg

O4 - HKCU\..\Run: [EPSON SX218 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_SE15.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Greenshot] "C:\Program Files (x86)\Greenshot\Greenshot.exe"

O4 - HKCU\..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [Grammar.net’s Grammar Checker] C:\Program Files (x86)\Grammar.net’s Grammar Checker\GrammarChecker.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: Dropbox.lnk = C:\Users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe

O4 - Startup: Feed Notifier.lnk = C:\Program Files (x86)\Feed Notifier\notifier.exe

O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: OpenOffice.org 3.2 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

O4 - Global Startup: ASETRES.EXE

O4 - Global Startup: Empowering Technology Launcher.lnk = ?

O4 - Global Startup: McAfee Security Scan Plus.lnk = ?

O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files (x86)\Sitecom\Common\RaUI.exe

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: Download Web &Images with SoMud - C:\Program Files (x86)\SoMud\scripts\ie\images-url.html

O8 - Extra context menu item: Download with SoMud - C:\Program Files (x86)\SoMud\scripts\ie\link-url.html

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - AppInit_DLLs: C:\PROGRA~2\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: McAfee Application Installer Cleanup (0148221350970653) (0148221350970653mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\014822~1.EXE

O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe

O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe

O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe

O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe

O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE

O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: RoboSoft Database Server (RSDBServerService) - Rudenko Software - C:\Program Files (x86)\RoboSoft4\RSDBServer.exe

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: SiteAdvisor-service (SiteAdvisor Service) - Unknown owner - C:\Program Files (x86)\SiteAdvisor\6172\SAService.exe

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 24050 bytes

Link naar reactie
Delen op andere sites

Je hebt wel een heleboel rotzooi en nutteloze troep op je pc staan hoor.

Geen wonder dat internet vastloopt.

Ga naar start - alle programma's - bureauaccesoires.

Zoek het icoon van het opdrachtprompt en klik er op met de rechter muisknop en kies dan in het lijstje voor uitvoeren als administrator om het opdrachtprompt te openen.

Tik in: sc stop 0148221350970653mcinstcleanup en druk op Enter.

Tik in: sc delete 0148221350970653mcinstcleanup en druk op Enter.

Tik in exit en druk Enter.

Als je op een van deze instructies een foutmelding krijgt, ga dan gewoon door met de volgende instructie.

Klik met de rechter muisknop op de icoon van Hijackthis en kies dan voor “Run as administrator" of "Uitvoeren als administrator".

Selecteer “Do a system scan only”.

Vink alleen de items aan die hieronder zijn genoemd:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=2&barid={4B45C800-58B1-11E1-A7DE-002421827688}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Analysis of program downloads scanned for viruses and spyware.

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

R3 - URLSearchHook: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

R3 - URLSearchHook: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\SoMud Toolbar\tbhelper.dll

R3 - URLSearchHook: PHPNukeDU Toolbar - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

R3 - URLSearchHook: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

R3 - URLSearchHook: Serif WebPlus Toolbar - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

O2 - BHO: script helper for ie - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Serif WebPlus - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

O2 - BHO: CrossriderApp0005060 - {11111111-1111-1111-1111-110011501160} - C:\Program Files (x86)\Savings Sidekick\Savings Sidekick.dll

O2 - BHO: Updater For Spam Free Search Bar - {20a0be68-8fd9-4539-8712-ce3d1c1fdfc6} - C:\Program Files (x86)\blekkotb\auxi\blekkoAu.dll

O2 - BHO: Ironsource LTD Helper Object - {25927741-5E5B-4D27-8D8B-9188FE64373F} - C:\Program Files (x86)\Ironsource\searchya\1.5.11.13\bh\searchya.dll

O2 - BHO: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll

O2 - BHO: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll

O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

O2 - BHO: PHPNukeDU - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

O2 - BHO: BrotherSoft Extreme - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

O2 - BHO: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\ToolBar\searchqudtx.dll

O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll

O2 - BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O2 - BHO: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll

O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\SoMud Toolbar\tbcore3.dll

O3 - Toolbar: Softonic Netherlands Toolbar - {65ca59ee-9920-4d7f-8c41-bfa12403261a} - C:\Program Files (x86)\Softonic_Netherlands\tbSoft.dll

O3 - Toolbar: SoMud Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\SoMud Toolbar\tbcore3.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll

O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\ToolBar\searchqudtx.dll

O3 - Toolbar: PHPNukeDU Toolbar - {46735dee-f862-49d1-876d-6382794dc625} - C:\Program Files (x86)\PHPNukeDU\prxtbPHPN.dll

O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll

O3 - Toolbar: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBro0.dll

O3 - Toolbar: Serif WebPlus Toolbar - {07364a98-eb02-4736-bc54-ebe437fccb87} - C:\Program Files (x86)\Serif__WebPlus\prxtbSeri.dll

O3 - Toolbar: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.7\youtubedownloaderToolbarIE.dll

O3 - Toolbar: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O3 - Toolbar: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll

O3 - Toolbar: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll

O3 - Toolbar: SearchYa Toolbar - {33AA308B-B565-4376-AC66-59EE9B6AD13E} - C:\Program Files (x86)\Ironsource\searchya\1.5.11.13\searchyaTlbr.dll

O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (file missing)

O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O4 - HKLM\..\Run: [babylonToolbar] "C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I

O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE

O4 - HKLM\..\Run: [searchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

O4 - HKLM\..\Run: [browser companion helper] "C:\Program Files (x86)\BrowserCompanion\BCHelper.exe" /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej

O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"

O4 - Global Startup: McAfee Security Scan Plus.lnk = ?

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll

O20 - AppInit_DLLs: C:\PROGRA~2\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI371A~1\Datamngr\IEBHO.dll

Klik op 'Fix checked' om de items te verwijderen.

Verwijder het programma Ask.com via Software (indien aanwezig) of verwijder anders volgende vetgedrukte map : C:\Program Files (x86)\Ask.com

Download MBAM (Malwarebytes Anti-Malware)

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.

MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.

Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken.

Daarna zal het vragen om de computer opnieuw op te starten... Dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.

Link naar reactie
Delen op andere sites

Ik heb twee log bestanden in Malwarebytes.

Ik heb een nieuwe scan gedaan in HijackThis en de inhoud van de nieuwe log hieronder geplakt.

