Ga naar inhoud

niels123

Lid
  • Items

    28
  • Registratiedatum

  • Laatst bezocht

Over niels123

  • Verjaardag 17-12-1995

PC Specificaties

  • Besturingssysteem
    windows 7 home premium
  • Processor
    intel core i7 2ghz
  • Geheugen
    300 gb

niels123's prestaties

  1. Hallo iedereen, Toen ik vandaag mijn pc op slaapstand zette, stond het na een half uur nog aan (zwart scherm, maar de rest stond nog aan). Hierop heb ik het manueel uitgeschakeld en terug opnieuw ingeschakeld, maar het scherm bleef een hele tijd zwart scherm. Na nog een keer opnieuw manueel opstarten kreeg ik een melding over opstartherstel (zie foto). Dit proces duurt dan ongeveer een kwartier om te herstellen, eens dit gedaan is kan ik wel aanmelden en werken, maar niet opgeslane bestanden was ik wel kwijt. Even later heb ik men pc perongeluk weer op slaapstand gezet (puur uit gewoonte) en moest ik heel dit proces weer herhalen waardoor ook me'n antivirus crashte en opnieuw moest installeren. Weet iemand hoe dit komt of hoe het kan opgelost worden? alvast bedankt
  2. ok bedankt, ik zal zo snel mogelijk contact opnemen, alvast bedankt voor de hulp!
  3. Ik heb net even een andere laptop gebruikt op het zelfde wifi-netwerk, pagina's laden duurt soms ook belachelijk lang, alhoewel de pc zelf goed werkt. Zou dit komen door de wifi router (gebruik een standaard router van telenet) en is dit op te lossen door vb. een zwaardere router te installeren?
  4. [ATTACH]36947[/ATTACH]bij deze het logje ComboFix.txt
  5. opstarten en documenten en programma's openen gaan al een stuk sneller, maar het internet is nog steeds traag - - - Updated - - - PS ik heb deze morgen een nieuw antivirus programma geïnstalleerd: bitdefender internet security 2015 de vorige antivirus was microsoft security essentials
  6. beste, ik heb een q-force laptop van drie jaar oud, maar de harde schijf is slechts een jaar oud. het probleem is namelijk dat het toestel sinds enkele weken traag werkt, kleine bestanden openen en paginas laden duren opeens veel langer? weet iemand hoe dit komt?
  7. hoi ik heb geen last meer van reclame en het werkt allemaal ook een stuk sneller en de pc is terwijl ook eens opgekuist heel veel dank voor alles, jullie hebben me echt geholpen ik vind het fantastisch dat jullie dit doen groeten niels
  8. Rapport de ZHPFix 2014.2.16.5 par Nicolas Coolman, Update du 16/02/2014 Fichier d'export Registre : Run by Gebruiker at 19/02/2014 13:37:37 High Elevated Privileges : OK Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Papierkorb geleert (00mn 01s) Reparatur von Browser-Verknüpfungen ========== Ordner ========== ENTFERNT: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\weidunewtab@gmail.com ENTFERNT: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} Löscht temporäre Windows (14) Flash-Cookies entfernt (0) ========== Dateien ========== ENTFERNT: c:\users\gebruiker\appdata\local\google\chrome\user data\default\preferences Löscht temporäre Windows (16) (909.423 octets) Flash-Cookies entfernt (0) (0 octets) ========== Zusammenfassung ========== 4 : Ordner 3 : Dateien End of clean in 00mn 01s ========== Pfad zu Datei-Bericht ========== C:\Users\Gebruiker\AppData\Roaming\ZHP\ZHPFix[R1].txt - 19/02/2014 13:37:39 [1016]
  9. Malwarebytes Anti-Malware (-evaluatieversie-) 1.75.0.1300 Malwarebytes : Free Anti-Malware Databaseversie: v2014.02.18.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 Gebruiker :: JFKPC [administrator] Bescherming: Ingeschakeld 18/02/2014 20:59:49 mbam-log-2014-02-18 (20-59-49).txt Scan type: Volledige scan (C:\|) Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scan opties: P2P Objecten gescand: 406405 Verstreken tijd: 26 minuut/minuten, 24 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 1 HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Succesvol in quarantaine geplaatst en verwijderd. Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Bestanden gedetecteerd: 3 C:\Users\Gebruiker\Downloads\Quad_POLARIS_BIG_BOSS_LuxFarm_Ls_2013.zip.exe (PUP.Optional.Tarma) -> Succesvol in quarantaine geplaatst en verwijderd. C:\zoek_backup\C_ProgramData_YoutubeAdblocker\aYz2U.exe (PUP.Optional.MultiPlug.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\zoek_backup\C_ProgramData_YoutubeAdblocker\bKj77xy.exe (PUP.Optional.MultiPlug.A) -> Succesvol in quarantaine geplaatst en verwijderd. (einde) - - - Updated - - - ~ Verslag van ZHPDiag v2014.2.17.15 - Nicolas Coolman (17/02/2014) ~ Gelanceerd door Gebruiker (18/02/2014 21:35:02) ~ Het adres van de website : http://nicolascoolman.webs.com ~ Gratis supportforum voor desinfectie : http://nicolascoolman.webs.com/apps/links/ ~ Vertaald door de gebruiker ~ Staat van de versie : ~ Lijst wit : Ingeschakeld door het programma ~ Tot misbruik van bevoegdheden : OK ~ Gebruikersaccountbeheer (UAC) : Deactivate by program ---\\ Internet-browsers MSIE: Internet Explorer v11.0.9600.16518 MFIE: Mozilla Firefox 27.0.1 (Defaut) GCIE: Google Chrome v32.0.1700.107 ---\\ Windows productinformatie ~ Langage: Néerlandais Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ Software om het systeem te beveiligen Malwarebytes Anti-Malware versie 1.75.0.1300 Microsoft Security Client v4.4.0304.0 Windows Defender W7 ---\\ Systeem optimalisatie software CCleaner v4.05 =>Piriform Ltd ---\\ Delen van software PeerToPeer ---\\ Software die extra aandacht behoeft Adobe Flash Player 12 Plugin Adobe Reader XI Java 7 Update 40 Java 7 Update 40 ---\\ Informatie over het systeem ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 8099 MB (66% free) System Restore: Activé (Enable) System drive C: has 152 GB (65%) free of 233 GB ---\\ Verbinding met het systeem-modus ~ Computer Name: JFKPC ~ User Name: Gebruiker ~ All Users Names: UpdatusUser, HomeGroupUser$, Gebruiker, Gast, Administrator, ~ Unselected Option: None Logged in as Administrator ---\\ Omgevingsvariabelen ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Gebruiker\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Gebruiker\AppData\Roaming\ ~ %Desktop% : C:\Users\Gebruiker\Desktop\ ~ %Favorites% : C:\Users\Gebruiker\Favorites\ ~ %LocalAppData% : C:\Users\Gebruiker\AppData\Local\ ~ %StartMenu% : C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Overzicht vaste en verwisselbare stations C: Hard drive, Flash drive, Thumb drive (Free 152 Go of 233 Go) D: CD-ROM drive (Not Inserted) ---\\ Staat van het Windows Beveiligingscentrum [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 46 Legitimates Filtered in 00mn 00s ---\\ Zoeken naar bepaalde algemene bestanden [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Windows Verkenner.) (.25/02/2011 - 7:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Windows Toepassing Opstarten.) (.14/07/2009 - 2:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.263B6E451526A90FF8B1CEC759F22956] - (.Microsoft Corporation - Internetuitbreidingen voor Win32.) (.6/02/2014 - 10:24:52.) -- C:\Windows\System32\wininet.dll [2334208] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Toepassing Windows-aanmelden.) (.21/11/2010 - 4:24:29.