Ga naar inhoud

Opm65

Lid
  • Items

    23
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door Opm65

  1. Uiteindelijk heb ik het probleem op kunnen lossen door de slaapstand volledig uit te schakelen (via de energie-instellingen van Windows 10) na de installatie van de Anniversary Update.
  2. Hoi, Hierbij een probleem met de Anniversary Update van Windows 10. Ik heb deze update inmiddels vier keer geïnstalleerd, en iedere keer liep Windows na het opnieuw opstarten vast, zodat ik terug moest gaan naar de vorige versie van Windows 10 (versie 1511). Ik kom bij dat vastlopen wel bij het gewone opstartscherm van Windows, maar kan niets aanklikken, de taakbalk en de iconen op het bureaublad zijn allemaal geblokkeerd. Ik heb een aantal oplossingen, gevonden op het internet, uitgeprobeerd maar niets helpt. Het gaat dan om de volgende oplossingen: 1. het uitschakelen van Snel Opstarten (bij energie-instellingen) 2. de opslaglocatie van apps veranderen van schijf D: naar schijf C: 3. na het installeren van de Anniversary Update, nog voor het opnieuw opstarten, de "Aan de Slag" app ("Get Started") verwijderen en het wsreset commando draaien, zodat de cache van de Windows Store geschoond wordt. Het idee is dat die "Get Started" app de freeze veroorzaakt 4. de Anniversary Update installeren onder een ander Microsoft account (met administrator rechten). Weet iemand nog een andere oplossing? De fix die Microsoft zelf in de update van 31/8/2016 (van de Anniversary Update) heeft geplaatst werkt bij mij in ieder geval niet, aangezien ik het vandaag nog geprobeerd heb (met oplossing 4 hierboven). Alvast mijn dank.
  3. Hoi falstring, Bedankt voor je reactie. Ik heb je advies opgevolgd, maar dat lost het probleem niet op. Ik heb de USB-poorten overigens één voor één opnieuw geïnstalleerd, omdat ik anders geen muis en toetsenbord meer heb om de PC opnieuw op te starten. Het vreemde blijft, dat Windows 10 op mijn PC als driver UASPSTOR.SYS laadt, terwijl op de laptop waarop de externe schijf wel gewoon werkt (met windows 10) USBSTOR.SYS geladen wordt. Dan ga je toch denken dat het aan een specifieke chipset ligt (in mijn geval Intel 5 Series/3400 Series).
  4. Hoi, Sinds de update naar Windows 10 werkt mijn externe harde schijf (Seagate Desktop Expansion 4TB) niet meer. Moederbord: Gigabyte GA-P55M-UD2. Onder Apparaatbeheer vond ik het volgende: Opslagcontrollers - Via USB aangesloten SCSI (UAS)-apparaat voor massaopslag: Dit apparaat start niet. (Code 10) {Bewerking mislukt} De aangevraagde bewerking is niet gelukt. Device USB\VID_0BC2&PID_3320\MSFT30NA4MB4F4 could not be migrated. Last Device Instance Id: USB\VID_0BC2&PID_3320\NA4MB4F4 Class Guid: {36FC9E60-C465-11CF-8056-444553540000} Location Path: PCIROOT(0)#PCI(1A07)#USBROOT(0)#USB(4) Migration Rank: 0xF0000000C0000103 Present: true Status: 0xC0000719 19-9-2015 13:15:37 Apparaat niet gemigreerd (= not migrated) 19-9-2015 13:15:37 Apparaat geconfigureerd (uaspstor.inf) 19-9-2015 13:15:58 Apparaat niet gestart (UASPStor) Op een andere PC met windows 10 (een ASUS laptop) werkt de externe schijf wel. Windows 10 laadt als driver UASPSTOR.SYS op mijn PC, maar dit zou USBSTOR.SYS moeten zijn, zoals op de genoemde laptop. De Seagate externe schijf kan USB 3 aan, maar zit op een USB 2 poort (mijn moederbord heeft geen USB3 poorten). Ligt dit aan het GIGABYTE moederbord (drivers, BIOS)? Weet iemand een oplossing voor dit probleem? Zowel Seagate als Gigabyte kon mij niet helpen. Volgens Gigabyte had Intel geen nieuwe drivers voor de P55 chipset voor windows 10.
  5. Bedankt voor je reactie. Omdat de opstartproblemen zelf nog niet opgelost bleken te zijn, heb ik windows 7 opnieuw geïnstalleerd. Ik had voor de inbouw van een Samsung SSD het besturingssysteem overgezet naar de SSD, maar hier was blijkbaar toch iets niet helemaal goed gegaan. Vandaar een nieuwe installatie van windows.
  6. Hoi. Ik heb een probleem met msconfig.exe. Om opstartproblemen op te lossen (na de inbouw van een nieuwe videokaart en een SSD) heb ik msconfig.exe gebruikt om op te starten in de opstartmethode 'Selectief Opstarten'. De problemen lijken opgelost te zijn (na het gebruik van een systeemherstelschijf), en ik wil nu weer gewoon opstarten. Maar ik kan msconfig.exe nu niet in de opstartmethode 'Normaal Opstarten' krijgen. Indien ik 'Normaal Opstarten' aanvink en op Toepassen druk, springt msconfig.exe weer automatisch op 'Selectief Opstarten'. De pc blijft nu voortdurend in een beperkte staat opstarten. Weet ieman een oplossing hiervoor? Alvast mijn dank.
