Zoek.exe v5.0.0.0 Updated 07-March-2014 Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Documents and Settings\Wesley&Lieselotte\Bureaublad\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-03-21-123251.log 8054 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG2014\avgwdsvc.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\AVG\AVG2014\avgui.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\WINDOWS\system32\C2MP\TrayMenu.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\TP-LINK\TP-LINK Draadloos configuratie hulpprogramma\TWCU.exe C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Wesley&Lieselotte\Bureaublad\zoek.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dvd] @=- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mov] @=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SysPlayer] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== "C:\Documents and Settings\Wesley&Lieselotte\Local Settings\Application Data\Installer\Install_11857\sysplayer_bu20_setup.exe" deleted ==== System Specs ====================== Operating System: Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 Manufacturer: NVIDIA - Model: AWRDACPI Install Date: 24/02/2013 17:00:27 Last Boot: 22/03/2014 10:53:43 Processor: AMD Athlon(tm) 64 Processor 3200+ Number of Processors: 1 Work Station Bootmode: Normal boot Total RAM: 1023 MB (free 644 MB - 62) Computername: DHONDT-4CF86C1E Domain: MSHOME User: Wesley&Lieselotte (Administrator account) Removable Disk: A:\ - - GB (free GB) Local Disk: C:\ - NTFS - 63 GB (free 16 GB) CD \ DVD Drive: D:\ CD \ DVD Drive: E:\ Local Disk: F:\ - NTFS - 50 GB (free 42 GB) Bootdevice: \Device\HarddiskVolume1 Windows update: 2014-03-21 12:43:49 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: AVG AntiVirus Free Edition 2014 On-access scanning disabled (Updated) Default Browser: Firefox 27.0.1 Internet Explorer version: 8.0.6001.18702 Mozilla Firefox version: 27.0.1 (x86 nl) Google Chrome version: 33.0.1750.154 Adobe Reader version: 11.0.06.70 Sun Java version: 1.7.0_51 (32-bit) Flash Player version: 12.0.0.77 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-03-08 09:58:20 AC97C7311F39CA07C785A7D77274A104 4068 ----a-w- C:\WINDOWS\SETUP.LST 2014-03-08 09:58:20 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\WINDOWS\ST6UNST.001 2014-03-08 09:57:57 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\WINDOWS\ST6UNST.000 ====== C:\DOCUME~1\WESLEY~1\LOCALS~1\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\system32 ===== ====== C:\WINDOWS\system32\drivers ===== ====== C:\WINDOWS\Tasks ====== 2014-03-07 08:43:27 CC2673012D358D573E85C667747AD339 246 ----a-w- C:\WINDOWS\Tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job 2014-03-07 08:43:22 3BAE8CFA078D3C55A7FF2D7334F2EB30 240 ----a-w- C:\WINDOWS\Tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-03-01 19:32:40 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard ======= C: ===== 2014-03-02 09:30:39 5384C577C033083072AF8BF4829D62B6 4092 ----a-w- C:\DelFix.txt 2014-03-01 20:41:56 17D7055859D99A0D606CFAF17AE38638 211 ----a-w- C:\Boot.bak 2014-03-01 20:41:46 271E9B6A3AEC7BCA63D9231A4B3575C0 261936 --sha-r- C:\cmldr 2014-03-21 12:43:48 11EE2BECE455394513C356C09CFF8523 25453696 ----a-w- C:\\Config.Msi\\60108.rbs 2014-03-21 12:43:48 11EE2BECE455394513C356C09CFF8523 25453696 ----a-w- C:\\Config.Msi\\\60108.rbs 2014-03-21 11:57:22 -------- d-----w- C:\\WINDOWS\\Temp 2014-03-21 11:57:22 -------- d-----w- C:\\WINDOWS\\\Temp 2014-03-17 18:48:18 -------- d-----w- C:\\AdwCleaner\\Backup 2014-03-17 18:48:18 -------- d-----w- C:\\AdwCleaner\\\Backup 2014-03-17 18:48:08 090226161A7BAEDE94280AB49F579C59 1967 ----a-w- C:\\AdwCleaner\\AdwCleaner[S0].txt 2014-03-17 18:48:08 090226161A7BAEDE94280AB49F579C59 1967 ----a-w- C:\\AdwCleaner\\\AdwCleaner[S0].txt 2014-03-17 18:46:30 791191603A04553DB907DC51A98C1ACB 2019 ----a-w- C:\\AdwCleaner\\AdwCleaner[R0].txt 2014-03-17 18:46:30 791191603A04553DB907DC51A98C1ACB 2019 ----a-w- C:\\AdwCleaner\\\AdwCleaner[R0].txt 