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Software Licensing-bibliotheek.) (.21/11/2010 - 4:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 2:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 2:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 0:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 4:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 4:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 4:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - i8042-poortstuurprogramma.) (.14/07/2009 - 0:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 1:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 3:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 4:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - NT-bestandssysteemstuurprogramma.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Stuurprogramma voor parallelle poort.) (.14/07/2009 - 1:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 4:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 1:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 4:24:32.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Volume Shadow Copy-stuurprogramma.) (.21/11/2010 - 4:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Status van de verborgen bestanden (verborgen/totaal) ~ Mes images (My Pictures) : 1/7 ~ Mes musiques (My Musics) : 18/170 ~ Mes Favoris (My Favorites) : 1/27 ~ Mes Documents (My Documents) : 1/11857 ~ Mon Bureau (My Desktop) : 1/18 ~ Menu demarrer (Programs) : 1/37 ~ Hidden Files: Scanned in 00mn 02s ---\\ Gestarte processen [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2248] [MD5.1775BDBEF28FD1B0F0AC43F10F483E08] - (.NVIDIA Corporation - NVIDIA NvTmru Application.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896] [PID.3428] [MD5.10E89F598469C60D8C87A8218089A87D] - (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\Gebruiker\AppData\Local\Akamai\netsession_win.exe [4489472] [PID.3864] [MD5.A5166249C8EA1ED70ECD684F6D2E2DE8] - (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe [1824000] [PID.4000] [MD5.01990FBC83F023A9159A60F0A05B0E43] - (.No owner - Auto Club Revolution Race App Launcher.) -- C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe [2880840] [PID.4092] [MD5.58FC1B36032F03342E4C02813F80DAC1] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\Gebruiker\AppData\Roaming\Dropbox\bin\Dropbox.exe [30714328] [PID.4332] [MD5.4A73AB8412D3AA6CFAD24051FF9DBFA7] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160] [PID.4448] [MD5.193B1D98DCD8FF8D1FCD0F990DC5EDA5] - (.Creative Technology Ltd - THXAudio.) -- C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720] [PID.4600] [MD5.9D51EA92A612B37E76E5E4621650C50A] - (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288] [PID.4736] [MD5.50689B640B59DDFE4F768C77FC4E3B3A] - (.Spotify Ltd - Spotify.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe [6137912] [PID.4036] [MD5.D9184C5FF3FD526761D518A95ABA74A3] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.5344] [MD5.AB44884BC129FC04D75A4649E0710203] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8338432] [PID.4708] [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1908] [MD5.3817558D8D5BBC8B0F190CF0D7C4720F] - (.Autodesk, Inc. - Content Service.) -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288] [PID.1080] [MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2104] [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2140] [MD5.005E474630A7AA05A617C574B702FEED] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2155296] [PID.2228] [MD5.C98ACDE22458C8F46FD0503CB9E2D01F] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe [223112] [PID.3024] [MD5.5FFDA96330357A914A69D79BE1988A38] - (.Valve Corporation - Steam Client Service.) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe [571816] [PID.4856] [MD5.8FFF9083252C16FE3960173722605E9E] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [13336] [PID.4868] [MD5.50C7CE53EF461870410355F1F2E7D515] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [326168] [PID.6092] [MD5.374EBDA379A8F38E0CFC2211611E7167] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2656280] [PID.2260] ~ Processes Running: Scanned in 00mn 00s ---\\ Google Chrome, start, zoeken, extensies (G0, G1, G2) C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Preferences G2 - GCE: Preference [user Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Winkel v.0.2 (Activé) G2 - GCE: Preference [user Data\Default] [akpelnjfckgfiplcikojhomllgombffc] Theme Creator v.2.5 (Activé) G2 - GCE: Preference [user Data\Default] [dcilimldmomiaihcfkmaldanopfejefg] WGT Golf Challenge v.45.0.0 (Activé) G2 - GCE: Preference [user Data\Default] [hcddigdgleeplimnncapfcfmmfndfbbg] WeBsave v.3.7 (Activé) G2 - GCE: Preference [user Data\Default] [ikimcdcgajipgcoehakmgloecbaacmoj] Digital Clock Widget [ANTP] v.1.1.3, (Activé) G2 - GCE: Preference [user Data\Default] [jemlklgaibiijojffihnhieihhagocma] Best Flash Save v.148 (Activé) G2 - GCE: Preference [user Data\Default] [jgoncnaabanepilgbggijndebemabhhf] Valuta omzetter v.1.0 (Activé) G2 - GCE: Preference [user Data\Default] [jjelhjjeiplbdlimhklicdkffchjcldo] Smartschool v.1.7.4, (Activé) G2 - GCE: Preference [user Data\Default] [kidknbkmfcapkiepmhchinffchkjglog] Booktrack Studio v.1.4.5.6 (Activé) G2 - GCE: Preference [user Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé) ~ Google Browser: 33 Legitimates Filtered in 00mn 05s ---\\ Mozilla Firefox, Plugins, start, zoeken, extensies (P2, M0, M1, M2, M3) M2 - MFEP: prefs.js [Gebruiker - uj8d4v3m.default\weidunewtab@gmail.com] [] New Tab Plus v (..) M2 - MFEP: prefs.js [Gebruiker - uj8d4v3m.default\{0545b830-f0aa-4d7e-8820-50a4629a56fe}] [] ColorfulTabs v (..) ~ Firefox Browser: 8 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, start, zoeken, URLSearchHook, Phishing (R0, R1, R3, R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jfk.be ~ IE Browser: 17 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, proxybeheer (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local> R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse van lijnen F0, F1, F2, F3 - IniFiles, Autoloading programma's F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts-bestand omleiding (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 21 ---\\ Andere Verwijzigingen gebruikers (O4) O4 - GS\Desktop [Public]: ACR Launcher.lnk . (...) -- C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe O4 - GS\Desktop [Public]: Autodesk 360.lnk . (...) -- C:\Program Files (x86)\Autodesk\Autodesk Sync\AdSync.exe (.not file.) O4 - GS\Desktop [Public]: Autodesk ReCap.lnk . (...) -- C:\Program Files (x86)\Autodesk\Autodesk ReCap\recap.exe (.not file.) O4 - GS\Desktop [Public]: eID Viewer.lnk . (.FedICT - eID Viewer.) -- C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe O4 - GS\Desktop [Public]: Free YouTube to MP3 Converter.lnk . (.DVDVideoSoft Ltd. - FreeYouTubeToMP3Converter.) -- C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\Desktop [Public]: LayOut 2013.lnk . (.Trimble Navigation Limited - LayOut.) -- C:\Program Files (x86)\SketchUp\SketchUp 2013\LayOut\LayOut.exe O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Desktop [Public]: SketchUp 2013.lnk . (.Trimble Navigation Limited - SketchUp Application.) -- C:\Program Files (x86)\SketchUp\SketchUp 2013\SketchUp.exe O4 - GS\Desktop [Public]: Style Builder 2013.lnk . (.Trimble Navigation Limited - Style Builder.) -- C:\Program Files (x86)\SketchUp\SketchUp 2013\Style Builder\Style Builder.exe O4 - GS\Desktop [Public]: Uninstall ACR.lnk . (...) -- C:\Program Files (x86)\ACR\unins000.exe O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\QuickLaunch [Gebruiker]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\QuickLaunch [Gebruiker]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\TaskBar [Gebruiker]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Program [Gebruiker]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\SystemTools [Gebruiker]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\SendTo [Gebruiker]: Bestandsoverdracht via Bluetooth.LNK . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\fsquirt.exe O4 - GS\Desktop [Gebruiker]: Farming Simulator 2013 .lnk . (.GIANTS Software GmbH - GIANTS Launcher.) -- C:\Program Files (x86)\Farming Simulator 2013\FarmingSimulator2013.exe O4 - GS\Desktop [Gebruiker]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Desktop [Gebruiker]: Spotify.lnk . (.Spotify Ltd - Spotify.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\spotify.exe ~ Global Startup: 91 Legitimates Filtered in 00mn 00s ---\\ Toepassingen gestart door register & bestand (O4) O4 - GS\Startup [Gebruiker]: ACR Launcher.lnk . (...) -- C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe O4 - GS\Startup [Gebruiker]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) -- C:\Users\Gebruiker\AppData\Roaming\Dropbox\bin\Dropbox.exe =>.Dropbox O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Realtek HD Audio configuratie.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe O4 - HKLM\..\Run: [THXCfg64] . (.Creative Technology Ltd. - No Comment.) -- C:\Windows\system32\THXCfg64.dll O4 - HKLM\..\Run: [synTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O4 - HKLM\..\Run: [intelWireless] . (.Intel® Corporation - Intel® PROSet/Wireless Framework.) -- C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [Nvtmru] . (.NVIDIA Corporation - NVIDIA NvTmru Application.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe O4 - HKLM\..\Run: [igfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKCU\..\Run: [spotify] . (.Spotify Ltd - Spotify.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe O4 - HKCU\..\Run: [spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\Gebruiker\AppData\Local\Akamai\netsession_win.exe O4 - HKCU\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKCU\..\Run: [steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKLM\..\Wow6432Node\Run: [iAStorIcon] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe O4 - HKLM\..\Wow6432Node\Run: [THX Audio Control Panel] . (.Creative Technology Ltd - THXAudio.) -- C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe O4 - HKLM\..\Wow6432Node\Run: [NUSB3MON] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [spotify] . (.Spotify Ltd - Spotify.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [spotify Web Helper] . (.Spotify Ltd - SpotifyWebHelper.) -- C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\Gebruiker\AppData\Local\Akamai\netsession_win.exe O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [Autodesk Sync] . (.Autodesk, Inc. - Autodesk 360.) -- C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe O4 - HKUS\S-1-5-21-52792044-1074444535-1282596425-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe ~ Application: Scanned in 00mn 00s ---\\ Domeinadres van de DNS (O17) wijzigen O17 - HKLM\System\CCS\Services\Tcpip\..\{493E6856-F761-4875-9BA9-F57B13446670}: DhcpNameServer = 195.130.131.133 195.130.130.5 O17 - HKLM\System\CS1\Services\Tcpip\..\{493E6856-F761-4875-9BA9-F57B13446670}: DhcpNameServer = 195.130.131.133 195.130.130.5 O17 - HKLM\System\CS2\Services\Tcpip\..\{493E6856-F761-4875-9BA9-F57B13446670}: DhcpNameServer = 195.130.131.133 195.130.130.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.130.131.133 195.130.130.5 ~ Domain: Scanned in 00mn 00s ---\\ Aanvullend Protocol (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML-viewer.) -- C:\Windows\System32\mshtml.dll O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ AppInit_DLLs waarde en subsleutels Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ AppInit_DLLs waarde en subsleutels Winlogon Notify (autorun) (O20) O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 327.) - C:\Windows\system32\nvinitx.dll ~ AppInit DLL: Scanned in 00mn 00s ---\\ Geïnstalleerde software (O42) O42 - Logiciel: ACR version 0.001 - (.Eutechnyx, Ltd.) [HKLM][64Bits] -- {D3D02004-0977-4BB1-8FE8-8BC4230DCEEC}}_is1 O42 - Logiciel: Simplo Video Camera - (.Simplo CO.,LTD.) [HKLM][64Bits] -- {82D571B5-ED0C-49BC-AABC-DB8E05BCFA8D} O42 - Logiciel: Stuurprogrammapakket voor Windows - Fedict SmartCard (10/04/2011 4.0.0.5) - (.Fedict.) [HKLM][64Bits] -- 3FE3642036A0F4AEC17772437CE14BB1E67006AA ~ Logic: 27 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\MLSync] [HKLM\Software\Wow6432Node\Simplo CO.,LTD] ~ Key Software: 258 Legitimates Filtered in 00mn 00s ---\\ 'Inhoud van mappen programma's, ProgramFiles, ProgramData, AppData (O43) O43 - CFD: 11/10/2013 - 9:54:01 - [0,496] ----D C:\Program Files (x86)\Simplo Video Camera O43 - CFD: 21/11/2013 - 20:14:58 - [0] ----D C:\ProgramData\FARO ~ Program Folder: 152 Legitimates Filtered in 00mn 03s ---\\ Meest recente bestanden gewijzigd of gemaakt op Windows en System32 (O44) O44 - LFC:[MD5.02940D6C7722E91342A32CFF5C60F4E4] - 17/02/2014 - 18:19:54 ---A- . (...) -- C:\Windows\zoek-delete.exe [24064] O44 - LFC:[MD5.6B9A2AC8A2E0F5A305FCF9A3792E8F11] - 17/02/2014 - 18:33:16 ---A- . (...) -- C:\zoek-results.log [35562] ~ Files: 50 Legitimates Filtered in 00mn 01s ---\\ Opsomming van het register sleutels PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Legitimates Filtered in 00mn 00s ---\\ Opsomming van de registersleutel PoliciesExplorer (CÖKVI) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s ---\\ Overzicht van de drivers (SDL) (O58) O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 2:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 2:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:[MD5.306521935042FC0A6988D528643619B3] - 5/10/2010 - 0:59:32 ---A- . (...) -- C:\Windows\SysWOW64\StarOpen.sys [5632] ~ Drivers: 16 Legitimates Filtered in 00mn 03s ---\\ Meest recente bestanden gewijzigd of gemaakt (gebruiker) (O61) O61 - LFC: 15/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Downloads\BALE_Kuhn_LSB1290iD.exe [5845848] O61 - LFC: 16/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Downloads\zoek(1).exe [1283584] O61 - LFC: 16/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Downloads\zoek.exe [1283584] O61 - LFC: 17/02/2014 - 21:35:33 ---A- . (...) -- C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [268173] O61 - LFC: 17/02/2014 - 21:35:33 ---A- . (...) -- C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [4] O61 - LFC: 17/02/2014 - 21:35:36 ---A- . (...) -- C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Local State [119139] O61 - LFC: 17/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Downloads\AdwCleaner.exe [1241834] O61 - LFC: 