Zoek.exe v5.0.0.0 Updated 13-February-2015 Tool run by jan on di 03-03-2015 at 8:50:03,83. Microsoft Windows 7 Enterprise 6.1.7600 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\jan\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Running Processes ====================== C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe C:\Program Files (x86)\Ralink\Common\RaUI.exe C:\Program Files (x86)\Ralink\Common\RaRegistry.exe C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\WUDFHost.exe C:\Program Files\CCleaner\CCleaner64.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe C:\Windows\system32\DllHost.exe C:\Users\jan\Desktop\zoek.exe C:\Windows\system32\conhost.exe C:\Windows\system32\sppsvc.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoUpdate.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\wbem\wmiprvse.exe ==== System Restore Info ====================== 3-3-2015 8:54:42 Zoek.exe System Restore Point Created Succesfully. ==== Windows Installer Info ====================== Ant.com IE add-on [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BA993752B535364B82D0556B61DB740]C:\Windows\Installer\131325.msi Cisco EAP-FAST Module [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7810FB462D3FB89499AE61A39FEAE69C]C:\Windows\Installer\78192.msi Cisco LEAP Module [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\70DA7C156F3C5364E8A83231608D01EF]C:\Windows\Installer\78198.msi Cisco PEAP Module [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5D6775DE4B957B64FA18F5D2497D6C04]C:\Windows\Installer\7819e.msi D3DX10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7BD4C90EC03660F46A13E87A329932FA]C:\Windows\Installer\36acc7.msi Junk Mail filter update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\807E9EB00CD53694C9DFA05A9190E097]C:\Windows\Installer\66da06.msi Microsoft .NET Framework 4 Client Profile [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DFC90B5F2B0FFA63D84FD16F6BF37C4B]C:\Windows\Installer\2e4c32.msi Microsoft .NET Framework 4 Client Profile NLD Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\41AE7654ACB69FE358B929EC841B7D40]C:\Windows\Installer\2e4c3e.msi Microsoft .NET Framework 4 Extended [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C28643E881181F13CBC489DC69571E2C]C:\Windows\Installer\2e4c38.msi Microsoft .NET Framework 4 Extended NLD Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8536B12037340CF30A4B74907B0E3D5E]C:\Windows\Installer\2e4c44.msi Microsoft Application Error Reporting [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000021599B0090400100000000F01FEC]C:\Windows\Installer\36acaf.msi Microsoft Security Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6B23D699926F467498B4BC429D1C0915]C:\Windows\Installer\1959eb.msi Microsoft Silverlight [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100]C:\Windows\Installer\223e2d.msi Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D034B0FAA6BD374B960AAD30DF10D8B]C:\Windows\Installer\36ace3.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EFEE0228DC83E77358593193D847A0EC]C:\Windows\Installer\371f77.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\67D6ECF5CD5FBA732B8B22BAC8DE1B4D]C:\Windows\Installer\37e49.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057]C:\Windows\Installer\1486a2.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E815EB96CCE9A53884E7857C57002F0]C:\Windows\Installer\5df09d.msi Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D04BB691875110D32B98EBCF771AA1E1]C:\Windows\Installer\1486a8.msi Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\22BEFC8F7E2A1793E9ADB411DEFE1C58]C:\Windows\Installer\330042.msi Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21EE4A31AE32173319EEFE3BD6FDFFE3]C:\Windows\Installer\33003c.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7205E5CD8E56BC1418C5A9BA84FB8B2E]C:\Windows\Installer\66dbd5.msi Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B4EB76DD26E75124FA3A1F328A003A98]C:\Windows\Installer\66db70.msi MSVCRT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6C64DD86500CEF47BA082BB611A1FF1]C:\Windows\Installer\36ac97.msi MSVCRT_amd64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\52744B0D6663D294EB6F85A741DBB99D]C:\Windows\Installer\36aca3.msi MSVCRT110 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8CDD41E806AE81E43B3E917301D4B5AD]C:\Windows\Installer\36ac9b.msi MSVCRT110_amd64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F187AF9E08E3993428A5DAE3112CC877]C:\Windows\Installer\36ac9f.msi Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4FB8353CB5373F540BE95C140A704E8E]C:\Windows\Installer\66dbb1.msi Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\048BED4F836BECB4CAB650E73FE10021]C:\Windows\Installer\66dbcd.msi Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E66BAA708174D2242981A4BFC329A217]C:\Windows\Installer\66da98.msi Windows Live Communications Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\80316C14DFC645D4BAA61763DE801AE8]C:\Windows\Installer\66d9e1.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B9A509B147BE07C48BB1F544C6715866]C:\Windows\Installer\66db93.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC56C1905EEA5044195608D0F788C001]C:\Windows\Installer\66dbe3.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C84AC3BCBC59B2147BEAF6E28A8F9970]C:\Windows\Installer\66d9ae.msi Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C27625EC9E0A05448857882A125DDC05]C:\Windows\Installer\36aca7.msi Windows Live Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C18BC956E45B1FD46B813F757793A345]C:\Windows\Installer\66d997.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\730C84D5214D86F41B79500EC34DF604]C:\Windows\Installer\66dbbf.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B62C577B8AAE11A4CAFB675ED26F8B50]C:\Windows\Installer\66da21.msi Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\12385052E33CB6949851F66DD463C2FA]C:\Windows\Installer\66d99f.