Ga naar inhoud

Ron2011

Lid
  • Items

    228
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door Ron2011

  1. Logfile of random's system information tool 1.10 (written by random/random)
    Run by RON12 at 2015-07-04 17:10:39
    Microsoft Windows 7 Home Premium  Service Pack 1
    System drive C: has 153 GB (33%) free of 469 GB
    Total RAM: 4095 MB (46% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 17:10:54, on 4-7-2015
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v11.0 (11.00.9600.17840)
    Boot mode: Normal

    Running processes:
    C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
    C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE
    C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe
    C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    C:\Users\RON\AppData\Roaming\uTorrent\updates\3.4.3_40298.exe
    C:\Program Files\trend micro\RON12.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure Hoster (45123)] "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -app -hosterid:1
    O4 - HKCU\..\Run: [uTorrent] C:\Users\RON\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED
    O4 - HKCU\..\Run: [softonicAssistant] "C:\Users\RON12\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe"
    O4 - HKCU\..\Run: [Obrona Block Ads] "C:\Users\RON12\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe" --hidden
    O4 - HKCU\..\Run: [EpicScale] C:\ProgramData\EpicScale\0\EpicScale.exe EpicScale StartMinimized
    O4 - HKCU\..\RunOnce: [Report] \AdwCleaner\AdwCleaner[s0].txt
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'RON')
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [spotify Web Helper] "C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" (User 'RON')
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'RON')
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart (User 'RON')
    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
    O23 - Service: F-Secure Dll Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 10149 bytes

    ======Listing Processes======

     

    \SystemRoot\System32\smss.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    wininit.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    winlogon.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\svchost.exe -k utcsvc
    "C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe"
    "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -hosterid:0
    "C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe"
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE" /service /stopevent=684 /ipcexch=712
    "C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
    "C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe"
    "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
    C:\Windows\system32\svchost.exe -k imgsvc
    "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
    WLIDSvcM.exe 2036
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE"
    oid 1.3.6.1.4.1.2213.11.1.27.64 HosterGroupType 0
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\fssm32.exe" 3 812 816 820
    "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-da4e99e8-2d4b-46c8-9478-e4b0ed79d14e -SystemEventPortName:HostProcess-0bf6fd6b-5a0b-4d7a-807d-2439f3a04d69 -IoCancelEventPortName:HostProcess-ff1c02c7-fe76-436f-9ffe-adad7d676a56 -NonStateChangingEventPortName:HostProcess-8a85d280-2485-40c0-b9b5-8c3bcb5694ad -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9b28d40a-9bad-4d89-823f-a5675af4b4f1 -DeviceGroupId:WpdFsGroup
    "taskhost.exe"
    "C:\Windows\system32\Dwm.exe"
    C:\Windows\Explorer.EXE
    "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
    "C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
    "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE" /splash
    "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -app -hosterid:1
    "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
    C:\Windows\system32\SearchIndexer.exe /Embedding
    "C:\Program Files\Windows Media Player\wmpnetwk.exe"
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    "C:\Windows\system32\GWX\GWX.exe"
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
    "C:\Users\RON\AppData\Roaming\uTorrent\updates\3.4.3_40298.exe"  /LAUNCHED
    "C:\Program Files\Internet Explorer\iexplore.exe" https://mail.google.com/mail/?tab=wm#inbox

    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\sppsvc.exe
    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe123_ Global\UsGthrCtrlFltPipeMssGthrPipe123 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
    "C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
    "C:\Users\RON\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KVNRVMF9\RSITx64.exe"
    C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler
    C:\Windows\tasks\Scheduled scanning task.job - C:\PROGRA~2\INTERN~2\apps\COMPUT~1\ANTI-V~1\fsav.exe   /HARD /POLICY /SCHED /REPORT="C:\PROGRA~2\INTERN~2\apps\COMPUT~1\ANTI-V~1\report.txt" 

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03 256456]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
    Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
    Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03 194504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03 256456]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03 194504]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=C:\Users\RON\AppData\Roaming\uTorrent\uTorrent.exe [2015-02-18 1742416]
    "SoftonicAssistant"=C:\Users\RON12\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe [2014-11-11 1829832]
    "Obrona Block Ads"=C:\Users\RON12\AppData\Local\Obrona Block Ads\ObronaBlockAds.exe [2014-12-10 1510680]
    "EpicScale"=C:\ProgramData\EpicScale\0\EpicScale.exe [2015-02-18 339440]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "Report"=\AdwCleaner\AdwCleaner[s0].txt [2015-01-06 1791]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2010-02-05 128296]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-08-12 261888]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 2184520]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
    C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecLiveUpdate]
    C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04 199464]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hotkey Utility]
    C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2009-08-18 629280]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
    C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon]
    C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-08-06 349480]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
    C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2010-02-09 181480]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-20 7981088]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
    C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-02 98304]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-27 39408]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "ArcadeDeluxeAgent"=C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2010-02-05 128296]
    "F-Secure Manager"=C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE [2013-08-27 310208]
    "F-Secure Hoster (45123)"=C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe [2015-02-09 187432]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=5
    "ConsentPromptBehaviorUser"=3
    "EnableUIADesktopToggle"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "EnableSecureUIAPath"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
    "vidc.mrle"=msrle32.dll
    "vidc.msvc"=msvidc32.dll
    "msacm.imaadpcm"=imaadp32.acm
    "msacm.msg711"=msg711.acm
    "msacm.msgsm610"=msgsm32.acm
    "msacm.msadpcm"=msadp32.acm
    "midimapper"=midimap.dll
    "wavemapper"=msacm32.drv
    "VIDC.UYVY"=msyuv.dll
    "VIDC.YUY2"=msyuv.dll
    "VIDC.YVYU"=msyuv.dll
    "VIDC.IYUV"=iyuv_32.dll
    "vidc.i420"=iyuv_32.dll
    "VIDC.YVU9"=tsbyuv.dll
    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm
    "wave1"=wdmaud.drv
    "midi1"=wdmaud.drv
    "mixer1"=wdmaud.drv
    "aux1"=wdmaud.drv
    "wave2"=wdmaud.drv
    "midi2"=wdmaud.drv
    "mixer2"=wdmaud.drv
    "aux2"=wdmaud.drv
    "wave3"=wdmaud.drv
    "midi3"=wdmaud.drv
    "mixer3"=wdmaud.drv
    "aux3"=wdmaud.drv
    "wave"=wdmaud.drv
    "midi"=wdmaud.drv
    "mixer"=wdmaud.drv
    "aux"=wdmaud.drv
    "MSVideo8"=VfWWDM32.dll
    "wave4"=wdmaud.drv
    "mixer4"=wdmaud.drv
    "vidc.mjpg"=bdmjpeg64.dll
    "vidc.mpeg"=bdmpegv64.dll
    "msacm.bdmpeg"=bdmpega64.acm
    "wave5"=wdmaud.drv
    "mixer5"=wdmaud.drv
    "wave6"=wdmaud.drv
    "mixer6"=wdmaud.drv
    "wave7"=wdmaud.drv
    "mixer7"=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    ======List of files/folders created in the last 1 month======

