Zoek.exe Version 4.0.0.5 Updated 26-October-2013 Tool run by user on za 02/11/2013 at 14:56:43,66. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\user\Desktop\Hijack 64 bit nieuw systeem\zoek.scr [Script inserted] ==== System Restore Info ====================== 2/11/2013 14:58:01 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "IncrediMail"=- ==== Deleting Files \ Folders ====================== C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} deleted C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} deleted C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted C:\PROGRA~2\AllGamesHome Toolbar deleted C:\PROGRA~2\ChatZum Toolbar deleted C:\PROGRA~2\iLivid deleted C:\PROGRA~2\Mario Forever deleted C:\Temporary deleted C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QuickStores.url deleted C:\Users\user\AppData\Roaming\Alawar deleted C:\Users\user\AppData\Roaming\Alawar Entertainment deleted C:\Users\user\AppData\Roaming\GoforFiles deleted C:\Users\user\AppData\Roaming\Babylon deleted C:\Users\user\AppData\Roaming\iWin deleted C:\Users\user\AppData\Roaming\Systweak deleted C:\Users\user\AppData\Roaming\YourFileDownloader deleted C:\Users\user\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com deleted C:\Users\user\AppData\Roaming\Media Finder deleted C:\Users\user\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP deleted C:\Users\user\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Qtrax Player-09102013-193558 deleted C:\ProgramData\Ask deleted C:\ProgramData\Alawar Stargaze deleted C:\ProgramData\AlawarGameBox deleted C:\ProgramData\AlawarWrapper deleted C:\ProgramData\Babylon deleted C:\ProgramData\Trymedia deleted C:\Users\user\AppData\Local\Ilivid Player deleted C:\Users\user\AppData\Local\CRE deleted C:\Users\user\AppData\Local\OpenCandy deleted C:\Users\user\AppData\Local\APN deleted C:\Users\user\AppData\Local\PackageAware deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mario Forever deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\user\Downloads\SoftonicDownloader_for_chromadrome-2.exe deleted C:\Users\user\AppData\LocalLow\searchquband deleted C:\Users\user\AppData\LocalLow\Incredibar.com deleted C:\Users\user\AppData\LocalLow\FunWebProducts deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\Windows\assembly\GAC_MSIL\QuickStoresToolbar deleted C:\Windows\Wininit.ini deleted C:\windows\SysNative\TASKS\Scheduled Update for Ask Toolbar deleted C:\windows\SysNative\tasks\Desk 365 RunAsStdUser deleted C:\windows\SysNative\Tasks\GoforFilesUpdate deleted C:\windows\SysNative\tasks\YourFile Update deleted C:\user.js deleted C:\Windows\SysWow64\AI_RecycleBin deleted C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} deleted "C:\Users\user\AppData\Roaming\froggy_scorebox" deleted "C:\Users\user\AppData\Roaming\Anabel\save_00.sav" deleted "C:\Program Files (x86)\IncrediMail\Bin\d3drm.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\dten600.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\Im3dU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImABU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImAnimU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImAppRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImDbU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImFeatRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImFoldrsU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\IMHttpComm.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImJunkU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImLookU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImMangrRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImMapiU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImNtUtilU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImSearchU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImSuppRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImUtilsU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImViewRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ImWrappU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe" deleted "C:\Program Files (x86)\IncrediMail\Bin\IncMailRU.