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4B2346D1D42EE5044ABA7D6E0D88BC9C]C:\Windows\Installer\66da67.msi Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A8F1162B7EFE88E478D5910FFEEA784E]C:\Windows\Installer\66d9ec.msi Windows Live SOXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00BA1CDCFF107CF418A6616CF790320C]C:\Windows\Installer\66d9d2.msi Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0003981D77AEC394D8DD2E2634E659B9]C:\Windows\Installer\66d9c9.msi Windows Live UX Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C8BD9F007D5674D4BAF56F89EE8385D0]C:\Windows\Installer\66d9fe.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A0B2C0921EEC55F4BA645417CE10AD69]C:\Windows\Installer\66db88.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\23644217C7B42CA40B4D9FA58CE8AD3D]C:\Windows\Installer\66dbde.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5304EB40E8C384B4FB8B615548C9C0B8]C:\Windows\Installer\66db7f.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E261E417F4DCB1F43820F7159704C952]C:\Windows\Installer\66da49.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B219630C148E0F64F9129301503DC9F9]C:\Windows\Installer\66dba4.msi ==== Empty Folders Check ====================== C:\PROGRA~3\Ralink deleted successfully C:\PROGRA~3\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted successfully C:\PROGRA~3\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} deleted successfully C:\Users\jan\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z deleted successfully C:\Users\jan\AppData\Roaming\dvdcss deleted successfully C:\Users\jan\AppData\Local\Adobe deleted successfully ==== Checking Systemdrive for Symlinks ====================== De volumenaam van station C is System Het volumenummer is C234-CFB0 Map van C:\ 14-07-2009 06:08 Documents and Settings [C:\Users] 0 bestand(en) 0 bytes Map van C:\Program Files\Windows NT 31-03-2014 18:44 Bureau-accessoires [C:\Program Files\Windows NT\Accessories] 0 bestand(en) 0 bytes Map van C:\ProgramData 14-07-2009 06:08 Application Data [C:\ProgramData] 31-03-2014 18:44 Bureaublad [C:\Users\Public\Desktop] 14-07-2009 06:08 Desktop [C:\Users\Public\Desktop] 31-03-2014 18:44 Documenten [C:\Users\Public\Documents] 14-07-2009 06:08 Documents [C:\Users\Public\Documents] 31-03-2014 18:44 Favorieten [C:\Users\Public\Favorites] 14-07-2009 06:08 Favorites [C:\Users\Public\Favorites] 31-03-2014 18:44 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 31-03-2014 18:44 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 14-07-2009 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 14-07-2009 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\ProgramData\Microsoft\Windows\Start Menu 31-03-2014 18:44 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users 14-07-2009 06:08 All Users [C:\ProgramData] 14-07-2009 06:08 Default User [C:\Users\Default] 0 bestand(en) 0 bytes Map van C:\Users\All Users 14-07-2009 06:08 Application Data [C:\ProgramData] 31-03-2014 18:44 Bureaublad [C:\Users\Public\Desktop] 14-07-2009 06:08 Desktop [C:\Users\Public\Desktop] 31-03-2014 18:44 Documenten [C:\Users\Public\Documents] 14-07-2009 06:08 Documents [C:\Users\Public\Documents] 31-03-2014 18:44 Favorieten [C:\Users\Public\Favorites] 14-07-2009 06:08 Favorites [C:\Users\Public\Favorites] 31-03-2014 18:44 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 31-03-2014 18:44 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 14-07-2009 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 14-07-2009 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Microsoft\Windows\Start Menu 31-03-2014 18:44 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Default 14-07-2009 06:08 Application Data [C:\Users\Default\AppData\Roaming] 14-07-2009 06:08 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies] 14-07-2009 06:08 Local Settings [C:\Users\Default\AppData\Local] 31-03-2014 18:44 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 31-03-2014 18:44 Mijn documenten [C:\Users\Default\Documents] 14-07-2009 06:08 My Documents [C:\Users\Default\Documents] 14-07-2009 06:08 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 31-03-2014 18:44 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 14-07-2009 06:08 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 14-07-2009 06:08 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 14-07-2009 06:08 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 31-03-2014 18:44 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 14-07-2009 06:08 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 14-07-2009 06:08 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Local 14-07-2009 06:08 Application Data [C:\Users\Default\AppData\Local] 31-03-2014 18:44 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 14-07-2009 06:08 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 14-07-2009 06:08 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 31-03-2014 18:44 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Default\Documents 31-03-2014 18:44 Mijn afbeeldingen [C:\Users\Default\Pictures] 31-03-2014 18:44 Mijn muziek [C:\Users\Default\Music] 31-03-2014 18:44 Mijn video's [C:\Users\Default\Videos] 14-07-2009 06:08 My Music [C:\Users\Default\Music] 14-07-2009 06:08 My Pictures [C:\Users\Default\Pictures] 14-07-2009 06:08 My Videos [C:\Users\Default\Videos] 0 bestand(en) 0 bytes Map van C:\Users\jan 31-03-2014 18:44 Application Data [C:\Users\jan\AppData\Roaming] 31-03-2014 18:44 Cookies [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Cookies] 31-03-2014 18:44 Local Settings [C:\Users\jan\AppData\Local] 31-03-2014 18:44 Menu Start [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu] 31-03-2014 18:44 Mijn documenten [C:\Users\jan\Documents] 31-03-2014 18:44 NetHood [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 31-03-2014 18:44 Netwerkprinteromgeving [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 31-03-2014 18:44 Recent [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Recent] 31-03-2014 18:44 SendTo [C:\Users\jan\AppData\Roaming\Microsoft\Windows\SendTo] 31-03-2014 18:44 Sjablonen [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\jan\AppData\Local 31-03-2014 18:44 Application Data [C:\Users\jan\AppData\Local] 31-03-2014 18:44 Geschiedenis [C:\Users\jan\AppData\Local\Microsoft\Windows\History] 31-03-2014 18:44 Temporary Internet Files [C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 bestand(en) 0 bytes Map van C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu 31-03-2014 18:44 Programma's [C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\jan\Documents 31-03-2014 18:44 Mijn afbeeldingen [C:\Users\jan\Pictures] 31-03-2014 18:44 Mijn muziek [C:\Users\jan\Music] 31-03-2014 18:44 Mijn video's [C:\Users\jan\Videos] 0 bestand(en) 0 bytes Map van C:\Users\Public\Documents 31-03-2014 18:44 Mijn afbeeldingen [C:\Users\Public\Pictures] 31-03-2014 18:44 Mijn muziek [C:\Users\Public\Music] 31-03-2014 18:44 Mijn video's [C:\Users\Public\Videos] 14-07-2009 06:08 My Music [C:\Users\Public\Music] 14-07-2009 06:08 My Pictures [C:\Users\Public\Pictures] 14-07-2009 06:08 My Videos [C:\Users\Public\Videos] 0 bestand(en) 0 bytes Map van C:\Windows\AppPatch 11-08-2014 14:43 spbin [C:\PROGRA~2\SearchProtect\SearchProtect\bin] 0 bestand(en) 0 bytes Totaal aantal weergegeven bestanden: 0 bestand(en) 0 bytes 77 map(pen) 47.766.933.504 bytes beschikbaar ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4179E980-CBFA-4939-96F5-E563077A9C60} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Adobe Flash Player 16 ActiveX Advanced SystemCare 8 Ant.com IE add-on CCleaner Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module D3DX10 Driver Booster 2 Freemake Video Converter versie 4.1.5 GemistDownloader Intel(R) Graphics Media Accelerator Driver IObit Malware Fighter IObit Uninstaller Junk Mail filter update Kodi Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile NLD Language Pack Microsoft .NET Framework 4 Extended Microsoft .NET Framework 4 Extended NLD Language Pack Microsoft Application Error Reporting Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 Movie Maker MSVCRT MSVCRT_amd64 MSVCRT110 MSVCRT110_amd64 Photo Common Photo Gallery PrivaZer Ralink RT2870 Wireless LAN Card Revo Uninstaller 1.95 Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Smart Defrag 3 Speccy Surfing Protection Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD Taalpakket voor Microsoft .NET Framework 4 Extended - NLD TeamViewer 9 Temp File Cleaner Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) VLC media player Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live MIME IFilter Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} not found C:\PROGRA~3\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} not found C:\PROGRA~2\Ant.com deleted C:\Users\jan\AppData\Roaming\ProductData deleted C:\PROGRA~3\ACE6F2A1.dot deleted C:\PROGRA~3\ProductData deleted C:\PROGRA~3\Package Cache deleted C:\Users\jan\AppData\Local\Installer deleted C:\Users\Public\Documents\GOOBZO deleted C:\Users\Public\Documents\ShopperPro deleted C:\Users\jan\Downloads\SoftonicDownloader_voor_xbmc.exe deleted C:\Users\jan\AppData\LocalLow\ADSRemoval deleted C:\Windows\tasks\IUCW.job deleted C:\windows\SysNative\tasks\IUCW deleted C:\Windows\AppPatch\AppPatch64\SPVCLdr64.dll deleted C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb deleted C:\windows\SysNative\Tasks\SPBIW_UpdateTask_Time_313438303637333636382d3437415a556c2a3223346c41 deleted C:\windows\SysNative\Tasks\YTAUpdate deleted C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb deleted C:\windows\SysNative\GroupPolicy\machine deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted C:\Windows\SysWOW64\AniGIF.ocx deleted C:\Users\jan\Desktop\SoftonicDownloader_voor_xbmc.exe deleted C:\Users\jan\AppData\Roaming\IUCW.exe deleted "C:\Users\jan\AppData\Roaming\IUCW" deleted ==== System Specs ====================== Operating System: Microsoft Windows 7 Enterprise 6.1.7600 64-bits Manufacturer: Hewlett-Packard - Model: HP Compaq dc7900 Small Form Factor Install Date: 31-3-2014 19:44:11 Last Boot: 3-3-2015 8:46:14 Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz Number of Processors: 2 Work Station Bootmode: Normal boot Total RAM: 1977 MB (free 487 MB - 24) Computername: JANBOVEN Domain: WORKGROUP User: jan (Administrator account) Local Disk: C:\ - NTFS - 74 GB (free 44 GB) Local Disk: D:\ - NTFS - 74 GB (free 57 GB) CD \ DVD Drive: E:\ Bootdevice: \Device\HarddiskVolume1 Windows update: Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated) Anti-Spyware: Microsoft Security Essentials disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: IObit Malware Fighter disabled (Outdated) Internet Explorer Version: 9.0.8112.16421 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\jan\AppData\Local\Temp ==== 2015-03-03 07:50:01 17947503B7EAA0AF4914B4B6EFBC1A01 20480 ----a-w- C:\Users\jan\AppData\Local\Temp\DaS_21.exe 2015-03-02 10:02:01 90C412ACD13DFEDDD6BE03CD55B81F44 203264 ----a-w- C:\Users\jan\AppData\Local\Temp\res.dll 2015-03-02 09:43:06 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\psmachine.dll 2015-03-02 09:43:06 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\psuser.dll 2015-03-02 09:43:06 42A53E197A37294711FE573E799CCE86 220672 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\npGoogleUpdate4.dll 2015-03-02 09:43:05 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdateHelper.msi 2015-03-02 09:43:05 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdateBroker.exe 2015-03-02 09:43:05 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdate.exe 2015-03-02 09:43:05 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdateOnDemand.exe 2015-03-02 09:43:05 6D8BE04930BA4BC1A0606193AA591F4C 761856 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\goopdate.dll 2015-03-02 09:43:05 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleCrashHandler.exe 2015-03-02 09:42:27 665BD8E8BF122446D7D0ED7C5841B3FA 212400 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_7709\ins_iwebar.exe 2015-03-02 09:33:48 E016C24380E135866D83DAB1DE24EF4D 17172816 ----a-w- C:\Users\jan\AppData\Local\Temp\atcMedia4091425292428.exe 2015-03-02 09:22:54 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\psmachine.dll 2015-03-02 09:22:54 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\psuser.dll 2015-03-02 09:22:54 6D8BE04930BA4BC1A0606193AA591F4C 761856 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\goopdate.dll 2015-03-02 09:22:54 42A53E197A37294711FE573E799CCE86 220672 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\npGoogleUpdate4.dll 2015-03-02 09:22:53 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdateHelper.msi 