Ga naar inhoud

Lau951

Lid
  • Items

    19
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door Lau951

  1. Nee, sorry de volgende is deze:

    Zoek.exe Version 4.0.0.5 Updated 26-October-2013

    Tool run by SYSTEM on ma 25/11/2013 at 18:40:14,72.

    Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86

    Running in: Safe Mode MINIMAL No Internet Access Detected

    Launched: C:\Windows\system32\config\systemprofile\Desktop\zoek.exe [script inserted]

    ==== Older Logs ======================

    \zoek-results2013-11-24-211730.log 16909 bytes

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Services ======================

    ==== Deleting Files \ Folders ======================

    "C:\Windows\system32\config\systemprofile\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" deleted

    "C:\cac4c9e88088a2c9042df8\MRT.exe" deleted

    "C:\cac4c9e88088a2c9042df8\$shtdwn$.req" not deleted

    ==== Folders Found In C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iOrgSoft ======================

    2013-11-04 12:00:05 d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iOrgSoft\Video Converter

    ==== Folders Found In C:\\Program Files\iOrgSoft ======================

    2013-11-04 11:59:57 d-----w- C:\\Program Files\iOrgSoft\Video Converter

    ==== Firefox Extensions Registry ======================

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]

    "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [10/09/2011 09:00]

    ==== Set IE to Default ======================

    Old Values:

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

    No DefaultScope Set For HKCU

    New Values:

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully

    ==== Deleting Registry Keys ======================

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core deleted successfully

    ==== Empty IE Cache ======================

    C:\\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Users\Laura\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Users\TEMP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    No FireFox Profiles found

    ==== Empty Chrome Cache ======================

    No Chrome User Data found

    ==== Empty All Flash Cache ======================

    No Flash Cache Found

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Windows\system32\config\SYSTEM~1\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\cac4c9e88088a2c9042df8\$shtdwn$.req" not found

    "C:\\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

    "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

    "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

    ==== EOF on ma 25/11/2013 at 20:42:13,19 ======================

  2. Voilà, hier is de volgende:

    Zoek.exeVersion 4.0.0.5 Updated 26-October-2013

    Tool run bySYSTEM on ma 25/11/2013 at 18:40:14,72.

    Microsoft®Windows Vista™ Home Premium 6.0.6002Service Pack 2 x86

    Running in:Safe Mode MINIMAL No Internet Access Detected

    Launched:C:\Windows\system32\config\systemprofile\Desktop\zoek.exe [script inserted]

    ==== Older Logs ======================

    \zoek-results2013-11-24-211730.log 16909 bytes

  3. 't is toevallig dit niet?

    Zoek.exe Version 4.0.0.5 Updated 14-November-2013

    Tool run by SYSTEM on zo 24/11/2013 at 21:55:38,69.

    Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86

    Running in: Safe Mode MINIMAL No Internet Access Detected

    Launched: C:\Windows\system32\config\systemprofile\Desktop\zoek.scr [script inserted] [Checkboxes used]

    ==== System Restore Info ======================

    ==== Reset Hosts File ======================

    # Copyright © 1993-2006 Microsoft Corp.

    #

    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.

    #

    # This file contains the mappings of IP addresses to host names. Each

    # entry should be kept on an individual line. The IP address should

    # be placed in the first column followed by the corresponding host name.

    # The IP address and the host name should be separated by at least one

    # space.

    #

    # Additionally, comments (such as these) may be inserted on individual

    # lines or following the machine name denoted by a '#' symbol.

    #

    # For example:

    #

    # 102.54.94.97 rhino.acme.com # source server

    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost

    ::1 localhost

    ==== Empty Folders Check ======================

    C:\Program Files\GAMESVOORIEDEREEN.NL deleted successfully

    C:\Program Files\MSXML 4.0 deleted successfully

    C:\Program Files\Origin Games deleted successfully

    C:\Program Files\OXXOGames deleted successfully

    C:\Program Files\trend micro deleted successfully

    C:\Program Files\Zylom Games deleted successfully

    C:\ProgramData\Big Fish Games deleted successfully

    C:\ProgramData\CanonEPP deleted successfully

    C:\ProgramData\CanonIJEPPEX2 deleted successfully

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Services ======================

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater15.4.0 deleted successfully

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\vToolbarUpdater15.4.0 deleted successfully

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater17.1.2 deleted successfully

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\vToolbarUpdater17.1.2 deleted successfully

    ==== Registry Fix Code ======================

    Windows Registry Editor Version 5.00

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    ==== Deleting Files \ Folders ======================

    C:\Program Files\MyFree Codec deleted

    C:\Program Files\AVG Secure Search deleted

    C:\Program Files\Common Files\AVG Secure Search deleted

    C:\ProgramData\AVG Secure Search deleted

    C:\ProgramData\Trymedia deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec deleted

    C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted

    C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job deleted

    C:\Windows\system32\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv deleted

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    2013-11-20 16:13:17 D051B721BCC7C839A61FB2E5EAC06C86 219011509 ----a-w- C:\Windows\MEMORY.DMP

    ====== C:\Windows\system32\config\SYSTEM~1\AppData\Local\Temp ====

    ====== Java Cache =====

    ====== C:\Windows\system32 =====

    2013-11-16 15:29:42 B798365F54AF889BFD7D04ED75C016B7 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

    2013-11-16 15:29:42 3CC9655434741363AF977498A2B5E425 73216 ----a-w- C:\Windows\System32\mshtmled.dll

    2013-11-16 15:29:40 677857FAC307E46E44F710B6C6F84607 420864 ----a-w- C:\Windows\System32\vbscript.dll

    2013-11-16 15:29:37 E26C86DE3AC36D09D201691B9D482D5B 176640 ----a-w- C:\Windows\System32\ieui.dll

    2013-11-16 15:29:37 375652E4B01E421683437896DA8D76C4 65024 ----a-w- C:\Windows\System32\jsproxy.dll

    2013-11-16 15:29:36 E2E9F49C84C49C2DB5ADAF85D8CD8F1C 142848 ----a-w- C:\Windows\System32\ieUnatt.exe

    2013-11-16 15:29:35 E1092FB18A2D53DFC20D2EA8AC158E4B 607744 ----a-w- C:\Windows\System32\msfeeds.dll

    2013-11-16 15:29:34 C36E38AD3C7FAFF0E30C4CBCB28CE7FB 1129472 ----a-w- C:\Windows\System32\wininet.dll

    2013-11-16 15:29:32 FFA200640B887CBB737DA74C299BCE62 717824 ----a-w- C:\Windows\System32\jscript.dll

    2013-11-16 15:29:30 D36137E26569D22B6C395EB68CBE0018 1806848 ----a-w- C:\Windows\System32\jscript9.dll

    2013-11-16 15:29:30 26ED02FA7B11FBFD87D4FF304EFFFFBF 231936 ----a-w- C:\Windows\System32\url.dll

    2013-11-16 15:29:29 58C300DB5ED80A46A778DECB9D02DA57 1796096 ----a-w- C:\Windows\System32\iertutil.dll

    2013-11-16 15:29:26 B8D440F705D52D9167C572ECF6522E89 1104896 ----a-w- C:\Windows\System32\urlmon.dll

    2013-11-16 15:29:26 AB3F4974C87DC6DE7E427CF713E88B28 1427968 ----a-w- C:\Windows\System32\inetcpl.cpl

    2013-11-16 15:29:20 048FF8515CE100990423E96678112CDF 9739264 ----a-w- C:\Windows\System32\ieframe.dll