  7. Heel erg bedankt voor de hulp, alles is weer netjes opgeruimd!
  8. Log van AdwCleaner: # AdwCleaner v3.017 - Report created 17/01/2014 at 13:38:29 # Updated 12/01/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Gebruiker - GEBRUIKER-PC # Running from : C:\Users\Gebruiker\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\Gebruiker\AppData\LocalLow\ZoneAlarm_Security ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASUS_N_Series_Screensaver Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2645238 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFC6B931-37B8-45EA-8185-F99F93C07DD9} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9776B328-1795-4B10-8673-4FBBACC20704} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ZoneAlarm_Security Key Deleted : HKLM\Software\Bandoo Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DeviceVM Key Deleted : HKLM\Software\ZoneAlarm_Security Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm_Security Toolbar Key Deleted : [x64] HKLM\SOFTWARE\DeviceVM ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16428 ************************* AdwCleaner[R0].txt - [5417 octets] - [17/01/2014 13:36:50] AdwCleaner[s0].txt - [5359 octets] - [17/01/2014 13:38:29] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [5419 octets] ########## De rommel van Conduite/Rockfuel is zo te zien nu ook verwijderd uit het register. Hitman Pro vindt nu ook niets meer.
  9. Bedankt voor je reactie. Maar is het niet veiliger om dat verwijderen via een tool zoals AdwCleaner? Of zou deze die items in het register van Windows niet aanpakken?
  10. Hitman Pro geeft nog twee meldingen: Rocketfuel in HKLM\SOFTWARE\Classes\Wow6432Node\SLSID en Rocketfuel in HKLM\SOFTWARE\Wow6432Node. Maar aangezien we geen licentie hebben voor Hitman Pro, kunnen we dit hiermee niet verwijderen.
  11. De log van zoek.exe: Zoek.exe v5.0.0.0 Updated 15-Januari-2014 Tool run by Gebruiker on do 16-01-2014 at 17:19:41,30. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Desktop\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== System Restore Info ====================== 16-1-2014 17:24:29 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\Panda Security deleted successfully C:\Program Files\CheckPoint deleted successfully C:\Program Files\Fighters deleted successfully C:\Program Files\Symantec deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] ==== Deleting Files \ Folders ====================== C:\PROGRA~2\ZoneAlarm_Security deleted C:\PROGRA~2\zonealarm_security_suite deleted C:\PROGRA~2\Conduit deleted C:\Users\Gebruiker\AppData\Local\Conduit deleted C:\Users\Gebruiker\AppData\LocalLow\Conduit deleted C:\Windows\Syswow64\tmp31C9.tmp deleted C:\Windows\Syswow64\tmp31DA.tmp deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.htm" deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.html" deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.rtf" deleted "C:\Users\Gebruiker\AppData\Roaming\temp" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== 2014-01-16 15:06:01 8629990396B6FA011E27B46ED6AC4BDB 808224 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\nvStInst.exe 2014-01-16 12:54:23 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-01-16 15:05:15 28AC0BD3E6712C07B663A48F2E5CE3AC 32544 ----a-w- C:\Windows\SysWOW64\nvaudcap32v.dll 2014-01-16 15:05:12 BDC32E3B7E5297EC0B4E0AEA2E2E55E0 9657464 ----a-w- C:\Windows\SysWOW64\nvopencl.dll 2014-01-16 15:05:11 D18F9D53B844B5E6FE614FEE8FBF186F 852768 ----a-w- C:\Windows\SysWOW64\NvIFR.dll 2014-01-16 15:05:11 C1E3CC280E6CB4F3C1BA9F9EC50683E2 2747680 ----a-w- C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-16 15:05:11 A403088619D575D43AA0C46AD56BB203 22960416 ----a-w- C:\Windows\SysWOW64\nvoglv32.dll 2014-01-16 15:05:11 9C1FBE3D3CBFCF88DCDFCB21D38307A3 2947872 ----a-w- C:\Windows\SysWOW64\nvcuvid.dll 2014-01-16 15:05:11 5F0E3FBF97F9AABBC6B7227B77F7E958 15230352 ----a-w- C:\Windows\SysWOW64\nvd3dum.dll 2014-01-16 15:05:11 5B9DF8156153C839A0E6449294030519 847648 ----a-w- C:\Windows\SysWOW64\NvFBC.dll 2014-01-16 15:05:11 39BD6D4EF0FDBC92D0B1CD86A4D0BFF0 9700224 ----a-w- C:\Windows\SysWOW64\nvcuda.dll 2014-01-16 15:05:10 5F67586FFD23EBEF5C074296AA1E0F76 17560352 ----a-w- C:\Windows\SysWOW64\nvcompiler.dll 2014-01-16 14:15:24 AD27563BC16AB1EAACAE3033E99C2F78 194048 ----a-w- C:\Windows\SysWOW64\elshyph.dll 2014-01-16 14:15:05 FB0D1CC2911A0645DDA6C0608473EB55 34816 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-16 14:15:05 F705F52FC41577641E82B9934728B02C 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-01-16 14:15:05 D9F12F54E3B5A092F1D5F191F5286E53 337408 ----a-w- C:\Windows\SysWOW64\html.iec 2014-01-16 14:15:05 C1A6E565B2782C09BC40AD749B46D9ED 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-16 14:15:05 B68750104FBA545C633B7E9AEA660208 2166272 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-01-16 14:15:05 B5EB5BD3066959611E1F7A80FD6CC172 1818112 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-01-16 14:15:05 9E170B0AF156B478BD2B1FD6A2250C9E 62464 ----a-w- C:\Windows\SysWOW64\tdc.ocx 2014-01-16 14:15:05 9B8701A380CEE1B05D651B4ED4048C8F 645120 ----a-w- C:\Windows\SysWOW64\jsIntl.dll 2014-01-16 14:15:05 4A7956EE34BE56D20C54CF6A47693C25 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-01-16 14:15:05 44D5C650C971910827EA65B4D989ED94 