2015-03-02 09:22:53 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdateBroker.exe 2015-03-02 09:22:53 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdate.exe 2015-03-02 09:22:53 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdateOnDemand.exe 2015-03-02 09:22:53 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleCrashHandler.exe 2015-03-02 09:22:27 F16B3B332F550C009169822360DD5F6B 212400 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_14870\ins_sense.exe 2015-03-02 09:12:57 374AECB3C099C158BB8EBD99A86918DB 224320 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YTAHUninstall.exe 2015-03-02 09:12:56 07A47E39D92A5F5C7B7DC63716675441 1733776 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YTAHelperSetup.exe 2015-03-02 09:12:55 D0A905C4DBB627779C7395F63E4695E4 668400 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\ytauninstall.exe 2015-03-02 09:12:54 96257545E464D8E48A767DCA7158AB18 727040 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\updater.exe 2015-03-02 09:12:51 F593C94827E130CDB5C3215E0753C781 392552 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\Res.dll 2015-03-02 09:12:51 E09FA1C699E985E4CF8CFC6457DBA9F1 189800 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\xmldb.dll 2015-03-02 09:12:51 7A9C58D8E215FCD47D371FE81D7AA1F6 95592 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\unelevate.exe 2015-03-02 09:12:51 6289966FD5C7D68CC37D526F6A40CDFA 177512 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\ytalsp.dll 2015-03-02 09:12:51 1B3F12F9710B8079619D87728F711CFB 1661800 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\lspinst2.exe 2015-03-02 09:12:48 BFE64F99674B43ADC1806CD3183F4FBD 1497960 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\testlsp.exe 2015-03-02 09:12:45 E3CA787C4EF41E3D3C212899DD361DAF 284520 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\ipc.dll 2015-03-02 09:12:45 CBA2FACB405FC377ECED6ABE5E8FE605 1432424 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\lspinst.exe 2015-03-02 09:12:45 A082E5473B2A9A4D846ED7DDF637AC76 8704 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\sporder.Dll 2015-03-02 09:12:42 6354FF478451DC33755FFAEA5163EABB 1510248 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe 2015-03-02 09:12:42 3F60C99839E22B593223EB083E1AE454 199528 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\helper.dll 2015-03-02 09:12:38 7A9C58D8E215FCD47D371FE81D7AA1F6 95592 ----a-w- C:\Users\jan\AppData\Local\Temp\unelevate.exe 2015-03-02 09:12:38 592989A426AE8BD543816906B4E404B6 2227048 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe 2015-03-02 09:12:38 3F4049D8BF040812A96680C5A6B377FD 98304 ----a-w- C:\Users\jan\AppData\Local\Temp\cabex.dll 2015-03-02 09:12:38 30A7767CE7EDD677B85DBF308476BE5E 2275176 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\engine.dll 2015-03-02 09:12:26 D403E49F1E819121F3E3CDA72E9A0409 4695824 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_32389\ins_shopperpro.exe 2015-03-02 09:12:23 F9092A47C8E3B49AE282A8B4E97D5599 1206160 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_654\ins_postInst.exe 2015-03-02 09:12:23 142AE006FFA3A2AE4B952DF36AF65C8C 7697808 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_654\ins_yta.exe 2015-03-02 09:12:05 D6EC2AD4BEF4152018049627DCECB4B6 1287219 ----a-w- C:\Users\jan\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe 2015-03-02 09:12:03 053AB8E7682DBBAF45299FF2888E1F93 1305880 ----a-w- C:\Users\jan\AppData\Local\Temp\startpoint_1.exe 2015-03-02 09:08:42 FEFEF2F226FD6BE184BC4A3378B02AAF 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\psmachine.dll 2015-03-02 09:08:42 FC7A2F466F7A0F3E873077505719C1A1 143360 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdateHelper.msi 2015-03-02 09:08:42 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdateBroker.exe 2015-03-02 09:08:42 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdate.exe 2015-03-02 09:08:42 8D90BB3A36521B50D0E512A781E36871 155648 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\psuser.dll 2015-03-02 09:08:42 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdateOnDemand.exe 2015-03-02 09:08:42 6D8BE04930BA4BC1A0606193AA591F4C 761856 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\goopdate.dll 2015-03-02 09:08:42 42A53E197A37294711FE573E799CCE86 220672 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\npGoogleUpdate4.dll 2015-03-02 09:08:42 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleCrashHandler.exe 2015-03-02 09:06:26 EF7D1863F4980AB0C8BDA142FEE67F92 200072 ----a-w- C:\Users\jan\AppData\Local\Temp\UpdateCheckerSetup.exe 2015-03-02 09:06:24 518879ABE3170DABD172DFFFCD165598 285558 ----a-w- C:\Users\jan\AppData\Local\Temp\appshat_generic.exe 2015-03-02 09:06:24 31F8D1CFFB02DFF93646F81D8CE3DD75 321632 ----a-w- C:\Users\jan\AppData\Local\Temp\setup.exe 2015-03-02 08:18:38 FD5ACE6741D122A6F1235957BD11A156 1560400 ----a-w- C:\Users\jan\AppData\Local\Temp\IMF3_BigUpgrade\IMFBigUpgrade.exe 2015-03-02 08:18:37 2F28FCA1AECCCA9C06A5043B0702FBBE 1753920 ----a-w- C:\Users\jan\AppData\Local\Temp\IMF3_BigUpgrade_Downloader\IMF_ActionCenterDownloader.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-03-02 09:36:22 5C8874EE321F4623FFF7A1315039DDBC 77824 ----a-w- C:\Windows\SysWOW64\fmcodec.DLL ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-02-24 09:40:20 8C0B4E0779E2CE5613C6E8E26123FBF8 268624 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT ====== C:\Windows\Sysnative\drivers ===== 2015-02-13 11:35:48 E77CB3736A702D46A6FB15FB4A9894E3 21184 ----a-w- C:\Windows\Sysnative\drivers\SmartDefragDriver.