Zoek.exe v5.0.0.0 Updated 18-01-2015 Tool run by Dave on vr 23/01/2015 at 19:33:20,95. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Dave\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Running Processes ====================== C:\WINDOWS\system32\wininit.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe C:\WINDOWS\system32\atiesrxx.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\IDT\WDM\STacSV64.exe C:\Program Files\Classic Shell\ClassicShellService.exe C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\WINDOWS\system32\svchost.exe -k apphost C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe c:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe C:\WINDOWS\system32\DllHost.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\WINDOWS\system32\DllHost.exe C:\WINDOWS\system32\vssvc.exe C:\WINDOWS\System32\svchost.exe -k swprv C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe C:\WINDOWS\System32\WinLogon.exe C:\WINDOWS\System32\dwm.exe C:\WINDOWS\system32\atieclxx.exe C:\Program Files\Classic Shell\ClassicStartMenu.exe C:\WINDOWS\system32\taskhostex.exe C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe C:\WINDOWS\Explorer.EXE C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe C:\Program Files\IDT\WDM\Beats64.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Dave\Downloads\zoek.exe C:\WINDOWS\system32\conhost.exe C:\WINDOWS\system32\wbem\wmiprvse.exe ==== System Restore Info ====================== 23/01/2015 19:35:24 Zoek.exe System Restore Point Created Succesfully. ==== Windows Installer Info ====================== Adobe AIR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\360D32EFD43992840A8D0036C47EB9A4]C:\WINDOWS\Installer\2d89a207.msi Adobe Help Manager [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A67173FAAC87B54543FEB8A61215D41D]C:\WINDOWS\Installer\2d89a20d.msi AMD Accelerated Video Transcoding [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9F557E66C8EE2A3A8D75951233D62646]c:\windows\Installer\4cf172a.msi AMD APP SDK Runtime [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D276F30548C6A844F8F8B43CA58C4314]C:\windows\Installer\1c636.msi AMD Catalyst Install Manager [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CBE8D524EEDE740A36AB0FA2D2D335E1]c:\windows\Installer\4cf1463.msi Catalyst Control Center - Branding [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\77E46F1B9B2E577409C4449528E76666]c:\windows\Installer\4cf164a.msi Catalyst Control Center [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1BE78CE12455323236B0FF7F4106D430]c:\windows\Installer\4cf16ed.msi Catalyst Control Center Graphics Previews Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\05E9B6E3DDC4E94414B037DCF714F88E]c:\windows\Installer\4cf1650.msi Catalyst Control Center InstallProxy [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\579367911F4F41D1D77DF0422597ACB7]c:\windows\Installer\4cf145c.msi Catalyst Control Center Localization All [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\14670283695A99C2D088BBE1BD75C953]c:\windows\Installer\4cf16da.msi Catalyst Control Center Profiles Desktop [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\280EDBDE532E741452E317EB4679F86D]c:\windows\Installer\4cf16e0.msi ccc-utility64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DF85E94788ECCD54C5A9B5F4648D4276]c:\windows\Installer\4cf16e6.msi CCC Help Chinese Standard [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8FA7DF8972683E5F9C0E7595964B66AE]c:\windows\Installer\4cf16ce.msi CCC Help Chinese Traditional [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\51C13EC28C16FE7B4DF367CEC63881D7]c:\windows\Installer\4cf16d4.msi CCC Help Czech [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E694179A07A13749F07FD04783A4BB84]c:\windows\Installer\4cf1656.msi CCC Help Danish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E953A0E0853044E047605A16598FE01B]c:\windows\Installer\4cf165c.msi CCC Help Dutch [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B136E07D1DAA74BE0E646FB66A5704FF]c:\windows\Installer\4cf169e.msi CCC Help English [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FA49B71B09897B5751B9D99F46EEE5C]c:\windows\Installer\4cf166e.msi CCC Help Finnish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B384277600A51F8F1222DE3C291F825E]c:\windows\Installer\4cf167a.msi CCC Help French [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DD7F7CEC0173355FE4E0F3955D3B55F6]c:\windows\Installer\4cf1680.msi CCC Help German [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3C76E553D4D100D9A5657AE66DD2CE69]c:\windows\Installer\4cf1662.msi CCC Help Greek [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0889AE8A44F4E9100981118D41DCBF17]c:\windows\Installer\4cf1668.msi CCC Help Hungarian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EF083EAD8F0DD7D3D55514B52FCF47F0]c:\windows\Installer\4cf1686.msi CCC Help Italian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AFF9B4CB1C944A8169D2F83B5BA0A08D]c:\windows\Installer\4cf168c.msi CCC Help Japanese [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\24CBDA6CB96B0E69EADF46A5C264C547]c:\windows\Installer\4cf1692.msi CCC Help Korean [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3FE3804FC6B4E49482644D368987A779]c:\windows\Installer\4cf1698.msi CCC Help Norwegian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\258F455B896D8DEA8AADC0585D2EAC7D]c:\windows\Installer\4cf16a4.msi CCC Help Polish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DF4FFE436EA28D2BEC41554158E7B6CD]c:\windows\Installer\4cf16aa.msi CCC Help Portuguese [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\50515D4185650704E0D07951EA677D19]c:\windows\Installer\4cf16b0.msi CCC Help Russian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A568D88C086FC655F5BAC0313C5C45E8]c:\windows\Installer\4cf16b6.msi CCC Help Spanish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B05C548CA7C3FC84E607FDC0E990AB9D]c:\windows\Installer\4cf1674.msi CCC Help Swedish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\09627F44D97B808B9DFA8D17E6A622D8]c:\windows\Installer\4cf16bc.msi CCC Help Thai [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0F22D77528E345DB8813BE57106C5D96]c:\windows\Installer\4cf16c2.msi CCC Help Turkish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3C3FD046BDFE276A3EEDF37D8A8416D1]c:\windows\Installer\4cf16c8.msi Classic Shell [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B0951AEFA045CF149AC56644398CA212]C:\windows\Installer\118f72.msi D3DX10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7BD4C90EC03660F46A13E87A329932FA]C:\windows\Installer\1c6b9.msi Fotogalerie [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AE30E91BC760F2148AE17271026E10BA]C:\windows\Installer\1c6d4.msi Galerie de photos [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0DDFD8EF345A38A47B9A4C113118495D]C:\windows\Installer\1c6e3.msi Google Update Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\93BAD29AC2E44034A96BCB446EB8552E]C:\WINDOWS\Installer\15f978ee.msi Hewlett-Packard ACLM.NET v1.2.2.3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\701043F6AA9F6C745BC43C1AF91155F3]C:\WINDOWS\Installer\1d0fe38.msi HP Connected Remote [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B43A342FF7BA56047B078BB567C742C7]c:\windows\Installer\1c658.msi HP Customer Experience Enhancements [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0694AF70830BBE9498B1F95939A05A44]C:\windows\Installer\1c64a.msi HP Postscript Converter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6D6E41E65713A1E49B43AC5B8A3676DC]C:\windows\Installer\1c671.msi HP Quick Start [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\659AC7CB4A2A55A4E8E6055CB9B4DDC5]c:\windows\Installer\16252aab.msi HP Registration Service [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE824E2CE6110C14E9482BD29ECC4AF2]c:\windows\Installer\1c581.msi HP Support Assistant [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\31B3A53EDC877694A88CAAF9AD96E3ED]C:\WINDOWS\Installer\1d0fe32.msi HP Support Information [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8C1B7B2BB8C7C674EBC24079135C9529]C:\windows\Installer\1c70e.msi HydraVision [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4A56790FD16B09AC7448E74213361B05]c:\windows\Installer\4cf1719.msi Intel© Trusted Connect Service Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DFA4044F3FE21C04C890925E3F6B79B2]c:\windows\Installer\1c594.msi LabelPrint [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C971C95CD8669A946BAE1012CCCF2134]c:\windows\Installer\1c68c.msi Media Suite [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42C6FBF1Df1C10144AB2C065F4E9E897]c:\windows\Installer\1c69a.msi Microsoft Application Error Reporting [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000021599B0090400100000000F01FEC]C:\windows\Installer\1c6aa.msi Microsoft Office Access MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109510031400000000000F01FEC]C:\windows\Installer\119059.msi Microsoft Office Excel MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109610031400000000000F01FEC]C:\windows\Installer\119016.msi Microsoft Office InfoPath MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109440031400000000000F01FEC]C:\windows\Installer\119027.msi Microsoft Office Office 64-bit Components 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A20000000100000000F01FEC]C:\windows\Installer\11905f.msi Microsoft Office Outlook Connector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004159180031400000000000F01FEC]C:\windows\Installer\56a2518.msi Microsoft Office Outlook MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A10031400000000000F01FEC]C:\windows\Installer\11901c.msi Microsoft Office PowerPoint MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109810031400000000000F01FEC]C:\windows\Installer\119022.msi Microsoft Office Professional Plus 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109110000000000000000F01FEC]C:\windows\Installer\119067.msi Microsoft Office Proof (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10031400000000000F01FEC]C:\windows\Installer\119031.msi Microsoft Office Proof (English) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10090400000000000F01FEC]C:\windows\Installer\119042.msi Microsoft Office Proof (French) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F100C0400000000000F01FEC]C:\windows\Installer\11903c.msi Microsoft Office Proof (German) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10070400000000000F01FEC]C:\windows\Installer\119036.msi Microsoft Office Proofing (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109C20031400000000000F01FEC]C:\windows\Installer\119047.msi Microsoft Office Publisher MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109910031400000000000F01FEC]C:\windows\Installer\11904d.msi Microsoft Office Shared 64-bit MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A20031400100000000F01FEC]C:\windows\Installer\11902c.msi Microsoft Office Shared MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109E60031400000000000F01FEC]C:\windows\Installer\119011.msi Microsoft Office Word MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109B10031400000000000F01FEC]C:\windows\Installer\119053.msi Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D034B0FAA6BD374B960AAD30DF10D8B]C:\windows\Installer\1c6c2.msi Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1af2a8da7e60d0b429d7e6453b3d0182]C:\WINDOWS\Installer\cd6a52.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\c1c4f01781cc94c4c8fb1542c0981a2a]C:\windows\Installer\1c696.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EFEE0228DC83E77358593193D847A0EC]C:\WINDOWS\Installer\4545afdf.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1007C6B46D7C017319E3B52CF3EC196E]c:\windows\Installer\1c709.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\67D6ECF5CD5FBA732B8B22BAC8DE1B4D]c:\windows\Installer\7c35a89.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1E4ACFA687B90463F8277AFB33442800]c:\WINDOWS\Installer\ffbe8c4.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057]c:\windows\Installer\1c676.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CFD2C1F142D260E3CB8B271543DA9F98]C:\windows\Installer\1c662.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E815EB96CCE9A53884E7857C57002F0]c:\windows\Installer\7c35a90.msi Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1926E8D15D0BCE53481466615F760A7F]c:\windows\Installer\145d3.msi Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D5E3C0FEDA1E123187686FED06E995A]c:\windows\Installer\12ba4.msi Microsoft_VC80_CRT_x86 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\91785D291CBB3CC40AB8659C8E48CCC2]C:\WINDOWS\Installer\2d89a201.msi Microsoft_VC90_CRT_x86 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\121E2D80A6F7BE3479DF26B944094330]C:\WINDOWS\Installer\2d89a1fb.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00A286F7794615542A6A60A36E761DFC]C:\windows\Installer\1c6d7.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7CF988168379A934693B71FA89B1DDFE]C:\windows\Installer\1c704.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BDA7BDCC346103C43BD95126FC5E4102]C:\windows\Installer\1c6f5.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E45CB17D6E4A60E468C6DFE61EE61A78]C:\windows\Installer\1c6c8.