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-01-16 14:15:05 2EE1E467D73642AFDDB03019F58C252B 1156608 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-01-16 14:15:05 298FDE634538B62CEEEC266D8773B21A 182272 ----a-w- C:\Windows\SysWOW64\msls31.dll 2014-01-16 14:15:05 22868FAAF9C851BFA924B8D7EDB6CBC1 11220992 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-01-16 14:15:05 08B56CF57B7CE44315034247CC76D0F1 244736 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-01-16 14:15:04 F862CD08F1AD4EE39BD506853F3C6103 16284 ----a-w- C:\Windows\SysWOW64\ieuinit.inf 2014-01-16 14:15:04 EC7038154490E50ACD405A022F51B204 83456 ----a-w- C:\Windows\SysWOW64\inseng.dll 2014-01-16 14:15:04 CFCE4EFF1D6D909EE2EA3AFCB8F1E677 233472 ----a-w- C:\Windows\SysWOW64\url.dll 2014-01-16 14:15:04 C3B0DBD04CC18574B0706CA119902474 367104 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-01-16 14:15:04 C17139EAF939964142C7A1AEEE02DC81 616104 ----a-w- C:\Windows\SysWOW64\ieapfltr.dat 2014-01-16 14:15:04 BE8B10D84DDD8F43A32EE013B54F5287 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-01-16 14:15:04 AB3B2CA52AFB695AFCDD2620A21E5B21 24576 ----a-w- C:\Windows\SysWOW64\licmgr10.dll 2014-01-16 14:15:04 9A33FDDD687A836A1FD478B43C5A95FD 151552 ----a-w- C:\Windows\SysWOW64\iexpress.exe 2014-01-16 14:15:04 81A605B0F3A29A117AB83A08D40F772F 1926656 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-01-16 14:15:04 71144A47CD02FDDC77DDF5EB5315767F 523776 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-01-16 14:15:04 6A92CEC8532056791C6832B2725D170D 139264 ----a-w- C:\Windows\SysWOW64\wextract.exe 2014-01-16 14:15:04 6A794439B6612E43FEDE0217C919B652 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-01-16 14:15:04 6922D7ED84AE102504174922D5D42F49 238288 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-01-16 14:15:04 64831CAD496A073398853A34A5813675 69632 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-01-16 14:15:04 5DFE55E0221F0C5FA4D6CECFA72B1D78 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-01-16 14:15:04 4F032F1FDEFEA5EC8EEA3562643B5EE8 69120 ----a-w- C:\Windows\SysWOW64\icardie.dll 2014-01-16 14:15:04 433161597584186EF806EFC8EA530433 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-01-16 14:15:04 2AF48780D879AFC43733159CB29CD8BD 1051136 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-16 14:15:04 03B3541AE6986602CF9CB5B3AD169C33 208384 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2014-01-16 14:15:03 F9F114B2A6F876C92D317A755494F233 17142784 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-01-16 14:15:03 F8DE2F74CD4323BABBDACAADD9A39254 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-01-16 14:15:03 F7B6E341F4B1947BEC0E14EEBE3C627E 111616 ----a-w- C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-16 14:15:03 BC2C13A3B664B686DA52D558FE5502FC 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-01-16 14:15:03 AE6A2C5ECD3E96556E22F12816842F60 48640 ----a-w- C:\Windows\SysWOW64\mshtmler.dll 2014-01-16 14:15:03 AE254DBF16E3E3D7C35ED017B4B55EC6 4240384 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-01-16 14:15:03 ABDFC692D9FE43E2BA8FE6CB5A8CB95A 13312 ----a-w- C:\Windows\SysWOW64\mshta.exe 2014-01-16 14:15:03 887055A3C8DD6C87D200D11EAFDBD45B 74240 ----a-w- C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-16 14:15:03 809804D8AED97AEA96B3D4B66A4C5C70 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-01-16 14:15:03 779E142FE2159935E78C0FA2E190FF1E 610304 ----a-w- C:\Windows\SysWOW64\jscript.dll 2014-01-16 14:15:03 6EB0B7301E00F717BD68A742D1391FAF 36352 ----a-w- C:\Windows\SysWOW64\imgutil.dll 2014-01-16 14:15:03 5EC13202430A3EB68DFF44CF1FEEA2BE 61952 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-16 14:15:03 55969AADF0210A614700F89B48976F68 43008 ----a-w- C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-16 14:15:03 53FC62C51CB18C9100A7DFAF2D2A6C47 12800 ----a-w- C:\Windows\SysWOW64\msfeedssync.exe 2014-01-16 14:15:03 4D4726D1AD5ED1590A62685F92900594 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-16 14:15:03 4BCC7EB5F20840DA67943BD86AE95735 56832 ----a-w- C:\Windows\SysWOW64\pngfilt.dll 2014-01-16 14:15:03 1AFBAA54BDF637F69B8E02A5578286B0 116736 ----a-w- C:\Windows\SysWOW64\iepeers.dll 2014-01-16 14:15:03 1200D9C7DB0ADC1B8143A0A9921BF7DA 127488 ----a-w- C:\Windows\SysWOW64\occache.dll 2014-01-16 14:15:02 83F49FD1BC0A999B006D564C540C7258 86016 ----a-w- C:\Windows\SysWOW64\iesysprep.dll 2014-01-16 11:37:12 02DF0628BE8B64B84D50FBE53549AA3B 12625408 ----a-w- C:\Windows\SysWOW64\wmploc.DLL 2014-01-16 11:37:11 6C4B2E1A25841077084EB9F76FF6FFA7 11410432 ----a-w- C:\Windows\SysWOW64\wmp.