    2015-06-10 12:01:59 ----A---- C:\Windows\system32\wmp.dll
    2015-06-10 12:01:57 ----A---- C:\Windows\SYSWOW64\wmp.dll
    2015-06-10 12:01:57 ----A---- C:\Windows\SYSWOW64\spwmp.dll
    2015-06-10 12:01:57 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
    2015-06-10 12:01:57 ----A---- C:\Windows\system32\spwmp.dll
    2015-06-10 12:01:57 ----A---- C:\Windows\system32\dxmasf.dll
    2015-06-10 12:01:56 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
    2015-06-10 12:01:56 ----A---- C:\Windows\system32\wmploc.DLL
    2015-06-10 12:01:53 ----A---- C:\Windows\system32\generaltel.dll
    2015-06-10 12:01:53 ----A---- C:\Windows\system32\appraiser.dll
    2015-06-10 12:01:53 ----A---- C:\Windows\system32\aeinv.dll
    2015-06-10 12:01:52 ----A---- C:\Windows\system32\invagent.dll
    2015-06-10 12:01:52 ----A---- C:\Windows\system32\devinv.dll
    2015-06-10 12:01:52 ----A---- C:\Windows\system32\aepic.dll
    2015-06-10 12:01:52 ----A---- C:\Windows\system32\acmigration.dll
    2015-06-10 12:01:51 ----A---- C:\Windows\system32\aepdu.dll
    2015-06-10 12:01:15 ----A---- C:\Windows\system32\diagtrack.dll
    2015-06-10 12:01:14 ----A---- C:\Windows\system32\KernelBase.dll
    2015-06-10 12:01:14 ----A---- C:\Windows\system32\kerberos.dll
    2015-06-10 12:01:13 ----A---- C:\Windows\SYSWOW64\kerberos.dll
    2015-06-10 12:01:13 ----A---- C:\Windows\system32\kernel32.dll
    2015-06-10 12:01:12 ----A---- C:\Windows\system32\lsasrv.dll
    2015-06-10 12:01:11 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
    2015-06-10 12:01:11 ----A---- C:\Windows\SYSWOW64\advapi32.dll
    2015-06-10 12:01:11 ----A---- C:\Windows\system32\advapi32.dll
    2015-06-10 12:01:10 ----A---- C:\Windows\system32\ntoskrnl.exe
    2015-06-10 12:01:10 ----A---- C:\Windows\system32\ntdll.dll
    2015-06-10 12:01:09 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\wow64.dll
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\winsrv.dll
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\tracerpt.exe
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\srcore.dll
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\rstrui.exe
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
    2015-06-10 12:01:09 ----A---- C:\Windows\system32\conhost.exe
    2015-06-10 12:01:08 ----A---- C:\Windows\SYSWOW64\schannel.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
    2015-06-10 12:01:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\system32\tdh.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\system32\schannel.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\system32\msv1_0.dll
    2015-06-10 12:01:08 ----A---- C:\Windows\system32\drivers\ksecdd.sys
    2015-06-10 12:01:07 ----A---- C:\Windows\SYSWOW64\tdh.dll
    2015-06-10 12:01:07 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
    2015-06-10 12:01:07 ----A---- C:\Windows\SYSWOW64\logman.exe
    2015-06-10 12:01:07 ----A---- C:\Windows\system32\wdigest.dll
    2015-06-10 12:01:07 ----A---- C:\Windows\system32\sechost.dll
    2015-06-10 12:01:07 ----A---- C:\Windows\system32\ncrypt.dll
    2015-06-10 12:01:07 ----A---- C:\Windows\system32\logman.exe
    2015-06-10 12:01:06 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
    2015-06-10 12:01:06 ----A---- C:\Windows\SYSWOW64\setup16.exe
    2015-06-10 12:01:06 ----A---- C:\Windows\SYSWOW64\sechost.dll
    2015-06-10 12:01:06 ----A---- C:\Windows\system32\TSpkg.dll
    2015-06-10 12:01:06 ----A---- C:\Windows\system32\sspicli.dll
    2015-06-10 12:01:06 ----A---- C:\Windows\system32\smss.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\SYSWOW64\wdigest.dll
    2015-06-10 12:01:05 ----A---- C:\Windows\SYSWOW64\typeperf.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\SYSWOW64\auditpol.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\system32\typeperf.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\system32\relog.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\system32\lsass.exe
    2015-06-10 12:01:05 ----A---- C:\Windows\system32\auditpol.exe
    2015-06-10 12:01:04 ----A---- C:\Windows\SYSWOW64\relog.exe
    2015-06-10 12:01:04 ----A---- C:\Windows\system32\srclient.dll
    2015-06-10 12:01:03 ----A---- C:\Windows\SYSWOW64\srclient.dll
    2015-06-10 12:01:03 ----A---- C:\Windows\SYSWOW64\diskperf.exe
    2015-06-10 12:01:03 ----A---- C:\Windows\system32\diskperf.exe
    2015-06-10 12:01:03 ----A---- C:\Windows\system32\csrsrv.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\wow64win.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\wow64cpu.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\sspisrv.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\secur32.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\ntvdm64.dll
    2015-06-10 12:01:02 ----A---- C:\Windows\system32\credssp.dll
    2015-06-10 12:01:01 ----A---- C:\Windows\SYSWOW64\wow32.dll
    2015-06-10 12:01:01 ----A---- C:\Windows\SYSWOW64\kernel32.dll
    2015-06-10 12:00:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-10 12:00:58 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-10 12:00:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-10 12:00:56 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-10 12:00:55 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-06-10 12:00:54 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-06-10 12:00:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-06-10 12:00:53 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-06-10 12:00:53 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-06-10 12:00:53 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-06-10 12:00:53 ----A---- C:\Windows\SYSWOW64\user.exe
    2015-06-10 12:00:53 ----A---- C:\Windows\SYSWOW64\instnm.exe
    2015-06-10 12:00:53 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
    2015-06-10 12:00:53 ----A---- C:\Windows\system32\apisetschema.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\SYSWOW64\msobjs.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\SYSWOW64\msaudite.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\SYSWOW64\adtschema.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\system32\UtcResources.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\system32\msobjs.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\system32\msaudite.dll
    2015-06-10 12:00:52 ----A---- C:\Windows\system32\adtschema.dll
    2015-06-10 12:00:04 ----A---- C:\Windows\system32\comctl32.dll
    2015-06-10 12:00:03 ----A---- C:\Windows\SYSWOW64\comctl32.dll
    2015-06-10 12:00:02 ----A---- C:\Windows\system32\win32k.sys
    2015-06-10 11:59:46 ----A---- C:\Windows\system32\drivers\stream.sys
    2015-06-10 11:59:32 ----A---- C:\Windows\SYSWOW64\iernonce.dll
    2015-06-10 11:59:32 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
    2015-06-10 11:59:32 ----A---- C:\Windows\system32\ieetwproxystub.dll
    2015-06-10 11:59:32 ----A---- C:\Windows\system32\ieetwcollector.exe
    2015-06-10 11:59:30 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
    2015-06-10 11:59:30 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\vbscript.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\urlmon.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\system32\iernonce.dll
    2015-06-10 11:59:29 ----A---- C:\Windows\system32\ie4uinit.exe
    2015-06-10 11:59:28 ----A---- C:\Windows\SYSWOW64\mshtml.dll
    2015-06-10 11:59:27 ----A---- C:\Windows\SYSWOW64\iesetup.dll
    2015-06-10 11:59:27 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
    2015-06-10 11:59:27 ----A---- C:\Windows\system32\urlmon.dll
    2015-06-10 11:59:27 ----A---- C:\Windows\system32\iedkcs32.dll
    2015-06-10 11:59:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
    2015-06-10 11:59:26 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
    2015-06-10 11:59:26 ----A---- C:\Windows\SYSWOW64\jscript.dll
    2015-06-10 11:59:26 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
    2015-06-10 11:59:26 ----A---- C:\Windows\SYSWOW64\iertutil.dll
    2015-06-10 11:59:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll
    2015-06-10 11:59:25 ----A---- C:\Windows\SYSWOW64\ieui.dll
    2015-06-10 11:59:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
    2015-06-10 11:59:25 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
    2015-06-10 11:59:25 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-06-10 11:59:25 ----A---- C:\Windows\system32\msfeeds.dll
    2015-06-10 11:59:25 ----A---- C:\Windows\system32\dxtrans.dll
    2015-06-10 11:59:24 ----A---- C:\Windows\system32\iesetup.dll
    2015-06-10 11:59:24 ----A---- C:\Windows\system32\ieapfltr.dll
    2015-06-10 11:59:23 ----A---- C:\Windows\system32\iertutil.dll
    2015-06-10 11:59:22 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
    2015-06-10 11:59:22 ----A---- C:\Windows\system32\vbscript.dll
    2015-06-10 11:59:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
    2015-06-10 11:59:21 ----A---- C:\Windows\SYSWOW64\jscript9.dll
    2015-06-10 11:59:21 ----A---- C:\Windows\system32\jsproxy.dll
    2015-06-10 11:59:21 ----A---- C:\Windows\system32\ieUnatt.exe
    2015-06-10 11:59:20 ----A---- C:\Windows\SYSWOW64\msrating.dll
    2015-06-10 11:59:20 ----A---- C:\Windows\system32\ieui.dll
    2015-06-10 11:59:20 ----A---- C:\Windows\system32\dxtmsft.dll
    2015-06-10 11:59:19 ----A---- C:\Windows\system32\ieframe.dll
    2015-06-10 11:59:18 ----A---- C:\Windows\system32\mshtmled.dll
    2015-06-10 11:59:16 ----A---- C:\Windows\system32\mshtmlmedia.dll
    2015-06-10 11:59:16 ----A---- C:\Windows\system32\jscript9diag.dll
    2015-06-10 11:59:16 ----A---- C:\Windows\system32\jscript.dll
    2015-06-10 11:59:15 ----A---- C:\Windows\system32\jscript9.dll
    2015-06-10 11:59:14 ----A---- C:\Windows\system32\wininet.dll
    2015-06-10 11:59:13 ----A---- C:\Windows\system32\msrating.dll
    2015-06-10 11:59:13 ----A---- C:\Windows\system32\MshtmlDac.dll
    2015-06-10 11:59:12 ----A---- C:\Windows\system32\mshtml.dll