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F64E64890E70FDB489A53EBF8A1C8577]C:\windows\Installer\1c6e6.msi MSVCRT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6C64DD86500CEF47BA082BB611A1FF1]C:\windows\Installer\1c69e.msi MSVCRT110 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8CDD41E806AE81E43B3E917301D4B5AD]C:\windows\Installer\1c6a1.msi MSVCRT110_amd64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0B8F248F2496039428F145E379B6C266]C:\windows\Installer\1c6a4.msi PDF Settings CS6 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\77EAAEFBF7DB43542B68C9C54B96E71B]C:\WINDOWS\Installer\2d89a222.msi Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\19CF135DE4F67A949B215182D9506B8F]C:\windows\Installer\1c6e0.msi Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3A0AF72BF08D9A14B8DA5C2F8D95BA22]C:\windows\Installer\1c6d1.msi Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4F74DB53B91CF474AACC8E0CEB8341A8]C:\windows\Installer\1c6fe.msi Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DEF6A77DC652F2E48937959CC258A4E4]C:\windows\Installer\1c6ef.msi Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7D95AA00D29B60A4D860506980C1E086]C:\windows\Installer\1c6f2.msi Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8F55E2B98AB554A46928CA6B2FCCD05A]C:\windows\Installer\1c6c5.msi Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E3B8D0C40F363774385F5C7B97B5F08B]C:\windows\Installer\1c701.msi PhotoDirector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A4432684C93A7984CA4D1AEB5D61C3A5]c:\windows\Installer\1c666.msi Power2Go [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D84D78A2FDF3df1479DC1A3E07FEFF2E]c:\windows\Installer\1c67a.msi PowerDirector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2D6F4B0BEA2FA1544969F6F2A698B723]c:\windows\Installer\1c67f.msi PowerDVD [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DE532CED4A8571542A874CE1D8EABAB3]c:\windows\Installer\1c687.msi PowerRecover [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BA0A2B44E214C8F40B851D8EEACCFD5F]c:\windows\Installer\1c64e.msi Samsung Kies [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1038C85769625584FA5435B4210089A0]C:\WINDOWS\Installer\134fb425.msi Spotnet [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42987821B012C0A4C86AC6967765AB23]C:\windows\Installer\3fa7c8.msi TomTom HOME [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8C1BB2A7D3095854F9B3ACDD760DD773]C:\WINDOWS\Installer\a5cc4b3.msi TomTom HOME Visual Studio Merge Modules [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5C13C3F8A3C98AA4E8AF1792A0A75D33]C:\WINDOWS\Installer\237c1bf0.msi Windows Live [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\98453F87D126DFF4CB7EC2C783794EC7]C:\windows\Installer\1c6dd.msi Windows Live Communications Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B96437AB7C8D3EF43BC331040DF97090]C:\windows\Installer\1c6b3.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\50DBCFBE3A773CF46A2D7212B8169D75]C:\windows\Installer\1c6fb.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\936DE89662A3FE941BFEDC98BC797C87]C:\windows\Installer\1c6ec.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E73EFAF2697D8B74ABF80D89911BD26F]C:\windows\Installer\1c6ce.msi Windows Live Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EF8EE67759115C4094794038AFC1BFA]C:\windows\Installer\1c6a7.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4047FD4664D9FA44FA1A2A8F5D46C8D2]C:\windows\Installer\1c6bf.msi Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B1157501EF8F0324E93DBA49A975EEA4]C:\windows\Installer\1c6b6.msi Windows Live SOXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F283A9F48744630409C57FD72FAE3007]C:\windows\Installer\1c6b0.msi Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\480F8AF4F24C1E547B5E0E8C1A80D35C]C:\windows\Installer\1c6ad.msi Windows Live UX Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CEC51392EC6E493448CDF668E2D8A925]C:\windows\Installer\1c6bc.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\210F98643E8CE6F4DBFE3176D1356ACD]C:\windows\Installer\1c6da.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5B414EA26EF73A94398C8D4661C2EDCB]C:\windows\Installer\1c6e9.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DB93F8160279FC748AC901A84BB14139]C:\windows\Installer\1c6cb.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E819B332DF993464EBDD9A58A565CFA3]C:\windows\Installer\1c6f8.msi ==== Empty Folders Check ====================== C:\PROGRA~2\AVS4YOU deleted successfully C:\PROGRA~2\Delhaize deleted successfully C:\PROGRA~2\Eidos Interactive deleted successfully C:\PROGRA~2\Optimizer Pro deleted successfully C:\PROGRA~3\374311380 deleted successfully C:\PROGRA~3\ALM deleted successfully C:\Users\Dave\AppData\Roaming\WinRAR deleted successfully C:\Users\Dave\AppData\Local\HP Quick Start deleted successfully ==== Checking Systemdrive for Symlinks ====================== Volume in drive C is OS Volume Serial Number is B4EB-8935 Directory of C:\ 22/08/2013 15:45 Documents and Settings [C:\Users] 0 File(s) 0 bytes Directory of C:\Program Files\Windows NT 28/10/2013 00:42 Bureau-accessoires [C:\Program Files\Windows NT\Accessories] 0 File(s) 0 bytes Directory of C:\ProgramData 22/08/2013 15:45 Application Data [C:\ProgramData] 11/10/2013 19:30 Bureaublad [C:\Users\Public\Desktop] 22/08/2013 15:45 Desktop [C:\Users\Public\Desktop] 11/10/2013 19:30 Documenten [C:\Users\Public\Documents] 22/08/2013 15:45 Documents [C:\Users\Public\Documents] 11/10/2013 19:30 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/10/2013 19:30 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 15:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 15:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\ProgramData\Microsoft\Windows\Start Menu 11/10/2013 19:30 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\SYSTEM.SAV\LOGS\SymLogs 08/08/2013 21:10 cclog [C:\Users\Public\Symantec\SymSilent\cclog] 0 File(s) 0 bytes Directory of C:\Users 22/08/2013 15:45 All Users [C:\ProgramData] 22/08/2013 15:45 Default User [C:\Users\Default] 0 File(s) 0 bytes Directory of C:\Users\All Users 22/08/2013 15:45 Application Data [C:\ProgramData] 11/10/2013 19:30 Bureaublad [C:\Users\Public\Desktop] 22/08/2013 15:45 Desktop [C:\Users\Public\Desktop] 11/10/2013 19:30 Documenten [C:\Users\Public\Documents] 22/08/2013 15:45 Documents [C:\Users\Public\Documents] 11/10/2013 19:30 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/10/2013 19:30 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 15:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 15:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\All Users\Microsoft\Windows\Start Menu 11/10/2013 19:30 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Dave 28/10/2013 00:32 Application Data [C:\Users\Dave\AppData\Roaming] 28/10/2013 00:32 Cookies [C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCookies] 28/10/2013 00:32 Local Settings [C:\Users\Dave\AppData\Local] 28/10/2013 00:32 Menu Start [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu] 28/10/2013 00:32 Mijn documenten [C:\Users\Dave\Documents] 28/10/2013 00:32 NetHood [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 28/10/2013 00:32 Netwerkprinteromgeving [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 28/10/2013 00:32 Recent [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Recent] 28/10/2013 00:32 SendTo [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\SendTo] 28/10/2013 00:32 Sjablonen [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Dave\AppData\Local 28/10/2013 00:32 Application Data [C:\Users\Dave\AppData\Local] 28/10/2013 00:32 Geschiedenis [C:\Users\Dave\AppData\Local\Microsoft\Windows\History] 28/10/2013 00:32 Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Dave\AppData\Local\Microsoft\Windows 28/10/2013 00:32 Temporary Internet Files [C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache 28/10/2013 00:51 Content.IE5 [C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 File(s) 0 bytes Directory of C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low 27/03/2014 02:06 Content.IE5 [C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE\] 0 File(s) 0 bytes Directory of C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu 28/10/2013 00:32 Programma's [C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Dave\Documents 28/10/2013 00:32 Mijn afbeeldingen [C:\Users\Dave\Pictures] 28/10/2013 00:32 Mijn muziek [C:\Users\Dave\Music] 28/10/2013 00:32 Mijn video's [C:\Users\Dave\Videos] 0 File(s) 0 bytes Directory of C:\Users\Default 22/08/2013 15:45 Application Data [C:\Users\Default\AppData\Roaming] 22/08/2013 15:45 Cookies [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCookies] 22/08/2013 15:45 Local Settings [C:\Users\Default\AppData\Local] 28/10/2013 00:42 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 28/10/2013 00:42 Mijn documenten [C:\Users\Default\Documents] 22/08/2013 15:45 My Documents [C:\Users\Default\Documents] 22/08/2013 15:45 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 28/10/2013 00:42 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/08/2013 15:45 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/08/2013 15:45 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 22/08/2013 15:45 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 28/10/2013 00:42 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 22/08/2013 15:45 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 22/08/2013 15:45 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Local 22/08/2013 15:45 Application Data [C:\Users\Default\AppData\Local] 28/10/2013 00:42 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 15:45 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 15:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Local\Microsoft\Windows 22/08/2013 15:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 28/10/2013 00:42 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Default\Documents 28/10/2013 00:42 Mijn afbeeldingen [C:\Users\Default\Pictures] 28/10/2013 00:42 Mijn muziek [C:\Users\Default\Music] 28/10/2013 00:42 Mijn video's [C:\Users\Default\Videos] 22/08/2013 15:45 My Music [C:\Users\Default\Music] 22/08/2013 15:45 My Pictures [C:\Users\Default\Pictures] 22/08/2013 15:45 My Videos [C:\Users\Default\Videos] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated 11/10/2013 19:30 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 11/10/2013 19:30 Mijn documenten [C:\Users\Default\Documents] 11/10/2013 19:30 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 11/10/2013 19:30 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\AppData\Local 11/10/2013 19:30 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu 11/10/2013 19:30 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\Documents 11/10/2013 19:30 Mijn afbeeldingen [C:\Users\Default\Pictures] 11/10/2013 19:30 Mijn muziek [C:\Users\Default\Music] 11/10/2013 19:30 Mijn video's [C:\Users\Default\Videos] 26/07/2012 08:22 My Music [C:\Users\Default\Music] 26/07/2012 08:22 My Pictures [C:\Users\Default\Pictures] 26/07/2012 08:22 My Videos [C:\Users\Default\Videos] 0 File(s) 0 bytes Directory of C:\Users\Public\Documents 11/10/2013 19:30 Mijn afbeeldingen [C:\Users\Public\Pictures] 11/10/2013 19:30 Mijn muziek [C:\Users\Public\Music] 11/10/2013 19:30 Mijn video's [C:\Users\Public\Videos] 22/08/2013 15:45 My Music [C:\Users\Public\Music] 22/08/2013 15:45 My Pictures [C:\Users\Public\Pictures] 22/08/2013 15:45 My Videos [C:\Users\Public\Videos] 0 File(s) 0 bytes Directory of C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache 27/12/2014 10:52 Content.IE5 [C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 File(s) 0 bytes Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache 27/12/2014 10:52 Content.IE5 [C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 File(s) 0 bytes Total Files Listed: 0 File(s) 0 bytes 91 Dir(s) 168˙956˙186˙624 bytes free ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\SearchScopes\{F4756FB4-F0ED-4FE5-AD0D-24CF3F2DA9F4} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1558c8c5-8e72-477f-8ae2-d029907908bc} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A932E66-DF20-475C-956C-72761F21DDAC} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1C497D5E-3775-4BFE-9C68-2C7210117AB3} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{376EDB01-2D48-454D-B116-8EA5B8D26F4} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38594EB-273F-483E-8911-65C8E7879D98} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{47F0A61D-DDD4-4030-A7A-CE8F5063136E} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5A5A13D-166C-49EC-BA94-9472D883CBA} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D20A5D8-8094-4C09-A5A8-ACE566775378} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E764B06-AECA-43C4-963C-9A7ACC23C66D} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{60EA3D2D-62DD-4B38-8021-56C4178D287} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75F4A82E-BF13-46A0-9088-2E6F861D1FA9} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BBFF9E6F-DEAD-43AB-847A-DD5FD1FAD5E9} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC6323D1-3D46-4DF0-BD30-6CB8403547E2} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bc730db1-ac37-40a9-b958-ae54db51f209} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D51F67DE-AE24-4560-82D0-17E32EFECD8C} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DEE70E9F-317A-43B3-87CA-2B10B7CC1077} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E08E37AE-AB16-4217-9246-CF22CCB5ABF1} deleted successfully HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E88D60EE-690E-46EB-AC79-A2AE5614185A} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Adobe AIR Adobe Flash Player 16 NPAPI Adobe Help Manager AMD Accelerated Video Transcoding AMD APP SDK Runtime AMD Catalyst Install Manager Be a King 2 Big Fish: Game Manager Build-a-lot Catalyst Control Center - Branding Catalyst Control Center Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All Catalyst Control Center Profiles Desktop ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner CEWE FOTOBOEK Cewe Photoservice Classic Shell Connected Music powered by Universal Music Group version 1.0 CyberLink