17/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Downloads\zoek-results.txt [35562] O61 - LFC: 18/02/2014 - 21:35:39 ---A- . (...) -- C:\Users\Gebruiker\AppData\Roaming\ZHP\Log.txt [16343] =>.Nicolas Coolman O61 - LFC: 18/02/2014 - 21:35:39 ---A- . (...) -- C:\Users\Gebruiker\AppData\Roaming\ZHP\TestsZHPDiag.txt [2956] =>.Nicolas Coolman O61 - LFC: 18/02/2014 - 21:35:41 ---A- . (...) -- C:\Users\Gebruiker\Documents\school\6de jaar\algemene vakken\dialoog engels.docx [13998] ~ 8 Fichiers temporaires (Temporary files) ~ 2 Fichiers cookies (Cookies files) ~ Files: 701 Legitimates Filtered in 00mn 09s ---\\ Lijst van cleaning tools (CLAB) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Overzicht met LEGACY services (LALS) (O64) O64 - Services: CurCS - 4/04/2013 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR O64 - Services: CurCS - 10/06/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV ~ Legacy: 106 Legitimates Filtered in 00mn 00s ---\\ Startmenu Internet (SMI) (O68) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Zoek "infecties in internetbrowsers (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com ~ Keys: Scanned in 00mn 00s ---\\ Lijst van uitzonderingen in de firewall (FirewallRules) (O87) O87 - FAEL: "TCP Query User{428ED246-AA8E-4745-9729-A50F4A44BC01}C:\program files (x86)\acr\autoclubrev\bin\acr.exe" | In - Public - P6 - TRUE | .(.Eutechnyx Ltd. - Auto Club Revolution Race App.) -- C:\program files (x86)\acr\autoclubrev\bin\acr.exe O87 - FAEL: "UDP Query User{0615F7BC-9435-4F90-8466-EE92FC9A3929}C:\program files (x86)\acr\autoclubrev\bin\acr.exe" | In - Public - P17 - TRUE | .(.Eutechnyx Ltd. - Auto Club Revolution Race App.) -- C:\program files (x86)\acr\autoclubrev\bin\acr.exe O87 - FAEL: "TCP Query User{CB4EA360-EAE6-4168-876A-2714BF86E042}C:\program files (x86)\acr\autoclubrev\bin\acr.exe" | In - Private - P6 - TRUE | .(.Eutechnyx Ltd. - Auto Club Revolution Race App.) -- C:\program files (x86)\acr\autoclubrev\bin\acr.exe O87 - FAEL: "UDP Query User{A7C1FAAE-AE04-44CA-B00D-2CA8C86D4FF3}C:\program files (x86)\acr\autoclubrev\bin\acr.exe" | In - Private - P17 - TRUE | .(.Eutechnyx Ltd. - Auto Club Revolution Race App.) -- C:\program files (x86)\acr\autoclubrev\bin\acr.exe ~ Firewall: 252 Legitimates Filtered in 00mn 00s ---\\ Overzicht van de productcodes van software (PUC) (O90) O90 - PUC: "B10CB57B68548F3439942D05BD892FF6" . (.SketchUp 2013.) -- C:\Windows\Installer\{B75BC01B-4586-43F8-9349-D250DB98F26F}\SketchUpARPIcon ~ Update Products: 58 Legitimates Filtered in 00mn 00s ---\\ Microsoft Installer-bestanden (WIS) (NTFS) (O93) [MD5.659306B0BB1459394DE1834EDCAD6FB1] [WIS][25/01/2013] (.AutoCAD Apps - This plug-in can be used with AutoCAD to simplify the process o.) -- C:\Windows\Installer\69e205.msi [3691520] [MD5.4CC41D22639EB702BC7C02CBAD1BE33E] [WIS][25/01/2013] (.AutoCAD Apps - A plug-in to see the apps featuerd on the Autodesk Exchange web.) -- C:\Windows\Installer\69e20a.msi [3034112] ~ WIS: 63 Legitimates Filtered in 00mn 09s ---\\ Algemene toestand van niet-Microsoft services (GSR) (SR = Running, SS = gestopt) SS - | Demand 5/02/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 7/11/2013 279000 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe SS - | Demand 11/10/2013 1045256 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe SS - | Demand 21/11/2013 1471352 | (FlexNet Licensing Service 64) . (.Flexera Software LLC.) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe SS - | Auto 12/10/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 12/10/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 13/02/2014 118896 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 5/01/2011 340240 | (MyWiFiDHCPDNS) . (...) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 5/09/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 13/12/2012 12288 | (Autodesk Content Service) . (.Autodesk, Inc..) - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe SR - | Auto 5/01/2011 1515792 | (EvtEng) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe SR - | Auto 5/11/2010 13336 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe SR - | Auto 1/02/2011 326168 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe SR - | Auto 4/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe SR - | Auto 4/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe SR - | Auto 23/10/2013 23808 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe SR - | Auto 27/08/2013 14997280 | (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe SR - | Auto 12/09/2013 920864 | (NVSvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SR - | Auto 27/08/2013 2155296 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe SR - | Auto 5/01/2011 836880 | (RegSrvc) . (.Intel® Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe SR - | Demand 27/01/2014 571816 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe SR - | Auto 1/02/2011 2656280 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 09s ---\\ Onderzoek gelijktijdige op de Master Boot Record (MBR) (O80) Run by Gebruiker at 18/02/2014 21:36:01 ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn 00s ---\\ Onderzoek de Master Boot Record op Infecties (MBRCheck) (O80) Written by ad13, http://ad13.geekstog Run by Gebruiker at 18/02/2014 21:36:03 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Extra scan (O88) Database Version : 13031 - (17/02/2014) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Additionnel Scan: 305863 Items scanned in 00mn 15s ~ 1781 Legitimates filtered by white list End of the scan (470 lines in 01mn 17s)(0)
  10. # AdwCleaner v3.019 - Report created 17/02/2014 at 21:06:42 # Updated 17/02/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Gebruiker - JFKPC # Running from : C:\Users\Gebruiker\Downloads\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\Gebruiker\AppData\Local\torch Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866} ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v27.0.1 (nl) [ File : C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\prefs.js ] -\\ Google Chrome v32.0.1700.107 [ File : C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2075 octets] - [17/02/2014 21:06:11] AdwCleaner[s0].txt - [1919 octets] - [17/02/2014 21:06:42] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [1979 octets] ########## - - - Updated - - - goeie avond, ik heb even verschillende sites gebruikt (youtube, facebook, wiki,...) en ik heb geen last meer van ongewenste reclame en de snelheid is ook een stuk beter moet ik nog iets doen?