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-03-02 19:03:38 -------- d-----w- C:\Program Files\trend micro 2015-03-02 16:44:43 -------- d-----w- C:\Program Files\Common Files\Lavasoft 2015-03-02 09:12:57 -------- d-----w- C:\Program Files\Common Files\ShopperPro ======= C:\PROGRA~2 ===== 2015-02-09 20:08:33 -------- d-----w- C:\PROGRA~2\Kodi ======= C: ===== 2015-03-02 14:11:01 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\asc_rdflag ====== C:\Users\jan\AppData\Roaming ====== 2015-03-02 16:45:10 -------- d-----w- C:\Users\jan\AppData\Roaming\LavasoftStatistics 2015-03-02 08:30:12 -------- d-----w- C:\Users\jan\AppData\Roaming\IsolatedStorage 2015-02-24 09:41:01 4A7D39FA37FA31CB5F18801CC6170E97 58016 ----a-w- C:\Users\jan\AppData\Local\GDIPFONTCACHEV1.DAT 2015-02-20 18:50:18 -------- d-----w- C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivaZer 2015-02-09 20:09:04 -------- d-----w- C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi 2015-02-09 15:29:23 -------- d-----w- C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GemistDownloader 2015-02-09 15:29:23 -------- d-----w- C:\Users\jan\AppData\Roaming\GemistDownloader 2015-02-05 14:34:19 -------- d-----w- C:\Users\jan\AppData\Roaming\Kodi ====== C:\Users\jan ====== 2015-03-02 19:03:20 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\jan\Desktop\RSITx64.exe 2015-03-02 16:44:12 -------- d-----w- C:\ProgramData\Lavasoft 2015-03-02 09:13:19 -------- d---a-w- C:\ProgramData\TEMP 2015-03-02 08:30:12 -------- d-----w- C:\ProgramData\IsolatedStorage 2015-02-13 11:35:47 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3 2015-02-13 11:33:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2015-02-13 11:33:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller ====== C: exe-files == 2015-03-03 07:50:01 17947503B7EAA0AF4914B4B6EFBC1A01 20480 ----a-w- C:\Users\jan\AppData\Local\Temp\DaS_21.exe 2015-03-02 19:03:50 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\jan.exe 2015-03-02 19:03:20 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\jan\Desktop\RSITx64.exe 2015-03-02 16:46:43 4DB5909D450AE68CC11DC865B9B84F71 2126848 ----a-w- C:\Users\jan\AppData\Local\Temporary Internet Files\Content.IE5\HB6FQO4I\AdwCleaner.exe 2015-03-02 16:46:43 4DB5909D450AE68CC11DC865B9B84F71 2126848 ----a-w- C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB6FQO4I\AdwCleaner.exe 2015-03-02 16:43:50 AEC4EF36AA23FD3985F4A32EC95A96F6 1923888 ----a-w- C:\Users\jan\AppData\Local\Temporary Internet Files\Content.IE5\GT6SILZQ\Adaware_Installer.exe 2015-03-02 16:43:50 AEC4EF36AA23FD3985F4A32EC95A96F6 1923888 ----a-w- C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GT6SILZQ\Adaware_Installer.exe 2015-03-02 12:43:10 DA2E6299C2BFC2C627E53890F2BF1816 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$IA858TR.EXE 2015-03-02 12:43:10 C5DFFF4CDAB08D819C13C8F72220DCEE 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$IOTY6YK.exe 2015-03-02 12:43:10 84548FAC8D8D52C3436F36452E35D537 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$IKETWCA.exe 2015-03-02 12:43:10 7556C85C66CE7249452F395AE8B7E469 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$ILDU3M0.exe 2015-03-02 12:43:10 74656E3C2FB9C57C98F4744D8113BF07 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$I129U1C.exe 2015-03-02 12:43:10 6966178A1F4416E084166023D484D43C 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$I07VZ3Q.exe 2015-03-02 12:43:10 4E73C1E6BCF004485A2089B0516C829A 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$IQW42NJ.exe 2015-03-02 12:41:26 E1C23ABD7E772F7C16E678111745FA23 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$IL5H2XU.exe 2015-03-02 09:43:05 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdateBroker.exe 2015-03-02 09:43:05 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdate.exe 2015-03-02 09:43:05 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleUpdateOnDemand.exe 2015-03-02 09:43:05 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.447432\GoogleCrashHandler.exe 2015-03-02 09:42:27 665BD8E8BF122446D7D0ED7C5841B3FA 212400 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_7709\ins_iwebar.exe 2015-03-02 09:33:48 E016C24380E135866D83DAB1DE24EF4D 17172816 ----a-w- C:\Users\jan\AppData\Local\Temp\atcMedia4091425292428.exe 2015-03-02 09:22:53 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdateBroker.exe 2015-03-02 09:22:53 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdate.exe 2015-03-02 09:22:53 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleUpdateOnDemand.exe 2015-03-02 09:22:53 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.487996\GoogleCrashHandler.exe 2015-03-02 09:22:27 F16B3B332F550C009169822360DD5F6B 212400 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_14870\ins_sense.exe 2015-03-02 09:13:16 374AECB3C099C158BB8EBD99A86918DB 224320 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$R129U1C.exe 2015-03-02 09:13:13 1B3F12F9710B8079619D87728F711CFB 1661800 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$RQW42NJ.exe 2015-03-02 09:13:09 D0A905C4DBB627779C7395F63E4695E4 668400 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$ROTY6YK.exe 2015-03-02 09:13:06 BFE64F99674B43ADC1806CD3183F4FBD 1497960 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$R07VZ3Q.exe 2015-03-02 09:13:06 96257545E464D8E48A767DCA7158AB18 727040 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$RKETWCA.exe 2015-03-02 09:13:06 7A9C58D8E215FCD47D371FE81D7AA1F6 95592 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$RLDU3M0.exe 2015-03-02 09:12:57 973567B98CDFC147DF4E60471D9DF072 153088 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$RA858TR.EXE 2015-03-02 09:12:57 374AECB3C099C158BB8EBD99A86918DB 224320 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YTAHUninstall.exe 2015-03-02 09:12:56 07A47E39D92A5F5C7B7DC63716675441 1733776 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YTAHelperSetup.exe 2015-03-02 09:12:55 D0A905C4DBB627779C7395F63E4695E4 668400 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\ytauninstall.exe 2015-03-02 09:12:54 96257545E464D8E48A767DCA7158AB18 727040 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\updater.exe 2015-03-02 09:12:51 7A9C58D8E215FCD47D371FE81D7AA1F6 95592 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\unelevate.exe 2015-03-02 09:12:51 1B3F12F9710B8079619D87728F711CFB 1661800 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\lspinst2.exe 2015-03-02 09:12:48 BFE64F99674B43ADC1806CD3183F4FBD 1497960 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\testlsp.exe 2015-03-02 09:12:45 CBA2FACB405FC377ECED6ABE5E8FE605 1432424 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\lspinst.exe 2015-03-02 09:12:42 6354FF478451DC33755FFAEA5163EABB 1510248 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe 2015-03-02 09:12:38 7A9C58D8E215FCD47D371FE81D7AA1F6 