Hieronder de inhoud van deze bestanden en van het nieuwe HijackThis log:

Malwarebytes bestand 1:

------------------------

Malwarebytes Anti-Malware (-evaluatieversie-) 1.65.1.1000

Malwarebytes : Free anti-malware download

Databaseversie: v2012.10.24.01

Windows Vista Service Pack 2 x64 NTFS

Internet Explorer 9.0.8112.16421

acer m3641 :: PC_VAN_ACERM364 [administrator]

Realtime bescherming: Ingeschakeld

24-10-2012 9:14:10

mbam-log-2012-10-24 (09-14-10).txt

Scantype: Snelle scan

Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scanopties: P2P

Objecten gescand: 246595

Verstreken tijd: 5 minuut/minuten, 38 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 25

HKCR\CLSID\{33AA308B-B565-4376-AC66-59EE9B6AD13E} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\Babylon.dskBnd.1 (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\Babylon.dskBnd (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\ironsource.searchyadskBnd.1 (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\ironsource.searchyadskBnd (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{33AA308B-B565-4376-AC66-59EE9B6AD13E} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{33AA308B-B565-4376-AC66-59EE9B6AD13E} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{25927741-5E5B-4D27-8D8B-9188FE64373F} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25927741-5E5B-4D27-8D8B-9188FE64373F} (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4} (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7647A02C-1158-4DA9-A467-507550047B35} (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7647A02C-1158-4DA9-A467-507550047B35} (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

Registerwaarden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 20

C:\ProgramData\TheBflix (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\data (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\acer m3641\AppData\Roaming\HBLite (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\HBLiteSA (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\acer m3641\AppData\Roaming\ShopperReports3 (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite\bin (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite\bin\11.0.349.0 (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite\bin\11.0.349.0\firefox (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite\bin\11.0.349.0\firefox\extensions (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3 (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0 (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\chrome\content (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

Bestanden gedetecteerd: 27

C:\Program Files (x86)\Ironsource\searchya\1.5.11.13\searchyaTlbr.dll (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (PUP.SearchYa) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\background.html (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\ajhcekcffkpnaednoeoegnmnjdlnjjmg.crx (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\content.js (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\settings.ini (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\uninstall.exe (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\data\content.js (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\TheBflix\data\jsondb.js (PUP.BFlix) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\blabbers-ff-full.xpi (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\BCHelper.exe (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\logo.ico (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\sqlite3.dll (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\toolbar.dll (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\uninstall.exe (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\updater.ini (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\BrowserCompanion\widgetserv.exe (PUP.Blabbers) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\HBLiteSA\HBLiteSAAbout.mht (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\ProgramData\HBLiteSA\HBLiteSAEULA.mht (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\HBLite\bin\11.0.349.0\firefox\extensions\install.rdf (Adware.Hotbar) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.xpt (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt (Adware.ShopperReports) -> Succesvol in quarantaine geplaatst en verwijderd.

(einde)

Malwarebytes bestand 2:

-------------------------

2012/10/24 09:10:43 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting protection

2012/10/24 09:10:43 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Protection started successfully

2012/10/24 09:10:43 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting IP protection

2012/10/24 09:10:48 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE IP Protection started successfully

2012/10/24 09:10:57 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting database refresh

2012/10/24 09:10:57 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Stopping IP protection

2012/10/24 09:10:57 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE IP Protection stopped successfully

2012/10/24 09:11:00 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Database refreshed successfully

2012/10/24 09:11:00 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting IP protection

2012/10/24 09:11:04 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE IP Protection started successfully

2012/10/24 09:11:48 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 207.232.22.60 (Type: outgoing, Port: 50473, Process: avastsvc.exe)

2012/10/24 09:12:12 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 207.232.22.60 (Type: outgoing, Port: 50501, Process: avastsvc.exe)

2012/10/24 09:22:22 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 178.90.90.169 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:25:53 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 58.241.9.30 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:26:01 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 222.71.82.205 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:27:55 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 109.230.220.234 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:29:25 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 222.65.40.129 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:32:24 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 218.8.129.169 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:37:00 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 178.90.90.169 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:43:23 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 94.102.51.136 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:46:32 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 93.174.91.131 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:52:04 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 178.90.90.169 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 09:56:18 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting protection

2012/10/24 09:56:18 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Protection started successfully

2012/10/24 09:56:18 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE Starting IP protection

2012/10/24 09:56:22 +0200 PC_VAN_ACERM364 acer m3641 MESSAGE IP Protection started successfully

2012/10/24 09:58:59 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 213.55.114.173 (Type: outgoing, Port: 49277, Process: somud.exe)

2012/10/24 10:00:22 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 207.232.22.60 (Type: outgoing, Port: 49470, Process: avastsvc.exe)

2012/10/24 10:02:48 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 89.28.31.195 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 10:04:33 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 89.28.48.37 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 10:05:13 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 91.188.37.36 (Type: outgoing, Port: 6881, Process: somud.exe)

2012/10/24 10:06:09 +0200 PC_VAN_ACERM364 acer m3641 IP-BLOCK 77.78.201.34 (Type: outgoing, Port: 6881, Process: somud.exe)

HijackThis bestand:

-------------------

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 10:12:11, on 24-10-2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16450)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\SoMud\somud.exe

C:\Program Files (x86)\TechSmith\Jing\Jing.exe

C:\Program Files (x86)\Sitecom\Common\RaUI.exe

C:\Program Files (x86)\WinZip\WZQKPICK.EXE

C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe

C:\Program Files (x86)\Google\Google Talk\googletalk.exe

C:\Program Files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

C:\Users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Feed Notifier\notifier.exe

C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

C:\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe

C:\Windows\SysWOW64\conime.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

F2 - REG:system.ini: UserInit=userinit.exe,

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - C:\Program Files (x86)\Logia\eSnipsDownloader\eSnipsBHO.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"

O4 - HKLM\..\Run: [siteAdvisor] "C:\Program Files (x86)\SiteAdvisor\6172\SiteAdv.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe

O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"

O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart

O4 - HKLM\..\Run: [eSnips_Downloader] "C:\Program Files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe" -startup

O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [sweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe

O4 - HKLM\..\Run: [azontop100analyzer] "C:\Program Files (x86)\AzonTop100Analyzer\azontop100analyzer.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [soMud] "C:\Program Files (x86)\SoMud\somud.exe" /bg

O4 - HKCU\..\Run: [EPSON SX218 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_SE15.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Greenshot] "C:\Program Files (x86)\Greenshot\Greenshot.exe"

O4 - HKCU\..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [Grammar.net’s Grammar Checker] C:\Program Files (x86)\Grammar.net’s Grammar Checker\GrammarChecker.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: Dropbox.lnk = C:\Users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe

O4 - Startup: Feed Notifier.lnk = C:\Program Files (x86)\Feed Notifier\notifier.exe

O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: OpenOffice.org 3.2 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

O4 - Global Startup: ASETRES.EXE

O4 - Global Startup: Empowering Technology Launcher.lnk = ?