    2013-11-16 15:29:18 AC986A1AD35CDBF07B0E5D1AC9D527B5 12344832 ----a-w- C:\Windows\System32\mshtml.dll

    2013-11-14 19:27:12 872363237F24BCB03D73E2A3B4FBF38D 297984 ----a-w- C:\Windows\System32\gdi32.dll

    2013-11-14 19:27:03 0317420D419E1885894B3ED9D375D245 993792 ----a-w- C:\Windows\System32\crypt32.dll

    2013-11-14 19:26:44 EE16F3E01C4A6C77383F1BBBD10AD6C2 596480 ----a-w- C:\Windows\System32\FWPUCLNT.DLL

    2013-11-14 19:26:44 4687EE0C0DD2CE5F7AAA9C2E33C1DC78 444928 ----a-w- C:\Windows\System32\IKEEXT.DLL

    2013-11-14 19:26:44 14D9A057A082E00116A7A4415051D07C 218228 ----a-w- C:\Windows\System32\WFP.TMF

    ====== C:\Windows\system32\drivers =====

    ====== C:\Windows\Tasks ======

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    2013-11-04 11:59:57 -------- d-----w- C:\Program Files\iOrgSoft

    2013-10-29 13:09:27 -------- d-----w- C:\Program Files\E.M. PowerPoint Video Converter

    ======= =====

    ====== ======

    2013-11-22 16:21:50 42520DC49652D0F0EEF5F102F0296D0D 4608 ----a-w- C:\Windows\system32\config\systemprofile\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    2013-11-22 16:10:28 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Adobe

    2013-11-22 16:10:27 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe

    2013-11-22 15:44:31 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Temp

    ====== C:\Windows\system32\config\systemprofile ======

    2013-11-23 18:40:44 ED09CD34C33E64AECDDEC28B14BB1E3A 34447 ----a-w- C:\\rsit\info.txt

    2013-11-22 15:45:14 -------- d-----r- C:\Windows\system32\config\systemprofile\Favorites

    2013-11-22 15:44:31 -------- d-----r- C:\Windows\system32\config\systemprofile\Desktop

    2013-11-22 15:22:46 -------- d-----w- C:\\Users\TEMP

    2013-11-20 16:13:17 D051B721BCC7C839A61FB2E5EAC06C86 219011509 ----a-w- C:\\Windows\MEMORY.DMP

    2013-11-16 15:29:42 3CC9655434741363AF977498A2B5E425 73216 ----a-w- C:\\Windows\System32\mshtmled.dll

    2013-11-16 15:29:40 677857FAC307E46E44F710B6C6F84607 420864 ----a-w- C:\\Windows\System32\vbscript.dll

    2013-11-16 15:29:40 1EBB9D33648776F54450680EC5B9BAAB 149744 ----a-w- C:\\Program Files\Internet Explorer\sqmapi.dll

    2013-11-16 15:29:38 C1B9701790C21E12AE30667BE8A166FA 194560 ----a-w- C:\\Program Files\Internet Explorer\IEShims.dll

    2013-11-16 15:29:37 E26C86DE3AC36D09D201691B9D482D5B 176640 ----a-w- C:\\Windows\System32\ieui.dll

    2013-11-16 15:29:37 375652E4B01E421683437896DA8D76C4 65024 ----a-w- C:\\Windows\System32\jsproxy.dll

    2013-11-16 15:29:36 E2E9F49C84C49C2DB5ADAF85D8CD8F1C 142848 ----a-w- C:\\Windows\System32\ieUnatt.exe

    2013-11-16 15:29:35 E1092FB18A2D53DFC20D2EA8AC158E4B 607744 ----a-w- C:\\Windows\System32\msfeeds.dll

    2013-11-16 15:29:34 C36E38AD3C7FAFF0E30C4CBCB28CE7FB 1129472 ----a-w- C:\\Windows\System32\wininet.dll

    2013-11-16 15:29:34 6935E5E45A2A93B5EB5D2EBDA0E444B6 194560 ----a-w- C:\\Program Files\Internet Explorer\ieproxy.dll

    2013-11-16 15:29:32 FFA200640B887CBB737DA74C299BCE62 717824 ----a-w- C:\\Windows\System32\jscript.dll

    2013-11-16 15:29:30 D36137E26569D22B6C395EB68CBE0018 1806848 ----a-w- C:\\Windows\System32\jscript9.dll

    2013-11-16 15:29:30 26ED02FA7B11FBFD87D4FF304EFFFFBF 231936 ----a-w- C:\\Windows\System32\url.dll

    2013-11-16 15:29:30 06085B62BC7E0C8E2605CEA38774D956 757488 ----a-w- C:\\Program Files\Internet Explorer\iexplore.exe

    2013-11-16 15:29:29 58C300DB5ED80A46A778DECB9D02DA57 1796096 ----a-w- C:\\Windows\System32\iertutil.dll

    2013-11-16 15:29:28 FD76B69D16DEC2960579837B2C0CBF5A 387584 ----a-w- C:\\Program Files\Internet Explorer\jsdbgui.dll

    2013-11-16 15:29:28 EF3C68E5C2327692E97953AA5AB774CF 104448 ----a-w- C:\\Program Files\Internet Explorer\jsdebuggeride.dll

    2013-11-16 15:29:26 EA7048B9AD68DD1483AC7686D0829FCC 678912 ----a-w- C:\\Program Files\Internet Explorer\iedvtool.dll

    2013-11-16 15:29:26 B8D440F705D52D9167C572ECF6522E89 1104896 ----a-w- C:\\Windows\System32\urlmon.dll

    2013-11-16 15:29:20 048FF8515CE100990423E96678112CDF 9739264 ----a-w- C:\\Windows\System32\ieframe.dll

    2013-11-16 15:29:18 AC986A1AD35CDBF07B0E5D1AC9D527B5 12344832 ----a-w- C:\\Windows\System32\mshtml.dll

    2013-11-16 15:21:51 -------- d-----w- C:\\Windows\pss

    2013-11-16 14:53:53 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\\cac4c9e88088a2c9042df8\MRT.exe

    2013-11-16 14:52:39 DF7119A5D3CAEDA80BF0FB6F8E53DE8F 788 ---ha-w- C:\\cac4c9e88088a2c9042df8\$shtdwn$.req

    2013-11-14 19:27:12 872363237F24BCB03D73E2A3B4FBF38D 297984 ----a-w- C:\\Windows\System32\gdi32.dll

    2013-11-14 19:27:03 0317420D419E1885894B3ED9D375D245 993792 ----a-w- C:\\Windows\System32\crypt32.dll

    2013-11-14 19:26:44 EE16F3E01C4A6C77383F1BBBD10AD6C2 596480 ----a-w- C:\\Windows\System32\FWPUCLNT.DLL

    2013-11-14 19:26:44 4687EE0C0DD2CE5F7AAA9C2E33C1DC78 444928 ----a-w- C:\\Windows\System32\IKEEXT.DLL

    2013-11-07 14:56:36 0AB5E20FD383D7FF0265C706E1AA99E3 4938294 ----a-w- C:\\cac4c9e88088a2c9042df8\mrt.exe._p

    2013-11-07 14:50:02 33AAC26B735F72DEEF920692A28FE796 89304 ----a-w- C:\\cac4c9e88088a2c9042df8\mrtstub.exe