LabelPrint CyberLink Media Suite 10 CyberLink PhotoDirector CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD D3DX10 Elf Bowling 7 1/7: The Last Insult Fotoalbum.be Fotogalerie Fotogoed Designer 3.8.4 G DATA INTERNET SECURITY Galerie de photos Google Chrome Google Update Helper GrabIt 1.7.2 Beta 6 (build 1008) Hewlett-Packard ACLM.NET v1.2.2.3 HP Connected Music (Meridian - installer) HP Connected Remote HP Customer Experience Enhancements HP Postscript Converter HP Quick Start HP Registration Service HP Support Information HydraVision IDT Audio Intel(R) Management Engine Components Intel© Trusted Connect Service Client Master of Defense Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (Dutch) 2007 Microsoft Office Excel MUI (Dutch) 2007 Microsoft Office InfoPath MUI (Dutch) 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (Dutch) 2007 Microsoft Office PowerPoint MUI (Dutch) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (Dutch) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proofing (Dutch) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (Dutch) 2007 Microsoft Office Shared 64-bit MUI (Dutch) 2007 Microsoft Office Shared MUI (Dutch) 2007 Microsoft Office Word MUI (Dutch) 2007 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_CRT_x86 Microsoft_VC90_CRT_x86 Movie Maker MSVCRT MSVCRT110 MSVCRT110_amd64 MyFreeCodec PDF Settings CS6 Photo Common Photo Gallery Pinup Strip Poker Pinup Strip Poker Demo Ralink RT5390R 802.11bgn Wi-Fi Adapter Realtek Ethernet Controller Driver Recovery Manager Risk II RiskT Roads of Rome Samsung Kies SAMSUNG USB Driver for Mobile Phones Samsung_MonSetup Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596927) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2878233) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2920790) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2920792) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2984942) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2817565) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2920793) 32-Bit Edition Spotnet Star Defender 4 Star Defender II Star Defender III TI xHCI Filter Driver 1.0.0.4 TomTom HOME TomTom HOME Visual Studio Merge Modules Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2920789) 32-Bit Edition Update for Microsoft Office PowerPoint 2007 (KB2597972) 32-Bit Edition Update voor Microsoft Office Excel 2007 Help (KB963678) Update voor Microsoft Office Powerpoint 2007 Help (KB963669) Update voor Microsoft Office Word 2007 Help (KB963665) VLC media player 2.1.3 Windows Live Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack World Mosaics Chroma ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Connected Music powered by Universal Music Group deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted C:\WINDOWS\SysNative\config\systemprofile\Searches deleted C:\Users\Dave\Documents\Optimizer Pro deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8148 MB CPU Info: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz CPU Speed: 3482,4 MHz Sound Card: Speakers / Headphones (IDT High | Display Adapters: AMD Radeon R7 200 Series | AMD Radeon R7 200 Series Monitors: 1x; SD590_S27D590P (HDMI) | Screen Resolution: 1920 X 1080 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Ralink RT5390R 802.11bgn Wi-Fi Adapter | Realtek PCIe GBE Family-controller CD / DVD Drives: 1x (E: | ) E: hp CDDVDW SH-216BB Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 3 Button Wheel Mouse Present Hard Disks: C: 459,6GB | D: 12,3GB | H: 457,8GB Hard Disks - Free: C: 157,3GB | D: 1,4GB | H: 350,2GB Manufacturer *: AMI BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1072009 Time Zone: Romance (standaardtijd) Motherboard *: Foxconn 2ADA Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: G DATA INTERNET SECURITY On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: G DATA INTERNET SECURITY disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Firewall: G DATA Personal Firewall disabled Default Browser: Google Chrome 40.0.2214.91 Internet Explorer Version: 11.0.9600.17498 Google Chrome version: 40.0.2214.91 Flash Player version: 16.0.0.287 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\Dave\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-01-14 07:53:02 DCE9FD22B136C127C85F285E083B928B 65536 ----a-w- C:\WINDOWS\SysWOW64\nlaapi.dll 2015-01-14 07:53:01 D9F17FC61102D89A67A2AA3DD21231F5 33584 ----a-w- C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 07:53:01 7C36A441C73F079781ABA8F3DAEDFB37 136296 ----a-w- C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 07:53:01 1F9C1925A85C6CC592C2FF612A610412 372408 ----a-w- C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 07:53:01 1EB1C1E43C1901865C5AE34A9771C069 448792 ----a-w- C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 07:53:01 1275462A4337DBC5518859316BEF262C 413136 ----a-w- C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 07:53:00 BFFD9961B29DAB8084278DB2314D6027 33280 ----a-w- C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 07:53:00 B5867FF96CD0F7712CB4985EAC9F9147 370424 ----a-w- C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 07:53:00 7B2643AE85322EA168B0E760B73258FF 424544 ----a-w- C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 07:53:00 4B07B24705A9225EB565650569BDA26B 344536 ----a-w- C:\WINDOWS\SysWOW64\AUDIOKSE.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-01-14 07:53:02 FE11972797DED38CA55E88BD3579F6A2 360448 ----a-w- C:\WINDOWS\Sysnative\ncsi.dll 2015-01-14 07:53:02 E94EB2A95D7D016E119C4D6868788831 391680 ----a-w- C:\WINDOWS\Sysnative\nlasvc.dll 2015-01-14 07:53:02 6319232C1CE39AC35316CF51910EEEB5 86016 ----a-w- C:\WINDOWS\Sysnative\nlaapi.dll 2015-01-14 07:53:02 19424364D8C03B990C4281BE53963FD0 225280 ----a-w- C:\WINDOWS\Sysnative\profsvc.dll 2015-01-14 07:53:01 A41B72F81B389786805CC4D5767B5FBC 531616 ----a-w- C:\WINDOWS\Sysnative\ci.dll 2015-01-14 07:53:01 9404704666256045F5BA9B290953B4D0 38264 ----a-w- C:\WINDOWS\Sysnative\WerFaultSecure.exe 2015-01-14 07:53:01 8EBC741DDE9409038262E2F317ED7CCE 535640 ----a-w- C:\WINDOWS\Sysnative\wer.dll 2015-01-14 07:53:01 8779FDAE68BC948B0FE152E758CC8DA7 229888 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2015-01-14 07:53:01 6DCD12586353DC6307AC781045CA13A4 465320 ----a-w- C:\WINDOWS\Sysnative\WerFault.exe 2015-01-14 07:53:01 41C501FD9D42F3F04A8532C73E09F356 108944 ----a-w- C:\WINDOWS\Sysnative\EncDump.dll 2015-01-14 07:53:01 2C354FA91EF605007FD11BB89EED2266 413248 ----a-w- C:\WINDOWS\Sysnative\Faultrep.dll 2015-01-14 07:53:01 29A888F3136B2643E22113B5422B46F9 87040 ----a-w- C:\WINDOWS\Sysnative\TSWbPrxy.exe 2015-01-14 07:53:00 E24D3259769A0218FE19BB306821C2E5 394120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2015-01-14 07:53:00 D1E3B8D9130C70F6A3D4FDB52373FF34 37888 ----a-w- C:\WINDOWS\Sysnative\werdiagcontroller.dll 2015-01-14 07:53:00 770BAA636F3B61DA7E414421444F84FD 272248 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2015-01-14 07:53:00 6F237EE5DDA34EAF3D9C79D4A283E250 482872 ----a-w- C:\WINDOWS\Sysnative\AudioEng.dll 2015-01-14 07:53:00 61EA45A645854FE81D8A924E2D93DFFE 911360 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2015-01-14 07:53:00 428F083690D7AAA012338FD5A0663EE3 500016 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2015-01-14 07:53:00 0BCDEB035B9346D3C3C6C8BB1AA7F38C 139984 ----a-w- C:\WINDOWS\Sysnative\wermgr.exe ====== C:\WINDOWS\Sysnative\drivers ===== 2015-01-14 07:53:02 F0CB6DB513CAC393D04A0FCE0A59E1BF 75776 ----a-w- C:\WINDOWS\Sysnative\drivers\ahcache.sys 2015-01-14 07:53:02 DB32958F0E704EFBF7F15161A569E39F 140800 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxdav.sys 2015-01-03 09:23:40 4D7109EDC2805B5FDBE614047BF72B28 18160 ----a-w- C:\WINDOWS\Sysnative\drivers\GdPhyMem.sys 2015-01-03 09:23:39 57875BA7B65C5FE5A87630DC1544C420 106272 ----a-w- C:\WINDOWS\Sysnative\drivers\GRD.sys 2014-12-27 09:43:33 383FA07DC3CBD2B084BB90E9A9A4A87B 64000 ----a-w- C:\WINDOWS\Sysnative\drivers\PktIcpt.sys 2014-12-27 09:43:28 3AEF393C011738ADDF09057E221EE7D8 20992 ----a-w- C:\WINDOWS\Sysnative\drivers\GDKBFlt64.sys 2014-12-27 09:43:11 0313E2A2B18A2AF40F3C9445653FDE9A 68608 ----a-w- C:\WINDOWS\Sysnative\drivers\gdwfpcd64.sys 2014-12-27 09:43:07 F5A571A95A3E22877D0CBC60F7D66E05 142336 ----a-w- C:\WINDOWS\Sysnative\drivers\MiniIcpt.sys 2014-12-27 09:43:07 EB6EB3DCC2AD18236EEC42B2FC7BD806 61440 ----a-w- C:\WINDOWS\Sysnative\drivers\HookCentre.sys 2014-12-27 09:43:07 A90A90714221E50856FC009545E9A5CB 55808 ----a-w- C:\WINDOWS\Sysnative\drivers\GDBehave.sys ====== C:\WINDOWS\Tasks ====== 2014-12-31 16:13:57 AC8A68EE0595FACA1BC70CAB7D7FD0AC 4038 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineUA 2014-12-31 16:13:56 5D69B1544B33437E0B4F0A12EAB6A690 3802 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineCore 2014-12-31 16:13:56 58568C887100E008880E953B0C515752 1066 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-31 16:13:55 CF0E3FB6AB1FCDF7DA440CF48CBE4551 1062 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-01-23 11:53:13 -------- d-----w- C:\Program Files\trend micro 2015-01-07 11:36:54 -------- d-----w- C:\Program Files\Cewe Photoservice ======= C:\PROGRA~2 ===== 2014-12-31 16:13:54 -------- d-----w- C:\PROGRA~2\Google ======= C: ===== ====== C:\Users\Dave\AppData\Roaming ====== 2015-01-09 16:00:39 -------- d-----w- C:\Users\Dave\AppData\Local\Diagnostics 2014-12-31 16:13:52 -------- d-----w- C:\Users\Dave\AppData\Local\Google 2014-12-27 09:39:34 -------- d-s---w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Locallow\Microsoft ====== C:\Users\Dave ====== 2015-01-07 11:39:33 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cewe Photoservice 2015-01-01 23:23:21 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2014-12-31 16:14:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome ====== C: exe-files == 2015-01-23 12:16:16 A45249B532A9E208E80BFC19E7B4F5B3 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1394563540-393045568-558702254-1001\$INFFARG.exe 2015-01-23 11:53:15 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Dave.exe 2015-01-23 11:52:42 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\$Recycle.Bin\S-1-5-21-1394563540-393045568-558702254-1001\$RNFFARG.exe 2015-01-23 07:18:37 F1A2E9146124E17D752AAACAE7D8F6EC 7265872 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\40.0.2214.91\40.0.2214.91_39.0.2171.99_chrome_updater.exe === C: other files == ======== System Restore Points ======== RP79: 11/01/2015 8:49:43 - Gepland controlepunt RP80: 14/01/2015 9:17:09 - Windows Update RP81: 23/01/2015 9:20:25 - Windows Update ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-1394563540-393045568-558702254-1001\Software\Microsoft\Windows\CurrentVersion\Run] "KiesPreload"="C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload" @="C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" "TomTomHOME.exe"="C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" "GoogleChromeAutoLaunch_C62251D359A8F5B5CC8EADB510991ABB"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" "AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin" "KiesTrayAgent"="C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" "GDFirewallTray"="C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "KiesPreload"="C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload" @="C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" "TomTomHOME.exe"="C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" "GoogleChromeAutoLaunch_C62251D359A8F5B5CC8EADB510991ABB"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "KiesTrayAgent"="C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" "BeatsOSDApp"="C:\Program Files\IDT\WDM\beats64.exe" "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [22/01/2015 20:02] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31/12/2014 17:13] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31/12/2014 17:13] C:\WINDOWS\tasks\HPCeeScheduleForDave.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [13/09/2010 22:15] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\AdobeAAMUpdater-1.0-Living-Dave" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CLVDLauncher" [c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForDave" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{C2B740A5-252F-4ACD-A806-CD3DA12940A9}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Dave\AppData\Roaming\TomTom\HOME\Profiles\kloywofc.default - Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com ==== Firefox Plugins ====================== ==== Chromium Look ====================== Google Chrome Version: 40.0.2214.91 (Possible outdated, latest Stable version: 39.0.2171.99) Google Slides - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Booking.com for Chrome™ - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip Google Wallet - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1553-29906-12136-18/4" ==== Reset Google Chrome ====================== C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== shortcuts on Users Desktops ====================== C:\Users\Dave\Desktop\Adobe Photoshop CS6.