    ======List of files/folders modified in the last 1 month======

    2015-07-04 17:10:54 ----D---- C:\Windows\Prefetch
    2015-07-04 17:10:53 ----D---- C:\Windows\Temp
    2015-07-04 17:10:44 ----D---- C:\Program Files\trend micro
    2015-07-04 16:24:35 ----D---- C:\TEMP
    2015-07-04 10:32:29 ----D---- C:\Windows\system32\config
    2015-07-04 03:24:27 ----D---- C:\Windows\Minidump
    2015-07-04 03:24:11 ----D---- C:\Windows
    2015-07-01 19:41:39 ----D---- C:\Windows\System32
    2015-07-01 19:41:39 ----D---- C:\Windows\inf
    2015-07-01 19:41:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2015-06-30 08:37:33 ----SHD---- C:\System Volume Information
    2015-06-24 10:13:27 ----D---- C:\Windows\SysWOW64
    2015-06-24 10:13:22 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
    2015-06-22 19:14:00 ----D---- C:\Windows\system32\catroot2
    2015-06-10 15:51:03 ----D---- C:\Windows\winsxs
    2015-06-10 15:48:06 ----D---- C:\Program Files\Windows Media Player
    2015-06-10 15:48:06 ----D---- C:\Program Files (x86)\Windows Media Player
    2015-06-10 15:48:05 ----SD---- C:\Windows\system32\CompatTel
    2015-06-10 15:48:05 ----D---- C:\Windows\system32\appraiser
    2015-06-10 15:48:05 ----D---- C:\Windows\AppPatch
    2015-06-10 15:48:04 ----D---- C:\Windows\SYSWOW64\nl-NL
    2015-06-10 15:48:03 ----D---- C:\Windows\system32\nl-NL
    2015-06-10 15:48:03 ----D---- C:\Windows\system32\drivers
    2015-06-10 15:48:01 ----D---- C:\Program Files\Internet Explorer
    2015-06-10 15:48:00 ----D---- C:\Windows\SYSWOW64\en-US
    2015-06-10 15:48:00 ----D---- C:\Windows\system32\en-US
    2015-06-10 15:48:00 ----D---- C:\Windows\PolicyDefinitions
    2015-06-10 15:47:59 ----D---- C:\Program Files (x86)\Internet Explorer
    2015-06-10 13:00:53 ----SHD---- C:\Windows\Installer
    2015-06-10 13:00:53 ----D---- C:\ProgramData\Microsoft Help
    2015-06-10 13:00:53 ----D---- C:\Config.Msi
    2015-06-10 12:59:36 ----D---- C:\Windows\system32\MRT
    2015-06-10 12:54:32 ----A---- C:\Windows\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 fsbts;fsbts; C:\Windows\system32\Drivers\fsbts.sys [2015-05-26 55336]
    R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 408600]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
    R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-04-12 49952]
    R1 F-Secure HIPS;F-Secure HIPS Driver; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\HIPS\drivers\fshs.sys [2015-06-23 71080]
    R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [2013-08-27 13248]
    R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
    R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
    R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
    R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};Power Control [2012/04/26 17:18:11]; \??\C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2010-02-09 146928]
    R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
    R3 athr;Wireless PCI Adapter Driver Service; C:\Windows\system32\DRIVERS\athrx.sys [2010-11-23 1579520]
    R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
    R3 e1yexpress;Intel® Gigabit Network Connections Driver; C:\Windows\system32\DRIVERS\e1y62x64.sys [2009-06-12 287960]
    R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [2015-06-11 208424]
    R3 fsni;fsni; \??\C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Scanning\bin\fsni64.sys [2015-06-15 95784]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-20 1831968]
    R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
    R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-07-17 201472]
    R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
    S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [2014-04-09 31920]
    S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys [2009-06-04 114192]
    S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
    S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
    S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
    S3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n64.sys [2009-07-03 452128]
    S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
    S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
    S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
    R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [2014-09-11 9216]
    R2 fshoster;F-Secure Dll Hoster; C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe [2015-02-09 187432]
    R2 FSORSPClient;F-Secure ORSP Client; C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe [2015-03-09 60456]
    R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
    R2 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
    R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-03-28 249648]
    R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
    R3 FSMA;F-Secure Management Agent; C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE [2013-08-27 207808]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
    S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24 268464]
    S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
    S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
    S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-11 194032]
    S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-22 114688]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
    S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-10-01 150648]
    S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1255736]
    S4 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
    S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
    S4 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
    S4 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
    S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
    S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-28 935208]
    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
    S4 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-13 62208]
    S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [2009-02-16 247152]
    S4 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
    S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

    -----------------EOF-----------------

  2. Ik heb de pc volledig laten scannen, niks gevonden.

     

     

    Scanrapport

     

     

    dinsdag 6 januari 2015 13:15:21 - 13:54:05

     

     

    Computernaam: RON-PC

     

    Scantype: Volledige scan

     

    Doel: C:\ D:\ F:\ + systeem

     

     

     

    Resultaat

     

    Geen malware aangetroffen

     

     

     

     

     

     

     

     

    Statistieken

     

    Gescand: •Bestanden: 78942

     

    •Niet gescand: 27

     

    Resultaat: •Virussen: 0

     

    •Spyware: 0

     

    •Verdachte items: 0

     

    •Riskware: 0

     

    Acties: •Gedesinfecteerd: 0

     

    •Naam gewijzigd: 0

     

    •Verwijderd: 0

     

    •Geïsoleerd: 0

     

    •Mislukt: 0

     

    Bootsectoren: •Gescand: 8

     

    •Geïnfecteerd: 0

     

    •Verdachte items: 0

     

    •Gedesinfecteerd: 0

     

    Bestanden niet gescand: •Kan bestand (klik hier voor meer informatie) niet openen C:\PAGEFILE.SYS

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\HIBERFIL.SYS

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\TASKS\SCHEDULED SCANNING TASK.JOB

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\TASKS\GOOGLEUPDATETASKMACHINEUA.JOB

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\TASKS\ADOBE FLASH PLAYER UPDATER.JOB

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\TASKS\GOOGLEUPDATETASKMACHINECORE.JOB

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SYSTEM32\SYSPREP\PANTHER\DIAGWRN.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SYSTEM32\SYSPREP\PANTHER\DIAGERR.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SYSTEM32\SYSPREP\PANTHER\IE\DIAGWRN.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SYSTEM32\SYSPREP\PANTHER\IE\DIAGERR.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SYSTEM32\OEM\FACTORY\FACTORY.CMD