    2013-11-04 12:00:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iOrgSoft

    2013-11-04 11:59:57 -------- d-----w- C:\\Program Files\iOrgSoft

    2013-11-01 13:52:47 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    2013-10-29 13:09:38 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\E.M. PowerPoint Video Converter

    2013-10-29 13:09:27 -------- d-----w- C:\\Program Files\E.M. PowerPoint Video Converter

    ====== C: exe-files ==

    2013-11-20 15:11:42 E714A26715478EAC94DEB4514BF68EA2 35300192 ----a-w- C:\Users\Laura\AppData\Local\Google\Update\Install\{28192936-A513-45AF-A8E5-439F6C259333}\31.0.1650.57_chrome_installer.exe

    2013-11-20 15:11:37 E714A26715478EAC94DEB4514BF68EA2 35300192 ----a-w- C:\Users\Laura\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.57\31.0.1650.57_chrome_installer.exe

    2013-11-18 15:19:23 1A7C91AC6F14EBB22688704A13DC8D17 12598112 ----a-w- C:\Users\Laura\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.57\31.0.1650.57_30.0.1599.101_chrome_updater.exe

    === C: other files ==

    ==== Startup Registry Enabled ======================

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

    "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

    "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide"

    "vProt"="C:\Program Files\AVG Secure Search\vprot.exe"

    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime"

    "Persistence"="C:\Windows\system32\igfxpers.exe"

    "KiesTrayAgent"="C:\Program Files\Samsung\Kies\KiesTrayAgent.exe"

    "IgfxTray"="C:\Windows\system32\igfxtray.exe"

    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe"

    "AVG_UI"="C:\Program Files\AVG\AVG2014\avgui.exe /TRAYONLY"

    "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"

    ==== Startup Registry Disabled ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Adobe ARM"

    "hkey"="HKLM"

    "command"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Adobe Reader Speed Launcher"

    "hkey"="HKLM"

    "command"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonMyPrinter]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="CanonMyPrinter"

    "hkey"="HKLM"

    "command"="C:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe /logon"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonSolutionMenuEx]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="CanonSolutionMenuEx"

    "hkey"="HKLM"

    "command"="C:\\Program Files\\Canon\\Solution Menu EX\\CNSEMAIN.EXE /logon"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EA Core]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="EA Core"

    "hkey"="HKCU"

    "command"="\"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe\" -silent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]

    "Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""

    "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

    "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\""

    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"

    "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [22/08/2013 11:01]

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [27/02/2013 16:54]

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [27/02/2013 16:54]

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000Core.job --a------ C:\Users\Laura\AppData\LoC:al\Google\Update\GoogleUpdate.exe []

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000UA.job --a------ C:\Users\Laura\AppData\Local\Google\Update\GoogleUpdate.exe [28/10/2011 16:46]

    ==== Other Scheduled Tasks ======================

    "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]

    "C:\Windows\system32\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe]

    "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe]

    "C:\Windows\system32\tasks\Google Updater and Installer" [C:\Users\Laura\AppData\Local\Google\Update\GoogleUpdate.exe]

    "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]

    "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]

    "C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000Core" [C:\Users\Laura\AppData\Local\Google\Update\GoogleUpdate.exe]

    "C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000UA" [C:\Users\Laura\AppData\Local\Google\Update\GoogleUpdate.exe]

    "C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe]

    "C:\Windows\system32\tasks\User_Feed_Synchronization-{5DCE6494-DC12-4BE0-9813-71640E5F7B99}" [C:\Windows\system32\msfeedssync.exe]

    "C:\Windows\system32\tasks\WebReg Deskjet F4100 series" [C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe]

    "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe]

    ==== Firefox Extensions Registry ======================

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]

    "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [10/09/2011 09:00]

  4. Oké, dit is de tweede:

    Logfile of random's system information tool 1.09 (written by random/random)

    Run by Laura at 2013-11-23 19:40:36

    Microsoft® Windows Vista™ Home Premium Service Pack 2

    System drive C: has 36 GB (24%) free of 151 GB

    Total RAM: 2038 MB (84% free)

    HijackThis download failed

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job

    C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000Core.job

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3677436180-1221689071-2926320938-1000UA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30 75232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]

    Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

    AVG Safe Search

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

    Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-09-24 329712]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

    Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    AVG Security Toolbar - C:\Program Files\AVG Secure Search\17.1.2.1\AVG Secure Search_toolbar.dll [2013-11-14 3353624]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]

    Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

    Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-09-24 59376]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]

    {95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\17.1.2.1\AVG Secure Search_toolbar.dll [2013-11-14 3353624]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

    "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]

    "vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2013-11-14 2420248]

    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]

    "Persistence"=C:\Windows\system32\igfxpers.exe [2009-10-02 150552]

    "KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2012-06-08 3521464]

    "IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-10-02 141848]

    "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-10-02 173592]

    "AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2013-10-07 4908592]

    "APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]

    "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]

    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-05-31 152392]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-11 919008]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-07-31 38872]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]

    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2516296]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]

    C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]

    C:\Program Files\Electronic Arts\EADM\Core.exe -silent []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]

    C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

    "dontdisplaylastusername"=0

    "legalnoticecaption"=

    "legalnoticetext"=

    "shutdownwithoutlogon"=1

    "undockwithoutlogon"=1

    "EnableUIADesktopToggle"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

    "BindDirectlyToPropertySetStorage"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

    "vidc.mrle"=msrle32.dll

    "vidc.msvc"=msvidc32.dll

    "msacm.imaadpcm"=imaadp32.acm

    "msacm.msg711"=msg711.acm

    "msacm.msgsm610"=msgsm32.acm

    "msacm.msadpcm"=msadp32.acm

    "midimapper"=midimap.dll

    "wavemapper"=msacm32.drv

    "vidc.uyvy"=msyuv.dll

    "vidc.yuy2"=msyuv.dll

    "vidc.yvyu"=msyuv.dll

    "vidc.iyuv"=iyuv_32.dll

    "vidc.i420"=iyuv_32.dll

    "vidc.yvu9"=tsbyuv.dll

    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm

    "vidc.cvid"=iccvid.dll

    "vidc.VP60"=C:\Windows\system32\vp6vfw.dll

    "vidc.VP61"=C:\Windows\system32\vp6vfw.dll

    "msacm.siren"=sirenacm.dll

    "wave"=wdmaud.drv

    "midi"=wdmaud.drv

    "mixer"=wdmaud.drv

    "aux"=wdmaud.drv

    "wave1"=wdmaud.drv

    "midi1"=wdmaud.drv

    "mixer1"=wdmaud.drv

    "aux1"=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    .js - open - C:\Windows\System32\WScript.exe "%1" %*

    ======List of files/folders created in the last 1 month======

    2013-11-23 19:40:37 ----D---- C:\Program Files\trend micro

    2013-11-23 19:40:36 ----D---- C:\rsit

    2013-11-22 17:10:27 ----D---- C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe

    2013-11-22 17:09:27 ----D---- C:\Mijn documenten

    2013-11-20 17:13:23 ----A---- C:\Windows\ntbtlog.txt

    2013-11-16 16:29:42 ----A---- C:\Windows\system32\mshtmled.dll

    2013-11-16 16:29:40 ----A---- C:\Windows\system32\vbscript.dll

    2013-11-16 16:29:37 ----A---- C:\Windows\system32\jsproxy.dll

    2013-11-16 16:29:37 ----A---- C:\Windows\system32\ieui.dll

    2013-11-16 16:29:36 ----A---- C:\Windows\system32\ieUnatt.exe

    2013-11-16 16:29:35 ----A---- C:\Windows\system32\msfeeds.dll

    2013-11-16 16:29:34 ----A---- C:\Windows\system32\wininet.dll

    2013-11-16 16:29:32 ----A---- C:\Windows\system32\jscript.dll

    2013-11-16 16:29:30 ----A---- C:\Windows\system32\url.dll

    2013-11-16 16:29:30 ----A---- C:\Windows\system32\jscript9.dll

    2013-11-16 16:29:29 ----A---- C:\Windows\system32\iertutil.dll

    2013-11-16 16:29:26 ----A---- C:\Windows\system32\urlmon.dll

    2013-11-16 16:29:20 ----A---- C:\Windows\system32\ieframe.dll

    2013-11-16 16:29:18 ----A---- C:\Windows\system32\mshtml.dll

    2013-11-16 16:21:51 ----D---- C:\Windows\pss

    2013-11-16 15:52:36 ----D---- C:\cac4c9e88088a2c9042df8

    2013-11-14 20:27:12 ----A---- C:\Windows\system32\gdi32.dll

    2013-11-14 20:27:03 ----A---- C:\Windows\system32\crypt32.dll

    2013-11-14 20:26:44 ----A---- C:\Windows\system32\IKEEXT.DLL

    2013-11-14 20:26:44 ----A---- C:\Windows\system32\FWPUCLNT.DLL

    2013-11-04 12:59:57 ----D---- C:\Program Files\iOrgSoft

    2013-10-29 14:09:27 ----D---- C:\Program Files\E.M. PowerPoint Video Converter

    ======List of files/folders modified in the last 1 month======

    2013-11-23 19:40:37 ----RD---- C:\Program Files

    2013-11-23 17:53:36 ----D---- C:\Windows\Temp

    2013-11-22 18:10:48 ----SD---- C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft

    2013-11-22 18:07:18 ----D---- C:\Windows\System32

    2013-11-22 18:07:17 ----D---- C:\Windows\inf

    2013-11-22 18:07:17 ----A---- C:\Windows\system32\PerfStringBackup.INI

    2013-11-22 17:20:02 ----D---- C:\Windows\system32\config\systemprofile\AppData\Roaming\Apple Computer

    2013-11-22 16:36:07 ----D---- C:\ProgramData\MFAData

    2013-11-22 16:23:47 ----D---- C:\Windows\Prefetch

    2013-11-22 16:22:46 ----RD---- C:\Users

    2013-11-22 16:22:24 ----D---- C:\Windows\Minidump

    2013-11-22 16:22:12 ----D---- C:\Windows

    2013-11-18 16:43:46 ----D---- C:\Windows\rescache

    2013-11-16 16:37:12 ----D---- C:\Windows\system32\migration

    2013-11-16 16:37:08 ----D---- C:\Program Files\Internet Explorer

    2013-11-16 16:37:04 ----D---- C:\Windows\system32\nl-NL

    2013-11-16 16:30:55 ----D---- C:\Windows\winsxs

    2013-11-16 16:30:35 ----D---- C:\Windows\system32\catroot2

    2013-11-16 16:30:35 ----D---- C:\Windows\system32\catroot

    2013-11-16 16:29:11 ----SHD---- C:\Windows\Installer

    2013-11-16 16:29:11 ----HD---- C:\Config.Msi

    2013-11-16 16:29:10 ----D---- C:\ProgramData\Microsoft Help

    2013-11-16 16:22:53 ----D---- C:\Windows\system32\MRT

    2013-11-16 16:18:19 ----HD---- C:\ProgramData

    2013-11-16 16:18:19 ----D---- C:\Program Files\Zylom Games

    2013-11-16 16:07:46 ----D---- C:\Windows\Debug

    2013-11-16 16:07:20 ----A---- C:\Windows\system32\mrt.exe

    2013-11-16 16:05:41 ----SHD---- C:\System Volume Information

    2013-11-14 20:02:34 ----D---- C:\Program Files\AVG Secure Search

    2013-11-03 21:02:54 ----D---- C:\ProgramData\CanonIJPLM

    2013-11-01 15:52:13 ----D---- C:\ProgramData\hps

    2013-11-01 15:14:28 ----D---- C:\ProgramData\tmp

    2013-11-01 14:53:02 ----D---- C:\Program Files\Java

    2013-11-01 14:26:56 ----D---- C:\Program Files\Google

    2013-10-29 14:09:38 ----RSD---- C:\Windows\Fonts

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2013-09-02 145720]

    R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2013-09-02 223032]

    R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2013-08-20 102200]

    R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2013-09-08 27448]

    R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2007-11-09 23640]

    R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2013-11-14 37664]

    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]

    R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]

    S1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2013-09-25 120632]

    S1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2013-09-02 209208]

    S1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2013-09-10 22840]

    S1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2013-09-02 176952]

    S1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2013-08-01 193848]

    S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-02 983552]

    S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]

    S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-18 92160]

    S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]

    S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]

    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2012-05-21 80824]

    S3 Dot4;Microsoft IEEE-1284.4-stuurprogramma; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]

    S3 Dot4Print;Stuurprogramma voor printerklasse voor IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]

    S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]

    S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]

    S3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]

    S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]

    S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]

    S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]

    S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]

    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]

    S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]

    S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]

    S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]

    S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]

    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2012-05-21 181432]

    S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudobex.sys [2012-05-21 181432]

    S3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\Windows\system32\DRIVERS\serscan.sys [2008-01-18 9216]

    S3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2011-10-28 168448]

    S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2012-12-13 45056]

    S3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]

    S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]

    S3 WinUSB;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2009-07-14 34944]

    S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]

    S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008]

    S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2013-10-03 3538480]

    S2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2013-09-25 301152]

    S2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-18 21504]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

    S2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504]

    S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-02-27 136176]

    S2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]

    S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]

    S2 ogmservice;Online Games Manager; C:\Program Files\Online Games Manager\ogmservice.exe [2013-08-08 559552]

    S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]

    S2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [2013-07-29 1616048]

    S2 vToolbarUpdater17.1.2;vToolbarUpdater17.1.2; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.1.2\ToolbarUpdater.exe [2013-11-14 1734680]

    S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-22 257416]

    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-02-27 136176]

    S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-27 194032]

    S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2013-05-31 553288]

    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

    S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 756392]

    -----------------EOF-----------------

  5. Dit is de log (er was ook nog een ander kladblok-bestand):

    info.txtlogfile of random's system information tool 1.09 2013-11-23 19:40:44

    ======Uninstalllist======

    Update for Microsoft Office 2007(KB2508958)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}

    32 Bit HPCIO Components Installer-->MsiExec.exe/I{A80FA752-C491-4ED9-ABF0-4278563160B2}

    Adobe FlashPlayer 11ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe-maintain activex

    AdobeReader 9.5.2 - Nederlands-->MsiExec.exe/I{AC76BA86-7AD7-1043-7B44-A95000000001}

    AdobeShockwave Player 11.6-->"C:\Windows\system32\Adobe\Shockwave11\uninstaller.exe"

    AppleApplication Support-->MsiExec.exe /I{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}

    AppleMobile Device Support-->MsiExec.exe /I{E14ADE0E-75F3-4A46-87E5-26692DD626EC}

    AppleSoftware Update-->MsiExec.exe /I{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}