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-01-16 15:05:13 DF2393DCDA345251F6CC0F59D5AE6DBF 31520 ----a-w- C:\Windows\Sysnative\nvhdap64.dll 2014-01-16 15:05:13 B99F55FC24FC321036BAD3F025DE5EB1 1515296 ----a-w- C:\Windows\Sysnative\nvhdagenco6420103.dll 2014-01-16 15:05:13 1675579489A3CC59B0A2ED3C1514E883 74016 ----a-w- C:\Windows\Sysnative\nvapo64v.dll 2014-01-16 15:05:11 D22521804E3CB0DFB4FCB11A0E2A0CFF 879392 ----a-w- C:\Windows\Sysnative\NvFBC64.dll 2014-01-16 15:05:11 CBF3BF5CFA0AB6D77AB59272605F625B 1884448 ----a-w- C:\Windows\Sysnative\nvdispco6433221.dll 2014-01-16 15:05:11 96E23AC6B6E6007CC2B42C9FE2BD4E69 3132704 ----a-w- C:\Windows\Sysnative\nvcuvid.dll 2014-01-16 15:05:11 8C0E8871D4E2FFAB20319FB4162FDA00 11554264 ----a-w- C:\Windows\Sysnative\nvopencl.dll 2014-01-16 15:05:11 55DFCF0031E7257E3DE83E219DC49E8B 882464 ----a-w- C:\Windows\Sysnative\NvIFR64.dll 2014-01-16 15:05:11 334ECC4245D7E8A648D338E325E11C57 3125024 ----a-w- C:\Windows\Sysnative\nvcuvenc.dll 2014-01-16 15:05:11 328D7B3C63E21B9B0D557484F99C177F 1511712 ----a-w- C:\Windows\Sysnative\nvdispgenco6433221.dll 2014-01-16 15:05:11 006A27B58271126AD1D58302666F1471 30372640 ----a-w- C:\Windows\Sysnative\nvoglv64.dll 2014-01-16 15:05:10 CD4EC143C035E069B40775197336DD1A 25257248 ----a-w- C:\Windows\Sysnative\nvcompiler.dll 2014-01-16 15:05:10 10A5FF3ACDBA9289381772C5535CB55C 11605752 ----a-w- C:\Windows\Sysnative\nvcuda.dll 2014-01-16 14:15:24 344DA9D196C0D98A738289BB09CE4CF6 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-01-16 14:15:05 8F7FBD0177F79727CF945ABDA657A0AC 235008 ----a-w- C:\Windows\Sysnative\elshyph.dll 2014-01-16 14:15:02 E6CB36B85BE59095337427E853A5B65A 2332160 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-01-16 14:15:02 E4A6577D74B2439974C8018AB5F1BFEA 13312 ----a-w- C:\Windows\Sysnative\msfeedssync.exe 2014-01-16 14:15:02 D31AE751B6DACAFD0D7CC99EAE9606C2 131072 ----a-w- C:\Windows\Sysnative\IEAdvpack.dll 2014-01-16 14:15:02 6F1AF8E1206E92256459E3012C20472A 942592 ----a-w- C:\Windows\Sysnative\jsIntl.dll 2014-01-16 14:15:02 5BECC17076F1806F60BB259B654FAC5C 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-01-16 14:15:02 43D9CE875F8FC8370C6BA2F74D50D01C 1394176 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-01-16 14:15:02 4399857346DD183683332921500046B1 86016 ----a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe 2014-01-16 14:15:02 3168FA85740503BAE77DB821CB3EE4FB 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-01-16 14:15:02 2EBD0C5B090125AECF017C57344C45AB 247808 ----a-w- C:\Windows\Sysnative\msls31.dll 2014-01-16 14:15:02 092F3E7D054FDF779054E29A0A0D4267 2764288 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-01-16 14:15:02 038ABC9BCC86DFF9E181D44E43E2CEBA 52224 ----a-w- C:\Windows\Sysnative\msfeedsbs.dll 2014-01-16 14:15:01 FB9459892AF2AD60BDA98F820C1A28C3 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-01-16 14:15:01 F862CD08F1AD4EE39BD506853F3C6103 16284 ----a-w- C:\Windows\Sysnative\ieuinit.inf 2014-01-16 14:15:01 E36FDC470352C8F351F31959619CADD8 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-01-16 14:15:01 D6C88A6094D1FDAC56A186BBD7F06357 40448 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-01-16 14:15:01 D36A88D22B843C3812B501434E5A67A0 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-01-16 14:15:01 CE8831D2DCB5803A4CBC8EDCCBBC2A05 77312 ----a-w- C:\Windows\Sysnative\tdc.ocx 2014-01-16 14:15:01 C92173481A58935BE15172079CF122B8 235520 ----a-w- C:\Windows\Sysnative\url.dll 2014-01-16 14:15:01 C70F72684CDCF9BB142F50F98BB1DD9C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-01-16 14:15:01 C6ECA2F7A1B189025171E6A29F2605AA 453120 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-01-16 14:15:01 C17139EAF939964142C7A1AEEE02DC81 616104 ----a-w- C:\Windows\Sysnative\ieapfltr.dat 2014-01-16 14:15:01 B99C7CC6ED6917E3035A12171F40D240 5765120 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-01-16 14:15:01 95951E6A277F78FA13A85F2F408F4C0B 12995584 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-01-16 14:15:01 5FAC15F872026BBC31C11D3A32B84624 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-01-16 14:15:01 5141B67F14E2B6CBB6ADF851ABE364A5 90112 ----a-w- C:\Windows\Sysnative\SetIEInstalledDate.exe 2014-01-16 14:15:01 3A4FD19F13F8809BA08E9F76C0E38832 413696 ----a-w- C:\Windows\Sysnative\html.iec 2014-01-16 14:15:01 2405D24AA28CCC4CC7E0CC0AE008746F 48640 ----a-w- C:\Windows\Sysnative\mshtmler.dll 2014-01-16 14:15:01 0FBEBD36FEFFEE5AF25FDAEE5E35EE99 105984 ----a-w- C:\Windows\Sysnative\iesysprep.dll 2014-01-16 14:15:01 0A9D5716CB1F3AFA73703F39647BB8C2 81408 ----a-w- C:\Windows\Sysnative\icardie.dll 2014-01-16 14:15:01 05018A4E76F1636EFBB7DCB76900872A 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-01-16 14:15:01 0134898497B6C6CD50F7FC5DE85712A6 296960 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-01-16 14:15:00 FD61D51199F3FC9EB0023FBF405EAAD0 147968 ----a-w- C:\Windows\Sysnative\occache.dll 2014-01-16 14:15:00 F00AE7B953ABEF1B53FBBA187DFC8238 243200 ----a-w- C:\Windows\Sysnative\webcheck.dll 2014-01-16 14:15:00 EE10AB99A480875E012CA339EC48F02B 1228800 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2014-01-16 14:15:00 E949B344680691F255C0E662D4B5BFF1 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-01-16 14:15:00 D233E1A32CE6AF918C9DE1BC44AFEB2A 23212032 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-01-16 14:15:00 CC84F4E36AA96810AD766C88DD657ADB 626176 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-01-16 14:15:00 A8C830CABD7640EE8E6F0F1019F91E83 548352 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-01-16 14:15:00 9675B272086CF5D22B83B541FAA8D4EA 30208 ----a-w- C:\Windows\Sysnative\licmgr10.dll 2014-01-16 14:15:00 77FBE2E014EFB93FD037FA33AB8C7D6E 263376 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-01-16 14:15:00 68899208A26E4522D25DBA87FF2E98D1 84992 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-01-16 14:15:00 612DC699EBF0AA1AAA065898D33B553A 1993728 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-01-16 14:15:00 