O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files (x86)\Sitecom\Common\RaUI.exe

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: Download Web &Images with SoMud - C:\Program Files (x86)\SoMud\scripts\ie\images-url.html

O8 - Extra context menu item: Download with SoMud - C:\Program Files (x86)\SoMud\scripts\ie\link-url.html

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe

O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe

O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe

O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe

O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE

O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: RoboSoft Database Server (RSDBServerService) - Rudenko Software - C:\Program Files (x86)\RoboSoft4\RSDBServer.exe

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: SiteAdvisor-service (SiteAdvisor Service) - Unknown owner - C:\Program Files (x86)\SiteAdvisor\6172\SAService.exe

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 16006 bytes

Link naar reactie
Delen op andere sites

Dit ziet er al heel wat beter uit :-)

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

Klik hier

2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.

3. Dubbelklik op "Combofix.exe" om de tool te starten.

4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion", herstart dan de computer.

5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

ComboFix 12-10-24.01 - acer m3641 24-10-2012 16:54:42.1.4 - x64

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.4094.2497 [GMT 2:00]

Gestart vanuit: c:\users\acer m3641\Downloads\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\progra~2\SPINWR~1\SPINwr~1.exe

c:\program files (x86)\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

c:\program files (x86)\Savings Sidekick

c:\program files (x86)\Savings Sidekick\Savings Sidekick-bg.exe

c:\program files (x86)\Savings Sidekick\Savings Sidekick.exe

c:\program files (x86)\Savings Sidekick\Savings Sidekick.ico

c:\program files (x86)\Savings Sidekick\Savings Sidekick.ini

c:\program files (x86)\Savings Sidekick\Savings SidekickInstaller.log

c:\program files (x86)\Savings Sidekick\Uninstall.exe

c:\program files (x86)\SoMud Toolbar\tbHElper.dll

c:\programdata\100

c:\users\acer m3641\AppData\Local\Savings Sidekick

c:\users\acer m3641\AppData\Local\Savings Sidekick\Chrome\Savings Sidekick.crx

c:\users\acer m3641\AppData\Roaming\.#

c:\users\acer m3641\AppData\Roaming\.#\MBX@BF8@3A2990.###

c:\users\acer m3641\AppData\Roaming\.#\MBX@BF8@3A29C0.###

c:\users\acer m3641\AppData\Roaming\.#\MBX@BF8@3A29F0.###

c:\users\acer m3641\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk

c:\users\acer m3641\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3 .lnk

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\chrome.manifest

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\arwDwn.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ae.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\bg.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ch.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\cn.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\cz.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\de.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\eg.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\en.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\es.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\fr.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\gr.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\he.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\il.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\it.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ja.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\jp.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\nl.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\no.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\pl.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\pt.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ro.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ru.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\sa.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\se.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\sv.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\tr.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\ua.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\flgs\us.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\help_16.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\home.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\icon_seperator.png

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\logo.PNG

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\privecy_16_hot.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\specialoffer.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\imgs\tellafriend.gif

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\mtstart.js

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\searchya.css

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\searchya.xul

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\content\tmplt.js

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\extensions\ffxtlbr@searchya.com\install.rdf

c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\searchplugins\SearchquWebSearch.xml

c:\users\acer m3641\AppData\Roaming\ubot

c:\users\acer m3641\g2mdlhlpx.exe

D:\install.exe

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-09-24 to 2012-10-24 ))))))))))))))))))))))))))))))

.

.

2012-10-24 15:23 . 2012-10-24 15:23 -------- d-----w- c:\users\Evert\AppData\Local\temp

2012-10-24 15:23 . 2012-10-24 15:23 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-10-24 15:23 . 2012-10-24 15:23 -------- d-----w- c:\users\acer m3641\AppData\Local\temp

2012-10-24 14:48 . 2012-10-24 14:49 -------- d-----w- C:\32788R22FWJFW

2012-10-24 08:22 . 2012-10-24 08:22 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28EE2000-10E4-4061-B972-0BBCBEB6B0AD}\offreg.dll

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\users\acer m3641\AppData\Roaming\Malwarebytes

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\programdata\Malwarebytes

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-10-24 07:10 . 2012-09-29 17:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-10-23 16:33 . 2012-10-23 16:33 388096 ----a-r- c:\users\acer m3641\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-10-23 16:33 . 2012-10-23 16:33 -------- d-----w- c:\program files (x86)\Trend Micro

2012-10-23 14:29 . 2012-10-17 00:31 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28EE2000-10E4-4061-B972-0BBCBEB6B0AD}\mpengine.dll

2012-10-19 15:40 . 2012-10-19 15:40 -------- d-----w- c:\programdata\Ask

2012-10-19 15:38 . 2012-09-24 21:16 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-11 05:35 . 2012-10-20 07:25 12872 ----a-w- c:\windows\system32\bootdelete.exe

2012-10-10 05:10 . 2012-09-13 13:45 2048 ----a-w- c:\windows\system32\tzres.dll

2012-10-10 05:10 . 2012-09-13 13:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-10-10 05:10 . 2012-08-24 16:07 218624 ----a-w- c:\windows\system32\wintrust.dll

2012-10-10 05:10 . 2012-08-24 15:53 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-10-10 05:10 . 2012-06-02 00:20 1268736 ----a-w- c:\windows\system32\crypt32.dll

2012-10-10 05:10 . 2012-06-02 00:20 174592 ----a-w- c:\windows\system32\cryptsvc.dll

2012-10-10 05:10 . 2012-06-02 00:20 132096 ----a-w- c:\windows\system32\cryptnet.dll

2012-10-10 05:10 . 2012-06-02 00:02 985088 ----a-w- c:\windows\SysWow64\crypt32.dll

2012-10-10 05:10 . 2012-06-02 00:02 133120 ----a-w- c:\windows\SysWow64\cryptsvc.dll

2012-10-10 05:10 . 2012-06-02 00:02 98304 ----a-w- c:\windows\SysWow64\cryptnet.dll

2012-10-10 05:10 . 2012-08-29 11:40 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-10-09 08:16 . 2012-10-09 08:16 -------- d-----w- c:\program files (x86)\Market Samurai

2012-10-04 08:36 . 2012-10-24 06:54 -------- d-----w- c:\programdata\webex

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-10-11 05:12 . 2006-11-02 12:35 65309168 ----a-w- c:\windows\system32\mrt.exe

2012-10-09 09:23 . 2012-04-11 08:48 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-10-09 09:23 . 2011-10-22 05:46 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-09-10 18:35 . 2012-09-10 18:36 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-09-10 18:35 . 2010-09-13 17:32 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-08-24 11:15 . 2012-09-23 06:59 17810944 ----a-w- c:\windows\system32\mshtml.dll

2012-08-24 10:39 . 2012-09-23 06:59 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-08-24 10:31 . 2012-09-23 07:00 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-08-24 10:22 . 2012-09-23 07:00 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-08-24 10:21 . 2012-09-23 07:00 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-08-24 10:20 . 2012-09-23 07:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-08-24 10:18 . 2012-09-23 07:00 237056 ----a-w- c:\windows\system32\url.dll