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\PLA\SYSTEM\SYSTEM DIAGNOSTICS.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\PLA\SYSTEM\SYSTEM PERFORMANCE.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\PANTHER\UNATTENDGC\DIAGERR.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\PANTHER\UNATTENDGC\DIAGWRN.XML

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\INSTALLER\MSI1CB3.TMP

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\INSTALLER\MSIEE25.TMP

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON12\NTUSER.INI

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON\APPDATA\LOCAL\MICROSOFT\WINDOWS\WEBCACHE\WEBCACHEV01.TMP

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\PROGRAMDATA\MICROSOFT\WINDOWS\DRM\CACHE\INDIV01.TMP

     

    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\AVSDKList.zip\output.xml is gecodeerd

     

    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\ManualUninstallConfig.zip\out.xml is gecodeerd

     

    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\ProductReleaseNotes.zip\ProductReleaseNotes.xml is gecodeerd

     

    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\QATestedProducts.zip\QATestedProducts.xml is gecodeerd

     

    •Kan bestand (klik hier voor meer informatie) niet openen C:\PROGRAMDATA\AVG9\TEMP\FILE9514.TMP

     

    •Bestand C:\ProgramData\AVG2013\IDS\config\quarantinedList.zip\quarantinedList.xml is gecodeerd

     

    •Scannen van C:\OEM\Preload\Autorun\APP\Acer Arcade Deluxe\PMovie\data2.cab is afgebroken [F-Secure Aquarius]

     

     

     

     

     

    Opties

     

    Versie definities:•Virussen: 2015-01-06_04

     

    •Spyware: 2015-01-06_04

     

    Scanengines: •F-Secure Aquarius: 11.00.01, 2015-01-06

     

    •F-Secure Hydra: 5.13.68, 2015-01-06

     

    •F-Secure Online: 13.80.57, 0-00-00

     

    •F-Secure Gemini: 3.02.279, 2015-01-05

     

    Scanopties: •Opgegeven bestanden scannen: ANI ASP AX BAT BIN BOO CHM CMD COM CPL DLL DOC DOT DRV EML EXE HLP HTA HTM HTML HTT INF INI JOB JS JSE LNK LSP MDB MHT MPP MPT MSG MSO OCX PDF PHP PIF POT PPT RTF SCR SHS SWF SYS TD0 TMP VBE VBS VXD WBK WMA WMV WMF WSC WSF WSH WRI XLS XLT XML CLASS ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX

     

    •Scannen binnen archieven

     

    Acties:•Virussen: Vragen na scannen

     

    •Spyware: Vragen na scannen

     

     

     

    Foutinformatie

     

     

    De fout 'Kan bestand niet openen' is opgetreden.

     

    Het foutbericht 'Kan bestand niet openen' betekent dat de scanner het bestand neit kon openen en dat het niet is gescand. U kunt dit foutbericht meestal negeren, omdat dit bericht vaak wordt weergegeven om andere redenen dan beveiligingsdreigingen, zoals: •Het bestand was een systeembestand. Deze bestanden worden beschermd door het besturingssysteem. In dit geval kunt u dit bericht negeren.

     

    •U hebt geen toestemming om het bestand te lezen. Als u het bestand wilt scannen, moet u zich aanmelden met een gebruikersaccount met voldoende rechten (zoals de beheerdersaccount van de computer) en voert u de scan opnieuw uit.

     

    •Het bestand was tijdens de scan in gebruik. Als u dit bestand wilt scannen, sluit u alle toepassingen en voert u de scan opnieuw uit.

     

     

     

    Copyright © 1998-2012 Productondersteuning | Virusvoorbeeld verzenden naar F-Secure

     

     

    F-Secure aanvaardt geen aansprakelijkheid voor materiaal dat is vervaardigd of gepubliceerd door derden die bereikbaar zijn vanaf de website van F-Secure. Tenzij u duidelijk anderszins verklaart, gaat u door het inzenden van materiaal naar een van onze servers, bijvoorbeeld via e-mail of de CGI e-mail van F-Secure, ermee akkoord dat het toegezonden materiaal mag worden gepubliceerd op de webpagina's van F-Secure of in gedrukte publicaties. U kunt de openbare website van F-Secure bereiken door te klikken op de onderstreepte koppelingen. Wanneer u dat doet, wordt uw bezoek geregistreerd in onze eigen toegangsstatistieken, inclusief uw domeinnaam. Deze informatie wordt niet doorgegeven aan derden. U stemt ermee in dat u geen actie tegen ons zult ondernemen in verband met door u ingezonden materiaal. Tenzij u duidelijk anderszins verklaart, machtigt u F-Secure door het inzenden van het materiaal om de beginselen die erin worden beschreven zonder verdere verplichtingen op te nemen in producten en publicaties van F-Secure.

  3. # AdwCleaner v4.106 - Rapport aangemaakt 06/01/2015 op 07:43:32

     

    # Laatste Update 21/12/2014 door Xplode

     

    # Database : 2015-01-03.1 [Live]

     

    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

     

    # Gebruikersnaam : RON12 - RON-PC

     

    # Gestart vanuit : C:\Users\RON\Desktop\adwcleaner_4.106.exe

     

    # Optie : Verwijderen

     

     

    ***** [ Services ] *****

     

     

     

    ***** [ Bestanden / Mappen ] *****

     

     

    Map Verwijderd : C:\Program Files (x86)\AVG\AVG10\Toolbar

     

     

    ***** [ Taken ] *****

     

     

    Taak Verwijderd : Dealply

     

    Taak Verwijderd : Desk 365 RunAsStdUser

     

     

    ***** [ Snelkoppelingen ] *****

     

     

     

    ***** [ Register ] *****

     

     

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}

     

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}

     

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}

     

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{8DCB7100-DF86-4384-8842-8FA844297B3F}

     

    Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964

     

    Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

     

    Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

     

     

    ***** [ Browsers ] *****

     

     

    -\\ Internet Explorer v11.0.9600.17496

     

     

     

    -\\ Mozilla Firefox v

     

     

     

    *************************

     

     

    AdwCleaner[R0].txt - [1647 octets] - [06/01/2015 07:36:16]

     

    AdwCleaner[R1].txt - [1707 octets] - [06/01/2015 07:41:38]

     

    AdwCleaner[s0].txt - [1641 octets] - [06/01/2015 07:43:32]

     

     

    ########## EOF - \AdwCleaner\AdwCleaner[s0].txt - [1701 octets] ##########

  4. Logfile of random's system information tool 1.09 (written by random/random)
    Run by RON12 at 2015-01-03 08:29:06
    Microsoft Windows 7 Home Premium  Service Pack 1
    System drive C: has 139 GB (30%) free of 469 GB
    Total RAM: 4095 MB (65% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 8:29:25, on 3-1-2015
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v11.0 (11.00.9600.17496)
    Boot mode: Normal