5BBDBE5EBB49EA7C76A2EE7490A45D68 101376 ----a-w- C:\Windows\Sysnative\inseng.dll 2014-01-16 14:15:00 5A54ED24D5D42102A64904809215E0DC 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-01-16 14:15:00 46FD16F9B1924A2EA8CD5C6716CC654F 167424 ----a-w- C:\Windows\Sysnative\iexpress.exe 2014-01-16 14:15:00 1EA6500C25A80E8BDB65099C509AF993 143872 ----a-w- C:\Windows\Sysnative\wextract.exe 2014-01-16 14:14:59 F34C20D099CF94A606A2B5B0C668B570 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-01-16 14:14:59 E70D4270C43CE6C46841B684315B9EFF 62464 ----a-w- C:\Windows\Sysnative\pngfilt.dll 2014-01-16 14:14:59 BB6DEAFAC5F0AAEC37FEAF3F3AA48347 774144 ----a-w- C:\Windows\Sysnative\jscript.dll 2014-01-16 14:14:59 ADA5C3D49A12CED9F07913DC00E547A8 48128 ----a-w- C:\Windows\Sysnative\imgutil.dll 2014-01-16 14:14:59 9870EC900829595D191BB03C6C48B479 83968 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-01-16 14:14:59 95828D670CFD3B16EE188168E083C3C5 13824 ----a-w- C:\Windows\Sysnative\mshta.exe 2014-01-16 14:14:59 45152BA21450811F4619C9C1790E7353 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-01-16 14:14:59 3AFA03119583647136C49B80DAD38F19 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-01-16 14:14:59 1FCBE949A67939ADEAE7279E423AA684 135680 ----a-w- C:\Windows\Sysnative\iepeers.dll 2014-01-16 12:03:16 F2BF71FCEAB8FB8A691408C478E2FF4C 3156480 ----a-w- C:\Windows\Sysnative\win32k.sys 2014-01-16 11:37:12 AB272BBFB05A8585C3405EFA9F605774 12625920 ----a-w- C:\Windows\Sysnative\wmploc.DLL 2014-01-16 11:37:10 8CBBB27369F9F07BC5E874E750EAF9D0 14631424 ----a-w- C:\Windows\Sysnative\wmp.dll ====== C:\Windows\Sysnative\drivers ===== 2014-01-16 15:05:16 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\Windows\Sysnative\drivers\nvvad64v.sys 2014-01-16 15:05:13 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\Windows\Sysnative\drivers\nvhda64v.sys 2014-01-16 15:05:11 0218E1CE8F7B5D404980192B9112D03A 12645664 ----a-w- C:\Windows\Sysnative\drivers\nvlddmkm.sys 2014-01-16 12:31:33 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2014-01-16 12:03:20 DCA68B0943D6FA415F0C56C92158A83A 99840 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-01-16 12:03:20 18A85013A3E0F7E1755365D287443965 53248 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-01-16 12:03:19 FFA06EF43987ED0DD42AD59B260C0C78 7808 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-01-16 12:03:19 DD253AFC3BC6CBA412342DE60C3647F3 30720 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-01-16 12:03:19 8D1196CFBB223621F2C67D45710F25BA 343040 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-01-16 12:03:19 765A92D428A8DB88B960DA5A8D6089DC 25600 ----a-w- C:\Windows\Sysnative\drivers\usbohci.sys 2014-01-16 12:03:19 12FEB33791920678F8433701C822BCFD 325120 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-01-16 12:01:29 3555BA97171CD153118F73FDCCC8BFDE 376768 ----a-w- C:\Windows\Sysnative\drivers\netio.sys ====== C:\Windows\Tasks ====== 2014-01-16 12:51:10 415F9C52A56AE58DBA1EB206FE3F1D00 3186 ----a-w- C:\Windows\Sysnative\Tasks\P4GIntlCtrl ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-01-16 13:41:40 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-01-16 12:06:16 -------- d-----w- C:\PROGRA~2\Microsoft XNA ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2014-01-16 12:31:13 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Programs ====== C:\Users\Gebruiker ====== 2014-01-16 13:40:51 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Gebruiker\Desktop\RSITx64.exe ====== C: exe-files == 2014-01-16 16:16:44 B96D9ACD9D4AAC1F231D66AB8D02AB17 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1453884697-2928237095-1140060775-1001\$IFODT42.exe 2014-01-16 15:48:56 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\$Recycle.Bin\S-1-5-21-1453884697-2928237095-1140060775-1001\$RFODT42.exe 2014-01-16 15:11:34 900B47792F30734A2805395EBEBB705E 1194784 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvxdsync.exe 2014-01-16 15:11:34 1E00A0A539E7C30DD418E774428BA35B 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\setup.exe 2014-01-16 15:11:32 B7973C405247C5A44BA46B12A4B7AEEA 922912 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvvsvc.exe 2014-01-16 15:11:31 556A74975E52F0853FCE02C05F83F9FF 2448160 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\NvTray.exe 2014-01-16 15:11:30 8E3B16C9BADBEAC35F92F4553E38B171 63264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvSmartMaxapp64.exe 2014-01-16 15:11:30 3C7224A0D1F629EB9B2BC2A79D86CAAE 63264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvSmartMaxapp.exe 2014-01-16 15:11:23 0FCBAB692485A4B867AC5EF896A2ED55 6866208 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvcplui.exe 2014-01-16 15:10:28 1E00A0A539E7C30DD418E774428BA35B 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{CBB17961-0EDC-40A1-91E0-396188DE45EC}\setup.exe 2014-01-16 15:08:36 AB3ADA6637B288371093B16BFBC9651A 266633424 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\332.21-notebook-win8-win7-64bit-international-whql-g.exe 2014-01-16 15:08:35 A2974CA40BC4457255E1B60F06BCC50C 30502520 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\GeForce_Experience_Update_v1.8.1.0.exe 2014-01-16 15:06:01 8629990396B6FA011E27B46ED6AC4BDB 808224 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\nvStInst.exe 2014-01-16 15:05:40 B942824E4901D50834EEB441BE98AB9A 1785120 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\nvspcaps64.exe 2014-01-16 15:05:40 94397226B4D18C9E62DC943A9CF6A487 1475360 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\nvspcaps.exe 2014-01-16 15:05:40 041DADF180B8175D06CBB6C442F4D960 540448 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\DXSETUP.exe 2014-01-16 15:05:36 336DF94267FC40D147FC3AC8798DFA73 87328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.LEDVisualizer.