2012-08-24 10:17 . 2012-09-23 07:00 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-08-24 10:14 . 2012-09-23 07:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-08-24 10:14 . 2012-09-23 07:00 816640 ----a-w- c:\windows\system32\jscript.dll

2012-08-24 10:13 . 2012-09-23 07:00 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-08-24 10:12 . 2012-09-23 07:00 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-08-24 10:11 . 2012-09-23 07:00 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-08-24 10:10 . 2012-09-23 07:00 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-08-24 10:09 . 2012-09-23 07:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-08-24 10:04 . 2012-09-23 07:00 248320 ----a-w- c:\windows\system32\ieui.dll

2012-08-24 06:59 . 2012-09-23 07:00 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-08-24 06:51 . 2012-09-23 07:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-08-24 06:51 . 2012-09-23 07:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-08-24 06:47 . 2012-09-23 07:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-08-24 06:47 . 2012-09-23 07:00 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-08-24 06:43 . 2012-09-23 07:00 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-08-21 09:13 . 2011-11-02 08:24 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys

2012-08-21 09:13 . 2011-11-02 08:24 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2012-08-21 09:13 . 2011-11-02 08:24 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2012-08-21 09:13 . 2011-11-02 08:24 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2012-08-21 09:13 . 2011-11-02 08:24 44272 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2012-08-21 09:13 . 2011-11-02 08:24 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2012-08-21 09:12 . 2011-11-02 08:24 41224 ----a-w- c:\windows\avastSS.scr

2012-08-21 09:12 . 2011-11-02 08:24 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe

2012-08-21 09:12 . 2011-02-10 10:48 285328 ----a-w- c:\windows\system32\aswBoot.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2008-03-04 21:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]

"SoMud"="c:\program files (x86)\SoMud\somud.exe" [2011-06-28 3888128]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-12 68856]

"Greenshot"="c:\program files (x86)\Greenshot\Greenshot.exe" [2010-07-12 548864]

"Jing"="c:\program files (x86)\TechSmith\Jing\Jing.exe" [2012-02-01 2918224]

"Grammar.net’s Grammar Checker"="c:\program files (x86)\Grammar.net’s Grammar Checker\GrammarChecker.exe" [2012-06-18 73216]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]

"SiteAdvisor"="c:\program files (x86)\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-25 98304]

"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]

"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]

"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"eSnips_Downloader"="c:\program files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe" [2010-05-24 1234432]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-12-21 206504]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

"SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]

"azontop100analyzer"="c:\program files (x86)\AzonTop100Analyzer\azontop100analyzer.exe" [2012-06-09 44474097]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

c:\users\Evert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OpenOffice.org 3.4.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-4-19 1199104]

.

c:\users\acer m3641\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

Feed Notifier.lnk - c:\program files (x86)\Feed Notifier\notifier.exe [2012-7-24 58368]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

ASETRES.EXE [2008-4-14 20480]

Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-9-23 535336]

Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\RaUI.exe [2010-6-3 1773568]

WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2010-11-30 608584]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36CrusaderBoot]

@=""

.

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]

S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 269448]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]

.

.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

Themes

.

Inhoud van de 'Gedeelde Taken' map

.

2012-10-24 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 09:23]

.

2012-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-05 07:29]

.

2012-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-05 07:29]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]

2012-03-15 21:26 287048 ----a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-08-21 09:11 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2008-03-04 21:39 51248 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvSvc"="c:\windows\system32\nvsvc64.dll" [2007-11-27 88064]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-27 10721312]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-27 74752]

"RtHDVCpl"="RAVCpl64.exe" [2008-03-25 6150656]

"Skytel"="Skytel.exe" [2007-11-20 1826816]

"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-03-04 560688]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-06-06 333344]

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uDefault_Search_URL = hxxp://www.google.com/ie

mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=1&o=vp64&d=1109&m=aspire_m3641

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Download Web &Images with SoMud - c:\program files (x86)\SoMud\scripts\ie\images-url.html

IE: Download with SoMud - c:\program files (x86)\SoMud\scripts\ie\link-url.html

IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1 192.168.1.1

FF - ProfilePath - c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine - Ask.com

FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/

FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=406&q=

FF - prefs.js: network.proxy.gopher -

FF - prefs.js: network.proxy.gopher_port - 0

FF - prefs.js: network.proxy.type - 0

FF - ExtSQL: 2012-10-24 09:58; {4ED1F68A-5463-4931-9384-8FFF5ED91D92}; c:\program files (x86)\McAfee\SiteAdvisor

FF - ExtSQL: !HIDDEN! 2010-06-06 09:50; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - ExtSQL: !HIDDEN! 2012-03-10 10:49; 5affxtbr@MyWebFace_5a.com; c:\program files (x86)\MyWebFace_5a\bar\1.bin

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(extensions.searchya_i.hmpg, true

FF - user.js: extensions.searchya_i.hmpgUrl - hxxp://searchya.com/?chnl=fap&s=0&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz

FF - user.js: extensions.searchya_i.dfltSrch - true

FF - user.js: extensions.searchya_i.srchPrvdr - SearchYa!

FF - user.js: extensions.searchya_i.dnsErr - true

FF - user.js: extensions.searchya_i.newTab - true

FF - user.js: extensions.searchya_i.newTabUrl - hxxp://searchya.com/?chnl=fap&s=2&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz

FF - user.js: extensions.searchya_i.tlbrSrchUrl - hxxp://searchya.com/?chnl=fap&s=3&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz&q=

FF - user.js: extensions.searchya_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.searchya_i.instlDay - 15378

FF - user.js: extensions.searchya_i.vrsn - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsni - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsnTs - 1.5.11.1316:16

FF - user.js: extensions.searchya_i.prtnrId - ironsrc

FF - user.js: extensions.searchya_i.prdct - searchya

FF - user.js: extensions.searchya_i.aflt - foxtab

FF - user.js: extensions.searchya_i.smplGrp - none

FF - user.js: extensions.searchya_i.tlbrId - base

FF - user.js: extensions.searchya_i.instlRef - fap

FF - user.js: extensions.searchya_i.dfltLng -

FF - user.js: extensions.searchya_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.hardId - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15400

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:41

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101241

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-10 - (no file)

Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe

Wow6432Node-HKLM-Run-eRecoveryService - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

Toolbar-10 - (no file)

WebBrowser-{65CA59EE-9920-4D7F-8C41-BFA12403261A} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

AddRemove-Allscoop RSS Submit Pro 1.0 - c:\windows\system32\ss2uinst.exe

AddRemove-InstallBrain Updater Service - c:\programdata\InstallBrainService\ibsvc.exe

AddRemove-Savings Sidekick - c:\program files (x86)\Savings Sidekick\Uninstall.exe

AddRemove-FoxTab PDF Creator - c:\program files (x86)\FoxTabPDFConverter\Uninstall\Uninstall.exe

AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files (x86)\Ask.com\Updater\Updater.exe

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Voltooingstijd: 2012-10-24 17:34:33

ComboFix-quarantined-files.txt 2012-10-24 15:34

.