95592 ----a-w- C:\Users\jan\AppData\Local\Temp\unelevate.exe 2015-03-02 09:12:38 592989A426AE8BD543816906B4E404B6 2227048 ----a-w- C:\Users\jan\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe 2015-03-02 09:12:26 D403E49F1E819121F3E3CDA72E9A0409 4695824 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_32389\ins_shopperpro.exe 2015-03-02 09:12:23 F9092A47C8E3B49AE282A8B4E97D5599 1206160 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_654\ins_postInst.exe 2015-03-02 09:12:23 142AE006FFA3A2AE4B952DF36AF65C8C 7697808 ----a-w- C:\Users\jan\AppData\Local\Temp\Install_654\ins_yta.exe 2015-03-02 09:12:05 D6EC2AD4BEF4152018049627DCECB4B6 1287219 ----a-w- C:\Users\jan\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe 2015-03-02 09:12:03 053AB8E7682DBBAF45299FF2888E1F93 1305880 ----a-w- C:\Users\jan\AppData\Local\Temp\startpoint_1.exe 2015-03-02 09:08:42 F98DE4108614E4BB81E95E58E36C7000 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdateBroker.exe 2015-03-02 09:08:42 D858BA2EE718B1DB1CED20646E641D08 68608 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdate.exe 2015-03-02 09:08:42 7E767B342E55EB1DFD74A65D24EA4B70 46080 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleUpdateOnDemand.exe 2015-03-02 09:08:42 03114DADBD9977FC823F95B21FB987E7 72872 ----a-w- C:\Users\jan\AppData\Local\Temp\comh.63943\GoogleCrashHandler.exe 2015-03-02 09:06:26 EF7D1863F4980AB0C8BDA142FEE67F92 200072 ----a-w- C:\Users\jan\AppData\Local\Temp\UpdateCheckerSetup.exe 2015-03-02 09:06:24 518879ABE3170DABD172DFFFCD165598 285558 ----a-w- C:\Users\jan\AppData\Local\Temp\appshat_generic.exe 2015-03-02 09:06:24 31F8D1CFFB02DFF93646F81D8CE3DD75 321632 ----a-w- C:\Users\jan\AppData\Local\Temp\setup.exe 2015-03-02 08:18:38 FD5ACE6741D122A6F1235957BD11A156 1560400 ----a-w- C:\Users\jan\AppData\Local\Temp\IMF3_BigUpgrade\IMFBigUpgrade.exe 2015-03-02 08:18:37 2F28FCA1AECCCA9C06A5043B0702FBBE 1753920 ----a-w- C:\Users\jan\AppData\Local\Temp\IMF3_BigUpgrade_Downloader\IMF_ActionCenterDownloader.exe 2015-03-02 08:18:36 FD5ACE6741D122A6F1235957BD11A156 1560400 ----a-w- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFBigUpgrade.exe 2015-03-01 18:09:38 765DE0544A46D541E7259FB0837FB8D1 2346408 ----a-w- C:\Program Files\Common Files\ShopperPro\spbiu.exe 2015-03-01 18:09:14 2BA72D312969782C62872FBBBE8CE2C4 327168 ----a-w- C:\Program Files\Common Files\ShopperPro\spbia.exe 2015-03-01 18:09:00 9F5D97335340A27774EE5BC9E2F8E47F 516096 ----a-w- C:\Program Files\Common Files\ShopperPro\spbii64.exe 2015-03-01 18:08:02 3A255401AC7F35305E2B2673D1EFB759 388608 ----a-w- C:\Program Files\Common Files\ShopperPro\spbii32.exe 2015-02-27 12:16:09 635C1DC11C1B5CDDECF48DE70DC22E52 513824 ----a-w- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Sur10_Undelete.exe 2015-02-25 15:11:22 C18A32EF2FD1D60D436D173FB91218B7 436672 ----a-w- C:\$Recycle.Bin\S-1-5-21-822112502-3182099355-2256159949-1000\$RL5H2XU.exe === C: other files == 2015-03-01 18:09:38 B69A28F7A03C4840919E93149196AE22 41624 ----a-w- C:\Program Files\Common Files\ShopperPro\spbiw.sys ======== System Restore Points ======== RP145: 25-2-2015 11:18:31 - Windows Update RP146: 2-3-2015 9:27:28 - Windows Update RP147: 2-3-2015 10:56:16 - Revo Uninstaller's restore point - App Lid RP148: 2-3-2015 10:57:55 - Revo Uninstaller's restore point - mystartsearch uninstall RP149: 2-3-2015 10:59:29 - Revo Uninstaller's restore point - iWebar RP150: 2-3-2015 11:00:19 - Revo Uninstaller's restore point - Shopper-Pro RP151: 2-3-2015 11:01:11 - Revo Uninstaller's restore point - SensePlus RP152: 2-3-2015 11:01:53 - Revo Uninstaller's restore point - StartPoint RP153: 2-3-2015 13:38:51 - Revo Uninstaller's restore point - aTube Catcher versie 3.8 RP154: 2-3-2015 13:40:34 - Revo Uninstaller's restore point - Wajam RP155: 2-3-2015 13:41:38 - Revo Uninstaller's restore point - FilesFrog Update Checker RP156: 2-3-2015 13:42:26 - Revo Uninstaller's restore point - YouTube Accelerator RP157: 2-3-2015 13:50:09 - Revo Uninstaller's restore point - AppsHat Mobile Apps RP158: 2-3-2015 16:27:02 - Herstelbewerking RP159: 2-3-2015 17:41:32 - Revo Uninstaller's restore point - AppsHat Mobile Apps RP160: 2-3-2015 17:44:14 - AA11 RP161: 3-3-2015 8:54:25 - zoek.exe restore point ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Advanced SystemCare 8"="C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IObit Malware Fighter"="C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Advanced SystemCare 8"="C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" ==== Startup Folders ====================== 2014-03-31 17:50:35 1992 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [05-02-2015 15:29] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\ASC8_PerformanceMonitor" [C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe] "C:\Windows\SysNative\tasks\ASC8_SkipUac_jan" ["C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe" /SkipUac] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Driver Booster Scan" [C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe] "C:\Windows\SysNative\tasks\Driver Booster SkipUAC (jan)" [C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe] "C:\Windows\SysNative\tasks\Driver Booster Update" [C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe] "C:\Windows\SysNative\tasks\File1 Update Launch" [C:\Program Files (x86)\Ant.com\File1 Package Manager\File1UL.