{72BD2562-2CB9-4A92-8CA6-4D507C7F5581}\NvLedServiceHost.exe 2014-01-16 15:05:35 4A8B43D324521AEFCA813434B8AED3C2 127264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.LEDVisualizer.{72BD2562-2CB9-4A92-8CA6-4D507C7F5581}\NvLedVisualizer.exe 2014-01-16 15:05:25 62FE81A76C39AE1E37B9B1369B0B22CB 1015584 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{1240D026-2977-4C4F-A856-C5892C156182}\GFExperience.exe 2014-01-16 15:05:23 031A21DE7D208C6A2BAF75BE1B51426C 596768 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{1240D026-2977-4C4F-A856-C5892C156182}\7z.exe 2014-01-16 15:05:22 6AA2CC058B79B3C73ECB0C008F867DB0 636232 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\SteamLauncher\NVIDIA.SteamLauncher.exe 2014-01-16 15:05:20 3C447C228DEAC197E5D245474C404DB3 3063072 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\x86\server\nvstreamer.exe 2014-01-16 15:05:20 0F4FE8097C56739DA9A8BD71DF868981 14658848 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\x86\server\nvstreamsvc.exe 2014-01-16 15:05:18 68DE8D996D8FF628AB6B3D422035F862 15129376 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\amd64\server\nvstreamsvc.exe 2014-01-16 15:05:18 0CD3924E6EA85D62E4883796275C21FB 3960096 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\amd64\server\nvstreamer.exe 2014-01-16 15:05:17 A0012C1D9B8648C20C00202418B9D02F 2279712 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Update.Core.{B90EFFB4-C24B-4690-A30B-8A8278521F1C}\NvBackend.exe 2014-01-16 15:05:17 1F899DC290F02F7F0482F610C2873D61 194888 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Update.Core.{B90EFFB4-C24B-4690-A30B-8A8278521F1C}\WLMerger.exe 2014-01-16 15:05:13 903A40C958D471F9D30D29FA6D2800A4 1494304 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Network.Service.{745F2990-9A2B-4D3C-891B-90FE26E294C5}\NVNetworkService.exe 2014-01-16 15:05:13 82397849C695A1D86DE86AEE488BC9DA 23639304 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.3DVision.{415321A8-A5C4-4C61-9319-30E4AA9C6157}\3DVision_332.21.exe 2014-01-16 15:05:10 1ED211177754B06F6A1B923B52516FA6 74267360 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{EBD3978D-5FEE-47C9-8811-6C05A4B86E33}\NvCplSetupInt.exe 2014-01-16 15:05:09 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{EBD3978D-5FEE-47C9-8811-6C05A4B86E33}\dbInstaller.exe 2014-01-16 15:05:09 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe 2014-01-16 15:03:15 7495C8A57D0494D4371CD06A496B54CD 412960 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{8B89A600-61C6-4FE2-BFF7-B13663A2D22B}\setup.exe 2014-01-16 14:22:35 CC6CC1E54EE9EE46ACD124BC715B4D9A 486176 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nvTaskBar.exe 2014-01-16 14:22:35 8883E5C1820810403F610BE9A5962828 2747680 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nwiz.exe 2014-01-16 14:22:35 7495C8A57D0494D4371CD06A496B54CD 412960 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\setup.exe 2014-01-16 14:22:35 68DE8D996D8FF628AB6B3D422035F862 15129376 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\nvstreamsvc.exe 2014-01-16 14:22:35 3C447C228DEAC197E5D245474C404DB3 3063072 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\nvstreamer.exe 2014-01-16 14:22:35 1F899DC290F02F7F0482F610C2873D61 194888 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Update.Core\WLMerger.exe 2014-01-16 14:22:35 0F4FE8097C56739DA9A8BD71DF868981 14658848 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\nvstreamsvc.exe 2014-01-16 14:22:35 0CD3924E6EA85D62E4883796275C21FB 3960096 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\nvstreamer.exe 2014-01-16 14:22:34 B942824E4901D50834EEB441BE98AB9A 1785120 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\nvspcaps64.exe 2014-01-16 14:22:34 94397226B4D18C9E62DC943A9CF6A487 1475360 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\nvspcaps.exe 2014-01-16 14:22:34 903A40C958D471F9D30D29FA6D2800A4 1494304 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Network.Service\NVNetworkService.exe 2014-01-16 14:22:34 6AA2CC058B79B3C73ECB0C008F867DB0 636232 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\SteamLauncher\NVIDIA.SteamLauncher.exe 2014-01-16 14:22:34 4A8B43D324521AEFCA813434B8AED3C2 127264 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\LEDVisualizer\NvLedVisualizer.exe 2014-01-16 14:22:34 336DF94267FC40D147FC3AC8798DFA73 87328 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\LEDVisualizer\NvLedServiceHost.exe 2014-01-16 14:22:26 1ED211177754B06F6A1B923B52516FA6 74267360 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.Driver\NvCplSetupInt.exe 2014-01-16 14:22:25 E84A135B0CB2CACA91097BE598B2A937 802080 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nvAppBar.exe 2014-01-16 14:22:25 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.Driver\dbInstaller.exe 2014-01-16 14:22:25 