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe C:\Users\Dave\Desktop\Downloads.lnk - C:\Users\Dave\Downloads C:\Users\Dave\Desktop\GrabIt.lnk - C:\Program Files (x86)\GrabIt\GrabIt.exe C:\Users\Dave\Desktop\Serie opvolglijst - Snelkoppeling.lnk - H:\D\Overzichtlijsten\Serie opvolglijst.xlsx C:\Users\Dave\Desktop\verkochte artikelen 2013 - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2013.xls C:\Users\Dave\Desktop\verkochte artikelen 2014 kopie.xls - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2014 kopie.xls C:\Users\Dave\Desktop\verkochte artikelen 2015.xls - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2015.xls C:\Users\Dave\Desktop\Games\More Great Games.lnk - C:\Users\Dave\Desktop\Games\Play Be a King 2.lnk - C:\Program Files (x86)\Be a King 2\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Bejeweled 3.lnk - C:\Program Files (x86)\Bejeweled 3\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Brain Challenge.lnk - C:\Program Files (x86)\Brain Challenge\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Brain Training for Dummies.lnk - C:\Program Files (x86)\Brain Training for Dummies\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Brainiversity 2.lnk - C:\Program Files (x86)\Brainiversity 2\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Brainiversity.lnk - C:\Program Files (x86)\Brainiversity\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Build In Time.lnk - C:\Program Files (x86)\Build In Time\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Build-a-Lot - Mysteries.lnk - C:\Program Files (x86)\Build-a-Lot - Mysteries\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Build-a-lot.lnk - C:\Program Files (x86)\Build-a-lot\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Chicken Invaders 2.lnk - C:\Program Files (x86)\Chicken Invaders 2\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Crazy Machines - Inventor Training Camp.lnk - C:\Program Files (x86)\Crazy Machines - Inventor Training Camp\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Crazy Machines - New from the Lab.lnk - C:\Program Files (x86)\Crazy Machines - New from the Lab\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Crazy Machines.lnk - C:\Program Files (x86)\Crazy Machines\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Criminal Minds.lnk - C:\Program Files (x86)\Criminal Minds\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Elf Bowling 7 1-7 - The Last Insult.lnk - C:\Program Files (x86)\Elf Bowling 7 1-7 - The Last Insult\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Found - A Hidden Object Adventure.lnk - C:\Program Files (x86)\Found - A Hidden Object Adventure\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Ice Princess.lnk - C:\Program Files (x86)\Ice Princess\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Kasuko.lnk - C:\Program Files (x86)\Kasuko\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Luxor 2.lnk - C:\Program Files (x86)\Luxor 2\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Luxor 3.lnk - C:\Program Files (x86)\Luxor 3\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Master of Defense.lnk - C:\Program Files (x86)\Master of Defense\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Monopoly.lnk - C:\Program Files (x86)\Monopoly\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Ricochet Lost Worlds.lnk - C:\Program Files (x86)\Ricochet Lost Worlds\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Ricochet Recharged.lnk - C:\Program Files (x86)\Ricochet Recharged\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Risk.lnk - C:\Program Files (x86)\Risk\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Roads of Rome II.lnk - C:\Program Files (x86)\Roads of Rome II\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Roads of Rome III.lnk - C:\Program Files (x86)\Roads of Rome III\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Star Defender 4.lnk - C:\Program Files (x86)\Star Defender 4\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Star Defender II.lnk - C:\Program Files (x86)\Star Defender 2\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Star Defender III.lnk - C:\Program Files (x86)\Star Defender III\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Starlaxis - Rise of the Light Hunters.lnk - C:\Program Files (x86)\Starlaxis - Rise of the Light Hunters\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play The Amazing Brain Train.lnk - C:\Program Files (x86)\The Amazing Brain Train\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Trivia Machine Reloaded.lnk - C:\Program Files (x86)\Trivia Machine Reloaded\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play Trivia Machine.lnk - C:\Program Files (x86)\Trivia Machine\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play World Mosaics 6.lnk - C:\Program Files (x86)\World Mosaics 6\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Play World Mosaics Chroma.lnk - C:\Program Files (x86)\World Mosaics Chroma\LaunchGame.bfg C:\Users\Dave\Desktop\Games\Risk II.lnk - C:\Program Files (x86)\Microprose\Risk II\RiskII.exe C:\Users\Dave\Desktop\Games\Poker\Pinup Strip Poker.lnk - C:\Program Files (x86)\PinupStripPoker\PinupStripPoker.exe C:\Users\Dave\Desktop\General\Adobe Reader 8.lnk - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Users\Dave\Desktop\General\CCleaner.lnk - C:\Program Files (x86)\CCleaner\CCleaner.exe C:\Users\Dave\Desktop\General\Chicken Invaders 2.lnk - C:\Program Files (x86)\Chicken Invaders 2\CI2.exe C:\Users\Dave\Desktop\General\CyberLink PowerDVD 8.lnk - C:\Program Files (x86)\CyberLink\PowerDVD8\PowerDVD8.exe C:\Users\Dave\Desktop\General\Delhaize Fotoservice.lnk - C:\Program Files\Delhaize\Delhaize Fotoservice\Delhaize Fotoservice.exe C:\Users\Dave\Desktop\General\DVD Shrink 3.2.lnk - C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe C:\Users\Dave\Desktop\General\Game Manager.lnk - C:\Program Files (x86)\bfgclient\bfgclient.exe -u C:\Users\Dave\Desktop\General\Games.lnk - C:\Program Files (x86)\bfgclient\bfgclient.exe -u C:\Users\Dave\Desktop\General\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Dave\Desktop\General\HP Precisionscan Pro 3.1 .lnk - C:\Program Files (x86)\Hewlett-Packard\Precisionscan Pro 3.1\HP PrecisionScan Pro.exe C:\Users\Dave\Desktop\General\HP Quick Start.lnk - C:\Program Files (x86)\Hewlett-Packard\HP Quick Start\HPQuickstart.exe C:\Users\Dave\Desktop\General\Install remote access.lnk - C:\Program Files (x86)\Panda Security\Panda Global Protection 2013\Tools\RemoteAccess\BADriveWebSetup.exe C:\Users\Dave\Desktop\General\Launch Monitor Driver Installer.lnk - C:\Program Files (x86)\MonitorDriver\MonSetup.exe C:\Users\Dave\Desktop\General\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Dave\Desktop\General\Nero Burning ROM.lnk - C:\Program Files (x86)\Nero\Nero 9\Nero Burning ROM\Nero.exe -ScParameter=30003 C:\Users\Dave\Desktop\General\Nero StartSmart.lnk - C:\Program Files (x86)\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe -ScParameter=30003 C:\Users\Dave\Desktop\General\Orange Games.lnk - C:\Users\Dave\Desktop\General\Play Roads of Rome.lnk - C:\Program Files (x86)\Roads of Rome\LaunchGame.bfg C:\Users\Dave\Desktop\General\Premium 3D Screensavers.lnk - C:\Program Files (x86)\Running Clock 3D Screensaver\more.url C:\Users\Dave\Desktop\General\Running Clock 3D Screensaver.lnk - C:\WINDOWS\system32\Running Clock 3D Screensaver.scr C:\Users\Dave\Desktop\General\Verzendmap van Share-to-Web.lnk - C:\Users\Dave\Desktop\General\foto program\Adobe Photoshop CS6.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe C:\Users\Dave\Desktop\General\foto program\CEWE FOTOSHOW.lnk - C:\Program Files (x86)\Delhaize\Delhaize Fotoservice\CEWE FOTOSHOW.exe C:\Users\Dave\Desktop\General\foto program\Delhaize Fotoservice.lnk - C:\Program Files (x86)\Delhaize\Delhaize Fotoservice\Delhaize Fotoservice.exe C:\Users\Dave\Desktop\General\G DATA\G DATA INTERNET SECURITY.lnk - C:\Program Files (x86)\G Data\InternetSecurity\GUI\GDSC.exe C:\Users\Dave\Desktop\General\G DATA\G Data InternetSecurity 2014.lnk - C:\Program Files (x86)\G Data\InternetSecurity\GUI\GDSC.exe C:\Users\Dave\Desktop\General\G DATA\G Data InternetSecurity.lnk - C:\Program Files (x86)\G Data\InternetSecurity\GUI\GDSC.exe C:\Users\Dave\Desktop\General\G DATA\G Data Shredder - Snelkoppeling (2).lnk - C:\Users\Dave\Desktop\General\G DATA\G Data Shredder - Snelkoppeling (3).lnk - C:\Users\Dave\Desktop\General\G DATA\G Data Shredder - Snelkoppeling (4).lnk - C:\Users\Dave\Desktop\General\G DATA\G Data Shredder - Snelkoppeling (5).lnk - C:\Users\Dave\Desktop\General\G DATA\G DATA Shredder - Snelkoppeling (6).lnk - C:\Users\Dave\Desktop\General\G DATA\G DATA Shredder - Snelkoppeling.lnk - C:\Users\Dave\Desktop\General\Games\More Great Games.lnk - C:\Users\Dave\Desktop\General\Games\Pinup Strip Poker Demo.lnk - C:\Program Files (x86)\PinupStripPoker_Demo\PinupStripPoker_Demo.exe C:\Users\Dave\Desktop\General\Games\Play Be a King 2.lnk - C:\Program Files (x86)\Be a King 2\LaunchGame.bfg C:\Users\Dave\Desktop\General\Games\Play Build-a-lot.lnk - C:\Program Files (x86)\Build-a-lot\LaunchGame.bfg C:\Users\Dave\Desktop\General\Games\Play Master of Defense.lnk - C:\Program Files (x86)\Master of Defense\LaunchGame.bfg C:\Users\Dave\Desktop\General\Games\Play Pinup Strip Poker.lnk - C:\Program Files (x86)\PinupStripPoker\PinupStripPoker.exe C:\Users\Dave\Desktop\General\Games\Play Star Defender II.lnk - C:\Program Files (x86)\Star Defender 2\LaunchGame.bfg C:\Users\Dave\Desktop\General\General\Adobe Acrobat 9 Pro.lnk - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe C:\Users\Dave\Desktop\General\General\Adobe Reader 8.lnk - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Users\Dave\Desktop\General\General\CCleaner.lnk - C:\Program Files (x86)\CCleaner\CCleaner.exe C:\Users\Dave\Desktop\General\General\CyberLink PowerDVD 8.lnk - C:\Program Files (x86)\CyberLink\PowerDVD8\PowerDVD8.exe C:\Users\Dave\Desktop\General\General\DVD Shrink 3.2.lnk - C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe C:\Users\Dave\Desktop\General\General\HP Precisionscan Pro 3.1 .lnk - C:\Program Files (x86)\Hewlett-Packard\Precisionscan Pro 3.1\HP PrecisionScan Pro.exe C:\Users\Dave\Desktop\General\General\Nero Burning ROM.lnk - C:\Program Files (x86)\Nero\Nero 9\Nero Burning ROM\Nero.exe -ScParameter=30003 C:\Users\Dave\Desktop\General\General\Nero StartSmart.lnk - C:\Program Files (x86)\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe -ScParameter=30003 C:\Users\Dave\Desktop\General\General\Nitro PDF Professional.lnk - C:\Program Files (x86)\Nitro PDF\Professional\NitroPDF.exe C:\Users\Dave\Desktop\General\General\Orange Games.lnk - C:\Users\Dave\Desktop\General\General\QuickTime Player.lnk - C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe C:\Users\Dave\Desktop\General\General\Running Clock 3D Screensaver.lnk - C:\WINDOWS\system32\Running Clock 3D Screensaver.scr C:\Users\Dave\Desktop\General\General\Verzendmap van Share-to-Web.lnk - C:\Users\Dave\Desktop\General\General\ViewNX.lnk - C:\Program Files (x86)\Nikon\ViewNX\ViewNX.exe C:\Users\Dave\Desktop\General\General\Games\Free Game Downloads.lnk - C:\Program Files (x86)\PinupStripPoker\Maddataweb.url C:\Users\Dave\Desktop\General\General\Games\Play Pinup Strip Poker.lnk - C:\Program Files (x86)\PinupStripPoker\PinupStripPoker.exe C:\Users\Dave\Desktop\General\Misc\Adobe Reader 8.lnk - C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Users\Dave\Desktop\General\Misc\DVD Shrink 3.2.lnk - C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe C:\Users\Dave\Desktop\General\Misc\Verzendmap van Share-to-Web.lnk - C:\Users\Dave\Desktop\General\Panda\Install remote access.lnk - C:\Program Files (x86)\Panda Security\Panda Internet Security 2012\Tools\RemoteAccess\BADriveWebSetup.exe C:\Users\Dave\Desktop\General\Panda\Panda Global Protection 2011.lnk - C:\Program Files (x86)\Panda Security\Panda Global Protection 2011\Iface.exe C:\Users\Dave\Desktop\General\Panda\TeamViewer 7.lnk - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe C:\Users\Dave\Desktop\General\PC\Adobe Acrobat 9 Pro.lnk - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe C:\Users\Dave\Desktop\General\PC\CCleaner.lnk - C:\Program Files (x86)\CCleaner\CCleaner.exe C:\Users\Dave\Desktop\General\PC\CyberLink PowerDVD 8.lnk - C:\Program Files (x86)\CyberLink\PowerDVD8\PowerDVD8.exe C:\Users\Dave\Desktop\General\PC\HP Precisionscan Pro 3.1 .lnk - C:\Program Files (x86)\Hewlett-Packard\Precisionscan Pro 3.1\HP PrecisionScan Pro.exe C:\Users\Dave\Desktop\General\PC\Nitro PDF Professional.lnk - C:\Program Files (x86)\Nitro PDF\Professional\NitroPDF.exe C:\Users\Dave\Desktop\General\PC\QuickTime Player.lnk - C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe C:\Users\Dave\Desktop\General\PC\Snelkoppeling naar Driverwhiz.lnk - C:\Users\Dave\Desktop\Driverwhiz.exe C:\Users\Dave\Desktop\General\Photography\Adobe Download Assistant.lnk - C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe C:\Users\Dave\Desktop\General\Photography\Opanda PowerExif 1.2 Professional Trial.lnk - C:\Program Files (x86)\Opanda\PowerExif 1.2\PowerExif.exe C:\Users\Dave\Desktop\General\Scanner\Benodigdheden kopen - HP Photosmart 5510d series.lnk - C:\Program Files (x86)\HP\HP Photosmart 5510d series\Bin\hpqDTSS.exe C:\Users\Dave\Desktop\General\Scanner\HP ePrintCenter - HP Photosmart 5510d series.lnk - C:\Program Files (x86)\HP\HP Photosmart 5510d series\ePrintCenterShortcut.url C:\Users\Dave\Desktop\General\Scanner\HP Photo Creations.lnk - C:\Program Files (x86)\HP Photo Creations\PhotoProduct.exe C:\Users\Dave\Desktop\General\Scanner\HP Photosmart 5510d series.lnk - C:\Program Files (x86)\HP\HP Photosmart 5510d series\Bin\HP Photosmart 5510d series.exe C:\Users\Dave\Desktop\Verkoop lijsten\verkochte artikelen - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen.xls C:\Users\Dave\Desktop\Verkoop lijsten\verkochte artikelen 2010 - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2010.xls C:\Users\Dave\Desktop\Verkoop lijsten\verkochte artikelen 2011 - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2011.xls C:\Users\Dave\Desktop\Verkoop lijsten\verkochte artikelen 2012 - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2012.xls C:\Users\Dave\Desktop\Verkoop lijsten\verkochte artikelen 2014.xls - Snelkoppeling.lnk - H:\D\Overzichtlijsten\verkochte artikelen 2014.xls ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Cewe Photoservice.lnk - C:\Program Files\Cewe Photoservice\Cewe Photoservice\Cewe Photoservice.exe C:\Users\Public\Desktop\Spotnet.lnk - C:\Program Files (x86)\Spotnet\Spotnet.exe C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cewe Photoservice\CEWE FOTOSHOW.lnk - C:\Program Files\Cewe Photoservice\Cewe Photoservice\CEWE FOTOSHOW.