  11. Zoek.exe v5.0.0.0 Updated 31-January-2014 Tool run by Gebruiker on ma 17/02/2014 at 18:20:26,11. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Gebruiker\Downloads\zoek(1).exe [scan all users] [script inserted] ==== Older Logs ====================== C:\zoek-results2014-02-16-163900.log 41572 bytes ==== Creating Sample_20141702_1827.zip ====================== Process firefox.exe killed Copied folder C:\ProgramData\d623474cadbdb5bc to sample\d623474cadbdb5bc sample\d623474cadbdb5bc\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D} renamed to E1F3EEF95A062FE793C1842FD75EC992 sample\d623474cadbdb5bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} renamed to D83742A60AD3586F870B57FE61FBAF7A sample\d623474cadbdb5bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} renamed to 45951911D041D7C3FB5A9C1A287B1104 sample\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866} renamed to 752CF7654F41E4D23F83AE7EF81D79E0 sample\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}.old renamed to 2AD2D670448000F59E492006E7F9654E sample\d623474cadbdb5bc\{CF830981-8F31-C561-C7A0-FE2CE1878B40} renamed to 31AB29079E9020B1616E4426E85A2DF7 sample\d623474cadbdb5bc\{E32743D3-5789-6E4F-3998-06FB87C9214B} renamed to 75BF8281F20D2B84DB245E342B1888FC C:\Users\Public\Desktop\sample_20141702_1827.zip created successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default user.js not found ---- Lines enabledAddons" modified from prefs.js ---- user_pref("extensions.enabledAddons", "%7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:22.3,weidunewtab%40gmail.com:4.5.2,%7B972ce4c6-7e08-4474-a285-320819 ---- Lines installCache" modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program ---- FireFox user.js and prefs.js backups ---- prefs_20141702_1828_.backup ==== Deleting Files \ Folders ====================== C:\Users\Gebruiker\AppData\LocalLow\{2182D8A2-AC21-33EE-2CB9-4F93B82C4B7D} deleted C:\Users\Gebruiker\AppData\LocalLow\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted C:\Users\Gebruiker\AppData\Local\Packages\windows_ie_ac_001\AC\{2182D8A2-AC21-33EE-2CB9-4F93B82C4B7D} deleted C:\Users\Gebruiker\AppData\Local\Packages\windows_ie_ac_001\AC\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted C:\ProgramData\YoutubeAdblocker deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\ProgramData\InstallMate deleted C:\ProgramData\SummerSoft deleted C:\Users\Gebruiker\AppData\Local\cache deleted C:\Users\Gebruiker\Downloads\FreeYouTubeToMP3Converter.exe deleted C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\firefox@ghostery.com.xpi deleted C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\jetpack deleted "C:\ProgramData\d623474cadbdb5bc\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D}" deleted "C:\ProgramData\d623474cadbdb5bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted "C:\ProgramData\d623474cadbdb5bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}" deleted "C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}" deleted "C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}.old" deleted "C:\ProgramData\d623474cadbdb5bc\{CF830981-8F31-C561-C7A0-FE2CE1878B40}" deleted "C:\ProgramData\d623474cadbdb5bc\{E32743D3-5789-6E4F-3998-06FB87C9214B}" deleted "C:\ProgramData\d623474cadbdb5bc\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D}" deleted "C:\ProgramData\d623474cadbdb5bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted "C:\ProgramData\d623474cadbdb5bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}" deleted "C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}" deleted "C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}.old" deleted "C:\ProgramData\d623474cadbdb5bc\{CF830981-8F31-C561-C7A0-FE2CE1878B40}" deleted "C:\ProgramData\d623474cadbdb5bc\{E32743D3-5789-6E4F-3998-06FB87C9214B}" deleted "C:\ProgramData\d623474cadbdb5bc" deleted "C:\ProgramData\d623474cadbdb5bc" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [09/02/2014 21:31] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default - New Tab Plus - %ProfilePath%\extensions\weidunewtab@gmail.com - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Facebook Phishing Protector - %ProfilePath%\extensions\{023e9ca0-63f3-47b1-bcb2-9badf9d9ef28}.xpi - HootBar - %ProfilePath%\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}.xpi - YouTube High Definition - %ProfilePath%\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default FD6ACD9D85177259D442A0C4AC15F7B8 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll - Shockwave Flash FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Gebruiker\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin C2321043FA2CA4C32FF449DE6116B5D9 - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll - Shockwave for Director / Shockwave for Director AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 0C0C5C207121C7A78414A8250E8E099A - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chrome Look ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[30/12/2013 13:51] YTBoookeMarKa - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aemfppeeeldcpnhhnamjplmjjeblkeib Angry Birds - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj Theme Creator - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc YTBoookeMarKa - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd Lamborghini Sesto Elemento Theme - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dappigdjllcnkkoacaoolciaolaaiemb YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm AdBlock - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom WeBsave - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Digital Clock Widget [ANTP] - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikimcdcgajipgcoehakmgloecbaacmoj Best Flash Save - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma Smartschool - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjelhjjeiplbdlimhklicdkffchjcldo Booktrack - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidknbkmfcapkiepmhchinffchkjglog Awesome New Tab Page\u2122 - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg Instagram for Chrome - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb YTBoookeMarKa - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma ==== Chrome Fix ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fdmflapemlimcdfalpdeedlblljmggjm_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fdmflapemlimcdfalpdeedlblljmggjm_0.localstorage-journal deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fdmflapemlimcdfalpdeedlblljmggjm deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hcddigdgleeplimnncapfcfmmfndfbbg_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hcddigdgleeplimnncapfcfmmfndfbbg_0.localstorage-journal deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcddigdgleeplimnncapfcfmmfndfbbg deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gebruiker\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\UpdatusUser\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jemlklgaibiijojffihnhieihhagocma_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jemlklgaibiijojffihnhieihhagocma_0.localstorage-journal deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aemfppeeeldcpnhhnamjplmjjeblkeib deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aemfppeeeldcpnhhnamjplmjjeblkeib_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aemfppeeeldcpnhhnamjplmjjeblkeib_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.jfk.be/start" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.jfk.be/start" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_CLASSES_ROOT\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A5BFF1F2-764B-DA60-C483-C0BA8CF24923} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D54D3FD5-C849-72CC-8315-757A2E9AA83C} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF830981-8F31-C561-C7A0-FE2CE1878B40} deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\beid deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Gebruiker\AppData\Local\Mozilla\Firefox\Profiles\uj8d4v3m.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=674 folders=226 58858985 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\Gebruiker\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun-B1-53C9D589-6B66-4F30-9BAB-9A0193B0BAFC.lock" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found ==== EOF on ma 17/02/2014 at 18:33:16,10 ====================== - - - Updated - - - http://www.mijnbestand.nl/Bestand-DDRH8JFJMZCK.zip