A0012C1D9B8648C20C00202418B9D02F 2279712 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Update.Core\NvBackend.exe 2014-01-16 14:22:25 62FE81A76C39AE1E37B9B1369B0B22CB 1015584 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience\GFExperience.exe 2014-01-16 14:22:25 53406E9988306CBD4537677C5336ABA4 889416 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\MS.NET\dotNetFx40_Full_setup.exe 2014-01-16 14:22:25 041DADF180B8175D06CBB6C442F4D960 540448 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\DXSETUP.exe 2014-01-16 14:22:25 031A21DE7D208C6A2BAF75BE1B51426C 596768 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience\7z.exe 2014-01-16 14:22:23 82397849C695A1D86DE86AEE488BC9DA 23639304 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVision\3DVision_332.21.exe 2014-01-16 14:15:05 ED45D1C3FDA215374FBCFC161A57AA80 467456 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-01-16 14:15:05 CC02FE4520CA886508069245D9A6962F 222720 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-01-16 14:15:05 C8A8321292A459B0A17FB39A782A5C74 806096 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-01-16 14:15:03 7F7F391491C315A4A72EFCAC0D34FA93 25600 ----a-w- C:\Program Files (x86)\Internet Explorer\ExtExport.exe 2014-01-16 14:15:02 0685765C0CBE095BA0C6C8790BAE21EF 804560 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-01-16 14:15:01 D68007F924B9F387AA7C76F48D0A260A 223232 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-01-16 14:15:01 70D721CC971A9EFFCF7845CEFBB02704 480256 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-01-16 14:15:01 41F922D6A794C0F8425C8436D7077C84 359632 ----a-w- C:\Program Files\Internet Explorer\iediagcmd.exe 2014-01-16 13:41:41 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruiker.exe 2014-01-16 12:54:23 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe 2014-01-16 12:52:45 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXYKSRKM\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe 2014-01-16 12:30:53 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXYKSRKM\mbam-setup-1.75.0.1300.exe 2014-01-16 11:37:13 D21DD7BFC81C8623DE48EBB17133D59C 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2014-01-16 11:37:13 9AED8E824CF5FAAB67957EDBC5512060 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2014-01-16 11:30:11 CA29059459C98937578B0F6B45E56E0F 3110568 ----a-w- C:\Users\Gebruiker\AppData\Local\NVIDIA\NvBackend\Packages\000056e3\dao.17646152.exe === C: other files == 2014-01-16 15:05:16 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{B497EE22-DE60-4ADA-A83D-DF18077CBF6F}\nvvad64v.sys 2014-01-16 15:05:15 DAC9726D9C90631D6A1C0ECAA0226021 34080 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{B497EE22-DE60-4ADA-A83D-DF18077CBF6F}\nvvad32v.sys 2014-01-16 15:05:13 F4992A26D629288ADBBDC3A715629FA1 163104 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda64.sys 2014-01-16 15:05:13 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda64v.sys 2014-01-16 15:05:13 9F8EE4948B7ADD9D12F778F61A2758A4 162592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda32v.sys 2014-01-16 15:05:13 47FEB587AAE06F6717FCABF8BCF184FD 129312 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda32.sys 2014-01-16 14:23:05 F4992A26D629288ADBBDC3A715629FA1 163104 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda64.sys 2014-01-16 14:23:05 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda64v.sys 2014-01-16 14:23:05 DAC9726D9C90631D6A1C0ECAA0226021 34080 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NvVAD\nvvad32v.sys 2014-01-16 14:23:05 C7C75E4D199802EFCE0BEC2F6F823E31 451872 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb64.sys 2014-01-16 14:23:05 9F8EE4948B7ADD9D12F778F61A2758A4 162592 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda32v.sys 2014-01-16 14:23:05 47FEB587AAE06F6717FCABF8BCF184FD 129312 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda32.sys 2014-01-16 14:23:05 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NvVAD\nvvad64v.sys 2014-01-16 14:23:05 0819597CF50E316819493C7A832EDAEC 435232 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb32.sys 2014-01-16 12:53:10 AB51E1F08C8E789D6C9E8B94D15BE9A9 340432 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys 2014-01-16 12:53:10 000D82CC258E2D341605A6F350C4D1E6 606672 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Windows\CurrentVersion\Run] "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Steam"="D:\Program Files\Steam\Steam.exe -silent" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "EA Core"="C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HControlUser"="C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe" "ATKOSD2"="C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" "ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "MDS_Menu"="C:\Program Files (x86)\Cyberlink\MediaShowEspresso\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\MediaShowEspresso UpdateWithCreateOnce Software\CyberLink\MediaShow Espresso\5.0" "PDVD9LanguageShortcut"="C:\Program Files (x86)\Cyberlink\PowerDVD9\Language\Language.exe" "RemoteControl9"="C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5" "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0" "UpdatePDRShortCut"="C:\Program Files (x86)\Cyberlink\PowerDirector\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\PowerDirector UpdateWithCreateOnce Software\CyberLink\PowerDirector\7.0" "UpdatePSTShortCut"="C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\DVD Suite UpdateWithCreateOnce Software\CyberLink\PowerStarter" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "WinampAgent"="C:\Program Files (x86)\Winamp\winampa.