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cewe Photoservice\Cewe Photoservice Uninstall.lnk - C:\Program Files\Cewe Photoservice\Cewe Photoservice\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cewe Photoservice\Cewe Photoservice.lnk - C:\Program Files\Cewe Photoservice\Cewe Photoservice\Cewe Photoservice.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Delhaize Fotoservice\CEWE FOTOSHOW.lnk - C:\Program Files\Delhaize\Delhaize Fotoservice\CEWE FOTOSHOW.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Delhaize Fotoservice\Delhaize Fotoservice Uninstall.lnk - C:\Program Files\Delhaize\Delhaize Fotoservice\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Delhaize Fotoservice\Delhaize Fotoservice.lnk - C:\Program Files\Delhaize\Delhaize Fotoservice\Delhaize Fotoservice.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotogoed Designer\Fotogoed Designer.lnk - C:\Program Files (x86)\Fotogoed Designer\CCPublisher.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fotogoed Designer\Verwijder Fotogoed Designer.lnk - C:\Program Files (x86)\Fotogoed Designer\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY\G DATA Bootmedium.lnk - C:\Program Files (x86)\G Data\InternetSecurity\AVK\BootCDWizard.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G DATA INTERNET SECURITY\G DATA INTERNET SECURITY.lnk - C:\Program Files (x86)\G Data\InternetSecurity\GUI\GDSC.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==== shortcuts in Quick Launch ====================== C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GrabIt.lnk - C:\Program Files (x86)\GrabIt\GrabIt.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk - C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE /recycle C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe /lite C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CS6.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Outlook 2007.lnk - C:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== Uninstall List x64 ====================== Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FE23D063-934D-4829-A0D8-00634CE79B4A}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR] Adobe Flash Player 16 NPAPI [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] Adobe Help Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AF37176A-78CA-545B-34EF-8B6A21514DD1}] Adobe Help Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1] AMD Accelerated Video Transcoding [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{66E755F9-EE8C-A3A2-D857-5921336D6264}] AMD APP SDK Runtime [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{503F672D-6C84-448A-8F8F-4BC35AC83441}] AMD Catalyst Install Manager [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{425D8EBC-EDEE-A047-63BA-F02A2D3D531E}] Be a King 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Be a King 2] Big Fish: Game Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFGC] Build-a-lot [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Build-a-lot] Catalyst Control Center - Branding [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B1F64E77-E2B9-4775-904C-4459827E6666}] Catalyst Control Center [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1EC87EB1-5542-2323-630B-FFF714604D03}] Catalyst Control Center Graphics Previews Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3E6B9E50-4CDD-449E-410B-73CD7F418FE8}] Catalyst Control Center InstallProxy [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{19763975-F4F1-1D14-7DD7-0F245279CA7B}] Catalyst Control Center Localization All [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{38207641-A596-2C99-0D88-BB1EDB579C35}] Catalyst Control Center Profiles Desktop [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EDBDE082-E235-4147-253E-71BE64978FD6}] ccc-utility64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{749E58FD-CE88-45DC-5C9A-5B4F46D82467}] CCC Help Chinese Standard [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{98FD7AF8-8627-F5E3-C9E0-575969B466EA}] CCC Help Chinese Traditional [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2CE31C15-61C8-B7EF-D43F-76EC6C83187D}] CCC Help Czech [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A971496E-1A70-9473-0FF7-0D74384ABB48}] CCC Help Danish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0E0A359E-0358-0E44-7406-A56195F80EB1}] CCC Help Dutch [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D70E631B-AAD1-EB47-E046-F66BA67540FF}] CCC Help English [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{17B94AF3-890B-5B79-57B1-D9994FE6EEC5}] CCC Help Finnish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6772483B-5A00-F8F1-2122-EDC392F128E5}] CCC Help French [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CEC7F7DD-3710-F553-4E0E-3F59D5B3556F}] CCC Help German [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{355E67C3-1D4D-9D00-5A56-A76ED62DEC96}] CCC Help Greek [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A8EA9880-4F44-019E-9018-11D814CDFB71}] CCC Help Hungarian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DAE380FE-D0F8-3D7D-5D55-415BF2FC740F}] CCC Help Italian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BC4B9FFA-49C1-18A4-962D-8FB3B50A0AD8}] CCC Help Japanese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C6ADBC42-B69B-96E0-AEFD-645A2C465C74}] CCC Help Korean [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4083EF3-4B6C-494E-2846-D46398787A97}] CCC Help Norwegian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B554F852-D698-AED8-A8DA-0C85D5E2CAD7}] CCC Help Polish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{34EFF4FD-2AE6-B2D8-CE14-5514857E6BDC}] CCC Help Portuguese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{14D51505-5658-4070-0E0D-9715AE76D791}] CCC Help Russian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C88D865A-F680-556C-5FAB-0C13C3C5548E}] CCC Help Spanish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C845C50B-3C7A-48CF-6E70-DF0C9E09BAD9}] CCC Help Swedish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44F72690-B79D-B808-D9AF-D8716E6A228D}] CCC Help Thai [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{577D22F0-3E82-BD54-8831-EB7501C6D569}] CCC Help Turkish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{640DF3C3-EFDB-A672-E3DE-3FD7A848611D}] CCleaner [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner] CEWE FOTOBOEK [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CEWE FOTOBOEK] Cewe Photoservice [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Cewe Photoservice] Classic Shell [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FEA1590B-540A-41FC-A95C-664493C82A21}] Connected Music powered by Universal Music Group version 1.0 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1] CyberLink LabelPrint [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}] CyberLink LabelPrint [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}] CyberLink Media Suite 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] CyberLink Media Suite 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] CyberLink PhotoDirector [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4862344A-A39C-4897-ACD4-A1BED5163C5A}] CyberLink PhotoDirector [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}] CyberLink Power2Go 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}] CyberLink Power2Go 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}] CyberLink PowerDirector 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}] CyberLink PowerDirector 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}] CyberLink PowerDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] CyberLink PowerDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] D3DX10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}] Elf Bowling 7 1/7: The Last Insult [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Elf Bowling 7 1-7 - The Last Insult] Fotoalbum.be [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fotoalbum.be] Fotogalerie [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B19E03EA-067C-412F-A81E-271720E601AB}] Fotogoed Designer 3.8.4 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\fotogoed-nl_is1] G DATA INTERNET SECURITY [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{85203592-3610-4FB9-AA11-15B2255B5A12}] Galerie de photos [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FE8DFDD0-A543-4A83-B7A9-C411138194D5}] Google Chrome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome] Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}] GrabIt 1.7.2 Beta 6 (build 1008) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GrabIt_is1] Hewlett-Packard ACLM.NET v1.2.2.3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}] HP Connected Music (Meridian - installer) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\StartHPConnectedMusic] HP Connected Remote [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F243A34B-AB7F-4065-B770-B85B767C247C}] HP Customer Experience Enhancements [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{07FA4960-B038-49EB-891B-9F95930AA544}] HP Postscript Converter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}] HP Quick Start [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BC7CA956-A2A4-4A55-8E6E-50C59B4BDD5C}] HP Registration Service [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}] HP Support Information [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}] HydraVision [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F09765A4-B61D-CA90-4784-7E243163B150}] IDT Audio [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}] Intel(R) Management Engine Components [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}] Intel© Trusted Connect Service Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}] Master of Defense [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Master of Defense] Microsoft Office Professional Plus 2007 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PROPLUS] Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}] Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}] Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}] Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}] Microsoft_VC80_CRT_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}] Microsoft_VC90_CRT_x86 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{08D2E121-7F6A-43EB-97FD-629B44903403}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{61889FC7-9738-439A-96B3-17AF981BDDEF}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7F682A00-6497-4551-A2A6-063AE667D1CF}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9846E46F-07E0-4BDF-985A-E3FBA8C15877}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CCDB7ADB-1643-4C30-B39D-1562CFE51420}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}] MSVCRT [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}] MSVCRT110 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}] MSVCRT110_amd64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F842F8B0-6942-4930-821F-543E976B2C66}] MyFreeCodec [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec] PDF Settings CS6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}] Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{35BD47F4-C19B-474F-AACC-E8C0BE38148A}] Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B27FA0A3-D80F-41A9-8BAD-C5F2D859AB22}] Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D531FC91-6F4E-49A7-B912-15289D05B6F8}] Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D77A6FED-256C-4E2F-9873-59C92C854A4E}] Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{00AA59D7-B92D-4A06-8D06-0596081C0E68}] Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4C0D8B3E-63F0-4773-83F5-C5B7795B0FB8}] Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9B2E55F8-5BA8-4A45-9682-ACB6F2CC0DA5}] Pinup Strip Poker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pinup Strip Poker] Pinup Strip Poker Demo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pinup Strip Poker Demo] Ralink RT5390R 802.11bgn Wi-Fi Adapter [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}] Realtek Ethernet Controller Driver [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}] Recovery Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}] Risk II [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0EE11800-A1BD-11D3-BFEB-005004AF2D32}] RiskT [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Risk] Roads of Rome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Roads of Rome] Samsung Kies [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{758C8301-2696-4855-AF45-534B1200980A}] Samsung Kies [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\01_Simmental] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\02_Siberian] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\03_Swallowtail] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\04_semseyite] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\07_Schorl] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\09_Hsp] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\11_HSP_Plus_Default] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\16_Shrewsbury] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\20_NXP_Driver] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\24_flashusbdriver] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}\25_escape] SAMSUNG USB Driver for Mobile Phones [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}] Samsung_MonSetup [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8EA79DBF-D637-448A-89D6-410A087A4493}] Spotnet [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12878924-210B-4A0C-8CA6-6C697756BA32}] Spotnet [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spotnet 1.8.1.1] Star Defender 4 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Star Defender 4] Star Defender II [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Star Defender II] Star Defender III [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-Star Defender III] TI xHCI Filter Driver 1.0.0.4 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TI xHCI Filter Driver] TomTom HOME [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A2BB1C8-903D-4585-9F3B-CADD67D07D37}] TomTom HOME Visual Studio Merge Modules [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}] VLC media player 2.1.3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player] Windows Live [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{78F35489-621D-4FFD-BCE7-2C7C3897E47C}] Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BA73469B-D8C7-4FE3-B33C-1340D09F0709}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2FAFE37E-D796-47B8-BA8F-D09819B12DF6}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{698ED639-3A26-49EF-B1EF-CD89CB97C778}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EBFCBD05-77A3-4FC3-A6D2-27218B61D957}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite] Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}] Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1057511B-F8FE-4230-9ED3-AB949A57EE4A}] Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4F9A382F-4478-4036-905C-F77DF2EA0370}] Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}] Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{29315CEC-E6CE-4394-84DC-6F862E8D9A52}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{233B918E-99FD-4643-BEDD-A9855A56FC3A}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2AE414B5-7FE6-49A3-93C8-D864162CDEBC}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4689F012-C8E3-4F6E-BDEF-13671D53A6DC}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{618F39BD-9720-47CF-A89C-108AB41B1493}] World Mosaics Chroma [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BFG-World Mosaics Chroma] ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O2 - BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_C62251D359A8F5B5CC8EADB510991ABB] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe O9 - Extra 'Tools' menuitem: Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe O23 - Service: G DATA Scheduler (AVKService) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe O23 - Service: G Data Bestandssysteembewaker (AVKWCtl) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe O23 - Service: Classic Shell Service (ClassicShellService) - IvoSoft - C:\Program Files\Classic Shell\ClassicShellService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: G Data Personal Firewall (GDFwSvc) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Connected Remote Service (HPConnectedRemote) - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Silent Runners ====================== "Silent Runners.vbs", revision 69.2, http://www.silentrunners.org/ Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} AdobeBridge = (empty string) [file not found] KiesPreload = C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload [null data] (Default) = C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [Samsung] TomTomHOME.exe = "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [TomTom] GoogleChromeAutoLaunch_C62251D359A8F5B5CC8EADB510991ABB = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [Google Inc.] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} BeatsOSDApp = C:\Program Files\IDT\WDM\beats64.exe AdobeAAMUpdater-1.0 = "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [Adobe Systems Incorporated] KiesTrayAgent = C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [Samsung Electronics Co., Ltd.] SysTrayApp = C:\Program Files\IDT\WDM\sttray64.exe HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ {++} NCPluginUpdater = "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [null data] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++} StartCCC = "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [Advanced Micro Devices, Inc.] SwitchBoard = C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [Adobe Systems Incorporated] AdobeCS6ServiceManager = "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [Adobe Systems Incorporated] KiesTrayAgent = C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [Samsung Electronics Co., Ltd.] GDFirewallTray = C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [G Data Software AG] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {449D0D6E-2412-4E61-B68F-1CB625CD9E52}\(Default) = (no title provided) -> {HKLM...CLSID} = ExplorerBHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ExplorerBHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] {E76FD755-C1BA-4DCB-9F13-99BD91223ADE}\(Default) = HP Network Check Helper -> {HKLM...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [Hewlett-Packard] -> {HKLM...Wow...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [Hewlett-Packard] {EA801577-E6AD-4BD5-8F71-4BE0154331A4}\(Default) = (no title provided) -> {HKLM...CLSID} = ClassicIE9BHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ClassicIE9BHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll [IvoSoft] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {449D0D6E-2412-4E61-B68F-1CB625CD9E52}\(Default) = (no title provided) -> {HKLM...CLSID} = ExplorerBHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ExplorerBHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] {E76FD755-C1BA-4DCB-9F13-99BD91223ADE}\(Default) = HP Network Check Helper -> {HKLM...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [Hewlett-Packard] -> {HKLM...Wow...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [Hewlett-Packard] {EA801577-E6AD-4BD5-8F71-4BE0154331A4}\(Default) = (no title provided) -> {HKLM...CLSID} = ClassicIE9BHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ClassicIE9BHO Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll [IvoSoft] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ShareOverlay\(Default) = {594D4122-1F87-41E2-96C7-825FB4796516} -> {HKLM...CLSID} = ShareOverlay Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ ShareOverlay\(Default) = {594D4122-1F87-41E2-96C7-825FB4796516} -> {HKLM...Wow...CLSID} = ShareOverlay Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {5E2121EE-0300-11D4-8D3B-444553540000} = Catalyst Context Menu extension -> {HKLM...CLSID} = SimpleShlExt Class \InProcServer32\(Default) = c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [Advanced Micro Devices, Inc.] {5FCD4425-CA3A-48F4-A57C-B8A75C32ACB1} = NSE_WithSubFld -> {HKLM...CLSID} = NSE_WithSubFld \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\Recovery\Protect.dll [null data] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~1\Office12\MSOHEVI.DLL [MS] {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler -> {HKLM...CLSID} = Microsoft Office Metadata Handler \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler -> {HKLM...CLSID} = Microsoft Office Thumbnail Handler \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {65756541-C65C-11CD-0000-4B656E696100} = Panda Antivirus -> {HKLM...CLSID} = Panda Antivirus \InProcServer32\(Default) = C:\Program Files (x86)\Panda Security\Panda Global Protection 2013\PavOLE64.dll [file not found] {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} = Display CPL Extension -> {HKLM...CLSID} = DisplayCplExt Class \InProcServer32\(Default) = c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiama64.dll [Advanced Micro Devices, Inc.] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided) -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Editor Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {0006F045-0000-0000-C000-000000000046} = Microsoft Office Outlook Custom Icon Handler -> {HKLM...Wow...CLSID} = Outlook File Icon Extension \InProcServer32\(Default) = C:\PROGRA~2\MICROS~1\Office12\OLKFSTUB.DLL [MS] {00020D75-0000-0000-C000-000000000046} = Microsoft Office Outlook Desktop Icon Handler -> {HKLM...Wow...CLSID} = Microsoft Office Outlook \InProcServer32\(Default) = C:\PROGRA~2\MICROS~1\Office12\MLSHEXT.DLL [MS] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office12\msohevi.dll [MS] {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler -> {HKLM...Wow...CLSID} = Microsoft Office Metadata Handler \InProcServer32\(Default) = C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler -> {HKLM...Wow...CLSID} = Microsoft Office Thumbnail Handler \InProcServer32\(Default) = C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {E5A82055-B4B3-449B-9202-C714068617F9} = SOBVirtualFolder Class -> {HKLM...Wow...CLSID} = SOBVirtualFolder Class \InProcServer32\(Default) = C:\Program Files (x86)\G Data\InternetSecurity\AVK\SOBFilesNSE.dll [G Data Software AG] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ <> Userinit = C:\WINDOWS\SysWOW64\userinit.exe,C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe [MS], [file not found], [file not found], [file not found], [file not found], [file not found], [file not found], [file not found], [file not found] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\ {1ee7337f-85ac-45e2-a23c-37c753209769}\(Default) = Smartcard WinRT Provider -> {HKLM...CLSID} = Smartcard WinRT Provider \InProcServer32\(Default) = C:\WINDOWS\system32\SmartcardCredentialProvider.dll [MS] HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = {807563E5-5146-11D5-A672-00B0D022E945} -> {HKLM...CLSID} = Microsoft Office InfoPath XML Mime Filter \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL [MS] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ AVK9CM\(Default) = {CAF4C320-32F5-11D3-A222-004095200FF2} -> {HKLM...CLSID} = AVK9ContextMenue \InProcServer32\(Default) = C:\Program Files (x86)\G Data\InternetSecurity\AVK\ShellExt64.dll [G Data Software AG] CLVDShellExt\(Default) = {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [Cyberlink] WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\ Reisswolf\(Default) = {1F0F1EE7-36B9-11D2-8985-0080ADA96E9B} -> {HKLM...CLSID} = ReisswolfContextMenu \InProcServer32\(Default) = C:\Program Files (x86)\G Data\InternetSecurity\Shredder\Reisswlf64.dll [G Data Software AG] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\ ClassicCopyExt\(Default) = {8C83ACB1-75C3-45D2-882C-EFA32333491C} -> {HKLM...CLSID} = ClassicCopyExt Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ClassicCopyExt Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\ ACE\(Default) = {5E2121EE-0300-11D4-8D3B-444553540000} -> {HKLM...CLSID} = SimpleShlExt Class \InProcServer32\(Default) = c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [Advanced Micro Devices, Inc.] WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ AVK9CM\(Default) = {CAF4C320-32F5-11D3-A222-004095200FF2} -> {HKLM...CLSID} = AVK9ContextMenue \InProcServer32\(Default) = C:\Program Files (x86)\G Data\InternetSecurity\AVK\ShellExt64.dll [G Data Software AG] Reisswolf\(Default) = {1F0F1EE7-36B9-11D2-8985-0080ADA96E9B} -> {HKLM...CLSID} = ReisswolfContextMenu \InProcServer32\(Default) = C:\Program Files (x86)\G Data\InternetSecurity\Shredder\Reisswlf64.dll [G Data Software AG] HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\ ClassicCopyExt\(Default) = {8C83ACB1-75C3-45D2-882C-EFA32333491C} -> {HKLM...CLSID} = ClassicCopyExt Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] -> {HKLM...Wow...CLSID} = ClassicCopyExt Class \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ EnableCursorSuppression = (REG_DWORD) dword:0x00000001 {unrecognized setting} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ Wallpaper = C:\Users\Dave\Desktop\10931565_10202669406171200_3138990367817295573_o.jpg Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ SCRNSAVE.EXE = C:\WINDOWS\system32\Bubbles.scr [MS] Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ BridgeCS6ImportMediaOnArrival\ Provider = Adobe Bridge CS6 InvokeProgID = Adobe.adobebridgeCS6 InvokeVerb = launch HKLM\SOFTWARE\Classes\Adobe.adobebridgeCS6\shell\launch\command\(Default) = C:\Program Files (x86)\Adobe\Adobe Bridge CS6\bridgeproxy.exe -v %1 [Adobe Systems, Inc.] BridgeCS6NonVolumeHandler\ Provider = Adobe Bridge CS6 ProgID = Adobe.adobebridgeMTP_1 HKLM\SOFTWARE\Classes\Adobe.adobebridgeMTP_1\CLSID\(Default) = {1E6C711B-6D70-4a65-8AB6-745DC19BE2A6} -> {HKLM...CLSID} = Adobe Bridge CS6 \LocalServer32\(Default) = C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\bridgeproxy.exe -m [Adobe Systems, Inc.] CyberLink Media Suite10HandleCDBurningOnArrival\ Provider = Media Suite 10 InvokeProgID = BlankCD InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\BlankCD\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10HandleDVDBurningOnArrival\ Provider = Media Suite 10 InvokeProgID = BlankDVD InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\BlankDVD\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10MixedContentOnArrival\ Provider = Media Suite 10 InvokeProgID = MixedContent InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\MixedContent\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10PlayMusicFilesOnArrival\ Provider = Media Suite 10 InvokeProgID = MusicFiles InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\MusicFiles\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10PlayVideoFilesOnArrival\ Provider = Media Suite 10 InvokeProgID = VideoFiles InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\VideoFiles\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10ShowPicturesOnArrival\ Provider = Media