  12. Zoek.exe v5.0.0.0 Updated 15-February-2014 Tool run by Gebruiker on zo 16/02/2014 at 17:35:30,14. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== 16/02/2014 17:36:37 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Files \ Folders ====================== C:\ProgramData\greatsaver deleted ==== Files Found In C:\ProgramData\d623474cadbdb5bc ====================== 2014-02-02 11:01:41 36890 ----a-w- E1F3EEF95A062FE793C1842FD75EC992 C:\ProgramData\d623474cadbdb5bc\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D} 2014-02-02 11:02:01 38530 ----a-w- D83742A60AD3586F870B57FE61FBAF7A C:\ProgramData\d623474cadbdb5bc\{4820778D-AB0D-6D18-C316-52A6A0E1D507} 2014-02-02 11:02:06 30102 ----a-w- 75BF8281F20D2B84DB245E342B1888FC C:\ProgramData\d623474cadbdb5bc\{E32743D3-5789-6E4F-3998-06FB87C9214B} 2014-02-02 11:02:11 30102 ----a-w- 45951911D041D7C3FB5A9C1A287B1104 C:\ProgramData\d623474cadbdb5bc\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} 2014-02-02 11:02:15 2970 ----a-w- 31AB29079E9020B1616E4426E85A2DF7 C:\ProgramData\d623474cadbdb5bc\{CF830981-8F31-C561-C7A0-FE2CE1878B40} 2014-02-02 14:25:21 2754 ----a-w- 2AD2D670448000F59E492006E7F9654E C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866}.old 2014-02-02 14:25:21 918 ----a-w- 752CF7654F41E4D23F83AE7EF81D79E0 C:\ProgramData\d623474cadbdb5bc\{CA41BB14-E67B-1653-C57B-5CA99418A866} ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-02-14 22:40:42 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-02-14 22:40:19 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-02-14 22:40:19 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-02-14 22:40:19 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-02-14 22:40:18 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-02-14 22:40:18 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-02-14 22:40:17 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-14 22:40:17 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-02-14 22:40:17 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-14 22:40:17 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-02-14 22:40:16 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-02-14 22:40:16 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-02-14 22:40:16 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-02-14 22:40:15 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-02-14 22:40:15 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-02-14 22:40:15 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-02-14 22:40:14 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-02-14 22:40:13 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-02-14 22:40:13 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-02-14 22:07:39 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\SysWOW64\locale.nls 2014-02-14 22:07:39 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-02-14 22:07:39 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll 2014-02-14 22:07:36 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-14 22:07:36 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe 2014-02-14 22:07:36 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-14 22:07:35 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 ----a-w- C:\Windows\SysWOW64\secproc_isv.dll 2014-02-14 22:07:35 7FA485555BF802FE3DB5598004DBDFAC 390144 ----a-w- C:\Windows\SysWOW64\msdrm.dll 2014-02-14 22:07:35 12A9F24DC9F465DA79AC2272D829A81E 428032 ----a-w- C:\Windows\SysWOW64\secproc.dll 2014-02-14 22:07:35 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-14 22:07:34 9158DBE2F8483434FC72F320690C9DB8 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-14 22:07:34 58712A48D31B40EBCB35B47205F87771 87040 ----a-w- C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-14 22:07:33 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll 2014-02-14 22:07:33 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-02-14 22:40:42 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-02-14 22:40:19 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-02-14 22:40:19 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-02-14 22:40:19 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-02-14 22:40:18 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-02-14 22:40:18 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-02-14 22:40:18 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-02-14 22:40:18 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-02-14 22:40:18 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-02-14 22:40:17 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-02-14 22:40:17 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-02-14 22:40:17 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-02-14 22:40:17 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-02-14 22:40:17 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-02-14 22:40:16 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-02-14 22:40:16 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-02-14 22:40:16 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-02-14 22:40:15 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-02-14 22:40:15 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-02-14 22:40:15 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-02-14 22:40:14 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-02-14 22:40:12 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-02-14 22:07:39 EA093130471090037BB70A4AF86FAD1B 420008 ----a-w- C:\Windows\Sysnative\locale.nls 2014-02-14 22:07:39 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll 2014-02-14 22:07:39 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-02-14 22:07:36 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\Sysnative\RMActivate.exe 2014-02-14 22:07:36 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\Sysnative\RMActivate_isv.exe 2014-02-14 22:07:35 DC6DD779F35BB42E2E76FDFEC565C251 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll 2014-02-14 22:07:35 C6AC2C91541D24F9E236A670C0CA793D 528384 ----a-w- C:\Windows\Sysnative\msdrm.dll 2014-02-14 22:07:35 B41B1FEDEBBD955B4E25676B42087885 123392 ----a-w- C:\Windows\Sysnative\secproc_ssp.dll 2014-02-14 22:07:35 5693212AB2EBCACBBE05EC3A642113E2 485888 ----a-w- C:\Windows\Sysnative\secproc_isv.dll 2014-02-14 22:07:35 399FC1B75790EE606A6FD9F2FB4C891C 488448 ----a-w- C:\Windows\Sysnative\secproc.dll 2014-02-14 22:07:35 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe 2014-02-14 22:07:35 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\Sysnative\RMActivate_ssp.exe 2014-02-14 