    AVG2014-->"C:\Program Files\AVG\AVG2014\avgmfapx.exe" /AppMode=SETUP/Uninstall

    AVG2014-->MsiExec.exe /I{7DA4FC0C-4FB3-45A2-8095-B2F7A9CF8135}

    AVG2014-->MsiExec.exe /I{EEAFDDCF-0B0E-44DB-995B-886FB139CF1F}

    AVGSecurity Toolbar-->C:\Program Files\AVG Secure Search\UNINSTALL.exe /PROMPT/UNINSTALL

    CanonEasy-PhotoPrint EX-->C:\Program Files\Canon\Easy-PhotoPrint EX\uninst.exeUninst.ini uinstrsc.dll

    CanonEasy-WebPrint EX-->"C:\Program Files\Canon\Easy-WebPrintEX\Maint.exe" /UninstallRemove C:\Program Files\Canon\Easy-WebPrintEX\uninst.ini

    CanonInkjet Printer/Scanner/Fax Extended Survey Program-->C:\ProgramFiles\Canon\IJPLM\SETUP.EXE -R

    Canon MPNavigator EX 4.0-->"C:\Program Files\Canon\MP Navigator EX4.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX4.0\uninst.ini

    Canon MP280series MP Drivers-->"C:\Windows\system32\CanonIJ UninstallerInformation\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series\DelDrv.exe"/U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series /L0x0013

    Canon MyPrinter-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.iniuinstrsc.dll

    CanonSolution Menu EX-->"C:\Program Files\Canon\Solution MenuEX\uninst.exe" /UninstallRemove C:\Program Files\Canon\Solution MenuEX\uninst.ini

    CCleaner-->"C:\ProgramFiles\CCleaner\uninst.exe"

    D3DX10-->MsiExec.exe/X{E09C4DB7-630C-4F06-A631-8EA7239923AF}

    De Sims 2™ Je Eigen Winkel Collectie-->C:\ProgramFiles\EA GAMES\De Sims 2 Je Eigen Winkel Collectie\EAUninstall.exe

    De Sims™ 2Double Deluxe-->C:\Program Files\EA GAMES\De Sims 2 DoubleDeluxe\EAUninstall.exe

    De Sims™ 2 Huisdieren-->C:\Program Files\EA GAMES\De Sims2 Huisdieren\EAUninstall.exe

    De Sims™ 2 Op Reis-->C:\Program Files\EA GAMES\De Sims 2Op Reis\EAUninstall.exe

    De Sims™ 2 Vrije Tijd-->C:\Program Files\EA GAMES\De Sims2 Vrije Tijd\EAUninstall.exe

    De Sims™ 3Ambities-->"C:\Program Files\InstallShield InstallationInformation\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}\Sims3EP02Setup.exe"-runfromtemp -l0x0013 -removeonly

    De Sims™ 3Na Middernacht-->"C:\Program Files\InstallShield InstallationInformation\{45057FCE-5784-48BE-8176-D9D00AF56C3C}\setup.exe" -runfromtemp-l0x0013 -removeonly

    De Sims™ 3Studententijd-->"C:\Program Files\InstallShield InstallationInformation\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}\Sims3EP09Setup.exe"-runfromtemp -l0x0013 -removeonly

    De Sims™ 3Wereldavonturen-->"C:\Program Files\InstallShield InstallationInformation\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}\Sims3EP01Setup.exe"-runfromtemp -l0x0013 -removeonly

    De Sims™3-->"C:\Program Files\InstallShield InstallationInformation\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\setup.exe" -runfromtemp-l0x0013 -removeonly

    E.M. PowerPointVideo Converter 3.20-->"C:\Program Files\E.M. PowerPoint VideoConverter\unins000.exe"

    Gebruikersregistratievoor Canon MP280 series-->C:\Program Files\Canon\IJEREG\MP280series\UNINST.EXE

    GoogleUpdate Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

    Hotfix forMicrosoft .NET Framework 3.5 SP1(KB953595)-->C:\Windows\system32\msiexec.exe /package{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""

    Hotfix forMicrosoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe/package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall{A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""

    Hotfix forMicrosoft .NET Framework 4 Client Profile(KB2461678)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {99A120B0-F930-3427-A833-FAD753B85527} /parameterfolder Client

    Intel®Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe-uninstall

    Intel® TVWizard-->C:\Windows\system32\TVWizudlg.exe -uninstall

    iTunes-->MsiExec.exe/I{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}

    Java 7Update 25-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217025FF}

    Java 6Update 37-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216035FF}

    JuniorReisavonturen-->C:\Program Files\InstallShield InstallationInformation\{B0CDB2AE-801F-4F5B-99FA-6B8A133A914D}\setup.exe -runfromtemp-l0x0013 -removeonly

    Kruidvatfotoservice-->"C:\Program Files\Fotoservice\Kruidvatfotoservice\uninstall.exe"

    Little Shop- Road Trip-->"C:\Program Files\Denda Publishers\Little Shop - RoadTrip\Uninstall.exe"

    ManillenThe Game-->"C:\Program Files\R&R Software\Manillen TheGame\uninstall.exe"

    MediaPlayer Utilities 4.28-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}

    MessengerCompanion-->MsiExec.exe /I{8142D25E-028A-4563-86ED-5755783C8029}

    Microsoft.NET Framework 3.5 Language Pack SP1 - nld-->MsiExec.exe/I{101738D7-D805-37A9-BB91-1F2C351782BF}

    Microsoft.NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft.NET Framework 3.5 SP1\setup.exe

    Microsoft.NET Framework 3.5 SP1-->MsiExec.exe/I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

    Microsoft.NET Framework 4 Client Profile NLD Language Pack-->MsiExec.exe/X{2617FA1F-0C04-3ABB-AF64-7D5B6620C341}

    Microsoft.NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe/repair /x86 /parameterfolder Client

    Microsoft.NET Framework 4 Client Profile-->MsiExec.exe/X{3C3901C5-3455-3E0A-A214-0B093A5070A6}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0015-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0016-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0018-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0019-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package {90120000-001A-0413-0000-0000000FF1CE}/uninstall {26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-001B-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-0044-0413-0000-0000000FF1CE} /uninstall{26257879-B20D-4D30-A429-B387A4890929}

    MicrosoftOffice 2007 Service Pack 3 (SP3)-->msiexec /package{90120000-006E-0413-0000-0000000FF1CE} /uninstall {1D12BC91-360E-424C-97C4-813651313660}

    MicrosoftOffice Access MUI (Dutch) 2007-->MsiExec.exe/X{90120000-0015-0413-0000-0000000FF1CE}

    MicrosoftOffice Excel MUI (Dutch) 2007-->MsiExec.exe/X{90120000-0016-0413-0000-0000000FF1CE}

    MicrosoftOffice File Validation Add-In-->MsiExec.exe/I{90140000-2005-0000-0000-0000000FF1CE}

    Microsoft Office InfoPath MUI (Dutch) 2007-->MsiExec.exe/X{90120000-0044-0413-0000-0000000FF1CE}

    Microsoft Office Outlook MUI (Dutch) 2007-->MsiExec.exe/X{90120000-001A-0413-0000-0000000FF1CE}

    Microsoft Office PowerPoint MUI (Dutch)2007-->MsiExec.exe /X{90120000-0018-0413-0000-0000000FF1CE}

    Microsoft Office Professional Plus2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\OfficeSetup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL

    Microsoft Office Professional Plus 2007-->MsiExec.exe/X{90120000-0011-0000-0000-0000000FF1CE}