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Administrator" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_jan" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{FDC518F9-4283-4151-9E41-30231EEC6832}" [C:\Windows\system32\msfeedssync.exe] ==== Chromium Look ====================== ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{4179E980-CBFA-4939-96F5-E563077A9C60}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {4179E980-CBFA-4939-96F5-E563077A9C60} Vosteran Url="http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggbg_14_48_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByCyEtAtA0A0Dzz0A0C0F0BtDtN0D0Tzu0StCtDyCtBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDyB0AtDyCyC0BzytG0CtC0DtAtG0CyEtAzytGzz0C0FtAtGtDyC0B0AtCzzyCyBtAtB0FtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtBtByByD0DyByDtG0DzytCyBtGyE0FtBtAtG0Azy0EtCtG0DtC0E0E0C0C0Azy0FtD0CtD2Q&cr=2139178691&ir=" ==== Reset Google Chrome ====================== Nothing found to reset ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E924F4F-67F0-4BD8-9560-49F468E843D2} deleted successfully HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E924F4F-67F0-4BD8-9560-49F468E843D2} deleted successfully HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} deleted successfully HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2E924F4F-67F0-4BD8-9560-49F468E843D2} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-822112502-3182099355-2256159949-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2E924F4F-67F0-4BD8-9560-49F468E843D2} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{2E924F4F-67F0-4BD8-9560-49F468E843D2} deleted successfully ==== shortcuts on Users Desktops ====================== C:\Users\jan\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\Users\jan\Desktop\Disk Cleanup.lnk - C:\Windows\system32\cleanmgr.exe C:\Users\jan\Desktop\GemistDownloader.lnk - C:\Program Files (x86)\GemistDownloader\GemistDownloader.exe C:\Users\jan\Desktop\Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe C:\Users\jan\Desktop\Ontspanning - Snelkoppeling.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games C:\Users\jan\Desktop\Windows Live Mail.lnk - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Users\jan\Desktop\computeropruiming\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\Users\jan\Desktop\computeropruiming\IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\Users\jan\Desktop\computeropruiming\Revo Uninstaller.lnk - C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe C:\Users\jan\Desktop\computeropruiming\Temp File Cleaner.lnk - C:\Program Files (x86)\Temp File Cleaner\TempFileCleaner.exe C:\Users\jan\Desktop\computeropruiming\Windows Update.lnk - C:\Windows\system32\wuapp.exe startmenu C:\Users\jan\Desktop\PrivaZer\Privazer desinstalleren.lnk - C:\Program Files (x86)\PrivaZer\privazer_remover.exe C:\Users\jan\Desktop\PrivaZer\PrivaZer.lnk - C:\Program Files (x86)\PrivaZer\PrivaZer.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\Users\Public\Desktop\FileViewPro.lnk - C:\Program Files\FileViewPro\FileViewPro.exe C:\Users\Public\Desktop\Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe C:\Users\Public\Desktop\IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\Users\Public\Desktop\IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\Users\Public\Desktop\PrivaZer.lnk - C:\Program Files (x86)\PrivaZer\PrivaZer.exe C:\Users\Public\Desktop\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\Users\Public\Desktop\Speccy.lnk - C:\Program Files\Speccy\Speccy64.exe C:\Users\Public\Desktop\TeamViewer 9.lnk - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe ==== shortcuts in Users Start Menu ====================== C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake\Uninstall\Uninstall Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\Uninstall\unins000.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GemistDownloader\GemistDownloader.lnk - C:\Program Files (x86)\GemistDownloader\GemistDownloader.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GemistDownloader\HelpdeskWeb.nl.lnk - C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi\Kodi.lnk - C:\Program Files (x86)\Kodi\Kodi.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi\Uninstall Kodi.lnk - C:\Program Files (x86)\Kodi\Uninstall.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivaZer\Privazer desinstalleren.lnk - C:\Program Files (x86)\PrivaZer\privazer_remover.exe C:\Users\jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivaZer\PrivaZer.lnk - C:\Program Files (x86)\PrivaZer\PrivaZer.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk - C:\Program Files (x86)\Microsoft Security Client\msseces.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrivaZer.lnk - C:\Program Files (x86)\PrivaZer\PrivaZer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Bluetooth File Transfer Wizard.lnk - C:\Windows\System32\fsquirt.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Protect.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /Protect C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Toolbox.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /toolbox C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Turbo Boost.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /turboboost C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Verwijder Advanced SystemCare.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Verwijder Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake\Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter\IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter\Verwijder IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller\IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller\Uninstall IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallDisplay.exe uninstall_start C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Verwijder Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\unins000.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PrivaZer.lnk - C:\Program Files (x86)\PrivaZer\PrivaZer.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Uninstall Programs.