    Running processes:
    C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
    C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe
    C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE
    C:\Program Files\trend micro\RON12.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
    O4 - HKLM\..\Run: [F-Secure Hoster (45123)] "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -app -hosterid:1
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE" /splash
    O4 - HKCU\..\Run: [uTorrent] C:\Users\RON\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'RON')
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [spotify Web Helper] "C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" (User 'RON')
    O4 - HKUS\S-1-5-21-1255420860-2708843325-1920694139-1000\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'RON')
    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
    O23 - Service: F-Secure Dll Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 9500 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    wininit.exe
    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    winlogon.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    "C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe"
    "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -hosterid:0
    "C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe"
    "C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE" /service /stopevent=668 /ipcexch=808
    "C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe"
    "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
    C:\Windows\system32\svchost.exe -k imgsvc
    "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
    WLIDSvcM.exe 1960
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE"
    oid 1.3.6.1.4.1.2213.11.1.27.64 HosterGroupType 0
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\fssm32.exe" 3 796 800 812
    "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-57e9a97e-0f35-48d9-a20a-b854085b0592 -SystemEventPortName:HostProcess-54efeb05-6752-4cd2-b83a-d5594be3d031 -IoCancelEventPortName:HostProcess-b4352d0b-6ca4-46c4-834b-ad1086c08c04 -NonStateChangingEventPortName:HostProcess-05e5a801-bc2d-4215-971f-6c2b1d5798ac -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e8a3d82c-c9cc-46da-b844-74dd1497a1d2 -DeviceGroupId:WpdFsGroup
    "taskhost.exe"
    "C:\Windows\system32\Dwm.exe"
    C:\Windows\Explorer.EXE
    "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
    "C:\Users\RON\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
    "C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe" -app -hosterid:1
    "C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE" /splash
    C:\Windows\system32\SearchIndexer.exe /Embedding
    "C:\Program Files\Windows Media Player\wmpnetwk.exe"
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe18_ Global\UsGthrCtrlFltPipeMssGthrPipe18 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
    "C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
    "C:\Users\RON\Desktop\RSITx64.exe"
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
    C:\Windows\System32\svchost.exe -k WerSvcGroup

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\Scheduled scanning task.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-03-27 256456]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
    Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
    Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27 194504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-03-27 256456]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-27 194504]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=C:\Users\RON\AppData\Roaming\uTorrent\uTorrent.exe [2014-04-16 904272]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
    C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2010-02-05 128296]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-08-12 261888]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 2184520]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
    C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecLiveUpdate]
    C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04 199464]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hotkey Utility]
    C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2009-08-18 629280]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
    C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon]
    C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-08-06 349480]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
    C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2010-02-09 181480]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-20 7981088]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
    C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-02 98304]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-27 39408]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
    "ArcadeDeluxeAgent"=C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2010-02-05 128296]
    "F-Secure Hoster (45123)"=C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe [2012-11-26 183864]
    "F-Secure Manager"=C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSM32.EXE [2013-08-27 310208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"="C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-12-10 243200]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=5
    "ConsentPromptBehaviorUser"=3
    "EnableUIADesktopToggle"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "EnableSecureUIAPath"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
    "vidc.mrle"=msrle32.dll
    "vidc.msvc"=msvidc32.dll
    "msacm.imaadpcm"=imaadp32.acm
    "msacm.msg711"=msg711.acm
    "msacm.msgsm610"=msgsm32.acm
    "msacm.msadpcm"=msadp32.acm
    "midimapper"=midimap.dll
    "wavemapper"=msacm32.drv
    "VIDC.UYVY"=msyuv.dll
    "VIDC.YUY2"=msyuv.dll
    "VIDC.YVYU"=msyuv.dll
    "VIDC.IYUV"=iyuv_32.dll
    "vidc.i420"=iyuv_32.dll
    "VIDC.YVU9"=tsbyuv.dll
    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm
    "wave1"=wdmaud.drv
    "midi1"=wdmaud.drv
    "mixer1"=wdmaud.drv
    "aux1"=wdmaud.drv
    "wave2"=wdmaud.drv
    "midi2"=wdmaud.drv
    "mixer2"=wdmaud.drv
    "aux2"=wdmaud.drv
    "wave3"=wdmaud.drv
    "midi3"=wdmaud.drv
    "mixer3"=wdmaud.drv
    "aux3"=wdmaud.drv
    "wave"=wdmaud.drv
    "midi"=wdmaud.drv
    "mixer"=wdmaud.drv
    "aux"=wdmaud.drv
    "MSVideo8"=VfWWDM32.dll
    "wave4"=wdmaud.drv
    "mixer4"=wdmaud.drv
    "vidc.mjpg"=bdmjpeg64.dll
    "vidc.mpeg"=bdmpegv64.dll
    "msacm.bdmpeg"=bdmpega64.acm
    "wave5"=wdmaud.drv
    "mixer5"=wdmaud.drv
    "wave6"=wdmaud.drv
    "mixer6"=wdmaud.drv
    "wave7"=wdmaud.drv
    "mixer7"=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    ======List of files/folders created in the last 1 month======

    2015-01-03 08:29:06 ----D---- C:\rsit
    2014-12-18 08:07:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
    2014-12-18 08:07:29 ----A---- C:\Windows\system32\ieUnatt.exe
    2014-12-10 10:28:23 ----D---- C:\Windows\system32\appraiser
    2014-12-10 08:48:53 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
    2014-12-10 08:48:53 ----A---- C:\Windows\SYSWOW64\mfps.dll
    2014-12-10 08:48:53 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
    2014-12-10 08:48:53 ----A---- C:\Windows\SYSWOW64\mferror.dll
    2014-12-10 08:48:53 ----A---- C:\Windows\SYSWOW64\mf.dll
    2014-12-10 08:48:53 ----A---- C:\Windows\system32\rrinstaller.exe
    2014-12-10 08:48:53 ----A---- C:\Windows\system32\mfps.dll
    2014-12-10 08:48:53 ----A---- C:\Windows\system32\mfpmp.exe
    2014-12-10 08:48:53 ----A---- C:\Windows\system32\mferror.dll
    2014-12-10 08:48:52 ----A---- C:\Windows\system32\mf.dll
    2014-12-10 07:44:20 ----A---- C:\Windows\system32\appraiser.dll
    2014-12-10 07:44:20 ----A---- C:\Windows\system32\aitstatic.exe
    2014-12-10 07:44:20 ----A---- C:\Windows\system32\aepic.dll
    2014-12-10 07:44:20 ----A---- C:\Windows\system32\aeinv.dll
    2014-12-10 07:44:19 ----A---- C:\Windows\system32\invagent.dll
    2014-12-10 07:44:18 ----A---- C:\Windows\system32\generaltel.dll
    2014-12-10 07:44:18 ----A---- C:\Windows\system32\devinv.dll
    2014-12-10 07:44:17 ----A---- C:\Windows\system32\aepdu.dll
    2014-12-10 07:43:47 ----A---- C:\Windows\system32\WindowsCodecs.dll
    2014-12-10 07:43:46 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
    2014-12-10 07:43:44 ----A---- C:\Windows\system32\drivers\tdx.sys
    2014-12-10 07:43:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
    2014-12-10 07:43:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
    2014-12-10 07:43:27 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
    2014-12-10 07:43:27 ----A---- C:\Windows\system32\ieetwproxystub.dll
    2014-12-10 07:43:27 ----A---- C:\Windows\system32\ieetwcollector.exe
    2014-12-10 07:43:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
    2014-12-10 07:43:26 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
    2014-12-10 07:43:26 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
    2014-12-10 07:43:26 ----A---- C:\Windows\system32\iernonce.dll
    2014-12-10 07:43:26 ----A---- C:\Windows\system32\ie4uinit.exe
    2014-12-10 07:43:25 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
    2014-12-10 07:43:25 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
    2014-12-10 07:43:25 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-12-10 07:43:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
    2014-12-10 07:43:20 ----A---- C:\Windows\SYSWOW64\iesetup.dll
    2014-12-10 07:43:20 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
    2014-12-10 07:43:19 ----A---- C:\Windows\system32\urlmon.dll
    2014-12-10 07:43:19 ----A---- C:\Windows\system32\iedkcs32.dll
    2014-12-10 07:43:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
    2014-12-10 07:43:18 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
    2014-12-10 07:43:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll
    2014-12-10 07:43:18 ----A---- C:\Windows\system32\ieetwcollectorres.dll
    2014-12-10 07:43:17 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-12-10 07:43:16 ----A---- C:\Windows\SYSWOW64\ieui.dll
    2014-12-10 07:43:16 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
    2014-12-10 07:43:16 ----A---- C:\Windows\system32\msfeeds.dll
    2014-12-10 07:43:16 ----A---- C:\Windows\system32\dxtrans.dll
    2014-12-10 07:43:14 ----A---- C:\Windows\SYSWOW64\ieframe.dll
    2014-12-10 07:43:14 ----A---- C:\Windows\system32\iesetup.dll
    2014-12-10 07:43:13 ----A---- C:\Windows\system32\ieapfltr.dll
    2014-12-10 07:43:12 ----A---- C:\Windows\system32\iertutil.dll
    2014-12-10 07:43:11 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
    2014-12-10 07:43:10 ----A---- C:\Windows\SYSWOW64\wininet.dll
    2014-12-10 07:43:10 ----A---- C:\Windows\SYSWOW64\vbscript.dll
    2014-12-10 07:43:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
    2014-12-10 07:43:10 ----A---- C:\Windows\system32\jsproxy.dll
    2014-12-10 07:43:09 ----A---- C:\Windows\SYSWOW64\msrating.dll
    2014-12-10 07:43:09 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
    2014-12-10 07:43:08 ----A---- C:\Windows\system32\ieui.dll
    2014-12-10 07:43:08 ----A---- C:\Windows\system32\dxtmsft.dll
    2014-12-10 07:43:06 ----A---- C:\Windows\system32\ieframe.dll
    2014-12-10 07:43:05 ----A---- C:\Windows\system32\mshtmlmedia.dll
    2014-12-10 07:43:05 ----A---- C:\Windows\system32\mshtmled.dll
    2014-12-10 07:43:05 ----A---- C:\Windows\system32\jscript9diag.dll
    2014-12-10 07:43:04 ----A---- C:\Windows\system32\jscript9.dll
    2014-12-10 07:43:03 ----A---- C:\Windows\system32\wininet.dll
    2014-12-10 07:43:03 ----A---- C:\Windows\system32\vbscript.dll
    2014-12-10 07:42:59 ----A---- C:\Windows\system32\msrating.dll
    2014-12-10 07:42:59 ----A---- C:\Windows\system32\MshtmlDac.dll
    2014-12-10 07:42:53 ----A---- C:\Windows\system32\mshtml.dll
    2014-12-10 07:40:59 ----A---- C:\Windows\system32\charmap.exe
    2014-12-10 07:40:58 ----A---- C:\Windows\SYSWOW64\charmap.exe
    2014-12-10 07:40:57 ----A---- C:\Windows\system32\WsmSvc.dll
    2014-12-10 07:40:56 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
    2014-12-10 07:40:56 ----A---- C:\Windows\system32\WsmWmiPl.dll
    2014-12-10 07:40:56 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
    2014-12-10 07:40:56 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
    2014-12-10 07:40:55 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
    2014-12-10 07:40:55 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
    2014-12-10 07:40:55 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
    2014-12-10 07:40:55 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
    2014-12-10 07:40:55 ----A---- C:\Windows\system32\WsmAuto.dll
    2014-12-10 07:40:45 ----A---- C:\Windows\system32\tzres.dll
    2014-12-10 07:40:44 ----A---- C:\Windows\SYSWOW64\tzres.dll