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\PMC.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\SftTree_IX86_U_60.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\sqlite3.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\ssce5432.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\wflash3.dll" deleted "C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll" deleted "C:\Users\user\AppData\Roaming\Anabel" deleted "C:\Program Files (x86)\IncrediMail" deleted "C:\Program Files (x86)\IncrediMail\Bin" deleted ==== Files Found In C:\sh4ldr ====================== 2010-03-11 13:17:42 185835 ----a-w- 80D676F05E618C2F1D53F6392C566263 C:\sh4ldr\shldr 2010-03-29 15:37:58 1738256 ----a-w- 23D85DAB1CB6D33A9D14DDE6815581C9 C:\sh4ldr\vmlinuz 2010-04-30 15:52:14 6125131 ----a-w- A5CAD37300F32B3CD5C1F881F6862CEE C:\sh4ldr\initrd.gz 2013-10-09 12:53:33 8192 ----a-w- 025926B83A938B5215F3C1DCC882F21C C:\sh4ldr\shldr.mbr ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sao4pzrf.default-1357890479250 - AllGamesHome Toolbar - %ProfilePath%\extensions\{317EB79C-82C1-4D5A-9D04-342BAA96B7C0} AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\85kg5mu0.default-1381309708978 CFAF7B67C78D09D79688AEDCA3D090E2 - C:\Users\user\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll - Google Update 4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17 81D388824634378A37765FD943FB3144 - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director EDF220A1DCDB2CB01DCEA8E80B1435C5 - C:\Windows\SysWOW64\NPSWF32.dll - Shockwave Flash CE3D390F8BC1FECF847ABAA6E887931E - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll - Zylom Plugin 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Deleted Firefox Extensions ====================== C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sao4pzrf.default-1357890479250\extensions\{317EB79C-82C1-4D5A-9D04-342BAA96B7C0} deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions aanjjkgbodmfkdnkkhcjcghgnibdllak - C:\Users\user\AppData\Local\CRE\aanjjkgbodmfkdnkkhcjcghgnibdllak.crx[] dednnpigldgdbpgcdpfppmlcnnbjciel - C:\Users\user\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx[] dlnembnfbcpjnepmfjmngjenhhajpdfd - C:\Program Files\Web Assistant\source.crx[] ifohbjbgfchkkfhphahclmkpgejiplfo - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx[] jbpkiefagocgkmemidfngdkamloieekf - No path found[] lpmkgpnbiojfaoklbkpfneikocaobfai - C:\Users\user\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx[] nohfdhapjjlndfgjnmdlcabloeembdkj - C:\Users\user\AppData\Roaming\BabSolution\CR\delta2.crx[] pmlghpafmmnmmkjdhacccolfgnkiboco - C:\Program Files (x86)\1ClickDownload\oneclickdownloader10.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions aanjjkgbodmfkdnkkhcjcghgnibdllak - C:\Users\user\AppData\Local\CRE\aanjjkgbodmfkdnkkhcjcghgnibdllak.crx[] General Crawler - user - Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel LemurLeap - user - Default\Extensions\jlnfdbbladgcmhhamgkioifhbobjaoof Chrome In-App Payments service - user - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chrome Fix ====================== C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_apps.conduit.com_0.localstorage-journal deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage deleted successfully C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.hln.be/" "Default_Page_URL"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.hln.be/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found" {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} Unknown Url="Not_Found" {33BB0A4E-99AF-4226-BDF6-49120163DE86} Unknown Url="Not_Found" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} Unknown Url="Not_Found" {afdbddaa-5d3f-42ee-b79c-185a7020515b} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} deleted successfully HKEY_USERS\S-1-5-21-3424622331-577866346-4098538517-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\belgiumeid@eid.belgium.be deleted successfully ==== shortcuts on Users Desktops ====================== C:\Users\user\Desktop\18 Wheels of Steel American Long Haul.lnk - C:\Program Files (x86)\18 Wheels of Steel American Long Haul\alh.exe C:\Users\user\Desktop\2020.lnk - C:\Program Files (x86)\byLight\2020\2020.exe C:\Users\user\Desktop\4shared.lnk - C:\Program Files (x86)\4shared.com\Azangara\4shared.url C:\Users\user\Desktop\Alawar Games.lnk - C:\Program Files (x86)\Alawar\Alawar.url C:\Users\user\Desktop\AssassinsCreed3.