Suite 10 InvokeProgID = Picture InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\Picture\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] Fotoimport15625-38\ Provider = CEWE FOTOIMPORTEERDER InvokeProgID = Fotoimport15625-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoimport15625-38\shell\play\command\(Default) = "C:\Program Files (x86)\Fotoalbum\Fotoalbum.be\CEWE FOTOIMPORTEERDER.exe" -startDirectory %1 [null data] Fotoimport28049-38\ Provider = CEWE FOTOIMPORTEERDER InvokeProgID = Fotoimport28049-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoimport28049-38\shell\play\command\(Default) = "C:\Program Files\Cewe Photoservice\Cewe Photoservice\CEWE FOTOIMPORTEERDER.exe" -startDirectory %1 [null data] Fotoimport28121-18\ Provider = CEWE FOTOIMPORTEERDER InvokeProgID = Fotoimport28121-18 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoimport28121-18\shell\play\command\(Default) = "C:\Program Files\CEWEFOTOBOEK\CEWE FOTOBOEK\CEWE FOTOIMPORTEERDER.exe" -startDirectory %1 [null data] Fotoschau15625-38\ Provider = CEWE FOTOSHOW InvokeProgID = Fotoschau15625-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoschau15625-38\shell\play\command\(Default) = "C:\Program Files (x86)\Fotoalbum\Fotoalbum.be\CEWE FOTOSHOW.exe" -d %1 [null data] Fotoschau28049-38\ Provider = CEWE FOTOSHOW InvokeProgID = Fotoschau28049-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoschau28049-38\shell\play\command\(Default) = "C:\Program Files\Cewe Photoservice\Cewe Photoservice\CEWE FOTOSHOW.exe" -d %1 [null data] Fotoschau28121-18\ Provider = CEWE FOTOSHOW InvokeProgID = Fotoschau28121-18 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoschau28121-18\shell\play\command\(Default) = "C:\Program Files\CEWEFOTOBOEK\CEWE FOTOBOEK\CEWE FOTOSHOW.exe" -d %1 [null data] MSFhConfigBackup\ Provider = @C:\WINDOWS\system32\fhautoplay.dll,-100 InvokeProgID = FHConfig.AutoPlayHandler InvokeVerb = config HKLM\SOFTWARE\Classes\FHConfig.AutoPlayHandler\shell\config\command\(Default) = fhmanagew -autoplay [MS] MSLiveShowPicturesOnArrival\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS] MSPlayCDAudioOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.AudioCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS] MSPlayDVDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.DVD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS] MSPlaySuperVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSPlayVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSPromptEachTime\ Provider = @C:\WINDOWS\system32\shell32.dll,-17411 ProgID = Shell.Autoplay InitCmdLine = PromptEachTime HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7} -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS] MSPromptEachTimeNoContent\ Provider = @C:\WINDOWS\system32\shell32.dll,-17411 ProgID = Shell.Autoplay InitCmdLine = PromptEachTimeNoContent HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7} -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS] MSWMPBurnCDOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.BurnCD InvokeVerb = Burn HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS] PDirDVArrival\ Provider = PowerDirector ProgID = Shell.HWEventHandlerShellExecute InitCmdLine = "c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.exe" /DV HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} -> {HKLM...CLSID} = Shell Execute Hardware Event Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS] PDVD10PlayCDAudioOnArrival\ Provider = PowerDVD InvokeProgID = AudioCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlayDVDMovieOnArrival\ Provider = PowerDVD InvokeProgID = DVD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlaySVCDOnArrival\ Provider = PowerDVD InvokeProgID = SVCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\SVCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlayVCDMovieOnArrival\ Provider = PowerDVD InvokeProgID = VCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\VCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PhotoDirector2.0ShowPicturesOnArrival\ Provider = PhotoDirector 2 InvokeProgID = Picture InvokeVerb = PlayWithPhotoDirector2.0 HKLM\SOFTWARE\Classes\Picture\shell\PlayWithPhotoDirector2.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\PhotoDirector\PhotoDirector.exe" -importDlg "%L" [CyberLink Corp.] Power2Go8.0HandleBDBurningOnArrival\ Provider = Power2Go 8 InvokeProgID = BlankBD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\BlankBD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" "%L" [CyberLink Corp.] Power2Go8.0HandleCDBurningOnArrival\ Provider = Power2Go 8 InvokeProgID = BlankDVD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\BlankDVD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" "%L" [CyberLink Corp.] Power2Go8.0PlayCDAudioOnArrival\ Provider = Power2Go 8 InvokeProgID = AudioCD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" /AudioRipper "%L" [CyberLink Corp.] VLCPlayCDAudioOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.CDAudio InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file cdda:///%1 [VideoLAN] VLCPlayDVDAudioOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.OPENFolder InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" %1 [VideoLAN] VLCPlayDVDMovieOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.DVDMovie InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file dvd:///%1 [VideoLAN] VLCPlayMusicFilesOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.OPENFolder InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" %1 [VideoLAN] VLCPlaySVCDMovieOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.SVCDMovie InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.SVCDMovie\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file vcd:///%1 [VideoLAN] VLCPlayVCDMovieOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.VCDMovie InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.VCDMovie\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file vcd:///%1 [VideoLAN] VLCPlayVideoFilesOnArrival\ Provider = VideoLAN VLC media player InvokeProgID = VLC.OPENFolder InvokeVerb = Open HKLM\SOFTWARE\Classes\VLC.OPENFolder\shell\Open\command\(Default) = "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" %1 [VideoLAN] Non-disabled Scheduled Tasks: {++} ----------------------------- C:\Windows\System32\Tasks Adobe Flash Player Updater -> launches: C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated] AdobeAAMUpdater-1.0-Living-Dave -> launches: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled [Adobe Systems Incorporated] CCleanerSkipUAC -> launches: "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) [Piriform Ltd] CLMLSvc_P2G8 -> (HIDDEN!) launches: c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [CyberLink] CLVDLauncher -> (HIDDEN!) launches: c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [CyberLink Corp.] GoogleUpdateTaskMachineCore -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c [Google Inc.] GoogleUpdateTaskMachineUA -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.] HPCeeScheduleForDave -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForDave (null) [null data] User_Feed_Synchronization-{C2B740A5-252F-4ACD-A806-CD3DA12940A9} -> (HIDDEN!) launches: C:\WINDOWS\system32\msfeedssync.exe sync [MS] C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant HP Support Assistant Quick Start -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /taskrestart [null data] PC Health Analysis -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /L Analysis [null data] Update Check -> launches: C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe /s /p 1 [null data] WarrantyChecker -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [null data] WarrantyChecker_DeviceScan -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6 [null data] C:\Windows\System32\Tasks\Microsoft\Windows\.NET Framework .NET Framework NGEN v4.0.30319 -> (HIDDEN!) launches: {84F0FAE1-C27B-4F6F-807B-28CF6F96287D} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = mscoree.dll [MS] .NET Framework NGEN v4.0.30319 64 -> (HIDDEN!) launches: {429BC048-379E-45E0-80E4-EB1977941B5C} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = mscoree.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS] -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\AppID SmartScreenSpecific -> launches: {9f2b0085-9218-42a1-88b0-9f0e65851666} -> {HKLM...CLSID} = Windows SmartScreen Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\apprepsync.dll [MS] -> {HKLM...Wow...CLSID} = Windows SmartScreen Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\apprepsync.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience AitAgent -> launches: aitagent /increment [MS] Microsoft Compatibility Appraiser -> launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate -nolegacy [MS] ProgramDataUpdater -> launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate [MS] StartupAppTask -> launches: %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask [MS] C:\Windows\System32\Tasks\Microsoft\Windows\ApplicationData CleanupTemporaryState -> launches: %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Autochk Proxy -> launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Chkdsk ProactiveScan -> launches: {cf4270f5-2e43-4468-83b3-a8c45bb33ea1} -> {HKLM...CLSID} = Proactive Scan \InProcServer32\(Default) = C:\Windows\System32\pstask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program BthSQM -> (HIDDEN!) launches: {c8367320-6f85-11e0-a1f0-0800200c9a66} -> {HKLM...CLSID} = BthSQM \InProcServer32\(Default) = C:\WINDOWS\System32\BthSQM.dll [MS] Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS] KernelCeipTask -> (HIDDEN!) launches: {e7ed314f-2816-4c26-aeb5-54a34d02404c} -> {HKLM...CLSID} = KernelCeipCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\kernelceip.dll [MS] Uploader -> launches: %windir%\system32\WSqmCons.exe -u [MS] UsbCeip -> (HIDDEN!) launches: {c27f6b1d-fe0b-45e4-9257-38799fa69bc8} -> {HKLM...CLSID} = UsbCeip \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS] -> {HKLM...Wow...CLSID} = UsbCeip \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Data Integrity Scan Data Integrity Scan for Crash Recovery -> (HIDDEN!) launches: {DCFD3EA8-D960-4719-8206-490AE315F94F} -> {HKLM...CLSID} = Data Integrity Scan \InProcServer32\(Default) = C:\Windows\System32\discan.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Defrag ScheduledDefrag -> launches: %windir%\system32\defrag.exe -c -h -o -$ [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Device Setup Metadata Refresh -> (HIDDEN!) launches: {23C1F3CF-C110-4512-ACA9-7B6174ECE888} -> {HKLM...CLSID} = DsmRefreshTask Class \InProcServer32\(Default) = C:\WINDOWS\System32\DeviceSetupManagerAPI.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis Scheduled -> (HIDDEN!) launches: {c1f85ef8-bcc2-4606-bb39-70c523715eb3} -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\sdiagschd.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\DiskCleanup SilentCleanup -> launches: %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% [MS] C:\Windows\System32\Tasks\Microsoft\Windows\DiskFootprint Diagnostics -> launches: {5b6b6834-34f0-49b9-ad4e-81d4994c7a74} -> {HKLM...CLSID} = Disk Footprint Diagnostics Task \InProcServer32\(Default) = C:\WINDOWS\system32\DfpCommon.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\FileHistory File History (maintenance mode) -> launches: {89917B7C-A1A6-11DF-8BF6-18A90531A85A} -> {HKLM...CLSID} = FhTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\fhtask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Location Notifications -> launches: %windir%\System32\LocationNotifications.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance WinSAT -> launches: A9A33436-678B-4c9c-A211-7CC38785E79D -> {HKLM...CLSID} = WinSAT Task Manger Task \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS] -> {HKLM...Wow...CLSID} = WinSAT Task Manger Task \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic ProcessMemoryDiagnosticEvents -> (HIDDEN!) launches: {8168e74a-b39f-46d8-adcd-7bed477b80a3} -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS] RunFullMemoryDiagnostic -> (HIDDEN!) launches: {8168e74a-b39f-46d8-adcd-7bed477b80a3} -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts MNO Metadata Parser -> launches: %SystemRoot%\System32\MbaeParserTask.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\MUI Lpksetup -> launches: C:\windows\System32\lpksetup.exe -v [MS] LPRemove -> launches: %windir%\system32\lpremove.exe [MS] Mcbuilder -> launches: C:\windows\System32\mcbuilder.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} -> {HKLM...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS] -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetCfg BindingWorkItemQueueHandler -> launches: {5AA199A0-1CED-43A5-9B85-3226086738A3} -> {HKLM...CLSID} = Binding Engine Task Handler \InProcServer32\(Default) = C:\Windows\System32\netcfgx.dll [MS] -> {HKLM...Wow...CLSID} = Binding Engine Task Handler \InProcServer32\(Default) = C:\Windows\SysWOW64\netcfgx.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace GatherNetworkInfo -> launches: %windir%\system32\gatherNetworkInfo.vbs [null data] C:\Windows\System32\Tasks\Microsoft\Windows\PerfTrack BackgroundConfigSurveyor -> (HIDDEN!) launches: {EA9155A3-8A39-40B4-8963-D3C761B18371} -> {HKLM...CLSID} = PerfTrack TaskHandler class \InProcServer32\(Default) = C:\Windows\System32\perftrack.