    ======List of files/folders modified in the last 1 month======

    2015-01-03 08:29:19 ----D---- C:\Windows\Prefetch
    2015-01-03 08:29:17 ----D---- C:\Windows\Temp
    2015-01-03 08:29:15 ----D---- C:\Program Files\trend micro
    2015-01-03 08:08:17 ----D---- C:\Windows\tracing
    2015-01-03 07:53:28 ----D---- C:\Windows\system32\config
    2015-01-03 07:39:35 ----D---- C:\Windows\SysWOW64
    2015-01-02 14:43:26 ----D---- C:\Windows\System32
    2015-01-02 14:43:26 ----D---- C:\Windows\inf
    2015-01-02 14:43:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2014-12-31 08:35:58 ----SHD---- C:\System Volume Information
    2014-12-31 07:09:02 ----D---- C:\Windows\system32\catroot2
    2014-12-21 12:03:28 ----RD---- C:\Program Files (x86)
    2014-12-20 12:03:47 ----D---- C:\Windows\rescache
    2014-12-18 08:15:49 ----D---- C:\Windows\winsxs
    2014-12-18 08:04:21 ----D---- C:\Windows\system32\catroot
    2014-12-14 07:53:14 ----D---- C:\Program Files\Microsoft Silverlight
    2014-12-14 07:53:13 ----D---- C:\Program Files (x86)\Microsoft Silverlight
    2014-12-14 04:08:30 ----SHD---- C:\Windows\Installer
    2014-12-14 04:08:29 ----D---- C:\Config.Msi
    2014-12-12 07:40:45 ----D---- C:\Windows\SYSWOW64\nl-NL
    2014-12-12 07:40:45 ----D---- C:\Windows\system32\nl-NL
    2014-12-10 10:28:24 ----SD---- C:\Windows\system32\CompatTel
    2014-12-10 10:28:24 ----D---- C:\Windows\AppCompat
    2014-12-10 10:28:23 ----SD---- C:\ProgramData\Microsoft
    2014-12-10 10:28:22 ----D---- C:\Windows\SYSWOW64\en-US
    2014-12-10 10:28:22 ----D---- C:\Windows\system32\drivers
    2014-12-10 10:28:22 ----D---- C:\Program Files\Internet Explorer
    2014-12-10 10:28:21 ----D---- C:\Windows\system32\en-US
    2014-12-10 10:28:21 ----D---- C:\Windows\PolicyDefinitions
    2014-12-10 10:28:20 ----D---- C:\Program Files (x86)\Internet Explorer
    2014-12-10 08:54:38 ----D---- C:\ProgramData\Microsoft Help
    2014-12-10 08:53:53 ----D---- C:\Windows\system32\MRT
    2014-12-10 08:50:18 ----A---- C:\Windows\system32\MRT.exe
    2014-12-10 03:13:18 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 fsbts;fsbts; C:\Windows\system32\Drivers\fsbts.sys [2014-05-01 56016]
    R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 408600]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
    R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-04-12 49952]
    R1 F-Secure HIPS;F-Secure HIPS Driver; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\HIPS\drivers\fshs.sys [2014-11-18 71112]
    R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [2013-08-27 13248]
    R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
    R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
    R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
    R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};Power Control [2012/04/26 17:18:11]; \??\C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [2010-02-09 146928]
    R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
    R3 athr;Wireless PCI Adapter Driver Service; C:\Windows\system32\DRIVERS\athrx.sys [2010-11-23 1579520]
    R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
    R3 e1yexpress;Intel® Gigabit Network Connections Driver; C:\Windows\system32\DRIVERS\e1y62x64.sys [2009-06-12 287960]
    R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [2014-11-18 207400]
    R3 fsni;fsni; \??\C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Scanning\fsni64.sys [2013-04-25 80832]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-20 1831968]
    R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
    R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-07-17 201472]
    R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
    S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [2014-04-09 31920]
    S3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys [2009-06-04 114192]
    S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
    S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
    S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
    S3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n64.sys [2009-07-03 452128]
    S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
    S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
    S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [2014-09-11 9216]
    R2 fshoster;F-Secure Dll Hoster; C:\Program Files (x86)\Internetbeveiliging\fshoster32.exe [2012-11-26 183864]
    R2 FSORSPClient;F-Secure ORSP Client; C:\Program Files (x86)\Internetbeveiliging\apps\CCF_Reputation\fsorsp.exe [2014-05-01 60352]
    R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
    R2 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
    R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-03-28 249648]
    R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
    R3 FSMA;F-Secure Management Agent; C:\Program Files (x86)\Internetbeveiliging\apps\ComputerSecurity\Common\FSMA32.EXE [2013-08-27 207808]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
    S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10 267440]
    S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
    S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
    S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-11 194032]
    S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
    S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-10-01 150648]
    S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1255736]
    S4 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
    S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
    S4 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
    S4 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
    S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
    S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-28 935208]
    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
    S4 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
    S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [2009-02-16 247152]
    S4 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
    S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

    -----------------EOF-----------------

  5. Ik had mijn virusscanner laten draaien en hij gaf op dat die enkele bestanden niet kan verwijderen.

    Ik weet niet of het erg is.