22:07:33 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll 2014-02-14 22:07:33 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll ====== C:\Windows\Sysnative\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2014-02-16 09:54:27 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2014-02-02 11:02:01 -------- d-----w- C:\Users\Gebruiker\AppData\Locallow\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} 2014-02-02 11:01:49 -------- d-----w- C:\Users\Gebruiker\AppData\Locallow\{2182D8A2-AC21-33EE-2CB9-4F93B82C4B7D} 2014-02-02 11:01:49 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Packages 2014-02-02 11:01:40 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Torch 2014-02-02 11:01:40 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Google 2014-02-02 11:01:40 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Comodo 2014-02-02 11:01:40 -------- d-----w- C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-02-02 11:01:40 -------- d-----w- C:\Users\HomeGroupUser$\AppData\Local\Google 2014-02-02 11:01:40 -------- d-----w- C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Torch 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Comodo 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gast\AppData\Local\Torch 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gast\AppData\Local\Google 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gast\AppData\Local\Comodo 2014-02-02 11:01:40 -------- d-----w- C:\Users\Administrator\AppData\Local\Torch 2014-02-02 11:01:40 -------- d-----w- C:\Users\Administrator\AppData\Local\Google 2014-02-02 11:01:40 -------- d-----w- C:\Users\Administrator\AppData\Local\Comodo 2014-01-31 10:38:15 -------- d-----w- C:\Users\Gebruiker\AppData\Local\ElevatedDiagnostics ====== C:\Users\Gebruiker ====== 2014-02-16 09:53:36 10EA446EBB0F48D9D4BD1BD2631D7ADF 283064 ----a-w- C:\Users\Gebruiker\Downloads\Firefox Setup Stub 27.0.1.exe 2014-02-15 13:36:26 68B2BBDC51AA80CE98C3B1BC137C6E6B 5845848 ----a-w- C:\Users\Gebruiker\Downloads\BALE_Kuhn_LSB1290iD.exe 2014-02-09 20:29:51 41FA458935B4BAE373799E2918249CC4 34012056 ----a-w- C:\Users\Gebruiker\Downloads\FreeYouTubeToMP3Converter.exe 2014-02-02 20:01:37 4873C218B649867D57439AAFA8FAB969 31898240 ----a-w- C:\Users\Gebruiker\Downloads\UnimogU1200_U1600.exe 2014-02-02 20:01:18 4A6175ACE88F201D2BE26794884E7B16 9098576 ----a-w- C:\Users\Gebruiker\Downloads\claasquantum3800_v1_2.exe 2014-02-02 20:00:51 74C71CE664C24FAB9F4BB28DAD82EC82 1874768 ----a-w- C:\Users\Gebruiker\Downloads\LizardBaleForks.exe 2014-02-02 20:00:25 CF179C5D292D98F088CCC1743ACA3FE2 1464600 ----a-w- C:\Users\Gebruiker\Downloads\ZeppelinTanker.exe 2014-02-02 11:02:15 02C1EE40968BAA67C3A785CDA9807125 262 --sha-r- C:\ProgramData\ntuser.pol 2014-02-02 11:02:01 -------- d-----w- C:\ProgramData\YoutubeAdblocker 2014-02-02 11:01:41 -------- d-----w- C:\ProgramData\d623474cadbdb5bc 2014-02-02 11:01:40 -------- d-----w- C:\Users\HomeGroupUser$\AppData 2014-02-02 11:01:40 -------- d-----w- C:\Users\Gast\AppData 2014-02-02 11:01:40 -------- d-----w- C:\Users\Administrator\AppData ====== C: exe-files == 2014-02-16 09:54:27 FC558F42CA98DAB4465263FDE812A5B2 106212 ----a-w- C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe 2014-02-16 09:54:27 338037EFA0E8E8699B2667D57B751574 118896 ----a-w- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2014-02-16 09:53:36 10EA446EBB0F48D9D4BD1BD2631D7ADF 283064 ----a-w- C:\Users\Gebruiker\Downloads\Firefox Setup Stub 27.0.1.exe 2014-02-15 22:33:18 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe 2014-02-15 22:33:18 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateBroker.exe 2014-02-15 22:33:17 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdateSetup.exe 2014-02-15 22:33:10 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe 2014-02-15 22:33:10 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe 2014-02-15 22:33:09 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleUpdate.exe 2014-02-15 22:33:02 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe 2014-02-15 13:36:26 68B2BBDC51AA80CE98C3B1BC137C6E6B 5845848 ----a-w- C:\Users\Gebruiker\Downloads\BALE_Kuhn_LSB1290iD.exe 2014-02-14 22:40:18 9E8F9FDD407DDE997965EEFD9E635CCF 469504 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-02-14 22:40:18 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-02-14 22:40:17 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-02-14 22:40:17 AFAB9B381886ABE3490689B7633A858F 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-02-14 22:40:17 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-14 22:40:17 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-02-14 22:40:15 C6E1178294BDEAB1CACF50427688DF05 806104 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-02-14 22:40:15 4263F6C131E513CEA1AE82B5B81A4E1A 808152 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-02-14 22:07:36 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 ----a-w- C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-14 22:07:36 6142C5540C8D2764D59CBC11AF4A5900 572416 ----a-w- C:\Windows\SysWOW64\RMActivate.exe 2014-02-14 22:07:36 1B3741488AA7E237961A29D1E7A44C0A 626176 ----a-w- C:\Windows\System32\RMActivate.exe 2014-02-14 22:07:36 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe 2014-02-14 22:07:36 0F5FEF37588AF457E02125674F171A4F 508928 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-14 22:07:35 297926B15AE5390409F1007EB28A8EFB 552960 ----a-w- C:\Windows\System32\RMActivate_ssp_isv.exe 2014-02-14 22:07:35 08D323750350A8A29611D1004C0CF319 510976 ----a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-14 22:07:35 03F8F411F118CFDA508E77C747BB05EA 553984 ----a-w- C:\Windows\System32\RMActivate_ssp.exe 2014-02-14 22:03:17 19129245B9E945D834EF1FA57E5BD9CE 365432 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\000057ef\updatus.17846624_RUNASUSER.exe 2014-02-14 22:02:54 B0AB350E3E98C7FB1E4930F762D0477B 3273016 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\000057eb\DAO.17845377.exe 2014-02-11 20:45:24 7210E1DFEA4684431D432E4B0253EFFC 365160 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\000057d6\updatus.17831829_RUNASUSER.exe 2014-02-11 20:45:12 69BAC259A78561327ECFDE108BB5B686 3241056 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\000057d2\DAO.17829829.exe 2014-02-09 20:31:14 5FF9180745C75997ABB2B28A2413D94C 1176256 ----a-w- C:\Program Files (x86)\DVDVideoSoft\unins000.exe 2014-02-09 20:29:51 41FA458935B4BAE373799E2918249CC4 34012056 ----a-w- C:\Users\Gebruiker\Downloads\FreeYouTubeToMP3Converter.exe === C: other files == 2014-02-16 10:28:46 F08773939AAF28CB6CC5C8E9E3FCC982 61649 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi 2014-02-16 10:15:41 1E089762E8DE0925A6DD57963588FFD2 86000 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\{023e9ca0-63f3-47b1-bcb2-9badf9d9ef28}.xpi 2014-02-16 10:13:39 B9A96987C4F24F89A5CF29B6CAFFDF75 1388203 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\firefox@ghostery.com.xpi 2014-02-16 10:06:56 D155D78222E3A7E87599455AC146D235 156036 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}.xpi 2014-02-16 09:55:27 0EE1FF417D59B4F60467D19F76D0B896 940775 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 