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\PI Secure-Boot-Update -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] Sqm-Tasks -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play Device Install Group Policy -> (HIDDEN!) launches: {60400283-b242-4fa8-8c25-caf695b88209} -> {HKLM...CLSID} = Device Installation Group Policy Task Handler \InProcServer32\(Default) = C:\Windows\System32\pnppolicy.dll [MS] Device Install Reboot Required -> (HIDDEN!) launches: {48794782-6a1f-47b9-bd52-1d5f95d49c1b} -> {HKLM...CLSID} = Device Installation Reboot Dialog Task \InProcServer32\(Default) = C:\Windows\System32\pnpui.dll [MS] Plug and Play Cleanup -> launches: {DEF03232-9688-11E2-BE7F-B4B52FD966FF} -> {HKLM...CLSID} = Plug and Play Maintenance Task \InProcServer32\(Default) = C:\Windows\System32\pnpclean.dll [MS] Sysprep Generalize Drivers -> launches: %SystemRoot%\System32\drvinst.exe 6 [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics AnalyzeSystem -> launches: {927ea2af-1c54-43d5-825e-0074ce028eee} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\WINDOWS\System32\energytask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RAC RacTask -> (HIDDEN!) launches: {42060D27-CA53-41f5-96E4-B1E8169308A6} -> {HKLM...CLSID} = ReliabilityAnalysisCustomHandler \InProcServer32\(Default) = C:\WINDOWS\system32\RacEngn.dll [MS] -> {HKLM...Wow...CLSID} = ReliabilityAnalysisCustomHandler \InProcServer32\(Default) = C:\WINDOWS\system32\RacEngn.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Ras MobilityManager -> launches: {c463a0fc-794f-4fdf-9201-01938ceacafa} -> {HKLM...CLSID} = RasMobilityManager \InProcServer32\(Default) = C:\WINDOWS\system32\rasmbmgr.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Registry RegIdleBackup -> (HIDDEN!) launches: {ca767aa8-9157-4604-b64b-40747123d5f2} -> {HKLM...CLSID} = RegistryIdleBackupHandler \InProcServer32\(Default) = C:\WINDOWS\System32\regidle.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemovalTools MRT_HB -> launches: C:\WINDOWS\system32\MRT.exe /EHB /Q [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Servicing StartComponentCleanup -> launches: 752073A1-23F2-4396-85F0-8FDB879ED0ED [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync BackgroundUploadTask -> (HIDDEN!) launches: {59B9640B-3F70-4D1C-B159-F26EEB8A4C87} -> {HKLM...CLSID} = Delayed Background Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Delayed Background Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] BackupTask -> (HIDDEN!) launches: {60A4C78C-E2B8-4E6E-876F-DA203B02C05E} -> {HKLM...CLSID} = Backup Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Backup Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] NetworkStateChangeTask -> (HIDDEN!) launches: {A4173A49-F373-4475-9A0F-2D615204DC20} -> {HKLM...CLSID} = Network State Change Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Network State Change Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Shell CreateObjectTask -> (HIDDEN!) launches: {990a9f8f-301f-45f7-8d0e-68c5952dba43} -> {HKLM...CLSID} = Shell Create Object Task Delegate \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS] -> {HKLM...Wow...CLSID} = Shell Create Object Task Delegate \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS] FamilySafetyMonitor -> launches: %windir%\System32\wpcmon.exe [MS] FamilySafetyRefresh -> launches: {EBF00FCB-0769-4b81-9BEC-6C05514111AA} -> {HKLM...CLSID} = FamilySafety.WebSync \InProcServer32\(Default) = C:\Windows\System32\WpcWebSync.dll [MS] IndexerAutomaticMaintenance -> launches: {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6} -> {HKLM...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS] -> {HKLM...Wow...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SideShow GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SkyDrive Idle Sync Maintenance Task -> launches: {bf6c1e47-86ec-4194-9ce5-13c15dcb2001} [InProcServer32 entry not found] Routine Maintenance Task -> launches: {1b1f472e-3221-4826-97db-2c2324d389ae} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform SvcRestartTask -> (HIDDEN!) launches: {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} -> {HKLM...CLSID} = SppSvcRestartTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS] -> {HKLM...Wow...CLSID} = SppSvcRestartTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SpacePort SpaceAgentTask -> launches: %windir%\system32\SpaceAgent.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Sysmain WsSwapAssessmentTask -> launches: %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore SR -> launches: %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager Interactive -> (HIDDEN!) launches: {855fec53-d2e4-4999-9e87-3414e9cf0ff4} -> {HKLM...CLSID} = RunTask \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS] -> {HKLM...Wow...CLSID} = RunTask \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TaskScheduler Idle Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Maintenance Configurator -> launches: {645E29EA-4B0A-464C-8B7D-1A6B9F9D92A8} -> {HKLM...CLSID} = Maintenance Configurator \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Manual Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Regular Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} -> {HKLM...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS] -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization ForceSynchronizeTime -> launches: {A31AD6C2-FF4C-43D4-8E90-7101023096F9} -> {HKLM...CLSID} = Time Synchronization Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TimeSyncTask.dll [MS] SynchronizeTime -> launches: %windir%\system32\sc.exe start w32time task_started [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Time Zone SynchronizeTimeZone -> launches: %windir%\system32\tzsync.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TPM Tpm-Maintenance -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\UPnP UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WDI ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS] -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting QueueReporting -> launches: %windir%\system32\wermgr.exe -queuereporting [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing UpdateLibrary -> launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup ConfigNotification -> launches: %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem Calibration Loader -> launches: {B210D694-C8DF-490d-9576-9E20CDBC20BD} -> {HKLM...CLSID} = Color Calibration Loader \InProcServer32\(Default) = C:\Windows\System32\mscms.dll [MS] -> {HKLM...Wow...CLSID} = Color Calibration Loader \InProcServer32\(Default) = C:\Windows\SysWOW64\mscms.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate Scheduled Start -> launches: C:\WINDOWS\system32\sc.exe start wuauserv [MS] Scheduled Start With Network -> launches: C:\WINDOWS\system32\sc.exe start wuauserv [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Wininet CacheTask -> launches: {0358b920-0ac7-461f-98f4-58e32cd89148} -> {HKLM...CLSID} = Wininet Cache task object \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS] -> {HKLM...Wow...CLSID} = Wininet Cache task object \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WOF WIM-Hash-Management -> launches: {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} -> {HKLM...CLSID} = WOF Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\WofTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Work Folders Work Folders Logon Synchronization -> launches: {97d47d56-3777-49fb-8e8f-90d7e30e1a1e} -> {HKLM...CLSID} = Work Folder Logon Trigger Class \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS] Work Folders Maintenance Work -> launches: {63260bce-a3fb-4a34-aa51-d4d8e877b62b} -> {HKLM...CLSID} = Work Folder Maintenance Task Class \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WS Badge Update -> launches: {00CCDDF6-5107-424D-853D-3907AE5502DC} -> {HKLM...CLSID} = WinStore Tile Badge Updater \InProcServer32\(Default) = C:\WINDOWS\winstore\WinStoreUI.dll [MS] License Validation -> (HIDDEN!) launches: rundll32.exe WSClient.dll,WSpTLR licensing [MS] Sync Licenses -> launches: {10F591BE-3C84-418A-86DD-BAA002E2F36E} -> {HKLM...CLSID} = WinStore License Sync task \InProcServer32\(Default) = C:\WINDOWS\winstore\WinStoreUI.dll [MS] WSRefreshBannedAppsListTask -> (HIDDEN!) launches: rundll32.exe WSClient.dll,RefreshBannedAppsList [MS] WSTask -> launches: {E52C9A25-F3E8-49E4-BAA7-FAD0EF620129} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\WINDOWS\System32\WSService.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows Live\SOXE Extractor Definitions Update Task -> launches: {3519154C-227E-47F3-9CC9-12C3F05817F1} -> {HKLM...Wow...CLSID} = Windows Live Social Object Extractor Engine Definition Updater \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\SOXE\wlsoxe.dll [MS] C:\Windows\System32\Tasks\WPD SqmUpload_S-1-5-21-1394563540-393045568-558702254-1001 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {553891B7-A0D5-4526-BE18-D3CE461D6310} = (no title provided) -> {HKLM...CLSID} = Classic Explorer Bar \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\ {553891B7-A0D5-4526-BE18-D3CE461D6310} = (no title provided) -> {HKLM...Wow...CLSID} = Classic Explorer Bar \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] Explorer Bars HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = &Onderzoeken Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {25510184-5A38-4A99-B273-DCA8EEF6CD08}\ ButtonText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 MenuText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 Exec = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe [null data] {56753E59-AF1D-4FBA-9E15-31557124ADA2}\ MenuText = Classic IE9 Settings Exec = C:\Program Files\Classic Shell\ClassicIE9_32.exe [IvoSoft] {64964764-1101-4BBD-8891-B56B1A53B9B3}\ BandCLSID = {553891B7-A0D5-4526-BE18-D3CE461D6310} -> {HKLM...CLSID} = Classic Explorer Bar \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer64.dll [IvoSoft] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\ {25510184-5A38-4A99-B273-DCA8EEF6CD08}\ ButtonText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 MenuText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 Exec = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe [null data] {56753E59-AF1D-4FBA-9E15-31557124ADA2}\ MenuText = Classic IE9 Settings Exec = C:\Program Files\Classic Shell\ClassicIE9_32.exe [IvoSoft] {64964764-1101-4BBD-8891-B56B1A53B9B3}\ BandCLSID = {553891B7-A0D5-4526-BE18-D3CE461D6310} -> {HKLM...Wow...CLSID} = Classic Explorer Bar \InProcServer32\(Default) = C:\Program Files\Classic Shell\ClassicExplorer32.dll [IvoSoft] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ ButtonText = Research BandCLSID = {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -> {HKLM...Wow...CLSID} = &Onderzoeken \InProcServer32\(Default) = C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL [MS] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ AMD External Events Utility, AMD External Events Utility, C:\WINDOWS\system32\atiesrxx.exe [AMD] Audio Service, STacSV, C:\Program Files\IDT\WDM\STacSV64.exe [IDT, Inc.] Classic Shell Service, ClassicShellService, "C:\Program Files\Classic Shell\ClassicShellService.exe" [IvoSoft] G Data AntiVirus Proxy, AVKProxy, "C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe" [G Data Software AG] G Data Bestandssysteembewaker, AVKWCtl, "C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe" [G Data Software AG] G Data Personal Firewall, GDFwSvc, "C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe" [G Data Software AG] G Data Scanner, GDScan, "C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe" [G Data Software AG] G DATA Scheduler, AVKService, "C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe" [G Data Software AG] HP Connected Remote Service, HPConnectedRemote, "c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe" [null data] HP Support Assistant Service, HP Support Assistant Service, "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [null data] Hulpservice voor toepassingshost, AppHostSvc, C:\WINDOWS\system32\svchost.exe -k apphost {C:\WINDOWS\system32\inetsrv\apphostsvc.dll [MS]} Intel(R) Capability Licensing Service Interface, Intel(R) Capability Licensing Service Interface, "c:\Program Files\Intel\iCLS Client\HeciServer.exe" [Intel(R) Corporation] Intel(R) Dynamic Application Loader Host Interface Service, jhi_service, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [Intel Corporation] Intel(R) Management and Security Application Local Management Service, LMS, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [Intel Corporation] Intel(R) Management and Security Application User Notification Service, UNS, "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [Intel Corporation] Intel(R) ME Service, Intel(R) ME Service, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [Intel Corporation] Network Connection Broker, NcbService, C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted {C:\WINDOWS\System32\ncbservice.dll [MS]} TomTomHOMEService, TomTomHOMEService, "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe" [TomTom] Safe Mode Drivers & Services (subkey name, subkey default value): ----------------------------------------------------------------- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ <> SystemEventsBroker, Service <> PEVSystemStart, Service HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ <> SystemEventsBroker, Service <> PEVSystemStart, Service Keyboard Driver Filters: ------------------------ HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ <> UpperFilters = <> GDKBFlt [file not found],kbdclass [MS] Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ HP Universal Port Monitor\Driver = hpbprtmon.dll [Hewlett-Packard] ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=52 folders=44 2685001 bytes) ==== Empty Temp Folders ====================== C:\Users\Dave\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Dave\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on vr 23/01/2015 at 19:52:48,72 ======================