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Ubisoft\Assassin's Creed III\AssassinsCreed3.exe C:\Users\user\Desktop\AVS Video Converter.lnk - C:\Program Files (x86)\AVS4YOU\AVSVideoConverter\AVSVideoConverter.exe C:\Users\user\Desktop\AVS4YOU Software Navigator.lnk - C:\Program Files (x86)\AVS4YOU\AVSSoftwareNavigator\AVS4YOUSoftwareNavigator.exe C:\Users\user\Desktop\Babel Deluxe.lnk - C:\Program Files (x86)\Babel Deluxe\Babel.exe C:\Users\user\Desktop\BH6.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Resident Evil 6\BH6.exe C:\Users\user\Desktop\BookWorm.lnk - C:\games\BookWorm\BookWorm.exe C:\Users\user\Desktop\BurnoutLauncher.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe C:\Users\user\Desktop\Chromadrome 2 Portable.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Chromadrome 2\Chromadrome 2 Portable.exe C:\Users\user\Desktop\Corel PaintShop Pro X5.lnk - C:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe C:\Users\user\Desktop\Darksiders2.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Darksiders 2\Darksiders2.exe C:\Users\user\Desktop\deadspace3.exe - Snelkoppeling.lnk - B:\Games\Dead Space 3 Limited Edition FULL-MULTI(TMT33)\deadspace3.exe C:\Users\user\Desktop\Dropbox.lnk - C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\user\Desktop\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe C:\Users\user\Desktop\Eminent EM7285 - UPnP Render(eminent) - Snelkoppeling.lnk - C:\Users\user\Desktop\FileZilla.lnk - C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe C:\Users\user\Desktop\Flash Movie Player.lnk - C:\Program Files (x86)\Flash Movie Player\fmp.exe C:\Users\user\Desktop\FM Patcher.lnk - C:\Program Files (x86)\FMPatcher\FMPatcher.exe C:\Users\user\Desktop\Folder Marker.lnk - C:\Program Files (x86)\Folder Marker\FolderMarker.exe C:\Users\user\Desktop\Font Xplorer - Snelkoppeling.lnk - B:\Programmas\Font Xplorer\Font Xplorer.exe C:\Users\user\Desktop\HiJackThis.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe C:\Users\user\Desktop\HTMLKit.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Chami\HTML-Kit\Bin\HTMLKit.exe C:\Users\user\Desktop\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\Desktop\Macromedia Dreamweaver MX.lnk - C:\Program Files (x86)\Macromedia\Dreamweaver MX\Dreamweaver.exe C:\Users\user\Desktop\MKV Player.lnk - C:\Program Files (x86)\MKV Player\MKV Player.exe C:\Users\user\Desktop\MyPlayCity Games.lnk - C:\Program Files (x86)\MyPlayCity.com\Star Defender 4\MyPlayCity.url C:\Users\user\Desktop\PictureViewer.exe - Snelkoppeling.lnk - C:\Program Files (x86)\QuickTime\PictureViewer.exe C:\Users\user\Desktop\Play Free Online Games.lnk - C:\Program Files (x86)\BGames.com\Plasm Defence\BGames.url C:\Users\user\Desktop\Play Online Games.lnk - C:\Program Files (x86)\MyPlayCity.com\Star Defender 4\PlayOnlineGames.url C:\Users\user\Desktop\Plugin Commander Light.lnk - C:\Program Files (x86)\Plugin Commander Light\PiCoLight.exe C:\Users\user\Desktop\PopCap Game Pack.lnk - C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games for Windows\PopCap C:\Users\user\Desktop\PowerpointImageExtractor V1.2.lnk - C:\Program Files (x86)\PowerpointImageExtractor_V1_2\PowerpointImageExtractor.exe C:\Users\user\Desktop\Smilebox.lnk - C:\Users\user\AppData\Roaming\Smilebox\SmileboxStarter.exe C:\Users\user\Desktop\Spotnet.lnk - C:\Program Files (x86)\Spotnet\Spotnet.exe C:\Users\user\Desktop\SpyHunter.lnk - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe C:\Users\user\Desktop\SqirlzReflect.