2014-02-09 20:31:15 DB748C7DBA6F6518D82015FF24EEB51D 104045 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx 2014-02-09 20:31:15 9ECF2401CDB89BC76482E4E7C1ACD392 41015 ----a-w- C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Akamai NetSession Interface"="C:\Users\Gebruiker\AppData\Local\Akamai\netsession_win.exe" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "Facebook Update"="C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" [HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1002\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" "THX Audio Control Panel"="C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe /r" "NUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Akamai NetSession Interface"="C:\Users\Gebruiker\AppData\Local\Akamai\netsession_win.exe" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "Facebook Update"="C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="c:\\windows\\syswow64\\nvinit.dll " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "THXCfg64"="C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64" "IntelWireless"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe /tf Intel Wireless Tray" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\beid] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="beid" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Belgium Identity Card\\beid35gui.exe\" /startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdReg] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="UpdReg" "hkey"="HKLM" "command"="C:\\Windows\\UpdReg.EXE" ==== Startup Folders ====================== 2013-12-08 12:10:57 2151 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ACR Launcher.lnk 2013-12-01 15:39:19 1050 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [05/02/2014 16:04] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-52792044-1074444535-1282596425-1000Core.job --a------ C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe [17/12/2013 15:25] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-52792044-1074444535-1282596425-1000UA.job --a------ C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe [17/12/2013 15:25] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12/10/2013 15:41] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12/10/2013 15:41] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-52792044-1074444535-1282596425-1000Core" [C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-52792044-1074444535-1282596425-1000UA" [C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [09/02/2014 21:31] ==== Firefox Extensions ====================== ProfilePath: C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default - New Tab Plus - %ProfilePath%\extensions\weidunewtab@gmail.com - ColorfulTabs - %ProfilePath%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} - Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi - Facebook Phishing Protector - %ProfilePath%\extensions\{023e9ca0-63f3-47b1-bcb2-9badf9d9ef28}.xpi - HootBar - %ProfilePath%\extensions\{1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}.xpi - YouTube High Definition - %ProfilePath%\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\uj8d4v3m.default FD6ACD9D85177259D442A0C4AC15F7B8 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll - Shockwave Flash FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Gebruiker\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin C2321043FA2CA4C32FF449DE6116B5D9 - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll - Shockwave for Director / Shockwave for Director AF661355EBAB898EB92D5454AEF93CE0 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43 0C0C5C207121C7A78414A8250E8E099A - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chrome Look ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[30/12/2013 13:51] YTBoookeMarKa - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Administrator\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Administrator\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Administrator\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gast\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gast\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gast\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gast\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gebruiker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aemfppeeeldcpnhhnamjplmjjeblkeib Angry Birds - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj Theme Creator - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc Google Docs - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo YTBoookeMarKa - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd Google Search - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Lamborghini Sesto Elemento Theme - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dappigdjllcnkkoacaoolciaolaaiemb WGT Golf Challenge - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg Google - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm AdBlock - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom WeBsave - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Digital Clock Widget [ANTP] - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikimcdcgajipgcoehakmgloecbaacmoj Best Flash Save - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma Office - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgoncnaabanepilgbggijndebemabhhf Smartschool - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjelhjjeiplbdlimhklicdkffchjcldo Booktrack - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidknbkmfcapkiepmhchinffchkjglog Awesome New Tab Page\u2122 - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg DVDVideoSoft - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Google Wallet - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Background Tab - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic Battlefield Play4Free - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh Instagram for Chrome - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb Gmail - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia YTBoookeMarKa - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - Gebruiker\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma YTBoookeMarKa - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\cfkknfplhadfilobfaojdlnmmpcfbacd YoutubeAdblocker - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\fdmflapemlimcdfalpdeedlblljmggjm WeBsave - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\hcddigdgleeplimnncapfcfmmfndfbbg Best Flash Save - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma ==== IE Start and Search Settings ====================== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.jfk.be/start" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_USERS\S-1-5-21-52792044-1074444535-1282596425-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_CLASSES_ROOT\CLSID\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB101D49-D961-B6CA-2F05-7EE111D47B2E} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1 folders=1 61 bytes) ==== EOF on zo 16/02/2014 at 17:39:00,86 ======================
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.