    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe/X{90120000-001F-0413-0000-0000000FF1CE}

    Microsoft Office Proof (English) 2007-->MsiExec.exe/X{90120000-001F-0409-0000-0000000FF1CE}

    Microsoft Office Proof (French) 2007-->MsiExec.exe/X{90120000-001F-040C-0000-0000000FF1CE}

    Microsoft Office Proof (German) 2007-->MsiExec.exe/X{90120000-001F-0407-0000-0000000FF1CE}

    Microsoft Office Proofing (Dutch) 2007-->MsiExec.exe/X{90120000-002C-0413-0000-0000000FF1CE}

    Microsoft Office Proofing Tools 2007 Service Pack 3(SP3)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall{928D7B99-2BEA-49F9-83B8-20FA57860643}

    Microsoft Office Proofing Tools 2007 Service Pack 3(SP3)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall{1FF96026-A04A-4C3E-B50A-BB7022654D0F}

    Microsoft Office Proofing Tools 2007 Service Pack 3(SP3)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall{71F055E8-E2C6-4214-BB3D-BFE03561B89E}

    Microsoft Office Proofing Tools 2007 Service Pack 3(SP3)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall{2C95E7EE-FEA7-4B3A-A6E5-DF90A88B816A}

    Microsoft Office Publisher MUI (Dutch) 2007-->MsiExec.exe/X{90120000-0019-0413-0000-0000000FF1CE}

    Microsoft Office Shared MUI (Dutch) 2007-->MsiExec.exe/X{90120000-006E-0413-0000-0000000FF1CE}

    Microsoft Office Word MUI (Dutch) 2007-->MsiExec.exe/X{90120000-001B-0413-0000-0000000FF1CE}

    Microsoft Silverlight-->MsiExec.exe/X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

    Microsoft Visual C++ 2005 ATL Update kb973923 - x868.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}

    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe/X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}

    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe/X{7299052b-02a4-4627-81f2-1818da5d550d}

    Microsoft Visual C++ 2008 Redistributable - x869.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

    Microsoft Visual C++ 2008 Redistributable - x869.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}

    Microsoft Visual C++ 2008 Redistributable - x869.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}

    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe/X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}

    Microsoft WSE 3.0 Runtime-->MsiExec.exe/X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}

    Monopoly-->RunDll32C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup"C:\Program Files\InstallShield InstallationInformation\{D7E7EC5E-4349-4E40-B37C-4342188B86EC}\Setup.exe" -l0x13

    MSVCRT-->MsiExec.exe/I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}

    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe/I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

    MSXML 4.0 SP2 (KB973688)-->MsiExec.exe/I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

    Online Games Manager v1.21-->C:\Program Files\OnlineGames Manager\uninst.exe

    Origin-->C:\Program Files\Origin\OriginUninstall.exe

    Picasa 3-->"C:\ProgramFiles\Google\Picasa3\Uninstall.exe"

    QuickTime-->MsiExec.exe/I{B67BAFBA-4C9F-48FA-9496-933E3B255044}

    SAMSUNG Intelli-studio-->"C:\ProgramFiles\SAMSUNG\Intelli-studio\uninstall.exe"

    Samsung Kies-->"C:\Program Files\InstallShieldInstallation Information\{758C8301-2696-4855-AF45-534B1200980A}\setup.exe"-runfromtemp -l0x0409 -removeonly

    Samsung Kies-->MsiExec.exe/I{758C8301-2696-4855-AF45-534B1200980A}

    SAMSUNG USB Driver for Mobile Phones-->C:\ProgramFiles\Samsung\USB Drivers\Uninstall.exe

    Security Update for Microsoft .NET Framework 3.5 SP1(KB2604111)-->C:\Windows\system32\msiexec.exe /package{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall{94EFE014-E577-310B-B2D5-6973A21D8A90} /qb+ REBOOTPROMPT=""

    Security Update for Microsoft .NET Framework 3.5 SP1(KB2736416)-->C:\Windows\system32\msiexec.exe /package{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall{939AF4BC-EC42-38D1-AE82-91D4A7ED8911} /qb+ REBOOTPROMPT=""

    Security Update for Microsoft .NET Framework 3.5 SP1(KB2840629)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}/uninstall {A8433C01-319F-3370-850E-87C35496299A} /qb+REBOOTPROMPT=""

    Security Update for Microsoft .NET Framework 3.5 SP1(KB2861697)-->C:\Windows\system32\msiexec.exe /package{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {48B0C142-A0F4-3263-90E1-1984CBB8DD18}/qb+ REBOOTPROMPT=""

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2478663)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2518870)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2604121)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {67A5F99B-5EBA-3812-8D2E-BC251490DD3F} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2656351)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2656368v2)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {86BB5A25-8CC3-33CE-A393-CF28901682B2} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile (KB2656405)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {16EEC04A-B924-37E0-97CF-422DCEFC1B63} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile (KB2686827)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {C4D978AA-2668-3404-96DE-96E2AFC62FD7} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2729449)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {CD6D9B8A-BBC4-3FA7-B24D-D74CE90630CF} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2737019)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {ECBEE23D-AB7E-3DAA-B66B-CD52003198F1} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2742595)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {788818B1-B191-3217-A210-7ACFDE19CE4A} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2789642)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {B7C20E16-9A3A-3F05-A6B5-E15AA09200E0} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2804576)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {CF581973-77E0-3093-A1AC-A03130DE990F} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2832407)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {80774950-A707-386B-9C9B-D052D20BD54B} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2835393)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {576C07F8-777C-3981-B8BF-063A6B57254E} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile (KB2840628)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {90EA7C4E-7F03-31FD-BE27-B1A9B4AE56BD} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile (KB2840628v2)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {1E88AFAE-CEF7-3540-8FF6-6D00877B2767} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile (KB2858302v2)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {8BA4E34D-95C5-3907-87E4-62FBB31A2190} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 ClientProfile(KB2861188)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {21AEAFE4-6F0E-3169-A09C-9FB37C77E555} /parameterfolder Client

    Security Update for Microsoft Office 2007 suites (KB2596744)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {D33B9EF5-3801-496A-A2D6-B7F4BE972D75}

    Security Update for Microsoft Office 2007 suites (KB2596754)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {B145DBBB-7778-4A5D-9D2B-DA6569F02391}

    Security Update for Microsoft Office 2007 suites (KB2596792)32-Bit Edition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {E34960DB-2A93-45DB-A208-02650F7AB09C}

    Security Update for Microsoft Office 2007 suites (KB2596825)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {B7727B4D-5EA3-4C11-9D30-15E47616DCAF}

    Security Update for Microsoft Office 2007 suites (KB2596871)32-Bit Edition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {293FB6BE-D3EB-4162-B522-F9108040B9FE}

    Security Update for Microsoft Office 2007 suites (KB2597969)32-Bit Edition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {2B3C041A-A7F2-4A24-968D-4BEB6A123D15}

    Security Update for Microsoft Office 2007 suites (KB2597973)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {EA575F57-C5D1-4B5A-B9F9-F16EEBC6B58C}

    Security Update for Microsoft Office 2007 suites (KB2687309)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {E949D8B9-24FD-4AB7-B427-FC42AA8BB2D9}

    Security Update for Microsoft Office 2007 suites (KB2687439)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {3579CE34-B225-4B19-A3AF-DE5F562A212F}

    Security Update for Microsoft Office 2007 suites (KB2760411)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {79850906-6D2B-4061-8EAF-EAC84173DEC5}