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Live Mail.lnk - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Users\jan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 ==== Uninstall List x64 ====================== Adobe Flash Player 16 ActiveX [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX] Advanced SystemCare 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 8_is1] Ant.com IE add-on [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{57399AB2-35B2-4635-8BD2-50656BD17B04}] CCleaner [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner] Cisco EAP-FAST Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}] Cisco LEAP Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{51C7AD07-C3F6-4635-8E8A-231306D810FE}] Cisco PEAP Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}] D3DX10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}] Driver Booster 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1] Freemake Video Converter versie 4.1.5 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freemake Video Converter_is1] GemistDownloader [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GemistDownloader] Intel(R) Graphics Media Accelerator Driver [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}] IObit Malware Fighter [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObit Malware Fighter_is1] IObit Uninstaller [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall] Junk Mail filter update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}] Kodi [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Kodi] Microsoft .NET Framework 4 Client Profile [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}] Microsoft .NET Framework 4 Client Profile NLD Language Pack [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4567EA14-6BCA-3EF9-859B-92CE48B1D704}] Microsoft .NET Framework 4 Extended [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}] Microsoft .NET Framework 4 Extended NLD Language Pack [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{021B6358-4373-3FC0-A0B4-4709B7E0D3E5}] Microsoft Security Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{996D32B6-F629-4764-894B-CB24D9C19051}] Microsoft Security Essentials [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Security Client] Microsoft Silverlight [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}] Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}] Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{196BB40D-1578-3D01-B289-BEFC77A11A1E}] Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ce085a78-074e-4823-8dc1-8a721b94b76d}] Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}] Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DC5E5027-65E8-41CB-815C-9AAB48BFB8E2}] Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD67BE4B-7E62-4215-AFA3-F123A800A389}] MSVCRT [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}] MSVCRT_amd64 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D0B44725-3666-492D-BEF6-587A14BD9BD9}] MSVCRT110 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}] MSVCRT110_amd64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E9FA781F-3E80-4399-825A-AD3E11C28C77}] Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3538BF4-735B-45F3-B09E-C541A007E4E8}] Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{07AAB66E-4718-422D-9218-4AFB3C922A71}] Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4DEB840-B638-4BCE-AC6B-057EF31E0012}] PrivaZer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PrivaZer] Ralink RT2870 Wireless LAN Card [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}] Revo Uninstaller 1.95 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Revo Uninstaller] Smart Defrag 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag 3_is1] Speccy [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Speccy] Surfing Protection [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObit Surfing Protection_is1] TeamViewer 9 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\TeamViewer 9] Temp File Cleaner [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Temp File Cleaner] VLC media player [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player] Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1B905A9B-EB74-4C70-B81B-5F446C178566}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CB3CA48C-95CB-412B-B7AE-6F2EA8F89907}] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{091C65CB-AEE5-4405-9165-800D7F880C10}] Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CE52672C-A0E9-4450-8875-88A221D5CD50}] Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{659CB81C-B54E-4DF1-B618-F35777393A54}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5D48C037-D412-4F68-B197-05E03CD46F40}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B775C26B-EAA8-4A11-ACBF-76E52DF6B805}] Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{25058321-C33E-496B-8915-6FD64D362CAF}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}] Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}] Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}] Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D1893000-EA77-493C-8DDD-E262436E959B}] Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{290C2B0A-CEE1-4F55-AB46-4571EC01DA96}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{04BE4035-3C8E-4B48-BFB8-1655849C0C8B}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{71244632-4B7C-4AC2-B0D4-F95AC88EDAD3}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{714E162E-CD4F-4F1B-8302-7F5179409C25}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C036912B-E841-46F0-9F21-391005D39C9F}] ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O4 - HKCU\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files (x86)\Ralink\Common\RaUI.exe O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Download videos by Ant.com - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll (file missing) O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Broken Internet access because of LSP provider 'c:\program files (x86)\youtube accelerator\ytalsp.dll' missing O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: RalinkRegistryWriter - Ralink Technology, Corp. - C:\Program Files (x86)\Ralink\Common\RaRegistry.exe O23 - Service: RalinkRegistryWriter64 - Ralink Technology, Corp. - C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe O23 - Service: Ralink UPnP Media Server (RaMediaServer) - Unknown owner - C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Silent Runners ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\jan\AppData\Local\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Users\jan\AppData\Local\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=94 folders=29 29830594 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\jan\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\jan\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\jan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Users\jan\AppData\Local\Temporary Internet Files\Content.IE5\index.dat" not deleted ==== EOF on di 03-03-2015 at 10:24:59,96 ======================