     

    Hier is het rapport.

     

     
    Scanrapport

    vrijdag 2 januari 2015 9:30:00 - 9:59:18

    Computernaam: RON-PC
     Scantype: Volledige scan
     Doel : C:\ D:\ F:\ + systeem + rootkits

    Resultaat

    Riskware gevonden
    Application.SearchProtect.R (Riskware) •C:\Users\RON12\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYUGGTZ8\SPSetup[1].exe\stream_4036.bin
    •C:\Users\RON12\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYUGGTZ8\SPSetup[1].exe\stream_6062.bin\stream_3294.bin
    Gen:Variant.Application.SearchProtect (Riskware) •C:\Users\RON12\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYUGGTZ8\SPSetup[1].exe\stream_6062.bin\stream_882.bin
    •C:\Users\RON12\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYUGGTZ8\SPSetup[1].exe\stream_6062.bin

     

     

    Statistieken
     Gescand: •Bestanden: 82753
    •Niet gescand: 469
     Resultaat: •Virussen: 0
    •Spyware: 0
    •Verdachte items: 0
    •Riskware: 4
     Acties: •Gedesinfecteerd: 0
    •Naam gewijzigd: 0
    •Verwijderd: 0
    •Geïsoleerd: 0
    •Mislukt: 0
     Bootsectoren: •Gescand: 8
    •Geïnfecteerd: 0
    •Verdachte items: 0
    •Gedesinfecteerd: 0
     Bestanden niet gescand: •Kan bestand (klik hier voor meer informatie) niet openen C:\HIBERFIL.SYS
    •Kan bestand (klik hier voor meer informatie) niet openen C:\PAGEFILE.SYS
    •Kan bestand (klik hier voor meer informatie) niet openen C:\WINDOWS\SERVICEPROFILES\LOCALSERVICE\APPDATA\ROAMING\PEERNETWORKING\B13FAE75B826C21ED743E0A447661D3C\A1EBB249798EFBE6F0082AB01C88FFD9\GROUPING\DB.MDB
    •Scannen van C:\Users\RON12\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYUGGTZ8\SPSetup[1].exe\stream_1370.bin is afgebroken [F-Secure Aquarius]
    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON\APPDATA\LOCAL\TEMP\~DFA1CD5E55E937DD09.TMP
    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON\APPDATA\LOCAL\TEMP\~DFAEE17C2E21555C98.TMP
    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON\APPDATA\LOCAL\TEMP\~DFD035BA70F87CE1C1.TMP
    •Kan bestand (klik hier voor meer informatie) niet openen C:\USERS\RON\APPDATA\LOCAL\TEMP\~DFF239ADE64BE931F5.TMP
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar10.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar10.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar11.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar11.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar12.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar12.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar13.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar13.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar14.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar14.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar15.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar15.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar16.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar16.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar17.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar17.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar18.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar18.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar19.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar19.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonTóŒ< oolbar2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar20.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar20.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar21.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar21.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar22.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar22.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar23.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar23.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar24.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar24.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar25.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar25.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar26.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar26.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar27.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar27.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar28.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar28.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar29.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar29.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar30.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar30.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar31.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar31.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar32.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar32.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar33.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar33.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar34.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar34.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar35.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar35.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar36.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar36.zip\sbRecovery.ini is óŒ< gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar37.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar37.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar38.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar39.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar39.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar4.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar4.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar40.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar40.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar41.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar41.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar42.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar42.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar43.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar43.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar44.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar44.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar45.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar45.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar46.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar46.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar47.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar47.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar48.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar48.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar5.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar5.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar6.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar6.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar7.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar7.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar8.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar8.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar9.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BabylonToolbar9.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\SpybotóŒ< - Search & Destroy\Recovery\BanyaneSafe.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\ProgramData/eSafe/eDelayinfo.edb is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\ProgramData/eSafe/eGdpSvc.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\ProgramData/eSafe/eSafeSvc.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\ProgramData/eSafe/log/eGdpSvc.LOG is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\ProgramData/eSafe/log/eSafeSvc.LOG is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe10.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe11.zip\eDelayinfo.edb is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe11.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe12.zip\eSafeSvc.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe12.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe13.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe13.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe14.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe14.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe15.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe15.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe16.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe16.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe17.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe17.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe18.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe18.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe19.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe19.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe20.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe20.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe21.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe21.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe22.zip\ProgramData/eSafe/eDelayinfo.edb is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe22.zip\ProgramData/eSafe/eGdpSvc.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe22.zip\ProgramData/eSafe/log/eGdpSvc.LOG is gecodeerd
    •Bestand C:\ProgramData\Spybot - SóŒ< earch & Destroy\Recovery\BanyaneSafe22.zip\ProgramData/eSafe/log/eSafeSvc.LOG is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe22.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe4.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe4.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe5.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe5.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe6.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe6.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe7.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe7.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe9.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe9.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe8.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\BanyaneSafe8.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk10.zip\desk_settings.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk10.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk11.zip\process_mgr.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk11.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk13.zip\recent.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk13.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk12.zip\promote.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk12.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk15.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk15.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk14.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/icudt.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk14.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/libcef.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk14.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/locales/en-US.pak is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk14.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk16.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk16.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk17.zóŒ< ip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk17.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk18.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk18.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk20.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/accelerate is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/firstrun is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/components/component_libcef_1.1364.1123.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_1.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_2.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_3.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_4.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_5.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/desk_bkg/desk_bkg_default.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/337.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/barbie.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/facebook.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/GameCenter.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/google.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/mario.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/twitter.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/v9.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\Users/RON12/AppData/Roaming/Desk 365/promote/youtube.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk19.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk21.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/icudt.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk21.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/libcef.dll is gecodeerd
    •óŒ< Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk21.zip\Program Files (x86)/Common Files/337/libcef/1.1364.1123/locales/en-US.pak is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk21.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk4.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk4.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk5.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk5.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/desk_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/desk_settings.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/process_mgr.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/337_7c9140b13c049fd26989f7fa25b77cb1_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/337_yitien_180508add5d5d8e20fb6c5e91cc21ca5_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/angrybirds_00ff92c12703baaf0130d6aec427d047_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Barbie_00a67ff4ef657679a6c88553135d62ad_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/BigFarm_de933b0e5218a4db24bebe3d55ed3558_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Empire_22b42f57d1c467841280810e218d5510_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/ESPN_a7b078f5f5f5b87efcef66ab5783cf9d_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Facebook_aab07bc79cf599b25c0110f32d46a3ef_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/gcalendar_50b3e3c5fc202f0cfcae8032b2465c1b_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Gmail_731b6d011bd9f67463a916a496775935_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Google_60d75cb277f0c452fa60dba8350caf65_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/iexplore_03cf3b4b1b3f56718f5dd6e0484c1bd2.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/iexplore_03cf3b4b1b3f56718f5dd6e0484c1bd2_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Mario_52934d81761dc31187a93a3a0be7fecc_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Outlook_6f817b67fa6af1a9c8abfa3813a8595c_48_48.png is gecodeerd
    •Bestand C:\ProgramData\SpóŒ< ybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/sys_computer_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/sys_control_panel_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/sys_my_documents_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/sys_network_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/icons/Youtube_bf18fdfc4aefd6417a8bacae4be5b415_48_48.png is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/337_7c9140b13c049fd26989f7fa25b77cb1.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/337_yitien_180508add5d5d8e20fb6c5e91cc21ca5.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Barbie_00a67ff4ef657679a6c88553135d62ad.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Facebook_aab07bc79cf599b25c0110f32d46a3ef.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Google_60d75cb277f0c452fa60dba8350caf65.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Mario_52934d81761dc31187a93a3a0be7fecc.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/promote/Youtube_bf18fdfc4aefd6417a8bacae4be5b415.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/sysicons/imageres.dll_104.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/sysicons/imageres.dll_107.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/sysicons/imageres.dll_20.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/sysicons/shell32.dll_21.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r0.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r1.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r2.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r3.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r4.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r5.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r6.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r7.jpg is gecodeóŒ< erd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r8.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/wp/r9.jpg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/1/angrybirds.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/1/angrybirds.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/3/BigFarm.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/3/BigFarm.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/35/Gmail.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/35/Gmail.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/36/Outlook.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/36/Outlook.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/39/ESPN.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/39/ESPN.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/4/Empire.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/4/Empire.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/41/gcalendar.db is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/41/gcalendar.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\Users/RON/AppData/Roaming/Desk 365/app/config/42/pulse.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk6.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/desk_bkg_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/desk_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/desk_settings.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/process_mgr.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/promote.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\Program Files (x86)/Desk 365/recent.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk7.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk8.zip\desk_bkg_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk8.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk9.zip\desk_list.xml is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ElexDesk9.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\RansomMSconfig.zip\sbRecovery.reg is gecodeerdóŒ<
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\RansomMSconfig.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/_Setup.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO10.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO11.zip\_Setup.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO11.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO12.zip\_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO12.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO13.zip\Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO13.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO15.zip\Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO15.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/_Setup.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO16.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO17.zip\_Setup.dóŒ< ll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO17.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO18.zip\_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO18.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO19.zip\Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO19.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO22.zip\Program Files (x86)/WebCake/sqlite3.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO22.zip\Program Files (x86)/WebCake/WebCakeDesktop.Updater.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO22.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO21.zip\Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO21.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO23.zip\sqlite3.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO23.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO25.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO25.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO26.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO26.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO27.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO27.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO28.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO28.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO29.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO29.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO30.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO30.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO31.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO31.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO32.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO32.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO33.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO33.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO34.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO34.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO35.zip\sbRecovery.reg is gecodeerd óŒ<
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO35.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/_Setup.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\ProgramData/Tarma Installer/{361E80BE-388B-4270-BF54-A10C2B756504}/_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO37.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.dat is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.exe is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/Setup.ico is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/_Setup.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\ProgramData/Tarma Installer/{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}/_Setupx.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO38.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO39.zip\Users/RON12/AppData/Roaming/WebCake/WebCakeDesktop.exe_old is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO39.zip\Users/RON12/AppData/Roaming/WebCake/dat/Desktop.OS.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO39.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO4.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO4.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO5.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO5.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO6.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO6.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO7.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO7.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO8.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO8.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO9.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO9.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho1.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProóŒ< gramData\Spybot - Search & Destroy\Recovery\WinUrFacebho1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho2.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\WinUrFacebho3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage1.zip\YontooIEClient.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage1.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage10.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage10.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage11.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage11.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage12.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage12.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage13.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage13.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage14.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage14.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage15.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage15.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage16.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage16.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage17.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage17.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage18.zip\YontooIEClient.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage18.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage19.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip\Program Files (x86)/Yontoo/YontooIEClient.dll is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage20.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage20.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage21.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage21.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage22.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage22.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\SpyóŒ< bot - Search & Destroy\Recovery\YontooPagerage23.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage23.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage24.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage24.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage25.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage25.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage26.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage26.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage27.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage27.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage28.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage28.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage29.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage29.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage3.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage3.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage30.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage30.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage31.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage31.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage32.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage32.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage33.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage33.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage4.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage4.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage5.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage5.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage6.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage6.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage7.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage7.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage8.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage8.zip\sbRecovery.ini is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage9.zip\sbRecovery.reg is gecodeerd
    •Bestand C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage9.zip\sbRecovery.ini is gecodeerd
    •Kan bestand (klik hier voor meer informatieóŒ< ) niet openen C:\PROGRAMDATA\MICROSOFT\WINDOWS\DRM\CACHE\INDIV01.TMP
    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\AVSDKList.zip\output.xml is gecodeerd
    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\ManualUninstallConfig.zip\out.xml is gecodeerd
    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\ProductReleaseNotes.zip\ProductReleaseNotes.xml is gecodeerd
    •Bestand C:\ProgramData\f-secure\MySA\temp\download\download_service_45123_latebound_sidegrade_sidegrade.zip\content.zip\sidegrade\QATestedProducts.zip\QATestedProducts.xml is gecodeerd
    •Bestand C:\ProgramData\AVG2013\IDS\config\quarantinedList.zip\quarantinedList.xml is gecodeerd
    •Scannen van C:\OEM\Preload\Autorun\APP\Acer Arcade Deluxe\PMovie\data2.cab is afgebroken [F-Secure Aquarius]