    Security Update for Microsoft Office 2007 suites (KB2760415)32-Bit Edition -->msiexec /package {90120000-006E-0413-0000-0000000FF1CE}/uninstall {02AF2AA9-6FFA-47D7-BDBB-42B3A8AD8616}

    Security Update for Microsoft Office 2007 suites (KB2760585)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {8907F32C-DF89-4C2F-AEDE-0DB4B65451C0}

    Security Update for Microsoft Office 2007 suites (KB2760591)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {319FC809-3841-4739-A25F-FDBADF073697}

    Security Update for Microsoft Office 2007 suites (KB2827326)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {4CCE0378-386F-4DC2-9CC1-A3710C77057D}

    Security Update for Microsoft Office 2007 suites (KB2827329)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {81352C19-97CF-4365-8EAE-205BCC9A2DC8}

    Security Update for Microsoft Office Excel 2007 (KB2827324)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {686630EC-8033-4031-85C5-D8E5CD62A958}

    Security Update for Microsoft Office InfoPath 2007(KB2687440) 32-Bit Edition -->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall{8F311D6C-D8DD-4C32-9457-1A129CABD1A5}

    Security Update for Microsoft Office Outlook 2007(KB2825644) 32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {12A1DD97-E9A1-4370-837E-D1BBD088584B}

    Security Update for Microsoft Office PowerPoint 2007(KB2596764) 32-Bit Edition-->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall {AEA16A27-0B97-4670-818F-A98D06EC0A6F}

    Security Update for Microsoft Office PowerPoint 2007(KB2596912) 32-Bit Edition-->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall{0EF0D4FB-BB23-4515-AAEA-1240AC2DA525}

    Security Update for Microsoft Office Publisher 2007(KB2597971) 32-Bit Edition -->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall{9D689455-5858-4AE4-A3CA-6E4149FE3F70}

    Security Update for Microsoft Office Word 2007 (KB2827330)32-Bit Edition -->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {2C57A81A-7534-4DEE-A450-7FBE86F3200D}

    Security Update for Taalpakket voor Microsoft .NET Framework4 Client Profile - NLD(KB2478663)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe/uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolderClientLP

    Security Update for Taalpakket voor Microsoft .NET Framework4 Client Profile - NLD(KB2518870)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe/uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolderClientLP

    Segoe UI-->MsiExec.exe/I{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}

    swMSM-->MsiExec.exe/I{612C34C7-5E90-47D8-9B5C-0F717DD82726}

    System Requirements Lab for Intel-->MsiExec.exe/I{C71067FC-288F-4E0B-88C6-44DFDA8311E2}

    Taalpakket voor Microsoft .NET Framework 3.5 SP1 -NL-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5Language Pack SP1 - nld\setup.exe

    Taalpakket voor Microsoft .NET Framework 4 Client Profile -NLD-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe/repair /x86 /lcid 1043 /parameterfolder ClientLP

    Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\ProgramFiles\InstallShield InstallationInformation\{F7B05784-334C-4F76-8BAB-30ABEB7FD534}\setup.exe -runfromtemp-l0x0409

    Update for 2007 Microsoft Office System(KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE}/uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}

    Update for Microsoft .NET Framework 3.5 SP1(KB963707)-->C:\Windows\system32\msiexec.exe /package{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall{B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""

    Update for Microsoft .NET Framework 4 Client Profile(KB2468871)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile(KB2533523)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile(KB2600217)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {5D9961AC-7C99-36A2-9EF0-34678AED5384} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile(KB2836939)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {0160BA31-409C-3FD0-9C87-C7D95BF46986} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile(KB2836939v3)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe/uninstallpatch {D5B80B17-2443-3296-A700-792FAA0748BD} /parameterfolder Client

    Update for Microsoft Office 2007 suites (KB2596620) 32-BitEdition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall{A024FC7B-77DE-45DE-A058-1C049A17BFB3}

    Update for Microsoft Office 2007 suites (KB2687493) 32-BitEdition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}

    Update for Microsoft Office 2007 suites (KB2767849) 32-BitEdition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}

    Update for Microsoft Office 2007 suites (KB2767916) 32-BitEdition-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}

    Update for Microsoft Office Outlook 2007 (KB2687404) 32-BitEdition-->msiexec /package {90120000-001A-0413-0000-0000000FF1CE} /uninstall{F8564AF8-30AE-4427-ACF3-69714E1BB656}

    Update for Microsoft Office Outlook 2007 Junk Email Filter(KB2825642) 32-Bit Edition-->msiexec /package{90120000-0011-0000-0000-0000000FF1CE} /uninstall {9492511E-2CE0-4904-9400-203F44E1DC0D}

    Update voor Microsoft Office Excel 2007 Help(KB963678)-->msiexec /package {90120000-0016-0413-0000-0000000FF1CE}/uninstall {5CF7002F-6F49-4482-9564-5614FBE560FA}

    Update voor Microsoft Office Powerpoint 2007 Help(KB963669)-->msiexec /package {90120000-0018-0413-0000-0000000FF1CE}/uninstall {15D84E79-1ED7-42C5-B2FD-745C3FBDDDC5}

    Update voor Microsoft Office Word 2007 Help(KB963665)-->msiexec /package {90120000-001B-0413-0000-0000000FF1CE}/uninstall {A66AE6A1-8D8C-4102-BC18-38CBDE40F809}

    Visual Studio 2012 x86 Redistributables-->MsiExec.exe/I{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}

    VLC media player 0.9.8a-->C:\ProgramFiles\VideoLAN\VLC\uninstall.exe

    Windows Live Communications Platform-->MsiExec.exe/I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}

    Windows Live Essentials-->C:\Program Files\WindowsLive\Installer\wlarp.exe

    Windows Live Essentials-->MsiExec.exe/I{2A07C35B-8384-4DA4-9A95-442B6C89A073}

    Windows Live ID Sign-in Assistant-->MsiExec.exe/I{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}

    Windows Live Installer-->MsiExec.exe/I{0B0F231F-CE6A-483D-AA23-77B364F75917}

    Windows Live Messenger Companion Core-->MsiExec.exe/I{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}

    Windows Live Messenger-->MsiExec.exe/X{48294D95-EE9A-4377-8213-44FC4265FB27}

    Windows Live Messenger-->MsiExec.exe/X{E5B21F11-6933-4E0B-A25C-7963E3C07D11}

    Windows Live Photo Common-->MsiExec.exe/X{9BD262D0-B788-4546-A0A5-F4F56EC3834B}

    Windows Live Photo Common-->MsiExec.exe/X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}

    Windows Live PIMT Platform-->MsiExec.exe/I{83C292B7-38A5-440B-A731-07070E81A64F}

    Windows Live SOXE Definitions-->MsiExec.exe/I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}

    Windows Live SOXE-->MsiExec.exe/I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}

    Windows Live UX Platform Language Pack-->MsiExec.exe/I{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}

    Windows Live UX Platform-->MsiExec.exe/I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}

    ======Security center information======

    AS: Windows Defender

    =====Application event log=====

    Computer Name: PC_van_Laura

    Event Code: 9016

    Message: Kan Beheer van bureaubladvensters niet startenomdat een analyse van de hardware en configuratie heeft bepaald dat dit nietgoed werkt

    Record Number: 7100

    Source Name: Desktop Window Manager

    Time Written: 20120101153403.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Laura

    Event Code: 6000

    Message: De kennisgevingssubscriber van winlogon <SessionEnv> was niet beschikbaar omeen kennisgevingsgebeurtenis te verwerken.