Pre-Run: 201.533.083.648 bytes beschikbaar

Post-Run: 201.306.521.600 bytes beschikbaar

.

- - End Of File - - 72412980ADA6CF142E41C66432334121

Link naar reactie
Delen op andere sites

Open een nieuw kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

C:\32788R22FWJFW

c:\programdata\Ask

C:\Program Files (x86)\Ask.com

C:\Program Files (x86)\BrowserCompanion

C:\Program Files (x86)\PHPNukeDU

C:\Program Files (x86)\ConduitEngine

C:\Program Files (x86)\BabylonToolbar

C:\Program Files (x86)\Savings Sidekick

C:\PROGRA~2\WI371A~1

Firefox::

FF - ProfilePath - c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\

FF - prefs.js: browser.search.selectedEngine - Ask.com

FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=406&q=

FF - ExtSQL: !HIDDEN! 2012-03-10 10:49; 5affxtbr@MyWebFace_5a.com; c:\program files (x86)\MyWebFace_5a\bar\1.bin

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(extensions.searchya_i.hmpg, true

FF - user.js: extensions.searchya_i.hmpgUrl - hxxp://searchya.com/?chnl=fap&s=0&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtB tDzz

FF - user.js: extensions.searchya_i.dfltSrch - true

FF - user.js: extensions.searchya_i.srchPrvdr - SearchYa!

FF - user.js: extensions.searchya_i.dnsErr - true

FF - user.js: extensions.searchya_i.newTab - true

FF - user.js: extensions.searchya_i.newTabUrl - hxxp://searchya.com/?chnl=fap&s=2&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtB tDzz

FF - user.js: extensions.searchya_i.tlbrSrchUrl - hxxp://searchya.com/?chnl=fap&s=3&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtB tDzz&q=

FF - user.js: extensions.searchya_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.searchya_i.instlDay - 15378

FF - user.js: extensions.searchya_i.vrsn - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsni - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsnTs - 1.5.11.1316:16

FF - user.js: extensions.searchya_i.prtnrId - ironsrc

FF - user.js: extensions.searchya_i.prdct - searchya

FF - user.js: extensions.searchya_i.aflt - foxtab

FF - user.js: extensions.searchya_i.smplGrp - none

FF - user.js: extensions.searchya_i.tlbrId - base

FF - user.js: extensions.searchya_i.instlRef - fap

FF - user.js: extensions.searchya_i.dfltLng -

FF - user.js: extensions.searchya_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.hardId - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15400

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:41

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101241

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

Sla dit bestand op je bureaublad op als CFScript

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht

Link naar reactie
Delen op andere sites

ComboFix 12-10-24.02 - acer m3641 25-10-2012 7:50.2.4 - x64

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.4094.2618 [GMT 2:00]

Gestart vanuit: c:\users\acer m3641\Downloads\ComboFix.exe

gebruikte Opdracht switches :: c:\users\acer m3641\Desktop\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\progra~2\WI371A~1

c:\progra~2\WI371A~1\Datamngr\datamngr.dll

c:\progra~2\WI371A~1\Datamngr\datamngrUI.exe

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\chrome.manifest

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\components\DataMngrHlp.dll

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\components\DataMngrHlp.xpt

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\content\DataMngr.js

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\content\FFBHO.js

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\content\overlay.js

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\content\overlay.xul

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\content\Settings.xml

c:\progra~2\WI371A~1\Datamngr\FirefoxExtension\install.rdf

c:\progra~2\WI371A~1\Datamngr\x64\datamngrUI.exe

c:\progra~2\WI371A~1\ToolBar\as_guid.dat

c:\progra~2\WI371A~1\ToolBar\chrome\content\bandoocode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\data\search\engines.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\data\search\search.xsl

c:\progra~2\WI371A~1\ToolBar\chrome\content\imeshcode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\about.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\bandoocode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\dtxpanel.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\dtxpanelwin.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\dtxprefwin.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\dtxtransparentwin.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\dtxwin.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\emailnotifierproviders.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\external.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\imeshcode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\neterror.xhtml

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\nsDragAndDrop.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\vmncode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\lib\wmpstreamer.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\modules\datastore.jsm

c:\progra~2\WI371A~1\ToolBar\chrome\content\neterror.xhtml

c:\progra~2\WI371A~1\ToolBar\chrome\content\partner.coupons.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\preferences.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\radiobeta.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\template.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\toolbar.htm

c:\progra~2\WI371A~1\ToolBar\chrome\content\toolbar.xul

c:\progra~2\WI371A~1\ToolBar\chrome\content\vmncode.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\vmnrsswin.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\alert_coupon.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next-off.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous-off.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-coupon-blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-save.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-getcoupon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-next-blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-previous-blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\coupon-activated.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\couponTooltip.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css\ie7style.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-coupon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-dollar.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrow-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-left.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-right.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\bg_top.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-back.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-getcoupon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\coupon-activated.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\delete.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\loader.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollb.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\scrollt.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\sprite.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow-hover.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-arrow.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-l_BAK.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-off-r_BAK.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-over-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\tab-white-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images\vid-bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\index.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\jquery.contextMenu.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery-1.4.2.min.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.event.wheel.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\jquery.scrollTo-min.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\JSON.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\listnav.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js\main.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\page_white_copy.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\panel.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\partner.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\placeholder-logo.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\default.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\transparent.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right-resize.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\win-btm-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\main.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts\defscript.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\tb_icon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.jsw

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\widget_version.txt

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrow-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-left.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-right.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\back.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\delete.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollb.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\scrollt.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow-hover.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-arrow.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-over-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-red-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\tab-white-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\vid-bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\youtube.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\index.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\function.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\jquery-1.4.2.min.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js\JSON.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\bg-facebook.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\blank.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\default.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\transparent.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right-resize.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\win-btm-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\main.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\defscript.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts\jquery-1.4.2.min.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\tb_icon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.jsw

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\widget_version.txt

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\tb_icon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully\widget_version

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\css\twitter.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-login-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-login.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\btn-submit.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\loginbg.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\refresh-over.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\refresh.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrollbottom.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\scrolltop.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\twitter-logo48.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images\twitter_top.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js\jquery.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js\scripts.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\bg.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\default.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\transparent.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-right-resize.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images\win-btm-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\main.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts\defscript.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\tb_icon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\widget_version.txt

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css\autocomplete.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrow-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-left.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-right.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\bg.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\powered-by-youtube.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-red-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\tab-white-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\vid-bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images\youtube.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\index.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\autocomplete.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\jquery-1.4.3.min.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\paginator.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js\youtube.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\bg.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\default.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\transparent.gif

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right-resize.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\win-btm-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\main.html