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Sqirlz Water Reflections\SqirlzReflect.exe C:\Users\user\Desktop\Star Defender 4.lnk - C:\Program Files (x86)\MyPlayCity.com\Star Defender 4\Star Defender 4.exe C:\Users\user\Desktop\The Print Shop 3.0 Professional.lnk - C:\Windows\Installer\{4B75C418-A7DF-4C11-B854-EB5EBFB07C88}\NewShortcut1_D8B08C66F13C407B8A06CCC378026B6C.exe C:\Users\user\Desktop\Vampires vs. Zombies.lnk - C:\Program Files (x86)\Alawar\Vampires vs Zombies\Vampires VS Zombies.exe C:\Users\user\Desktop\Spellen\Air Force Missions.lnk - C:\Program Files (x86)\MyPlayCity.com\Air Force Missions\Air Force Missions.exe C:\Users\user\Desktop\Spellen\AmazingAdventures.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Games for Windows\Amazing Adventures (The Lost Tomb) [PopCap]\AmazingAdventures.exe C:\Users\user\Desktop\Spellen\ANGEL EGG.lnk - C:\Windows\Installer\{7BD17780-6A45-4E7E-AFC9-ED1E35D0FDF3}\_294823.exe C:\Users\user\Desktop\Spellen\Angry Birds Rio.exe - Snelkoppeling.lnk - C:\games\Angry Birds Rio\Angry Birds Rio.exe C:\Users\user\Desktop\Spellen\AngryBirds.exe - Snelkoppeling.lnk - B:\Games\Angry Birds\Angry Birds 4 PC\AngryBirds.exe C:\Users\user\Desktop\Spellen\AngryBirdsSeasons.exe - Snelkoppeling.lnk - C:\games\Angry Birds Seasons\AngryBirdsSeasons.exe C:\Users\user\Desktop\Spellen\Avatar.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Ubisoft\James Cameron's AVATAR - THE GAME\bin\Avatar.exe C:\Users\user\Desktop\Spellen\Azangara.lnk - C:\Program Files (x86)\4shared.com\Azangara\Azangara.exe C:\Users\user\Desktop\Spellen\Beetle Ju 3.lnk - C:\Program Files (x86)\GAMESVOORIEDEREEN.NL\BeetleJu3\BeetleJu3_og.exe C:\Users\user\Desktop\Spellen\beetleju2.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Beetle Bugs\Beetle Bug 2\beetleju2.exe C:\Users\user\Desktop\Spellen\BeJeweled 2 .lnk - C:\Program Files (x86)\Bejeweled 2 Deluxe\WinBej2.exe C:\Users\user\Desktop\Spellen\BejeweledTwist.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Games for Windows\Bejeweled Twist [PopCap]\BejeweledTwist.exe C:\Users\user\Desktop\Spellen\BH6.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Resident Evil 6\BH6.exe C:\Users\user\Desktop\Spellen\BIONICLE TM.lnk - C:\Program Files (x86)\LEGO Interactive\BIONICLE\BIONICLE.exe C:\Users\user\Desktop\Spellen\Bionicle.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Eidos\BIONICLE Heroes\Bionicle.exe C:\Users\user\Desktop\Spellen\Birds on a Wire.lnk - C:\Program Files (x86)\Alawar\Birds on a Wire\birds.exe C:\Users\user\Desktop\Spellen\Blitter2.exe - Snelkoppeling.lnk - B:\Games\Swarmblitter2\Blitter2.exe C:\Users\user\Desktop\Spellen\Born To Be Big.lnk - C:\Program Files (x86)\MyPlayCity.com\Born To Be Big\Born To Be Big.exe C:\Users\user\Desktop\Spellen\BugBits.lnk - C:\Program Files (x86)\MyPlayCity.com\BugBits\BugBits.exe C:\Users\user\Desktop\Spellen\BurnoutLauncher.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe C:\Users\user\Desktop\Spellen\Cake Shop 2.lnk - C:\Program Files (x86)\MyPlayCity.com\Cake Shop 2\Cake Shop 2.exe C:\Users\user\Desktop\Spellen\Cars - Radiator Springs Adventures.lnk - C:\Program Files (x86)\THQ\Disney-PIXAR\Cars\Radiator Springs Adventures\Cars.exe C:\Users\user\Desktop\Spellen\chainz2.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Zylom Games\Chainz 2 Deluxe\chainz2.exe C:\Users\user\Desktop\Spellen\Chicken Chase.lnk - C:\Program Files (x86)\Alawar\Chicken Chase\chicken_chase.exe C:\Users\user\Desktop\Spellen\Chicken Invaders 4 - Easter Edition.lnk - C:\Program Files (x86)\LeeGT-Games\Chicken Invaders 4 - Easter Edition\CI4Easter.exe C:\Users\user\Desktop\Spellen\Clash N Slash.lnk - C:\Program Files (x86)\Clash N Slash\Clash N Slash.exe C:\Users\user\Desktop\Spellen\Danger Strike.lnk - C:\Program Files (x86)\BGames.com\Danger Strike\Danger Strike.exe C:\Users\user\Desktop\Spellen\Delivery Application.lnk - C:\Program Files (x86)\Alawar\Delivery King\Delivery King.exe C:\Users\user\Desktop\Spellen\Diamond Drop.lnk - C:\Program Files (x86)\Alawar\Diamond Drop\DiamondDrop.exe C:\Users\user\Desktop\Spellen\Drome Racers.lnk - C:\Program Files (x86)\LEGO Interactive\Drome Racers\Drome Racers.exe C:\Users\user\Desktop\Spellen\engine.exe - Snelkoppeling.lnk - C:\Program Files (x86)\MyPlayCity.com\Sproink\engine.exe C:\Users\user\Desktop\Spellen\EscapeWhisperValley.