     

    Opties
     Versie definities:•Virussen: 2015-01-02_03
    •Spyware: 2015-01-02_03
     Scanengines: •F-Secure Aquarius: 11.00.01, 2015-01-02
    •F-Secure Hydra: 5.13.68, 2014-12-31
    •F-Secure Online: 13.80.57, 0-00-00
    •F-Secure BlackLight: 2.04.1099
     Scanopties: •Opgegeven bestanden scannen: ANI ASP AX BAT BIN BOO CHM CMD COM CPL DLL DOC DOT DRV EML EXE HLP HTA HTM HTML HTT INF INI JOB JS JSE LNK LSP MDB MHT MPP MPT MSG MSO OCX PDF PHP PIF POT PPT RTF SCR SHS SWF SYS TD0 TMP VBE VBS VXD WBK WMA WMV WMF WSC WSF WSH WRI XLS XLT XML CLASS ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
    •Scannen binnen archieven
     Acties:•Virussen: Geïnfecteerde bestanden desinfecteren
    •Spyware: Isoleren en verwijderen

    Foutinformatie

    De fout 'Kan bestand niet openen' is opgetreden.
     Het foutbericht 'Kan bestand niet openen' betekent dat de scanner het bestand neit kon openen en dat het niet is gescand. U kunt dit foutbericht meestal negeren, omdat dit bericht vaak wordt weergegeven om andere redenen dan beveiligingsdreigingen, zoals: •Het bestand was een systeembestand. Deze bestanden worden beschermd door het besturingssysteem. In dit geval kunt u dit bericht negeren.
    •U hebt geen toestemming om het bestand te lezen. Als u het bestand wilt scannen, moet u zich aanmelden met een gebruikersaccount met voldoende rechten (zoals de beheerdersaccount van de computer) en voert u de scan opnieuw uit.
    •Het bestand was tijdens de scan in gebruik. Als u dit bestand wilt scannen, sluit u alle toepassingen en voert u de scan opnieuw uit.

    Copyright © 1998-2012 Productondersteuning | Virusvoorbeeld verzenden naar F-Secure

    F-Secure aanvaardt geen aansprakelijkheid voor materiaal dat is vervaardigd of gepubliceerd door derden die bereikbaar zijn vanaf de website van F-Secure. Tenzij u duidelijk anderszins verklaart, gaat u door het inzenden van materiaal naar een van onze servers, bijvoorbeeld via e-mail of de CGI e-mail van F-Secure, ermee akkoord dat het toegezonden materiaal mag worden gepubliceerd op de webpagina's van F-Secure of in gedrukte publicaties. U kunt de openbare website van F-Secure bereiken door te klikken op de onderstreepte koppelingen. Wanneer u dat doet, wordt uw bezoek geregistreerd in onze eigen toegangsstatistieken, inclusief uw domeinnaam. Deze informatie wordt niet doorgegeven aan derden. U stemt ermee in dat u geen actie tegen ons zult ondernemen in verband met door u ingezonden materiaal. Tenzij u duidelijk anderszins verklaart, machtigt u F-Secure door het inzenden van het materiaal om de beginselen die erin worden beschreven zonder verdere verplichtingen op te nemen in producten en publicaties van F-Secure.
     

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.