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts\defscript.js

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\tb_icon.png

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.jsw

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget.xml

c:\progra~2\WI371A~1\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\widget_version.txt

c:\progra~2\WI371A~1\ToolBar\chrome\skin\babylon_logo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\bandoo.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\bluelite.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\bluesky.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-search-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-settings-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-settings.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-widgets-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn-widgets.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\btn_settings.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\ca.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\dictionary.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\divider.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\downloadcom.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\dtxlogo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\ebay.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\email.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\email_on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\facebook.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\games.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred0.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred0_5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred1.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred1_5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred2.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred2_5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred3.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred3_5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred4.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred4_5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphred5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\graphredna.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\grey.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\ico-shield.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\icon_radio_png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\icon_seperator_png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\images.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\imesh.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\add.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\aol.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\arrow-dn.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\arrow-right-disabled.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\arrow-right.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\arrow-up.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btn-divider.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btn-end.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btn-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btn-mdl_ff.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btn-start.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btnover-divider.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btnover-end.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btnover-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btnover-mdl_ff.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\bg-btnover-start.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\blank.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btn-widgets-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btn-widgets.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btn_slider.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnback-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnback-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnleft-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnleft-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnright-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\btnright-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\button-splitter-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\button-splitter-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\checkmark.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\chevron.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\collapse.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\comcast.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\dtx.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\edit-back-hot.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\edit-back.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\expand.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\found.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\gmail.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight_blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight_cyan.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight_lime.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight_magenta.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\highlight_yellow.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\hotmail.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\ico-check.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\imap.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\lastsearch-thumb-back.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\loadingMid.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\lock.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\logo-separator.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\mailcom.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menu_bg-basic.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menu_separator_bar.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menu_separator_white.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitem-splitter.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemback-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemback-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemleft-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemleft-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemright-down-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\menuitemright-vista.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\modify.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\move.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\movetarget.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\css\panels.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\css\popupAbout.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\css\popupGames.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\css\popupRSS.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\css\popupWidgets.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\css\dialog.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\bg.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\btn-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\btn-wide-close.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\default.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\tab-off-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\tab-off-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\tab-on-l.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\tab-on-r.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\transparent.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\ttlbar-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right-resize.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-btm-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\images\win-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\main.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\default\scripts\defscript.js

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\footer.htm

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\gamecategory.xsl

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\gameData.js

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\gameList.xsl

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\games.xsl

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\gametype.xsl

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\arrow-dn.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\arrow-sml-drop.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\arrow-sml.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\arrow-up.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\arrowr-bluew5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\bg-aboutbox.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\bg-btnover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\bg-pnl520x390.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-addtoolbar-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-back.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-close-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-close-greyover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-drag.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-mdl-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-mdl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-moredetails.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-next-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-next.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-play-left-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-play-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-previous-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-previous.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-right-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-try-left-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\btn-try-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\bullet-orange.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\gamethumb-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\gamethumb2-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-calendar.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-dollar.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-download.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-joystick24.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-news24.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-play.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\ico-tags.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\icon-Add.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\icon-download.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\icon-Info.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\icon-play.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\icon-shop.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\menul-bgon.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\menul-bgover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\panel-botm-noscroll.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scroll-bg-206.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scroll-bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scroll-topwin.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollb-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollb-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollb-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollb.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollt-disable.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollt-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollt-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\scrollt.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\star_x_grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\star_x_orange.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\TRUSTe_about.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\view-detailed-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\view-detailed-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\view-thumb-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\view-thumb-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\widgets-square-16px.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\widgets-square-24px.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\images\widgets.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\initHTML.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\popupGames.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\popupHTML.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\popupRSS.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\popupWidgets.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\panels\scroll.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\pop.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\css\manager.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\css\slider.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\bg-pnl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\btn-close-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\btn-close-greyover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\collapsed_button.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\expanded_button.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation-down.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\ico-playstation.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\ico-radio.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\music-note.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-play-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-btn-play.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-bg.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-buffer.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-busy.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-off.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-on.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-eq-warning.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-options-design-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-options-design.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-options-on.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-options.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-0.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-1.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-2.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-3.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\radio-volume-mute.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\scrollbar-handle.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\scrollbar-track.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\slider.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\slideron.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\images\track.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\managerpanel.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radio\volumeslider.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radiobeta-buffering.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radiobeta-connecting.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radiobeta-playing.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radiobeta-stopped.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\radiobeta.ico

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\reload.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\remove.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\rename.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\resize-box.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\rss.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\rsschannelback.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\RSSLogo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\rsstabdivider.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\scroll-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\scroll-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\search-go.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\search.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\text-ellipsis.xml

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\toolbarsplitter.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\transparent_1px.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_02.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_03.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_04.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_06.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_07.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_08.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_09.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_10.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_11.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_12.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_13.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_14.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_15.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_16.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_18.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_19.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_20.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\border_21.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\btn-close-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\btn-close-greyover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\close-hot.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\close-normal.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\loadingMid.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\proxy.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\template.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\template.xml

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\templateFF.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\uwa\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\icons\cond999.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\icons\icons.xml

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na-s.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na-t.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\icons\na.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\add.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-check.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.html

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lib\yahoo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\lichen.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\logo-about.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\logo-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\logo-separator.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\logo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\mail.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\maps.bmp

c:\progra~2\WI371A~1\ToolBar\chrome\skin\menuseparatorback.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\modify-save.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\modify.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\modifyhot.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\music.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\news.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\options\options-main.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\options\options-search.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\options\options-weather.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\options\options-weather.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\options\options-widgets.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\orange.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\pixsy.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\protect-id.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\radiobeta-buffering.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\radiobeta-connecting.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\radiobeta-playing.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\radiobeta-stopped.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\radiobeta.ico

c:\progra~2\WI371A~1\ToolBar\chrome\skin\relatedlinks.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-collapse.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-delete.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-expand.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-feed.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-folder-remove.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-folder-rename.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-folder.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-found.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-reload.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss-subscribe.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rss.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rssback.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\rsstopback.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\search-over.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\search.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\search_button_over_png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\search_button_png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\searchbar\searchbar-background-left.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\searchbar\searchbar-background-right.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\settings.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\shopping.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\siteinfo.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-bluelite.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-bluesky.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-grey.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-lichen.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-orange.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin-yellow.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\skin.xml

c:\progra~2\WI371A~1\ToolBar\chrome\skin\technorati.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\throbber.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\toolbarsplitter.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\translate.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\video.bmp

c:\progra~2\WI371A~1\ToolBar\chrome\skin\vmn.css

c:\progra~2\WI371A~1\ToolBar\chrome\skin\vmn.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\weather.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\web.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\widgets-square-16px.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\wikipedia.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\yahoosearch.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\yellow.gif

c:\progra~2\WI371A~1\ToolBar\chrome\skin\youtube.png

c:\progra~2\WI371A~1\ToolBar\chrome\skin\zoom.png

c:\progra~2\WI371A~1\ToolBar\components\windowmediator.js

c:\progra~2\WI371A~1\ToolBar\dtUser.exe

c:\progra~2\WI371A~1\ToolBar\manifest.xml

c:\progra~2\WI371A~1\ToolBar\searchquband.dll

c:\progra~2\WI371A~1\ToolBar\uninstall.exe

c:\progra~2\WI371A~1\uninstall.exe

c:\program files (x86)\BabylonToolbar

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbar.crx

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarApp.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarEng.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\uninstall.exe