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Games for Windows\Escape Whisper Valley [PopCap]\EscapeWhisperValley.exe C:\Users\user\Desktop\Spellen\FairyTower.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Fairy Tower\FairyTower.exe C:\Users\user\Desktop\Spellen\Feelers.lnk - C:\Program Files (x86)\Alawar\Feelers\Feelers.exe C:\Users\user\Desktop\Spellen\Fishdom.lnk - C:\Program Files (x86)\MyPlayCity.com\Fishdom\Fishdom.exe C:\Users\user\Desktop\Spellen\Froggys Adventures.lnk - C:\Program Files (x86)\Alawar\Froggys Adventures\Froggy.exe C:\Users\user\Desktop\Spellen\GALIDOR(TM) - Defenders of the Outer Dimension.lnk - C:\Program Files (x86)\LEGO Interactive\GALIDOR\GALIDORLAUNCH.exe C:\Users\user\Desktop\Spellen\GOLDEN LOGRES.lnk - C:\Windows\Installer\{F8EBF37E-86D7-4217-9B55-DCE7BA527FB5}\_4ae13d6c.exe C:\Users\user\Desktop\Spellen\Granny.exe - Snelkoppeling.lnk - C:\games\Supergranny6\Granny.exe C:\Users\user\Desktop\Spellen\graw2.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe C:\Users\user\Desktop\Spellen\Hyperballoid 2 - Time Rider.lnk - C:\Program Files (x86)\MyPlayCity.com\Hyperballoid 2 - Time Rider\Hyperballoid 2 - Time Rider.exe C:\Users\user\Desktop\Spellen\Ice Cream Mania.lnk - C:\Program Files (x86)\Ice Cream Mania\IceCream_Mania.exe C:\Users\user\Desktop\Spellen\Launcher.exe - Snelkoppeling.lnk - C:\Program Files (x86)\CAPCOM\RESIDENT EVIL 5\Launcher.exe C:\Users\user\Desktop\Spellen\Magic Ball 4.lnk - C:\Program Files (x86)\Alawar\MagicBall4\Magic Ball 4.exe C:\Users\user\Desktop\Spellen\Magic Orbz.lnk - C:\Program Files (x86)\LeeGT-Games\Magic Orbz\MagicOrbz.exe C:\Users\user\Desktop\Spellen\Mario Forever.lnk - C:\Program Files (x86)\Mario Forever\Mario Forever.exe C:\Users\user\Desktop\Spellen\MONSTER FAIR.lnk - C:\Windows\Installer\{13C82DCE-D929-485B-8053-2E90BD2BD6FE}\_4ae13d6c.exe C:\Users\user\Desktop\Spellen\Need For Extreme 3D.lnk - C:\Program Files (x86)\MyPlayCity.com\Need For Extreme 3D\Need For Extreme 3D.exe C:\Users\user\Desktop\Spellen\Neptune's Secret.lnk - C:\Program Files (x86)\Neptune's Secret\NeptunesSecret.exe C:\Users\user\Desktop\Spellen\Oozi.exe - Snelkoppeling.lnk - C:\Users\user\Downloads\Oozi - Earth Adventure\Oozi.exe C:\Users\user\Desktop\Spellen\Peggle Nights.lnk - C:\Program Files (x86)\GAMESVOORIEDEREEN.NL\PeggleNightsCD\PeggleNights_og.exe C:\Users\user\Desktop\Spellen\piratepoppers.exe - Snelkoppeling.lnk - C:\Program Files (x86)\Pirate Poppers\piratepoppers.exe C:\Users\user\Desktop\Spellen\plantsvszombies.exe - Snelkoppeling.lnk - C:\Users\user\AppData\Local\Zylom Games\Planten tegen Zombies Deluxe\plantsvszombies.exe C:\Users\user\Desktop\Spellen\Road Attack.lnk - C:\Program Files (x86)\MyPlayCity.com\Road Attack\Road Attack.exe C:\Users\user\Desktop\Spellen\SaveTheFurries.exe - Snelkoppeling.lnk - C:\games\Save the Furries\SaveTheFurries.exe C:\Users\user\Desktop\Spellen\Star Defender 2.lnk - C:\Program Files (x86)\MyPlayCity.com\Star Defender 2\Star Defender 2.exe C:\Users\user\Desktop\Spellen\strikeball3.exe - Snelkoppeling.lnk - B:\Games\Strike Ball 3\strikeball3.exe C:\Users\user\Desktop\Spellen\Subsea Relic.lnk - C:\Program Files (x86)\MyPlayCity.com\Subsea Relic\Subsea Relic.exe C:\Users\user\Desktop\Spellen\Super Motocross Africa.lnk - C:\Program Files (x86)\MyPlayCity.com\Super Motocross Africa\Super Motocross Africa.exe C:\Users\user\Desktop\Spellen\supersmasherdownload.exe - Snelkoppeling.lnk - B:\Games\Super smasher\supersmasherdownload.exe C:\Users\user\Desktop\Spellen\Tank Vs Worms.lnk - C:\Program Files (x86)\BGames.com\Tank Vs Worms\Tank Vs