2014-03-17 18:46:09 -------- d-----w- C:\\AdwCleaner\\Quarantine 2014-03-17 18:46:09 -------- d-----w- C:\\AdwCleaner\\\Quarantine 2014-03-16 10:07:19 D6830BB9A35F3E06C06117D9FE78F7FD 629120 ----a-w- C:\\!KillBox\\SysPlayerMenu.dll 2014-03-16 10:07:19 D6830BB9A35F3E06C06117D9FE78F7FD 629120 ----a-w- C:\\!KillBox\\\SysPlayerMenu.dll 2014-03-15 13:34:07 -------- d-----w- C:\\Documents and Settings\\Administrator.DHONDT-4CF86C1E 2014-03-15 13:34:07 -------- d-----w- C:\\Documents and Settings\\\Administrator.DHONDT-4CF86C1E 2014-03-15 13:29:50 -------- d-----w- C:\\Documents and Settings\\Administrator 2014-03-15 13:29:50 -------- d-----w- C:\\Documents and Settings\\\Administrator 2014-03-08 09:58:20 AC97C7311F39CA07C785A7D77274A104 4068 ----a-w- C:\\WINDOWS\\SETUP.LST 2014-03-08 09:58:20 AC97C7311F39CA07C785A7D77274A104 4068 ----a-w- C:\\WINDOWS\\\SETUP.LST 2014-03-08 09:58:20 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\\ST6UNST.001 2014-03-08 09:58:20 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\\\ST6UNST.001 2014-03-08 09:57:57 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\\ST6UNST.000 2014-03-08 09:57:57 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\\\ST6UNST.000 2014-03-01 20:41:56 D9707499E7F4BF465EEBF747B40C4CA7 438 ----a-w- C:\\cmdcons\\winnt.sif 2014-03-01 20:41:56 D9707499E7F4BF465EEBF747B40C4CA7 438 ----a-w- C:\\cmdcons\\\winnt.sif 2014-03-01 20:41:56 5780A0C2FD8B6A0CC93EEDB71C242582 22107 ----a-w- C:\\cmdcons\\migrate.inf 2014-03-01 20:41:56 5780A0C2FD8B6A0CC93EEDB71C242582 22107 ----a-w- C:\\cmdcons\\\migrate.inf 2014-03-01 20:41:56 4223086FAE6CF965DE5DF9BC1245E6A1 8192 ----a-w- C:\\cmdcons\\bootsect.dat 2014-03-01 20:41:56 4223086FAE6CF965DE5DF9BC1245E6A1 8192 ----a-w- C:\\cmdcons\\\bootsect.dat 2014-03-01 20:41:46 4CAC32AB7BEAD8D8CF4001883507D12C 453815 ----a-w- C:\\cmdcons\\txtsetup.sif 2014-03-01 20:41:46 4CAC32AB7BEAD8D8CF4001883507D12C 453815 ----a-w- C:\\cmdcons\\\txtsetup.sif 2014-03-01 20:41:45 5F1499F64F80AA219A94A5D945B3836D 610816 ----a-w- C:\\cmdcons\\autofmt.exe 2014-03-01 20:41:45 5F1499F64F80AA219A94A5D945B3836D 610816 ----a-w- C:\\cmdcons\\\autofmt.exe 2014-03-01 20:41:44 3C200120F6E86A1A42EDA2E1E2D17AEC 619008 ----a-w- C:\\cmdcons\\autochk.exe 2014-03-01 20:41:44 3C200120F6E86A1A42EDA2E1E2D17AEC 619008 ----a-w- C:\\cmdcons\\\autochk.exe 2014-03-01 20:41:44 -------- d-----w- C:\\cmdcons\\SYSTEM32 2014-03-01 20:41:44 -------- d-----w- C:\\cmdcons\\\SYSTEM32 2014-03-01 19:32:45 -------- d-----w- C:\\WINDOWS\\455F074C814E4520B69B5584BD90400C.TMP 2014-03-01 19:32:45 -------- d-----w- C:\\WINDOWS\\\455F074C814E4520B69B5584BD90400C.TMP 2014-03-01 19:19:53 -------- d-----w- C:\\WINDOWS\\ERUNT 2014-03-01 19:19:53 -------- d-----w- C:\\WINDOWS\\\ERUNT 2014-03-21 12:43:48 11EE2BECE455394513C356C09CFF8523 25453696 ----a-w- C:\\Config.Msi\60108.rbs 2014-03-21 11:57:22 -------- d-----w- C:\\WINDOWS\Temp 2014-03-17 18:48:18 -------- d-----w- C:\\AdwCleaner\Backup 2014-03-17 18:48:08 090226161A7BAEDE94280AB49F579C59 1967 ----a-w- C:\\AdwCleaner\AdwCleaner[S0].txt 2014-03-17 18:46:30 791191603A04553DB907DC51A98C1ACB 2019 ----a-w- C:\\AdwCleaner\AdwCleaner[R0].txt 2014-03-17 18:46:09 -------- d-----w- C:\\AdwCleaner\Quarantine 2014-03-16 10:07:19 D6830BB9A35F3E06C06117D9FE78F7FD 629120 ----a-w- C:\\!KillBox\SysPlayerMenu.dll 2014-03-15 13:34:07 -------- d-----w- C:\\Documents and Settings\Administrator.DHONDT-4CF86C1E 2014-03-15 13:29:50 -------- d-----w- C:\\Documents and Settings\Administrator 2014-03-08 09:58:20 AC97C7311F39CA07C785A7D77274A104 4068 ----a-w- C:\\WINDOWS\SETUP.LST 2014-03-08 09:58:20 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\ST6UNST.001 2014-03-08 09:57:57 4AF08CCBCCE59FDA9C64B29F5B206BEF 303 ----a-w- C:\\WINDOWS\ST6UNST.000 2014-03-01 20:41:56 D9707499E7F4BF465EEBF747B40C4CA7 438 ----a-w- C:\\cmdcons\winnt.sif 2014-03-01 20:41:56 5780A0C2FD8B6A0CC93EEDB71C242582 22107 ----a-w- C:\\cmdcons\migrate.inf 2014-03-01 20:41:56 4223086FAE6CF965DE5DF9BC1245E6A1 8192 ----a-w- C:\\cmdcons\bootsect.dat 