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe

c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe

c:\program files (x86)\BabylonToolbar\sqlite3.dll

c:\program files (x86)\ConduitEngine

c:\program files (x86)\ConduitEngine\appContextMenu.xml

c:\program files (x86)\ConduitEngine\ConduitEngine.dll

c:\program files (x86)\ConduitEngine\ConduitEngineHelper.exe

c:\program files (x86)\ConduitEngine\ConduitEngineUninstall.exe

c:\program files (x86)\ConduitEngine\engineContextMenu.xml

c:\program files (x86)\ConduitEngine\EngineSettings.json

c:\program files (x86)\ConduitEngine\INSTALL.LOG

c:\program files (x86)\ConduitEngine\toolbar.cfg

c:\program files (x86)\PHPNukeDU

c:\program files (x86)\PHPNukeDU\GottenAppsContextMenu.xml

c:\program files (x86)\PHPNukeDU\OtherAppsContextMenu.xml

c:\program files (x86)\PHPNukeDU\PHPNukeDUToolbarHelper.exe

c:\program files (x86)\PHPNukeDU\SharedAppsContextMenu.xml

c:\program files (x86)\PHPNukeDU\tbPHPN.dll

c:\program files (x86)\PHPNukeDU\toolbar.cfg

c:\program files (x86)\PHPNukeDU\ToolbarContextMenu.xml

c:\program files (x86)\PHPNukeDU\uninstall.exe

c:\programdata\Ask

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-09-25 to 2012-10-25 ))))))))))))))))))))))))))))))

.

.

2012-10-25 06:17 . 2012-10-25 06:17 -------- d-----w- c:\users\Evert\AppData\Local\temp

2012-10-25 06:17 . 2012-10-25 06:17 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-10-25 06:17 . 2012-10-25 06:17 -------- d-----w- c:\users\acer m3641\AppData\Local\temp

2012-10-24 14:48 . 2012-10-25 05:45 -------- d-----w- C:\32788R22FWJFW

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\users\acer m3641\AppData\Roaming\Malwarebytes

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\programdata\Malwarebytes

2012-10-24 07:10 . 2012-10-24 07:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-10-24 07:10 . 2012-09-29 17:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-10-23 16:33 . 2012-10-23 16:33 388096 ----a-r- c:\users\acer m3641\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-10-23 16:33 . 2012-10-23 16:33 -------- d-----w- c:\program files (x86)\Trend Micro

2012-10-23 14:29 . 2012-10-17 00:31 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28EE2000-10E4-4061-B972-0BBCBEB6B0AD}\mpengine.dll

2012-10-19 15:38 . 2012-09-24 21:16 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-11 05:35 . 2012-10-20 07:25 12872 ----a-w- c:\windows\system32\bootdelete.exe

2012-10-10 05:10 . 2012-09-13 13:45 2048 ----a-w- c:\windows\system32\tzres.dll

2012-10-10 05:10 . 2012-09-13 13:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-10-10 05:10 . 2012-08-24 16:07 218624 ----a-w- c:\windows\system32\wintrust.dll

2012-10-10 05:10 . 2012-08-24 15:53 172544 ----a-w- c:\windows\SysWow64\wintrust.dll

2012-10-10 05:10 . 2012-06-02 00:20 1268736 ----a-w- c:\windows\system32\crypt32.dll

2012-10-10 05:10 . 2012-06-02 00:20 174592 ----a-w- c:\windows\system32\cryptsvc.dll

2012-10-10 05:10 . 2012-06-02 00:20 132096 ----a-w- c:\windows\system32\cryptnet.dll

2012-10-10 05:10 . 2012-06-02 00:02 985088 ----a-w- c:\windows\SysWow64\crypt32.dll

2012-10-10 05:10 . 2012-06-02 00:02 133120 ----a-w- c:\windows\SysWow64\cryptsvc.dll

2012-10-10 05:10 . 2012-06-02 00:02 98304 ----a-w- c:\windows\SysWow64\cryptnet.dll

2012-10-10 05:10 . 2012-08-29 11:40 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-10-09 08:16 . 2012-10-09 08:16 -------- d-----w- c:\program files (x86)\Market Samurai

2012-10-04 08:36 . 2012-10-24 06:54 -------- d-----w- c:\programdata\webex

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-10-11 05:12 . 2006-11-02 12:35 65309168 ----a-w- c:\windows\system32\mrt.exe

2012-10-09 09:23 . 2012-04-11 08:48 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-10-09 09:23 . 2011-10-22 05:46 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-09-10 18:35 . 2012-09-10 18:36 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-09-10 18:35 . 2010-09-13 17:32 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-08-24 11:15 . 2012-09-23 06:59 17810944 ----a-w- c:\windows\system32\mshtml.dll

2012-08-24 10:39 . 2012-09-23 06:59 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-08-24 10:31 . 2012-09-23 07:00 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-08-24 10:22 . 2012-09-23 07:00 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-08-24 10:21 . 2012-09-23 07:00 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-08-24 10:20 . 2012-09-23 07:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-08-24 10:18 . 2012-09-23 07:00 237056 ----a-w- c:\windows\system32\url.dll

2012-08-24 10:17 . 2012-09-23 07:00 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-08-24 10:14 . 2012-09-23 07:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-08-24 10:14 . 2012-09-23 07:00 816640 ----a-w- c:\windows\system32\jscript.dll

2012-08-24 10:13 . 2012-09-23 07:00 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-08-24 10:12 . 2012-09-23 07:00 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-08-24 10:11 . 2012-09-23 07:00 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-08-24 10:10 . 2012-09-23 07:00 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-08-24 10:09 . 2012-09-23 07:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-08-24 10:04 . 2012-09-23 07:00 248320 ----a-w- c:\windows\system32\ieui.dll

2012-08-24 06:59 . 2012-09-23 07:00 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-08-24 06:51 . 2012-09-23 07:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-08-24 06:51 . 2012-09-23 07:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-08-24 06:47 . 2012-09-23 07:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-08-24 06:47 . 2012-09-23 07:00 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-08-24 06:43 . 2012-09-23 07:00 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-08-21 09:13 . 2011-11-02 08:24 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys

2012-08-21 09:13 . 2011-11-02 08:24 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2012-08-21 09:13 . 2011-11-02 08:24 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2012-08-21 09:13 . 2011-11-02 08:24 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2012-08-21 09:13 . 2011-11-02 08:24 44272 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2012-08-21 09:13 . 2011-11-02 08:24 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2012-08-21 09:12 . 2011-11-02 08:24 41224 ----a-w- c:\windows\avastSS.scr

2012-08-21 09:12 . 2011-11-02 08:24 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe

2012-08-21 09:12 . 2011-02-10 10:48 285328 ----a-w- c:\windows\system32\aswBoot.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 94208 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2008-03-04 21:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]

"SoMud"="c:\program files (x86)\SoMud\somud.exe" [2011-06-28 3888128]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-12 68856]

"Greenshot"="c:\program files (x86)\Greenshot\Greenshot.exe" [2010-07-12 548864]

"Jing"="c:\program files (x86)\TechSmith\Jing\Jing.exe" [2012-02-01 2918224]

"Grammar.net’s Grammar Checker"="c:\program files (x86)\Grammar.net’s Grammar Checker\GrammarChecker.exe" [2012-06-18 73216]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]

"SiteAdvisor"="c:\program files (x86)\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-25 98304]

"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]

"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]

"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"eSnips_Downloader"="c:\program files (x86)\Logia\eSnipsDownloader\eSnips_Downloader.exe" [2010-05-24 1234432]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-12-21 206504]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

"SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]

"azontop100analyzer"="c:\program files (x86)\AzonTop100Analyzer\azontop100analyzer.exe" [2012-06-09 44474097]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

c:\users\Evert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OpenOffice.org 3.4.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-4-19 1199104]

.

c:\users\acer m3641\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dropbox.lnk - c:\users\acer m3641\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

Feed Notifier.lnk - c:\program files (x86)\Feed Notifier\notifier.exe [2012-7-24 58368]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

ASETRES.EXE [2008-4-14 20480]

Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-9-23 535336]

Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\RaUI.exe [2010-6-3 1773568]

WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2010-11-30 608584]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36CrusaderBoot]

@=""

.

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]

S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]

S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 269448]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]

.

.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

Themes

.

Inhoud van de 'Gedeelde Taken' map

.

2012-10-25 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 09:23]

.

2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-05 07:29]

.

2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-05 07:29]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]

2012-03-15 21:26 287048 ----a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-08-21 09:11 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-02-18 05:12 97792 ----a-w- c:\users\acer m3641\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2008-03-04 21:39 51248 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvSvc"="c:\windows\system32\nvsvc64.dll" [2007-11-27 88064]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-27 10721312]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-27 74752]

"RtHDVCpl"="RAVCpl64.exe" [2008-03-25 6150656]

"Skytel"="Skytel.exe" [2007-11-20 1826816]

"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-03-04 560688]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-06-06 333344]

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uDefault_Search_URL = hxxp://www.google.com/ie

mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0413&s=1&o=vp64&d=1109&m=aspire_m3641

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Download Web &Images with SoMud - c:\program files (x86)\SoMud\scripts\ie\images-url.html

IE: Download with SoMud - c:\program files (x86)\SoMud\scripts\ie\link-url.html

IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1 192.168.1.1

FF - ProfilePath - c:\users\acer m3641\AppData\Roaming\Mozilla\Firefox\Profiles\vb3pdfou.default\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/

FF - prefs.js: network.proxy.gopher -

FF - prefs.js: network.proxy.gopher_port - 0

FF - prefs.js: network.proxy.type - 0

FF - ExtSQL: 2012-10-24 09:58; {4ED1F68A-5463-4931-9384-8FFF5ED91D92}; c:\program files (x86)\McAfee\SiteAdvisor

FF - ExtSQL: !HIDDEN! 2010-06-06 09:50; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - ExtSQL: !HIDDEN! 2012-03-10 10:49; 5affxtbr@MyWebFace_5a.com; c:\program files (x86)\MyWebFace_5a\bar\1.bin

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(extensions.searchya_i.hmpg, true

FF - user.js: extensions.searchya_i.hmpgUrl - hxxp://searchya.com/?chnl=fap&s=0&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz

FF - user.js: extensions.searchya_i.dfltSrch - true

FF - user.js: extensions.searchya_i.srchPrvdr - SearchYa!

FF - user.js: extensions.searchya_i.dnsErr - true

FF - user.js: extensions.searchya_i.newTab - true

FF - user.js: extensions.searchya_i.newTabUrl - hxxp://searchya.com/?chnl=fap&s=2&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz

FF - user.js: extensions.searchya_i.tlbrSrchUrl - hxxp://searchya.com/?chnl=fap&s=3&cr=879914219&cd=2XzutAtN2Y1L1QzutDtDyCtD0BtAyE0AtB0FtAyEtCyD0C0A0FtN0D0TzutBtDtCtBtDtBtDzz&q=

FF - user.js: extensions.searchya_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.searchya_i.instlDay - 15378

FF - user.js: extensions.searchya_i.vrsn - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsni - 1.5.11.13

FF - user.js: extensions.searchya_i.vrsnTs - 1.5.11.1316:16

FF - user.js: extensions.searchya_i.prtnrId - ironsrc

FF - user.js: extensions.searchya_i.prdct - searchya

FF - user.js: extensions.searchya_i.aflt - foxtab

FF - user.js: extensions.searchya_i.smplGrp - none

FF - user.js: extensions.searchya_i.tlbrId - base

FF - user.js: extensions.searchya_i.instlRef - fap

FF - user.js: extensions.searchya_i.dfltLng -

FF - user.js: extensions.searchya_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar_i.id - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.hardId - 84415caf0000000000000060b34a2f34

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15400

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:41

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101241

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-10 - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

WebBrowser-{65CA59EE-9920-4D7F-8C41-BFA12403261A} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

AddRemove-Allscoop RSS Submit Pro 1.0 - c:\windows\system32\ss2uinst.exe

AddRemove-BabylonToolbar - c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe

AddRemove-conduitEngine - c:\progra~2\CONDUI~1\ConduitEngineUninstall.exe

AddRemove-InstallBrain Updater Service - c:\programdata\InstallBrainService\ibsvc.exe

AddRemove-PHPNukeDU Toolbar - c:\progra~2\PHPNUK~1\UNINST~1.EXE

AddRemove-Savings Sidekick - c:\program files (x86)\Savings Sidekick\Uninstall.exe

AddRemove-Searchqu 406 MediaBar - c:\program files (x86)\Windows iLivid Toolbar\uninstall.exe

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Voltooingstijd: 2012-10-25 08:25:38

ComboFix-quarantined-files.txt 2012-10-25 06:25

ComboFix2.txt 2012-10-24 15:34

.

Pre-Run: 201.514.721.280 bytes beschikbaar

Post-Run: 201.413.840.896 bytes beschikbaar

.

- - End Of File - - 32C4A3B65C79EF8327CDC2C26E9D506D

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.