Worms.exe C:\Users\user\Desktop\Spellen\Tank-O-Box.lnk - C:\Program Files (x86)\Tank-O-Box\tank-o-box.exe C:\Users\user\Desktop\Spellen\Tanks - Total Destruction.lnk - C:\Program Files (x86)\AllGamesHome.com\Tanks - Total Destruction\Tanks - Total Destruction.exe C:\Users\user\Desktop\Spellen\Timeshock.exe - Snelkoppeling.lnk - C:\Users\user\Desktop\Spellen\Treasure Mole.lnk - C:\Program Files (x86)\Alawar\Treasure Mole\mole.exe C:\Users\user\Desktop\Spellen\Turtix - Rescue Adventures.lnk - C:\Program Files (x86)\MyPlayCity.com\Turtix - Rescue Adventures\Turtix - Rescue Adventures.exe C:\Users\user\Desktop\Spellen\Turtix.lnk - C:\Program Files (x86)\Alawar\Turtix\Turtix.exe C:\Users\user\Desktop\Spellen\Turtle Bay.lnk - C:\Program Files (x86)\GameHouse\TurtleBay\TurtleBay.exe C:\Users\user\Desktop\Spellen\ZumasRevenge.exe.lnk - B:\Games\Zumas.Revenge\ZumasRevenge.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\A Ruler for Windows.lnk - C:\Program Files\A Ruler for Windows\aruler.exe C:\Users\Public\Desktop\Adobe Acrobat 8 Professional.lnk - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe C:\Users\Public\Desktop\Alawar Game Box.lnk - C:\Program Files (x86)\Alawar\AlawarGameBox\AlawarArcade.exe C:\Users\Public\Desktop\AVG 2014.lnk - C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\Users\Public\Desktop\Cars - Radiator Springs Adventures.lnk - C:\Program Files (x86)\THQ\Disney-PIXAR\Cars\Radiator Springs Adventures\Cars.exe C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\Users\Public\Desktop\Corel Paint Shop Pro Photo X2.lnk - C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\Corel Paint Shop Pro Photo.exe C:\Users\Public\Desktop\Corel PaintShop Photo Pro X3.lnk - C:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe C:\Users\Public\Desktop\Corel PaintShop Pro X4.lnk - C:\Program Files (x86)\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe C:\Users\Public\Desktop\DAEMON Tools Lite.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe C:\Users\Public\Desktop\GAME CENTER.lnk - C:\Program Files (x86)\OXXOGames\NLGplayer\GPlayer.exe C:\Users\Public\Desktop\Hallmark Card Studio 2012 Deluxe.lnk - C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2012 Deluxe\HCS.exe C:\Users\Public\Desktop\Internetbrowser selecteren.lnk - C:\Windows\System32\browserchoice.exe /launch C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\Users\Public\Desktop\Jasc Paint Shop Pro 9.lnk - C:\Windows\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\PaintShopProExeIcon.ico C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Users\Public\Desktop\Nero Express.lnk - C:\Program Files (x86)\Nero\Nero Burning ROM\nero.exe /w C:\Users\Public\Desktop\New Super Mario Forever PC.lnk - C:\Users\user\AppData\Roaming\New Super Mario Forever\New Super Mario Forever PC.exe C:\Users\Public\Desktop\PowerArchiver.lnk - C:\Program Files (x86)\PowerArchiver\POWERARC.EXE C:\Users\Public\Desktop\QuickTime Player.lnk - C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk - C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Public\Desktop\Startpagina Dell printer.LNK - C:\Program Files (x86)\Dell\Dashboard\dl__Dashboard.exe C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe C:\Users\Public\Desktop\TeamViewer 8.lnk - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe C:\Users\Public\Desktop\TuneUp 1-klik Onderhoud.lnk - C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk - C:\Program Files (x86)\TuneUp Utilities 2013\Integrator.exe C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe C:\Users\Public\Desktop\WavePad Sound Editor.lnk - C:\Program Files (x86)\NCH Swift Sound\WavePad\wavepad.exe ==== shortcuts in Users Start Menu ====================== C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk - C:\Windows\explorer.exe "C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4.com" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\SpyHunter.lnk - C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter\Uninstall SpyHunter.lnk - C:\Windows\SysWOW64\msiexec.exe /X {1C7CC8E2-CFCF-41E6-A863-7C7A45CE8A78} C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG 2014.lnk - C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Burnout(TM) Paradise The Ultimate Box.