    Record Number: 7099

    Source Name: Microsoft-Windows-Winlogon

    Time Written: 20120101153402.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Laura

    Event Code: 4101

    Message: De licentie van Windows is gevalideerd.

    Record Number: 7098

    Source Name: Microsoft-Windows-Winlogon

    Time Written: 20120101153401.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Laura

    Event Code: 4625

    Message: Het EventSystem-subsysteem onderdrukt gedurende86400 seconden dubbele vermeldingen in het gebeurtenislogboek. De time-out vooronderdrukking kan worden ingesteld met de REG_DWORD-waardeSuppressDuplicateDuration in de volgende registersleutel:HKLM\Software\Microsoft\EventSystem\EventLog.

    Record Number: 7097

    Source Name: Microsoft-Windows-EventSystem

    Time Written: 20120101153358.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Laura

    Event Code: 900

    Message: De Software Licensing-service wordt gestart.

    Record Number: 7096

    Source Name: Microsoft-Windows-Security-Licensing-SLC

    Time Written: 20120101153356.000000-000

    Event Type: Informatie

    User:

    =====Security event log=====

    Computer Name: PC_van_Laura

    Event Code: 1100

    Message: De Event Logging-service is afgesloten.

    Record Number: 10846

    Source Name: Microsoft-Windows-Eventlog

    Time Written: 20111121174003.218800-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Laura

    Event Code: 4672

    Message: Speciale bevoegdheden toegewezen aan nieuweaanmelding.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: SYSTEEM

    Accountdomein: NT AUTHORITY

    Aanmeldings-id: 0x3e7

    Bevoegdheden: SeAssignPrimaryTokenPrivilege

    SeTcbPrivilege

    SeSecurityPrivilege

    SeTakeOwnershipPrivilege

    SeLoadDriverPrivilege

    SeBackupPrivilege

    SeRestorePrivilege

    SeDebugPrivilege

    SeAuditPrivilege

    SeSystemEnvironmentPrivilege

    SeImpersonatePrivilege

    Record Number: 10845

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111121173950.892324-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Laura

    Event Code: 4624

    Message: Er is een account aangemeld.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: PC_VAN_LAURA$

    Accountdomein: WORKGROUP

    Aanmeldings-id: 0x3e7

    Aanmeldingstype: 5

    Nieuwe aanmelding:

    Beveiligings-id: S-1-5-18

    Accountnaam: SYSTEEM

    Accountdomein: NT AUTHORITY

    Aanmeldings-id: 0x3e7

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Procesgegevens:

    Proces-id: 0x370

    Naamproces: C:\Windows\System32\services.exe

    Netwerkgegevens:

    Naam vanwerkstation:

    Netwerkadresvan bron: -

    Poort vanbron: -

    Gedetailleerde verificatiegegevens:

    Aanmeldingsproces: Advapi

    Verificatiepakket: Negotiate

    Doorgezetteservices: -

    Pakketnaam(alleen NTLM): -

    Sleutellengte: 0

    Deze gebeurtenis wordt gegenereerd wanneer eenaanmeldingssessie wordt gemaakt. De gebeurtenis wordt gegenereerd op de computerwaartoe toegang wordt verkregen.

    De velden Onderwerp bevatten de account op het lokalesysteem waardoor de aanmelding is aangevraagd. Dit is meestal een service zoalsde Server-service, of een lokaal proces zoals Winlogon.exe of Services.exe.

    In het veld Aanmeldingstype ziet u het type aanmelding. Demeest algemene typen zijn 2 (interactief) en 3 (netwerk).

    Het veld Nieuwe aanmelding bevat de account waarvoor denieuwe aanmelding is gemaakt. Dit is de account waarmee is aangemeld.

    In de netwerkvelden ziet u de bron van een externeaanmeldingsaanvraag. Naam van werkstation is niet altijd beschikbaar en kan insommige gevallen leeg zijn.

    De velden met verificatiegegevens bevatten gedetailleerdeinformatie over deze aanmeldingsaanvraag.

    -Aanmeldings-GUID is een unieke id die kan worden gebruikt om deze gebeurtenisaf te stemmen met een KDC-gebeurtenis.

    - InDoorgezette services ziet u welke tussentijdse services voor dezeaanmeldingsaanvraag zijn gebruikt.

    -Pakketnaam geeft aan welk subprotocol van de NTLM-protocollen is gebruikt.

    -Sleutellengte geeft de lengte van de gegenereerde sessiesleutel aan. Dit veldis 0 als er geen sessiesleutel is aangevraagd.

    Record Number: 10844

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111121173950.892324-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Laura

    Event Code: 4648

    Message: Poging tot aanmelden met expliciete referenties.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: PC_VAN_LAURA$

    Accountdomein: WORKGROUP

    Aanmeldings-id: 0x3e7

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Account waarvan de referenties zijn gebruikt:

    Accountnaam: SYSTEEM

    Accountdomein: NT AUTHORITY

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Doelserver:

    Naam vandoelserver: localhost

    Aanvullendegegevens: localhost

    Procesgegevens:

    Proces-id: 0x370

    Procesnaam: C:\Windows\System32\services.exe

    Netwerkgegevens:

    Netwerkadres: -

    Poort: -

    Deze gebeurtenis wordt gegenereerd wanneer een procesprobeert zich op een account aan te melden door expliciet de referenties vandie account op te geven. Meestal gebeurt dit in batchconfiguraties zoalsgeplande taken, of bij gebruik van de opdracht Uitvoeren als.

    Record Number: 10843

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111121173950.892324-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Laura

    Event Code: 4647

    Message: De gebruiker heeft een afmelding gestart:

    Onderwerp:

    Beveiligings-id: S-1-5-21-3677436180-1221689071-2926320938-1000

    Accountnaam: Laura

    Accountdomein: PC_van_Laura

    Aanmeldings-id: 0x1e2ff

    Deze gebeurtenis wordt gegenereerd wanneer een afmeldingwordt gestart maar het aantal tokenverwijzingen niet nul is en deaanmeldingssessie niet kan worden vernietigd. De gebruiker kan verder geenactiviteiten starten. Deze gebeurtenis kan worden geïnterpreteerd als eenafmeldingsgebeurtenis.

    Record Number: 10842

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111121173947.912724-000

    Event Type: Controle geslaagd

    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe

    "FP_NO_HOST_CHECK"=NO

    "OS"=Windows_NT

    "Path"=C:\Program Files\Common Files\MicrosoftShared\WindowsLive;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\ProgramFiles\Windows Live\Shared;C:\Program Files\QuickTime\QTSystem\

    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC

    "PROCESSOR_ARCHITECTURE"=x86

    "TEMP"=%SystemRoot%\TEMP

    "TMP"=%SystemRoot%\TEMP

    "USERNAME"=SYSTEM

    "windir"=%SystemRoot%

    "PROCESSOR_LEVEL"=6

    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15Stepping 13, GenuineIntel

    "PROCESSOR_REVISION"=0f0d

    "NUMBER_OF_PROCESSORS"=2

    "PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

    "asl.log"=Destination=file

    "CLASSPATH"=.;C:\ProgramFiles\Java\jre6\lib\ext\QTJava.zip

    "QTJAVA"=C:\ProgramFiles\Java\jre6\lib\ext\QTJava.zip

    "SAFEBOOT_OPTION"=MINIMAL

    -----------------EOF-----------------

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.