2014-03-01 20:41:46 4CAC32AB7BEAD8D8CF4001883507D12C 453815 ----a-w- C:\\cmdcons\txtsetup.sif 2014-03-01 20:41:45 5F1499F64F80AA219A94A5D945B3836D 610816 ----a-w- C:\\cmdcons\autofmt.exe 2014-03-01 20:41:44 3C200120F6E86A1A42EDA2E1E2D17AEC 619008 ----a-w- C:\\cmdcons\autochk.exe 2014-03-01 20:41:44 -------- d-----w- C:\\cmdcons\SYSTEM32 2014-03-01 19:32:45 -------- d-----w- C:\\WINDOWS\455F074C814E4520B69B5584BD90400C.TMP 2014-03-01 19:19:53 -------- d-----w- C:\\WINDOWS\ERUNT ====== C: exe-files == 2014-03-17 18:54:47 E677174AA15D1B9D9E0B0F1C8DB8CC56 892120 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.154\33.0.1750.154_33.0.1750.146_chrome_updater.exe 2014-03-17 18:44:50 DF06DC5837316EA78746E3F790A950ED 1950720 ----a-w- C:\Documents and Settings\Wesley&Lieselotte\Bureaublad\adwcleaner.exe 2014-03-16 10:06:04 32CABB7112E22422075279BAE1BF729B 92672 ----a-w- C:\Documents and Settings\Wesley&Lieselotte\Bureaublad\pocket-killbox-2.0.0.881-en.exe === C: other files == 2014-03-22 10:02:33 78239914871A91789BE51E1C612474E0 383 ----a-w- C:\Documents and Settings\All Users\Application Data\AVG2014\IDS\outbox\persist.zip 2014-03-17 18:48:27 7E1482AE43876330278F9A62B97F1B8D 12512151 ----a-w- C:\Documents and Settings\All Users\Application Data\AVG2014\IDS\outbox\p0\submit.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_USERS\S-1-5-21-1085031214-688789844-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe /background" "MyDriveConnect.exe"="C:\Program Files\MyDrive Connect\MyDriveConnect.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" "AVG_UI"="C:\Program Files\AVG\AVG2014\avgui.exe /TRAYONLY" "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe /background" "MyDriveConnect.exe"="C:\Program Files\MyDrive Connect\MyDriveConnect.exe" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [15/03/2014 15:01] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [19/07/2013 16:32] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [19/07/2013 16:32] C:\WINDOWS\tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job --a------ C:\WINDOWS\system32\xp_eos.exe [27/02/2014 00:28] C:\WINDOWS\tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job --a------ C:\WINDOWS\system32\xp_eos.exe [27/02/2014 00:28] C:\WINDOWS\tasks\User_Feed_Synchronization-{DC03EE8C-BFD8-4335-A7B0-9A75AE786F17}.job --ah----- C:\WINDOWS\system32\msfeedssync.exe [08/03/2009 04:31] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [25/02/2013 12:24] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== HijackThis Entries ====================== O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Mio Share] C:\Documents and Settings\Wesley&Lieselotte\Menu Start\Programma's\Mio\Mio Share.appref-ms O4 - HKCU\..\Run: [MyDriveConnect.exe] "C:\Program Files\MyDrive Connect\MyDriveConnect.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: CodecPackTrayMenu.lnk = C:\WINDOWS\system32\C2MP\TrayMenu.exe O4 - Global Startup: CodecPackUpdateChecker.lnk = C:\WINDOWS\system32\C2MP\UpdateChecker.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: TP-LINK Draadloos configuratie hulpprogramma.lnk = C:\Program Files\TP-LINK\TP-LINK Draadloos configuratie hulpprogramma\TWCU.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1361907569125 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe ==== Empty IE Cache ====================== C:\\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\\Documents and Settings\Administrator.DHONDT-4CF86C1E\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\\Documents and Settings\Wesley&Lieselotte\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=20 folders=11 3555862 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\DOCUME~1\WESLEY~1\LOCALS~1\Temp successfully emptied ==== Deleting Files / Folders ====================== "C:\\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\\Documents and Settings\Wesley&Lieselotte\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on za 22/03/2014 at 11:15:33,18 ======================