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Agenda.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe calendar C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Contactgegevens.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe contacts C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\E-mail.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe mail C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Herinneringen.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe reminders C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\iCloud-foto's.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\ShellStreamsShortcut.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\iCloud.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Notities.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe notes C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Zoek mijn iPhone.lnk - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudWeb.exe find C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Info iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.Resources\nl.lproj\About iTunes.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\Silverlight.Configuration.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Alawar Game Box.lnk - C:\Program Files (x86)\Alawar\AlawarGameBox\AlawarArcade.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free File Opener.lnk - C:\Program Files (x86)\Free File Opener\FreeFileOpener.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk - C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Plasm Defence.lnk - C:\Program Files (x86)\BGames.com\Plasm Defence\Plasm Defence.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smilebox.lnk - C:\Users\user\AppData\Roaming\Smilebox\SmileboxStarter.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Star Defender 4.lnk - C:\Program Files (x86)\MyPlayCity.com\Star Defender 4\Star Defender 4.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Tank Vs Worms.lnk - C:\Program Files (x86)\BGames.com\Tank Vs Worms\Tank Vs Worms.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk - C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Corel PaintShop Pro X5.lnk - C:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Notepad.lnk - C:\Windows\system32\notepad.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\WavePad Sound Editor.lnk - C:\Program Files (x86)\NCH Swift Sound\WavePad\wavepad.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk - C:\Windows\system32\calc.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Corel Paint Shop Pro Photo X2.lnk - C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\Corel Paint Shop Pro Photo.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\IncrediMail.lnk - C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TINTIN.lnk - C:\Program Files (x86)\Ubisoft\De avonturen van Kuifje - Het Geheim van de Eenhoorn\TINTIN.exe ==== shortcuts After Repair ====================== C:\Users\user\Desktop\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe -extoff C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe http://www.qvo6.com/?utm_source=b&utm_medium=gfl&utm_campaign=eXQ&utm_content=sc&from=gfl&uid=ST31000524AS_5VP8K609XXXX5VP8K609&ts=1378308340 C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google\Chrome\ExtensionInstallForcelist deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\aanjjkgbodmfkdnkkhcjcghgnibdllak deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\aanjjkgbodmfkdnkkhcjcghgnibdllak deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\85kg5mu0.default-1381309708978\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\user\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on za 02/11/2013 at 15:25:29,93 ======================