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Steam"="D:\Program Files\Steam\Steam.exe -silent" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "EA Core"="C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "EeeStorageBackup"="C:\Program Files (x86)\ASUS\Asus WebStorage\BackupService.exe" "AmIcoSinglun64"="C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" "ETDWare"="C:\Program Files\Elantech\ETDCtrl.exe" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" "hkey"="HKLM" "item"="Adobe Reader Speed Launcher" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ADSMTray] "command"="C:\\Program Files (x86)\\ASUS\\ASUS Data Security Manager\\ADSMTray.exe" "hkey"="HKLM" "item"="ADSMTray" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUS Screen Saver Protector] "command"="C:\\Windows\\AsScrPro.exe" "hkey"="HKLM" "item"="ASUS Screen Saver Protector" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer] "command"="\"C:\\Program Files (x86)\\CyberLink\\Power2Go\\CLMLSvc.exe\"" "hkey"="HKLM" "item"="CLMLServer" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISW] "command"="C:\\Program Files\\CheckPoint\\ZAForceField\\ForceField.exe /icon=\"hidden\"" "hkey"="HKLM" "item"="ISW" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s" "hkey"="HKLM" "item"="RtHDVCpl" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14-12-2013 00:52] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\ACMON" [C:\Program Files (x86)\ASUS\Splendid\ACMON.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\ASPG" [C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe] "C:\Windows\SysNative\tasks\ASUS Live Update" [C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe] "C:\Windows\SysNative\tasks\ASUS P4G" [C:\Program Files\P4G\BatteryLife.exe] "C:\Windows\SysNative\tasks\ASUS SmartLogon Console Sensor" [C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe] "C:\Windows\SysNative\tasks\ASUSControlDeck" [C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe"] "C:\Windows\SysNative\tasks\P4G Sidebar" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\P4GIntlCtrl" [C:\Program Files\P4G\IntlCtrl.exe] "C:\Windows\SysNative\tasks\WC3" [C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe] "C:\Windows\SysNative\tasks\{07ECAF20-A744-435A-AE62-C44D731143C3}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\{5325319D-9CFC-442D-B104-BE3D74AD6ACD}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\{677916E2-546F-46A6-92EE-615BB0FC3AF8}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF" [25-11-2013 15:28] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx[28-11-2013 14:56] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=42 folders=17 7508763 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\Gebruiker\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on do 16-01-2014 at 18:08:29,47 ======================
  12. Dit is het log bestand: Logfile of random's system information tool 1.09 (written by random/random) Run by Gebruiker at 2014-01-16 14:41:40 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 18 GB (15%) free of 119 GB Total RAM: 4095 MB (49% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:42:27, on 16-1-2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16750) Boot mode: Normal Running processes: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files\trend micro\Gebruiker.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: ZoneAlarm Security - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: AutorunsDisabled O4 - Global Startup: AutorunsDisabled O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Mystery%20P.I.%20-%20The%20Curious%20Case%20of%20Counterfeit%20Cove/Images/stg_drm.ocx O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files%20(x86)/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing) O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) - Unknown owner - C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 11841 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch "C:\Windows\system32\nvvsvc.exe" "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup "C:\Program Files\HitmanPro\hmpsched.exe" C:\Windows\system32\svchost.exe -k NetworkService "C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe" "C:\Program Files\ATKGFNEX\GFNEXSrv.exe" C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files\Bonjour\mDNSResponder.exe" C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" "C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe" "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL mmsys.cpl "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" WLIDSvcM.exe 2560 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe /Embedding "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\Windows\system32\nvvsvc.exe -session -first "taskhost.exe" "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray "C:\Windows\system32\Dwm.exe" C:\Windows\Explorer.EXE "C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe" "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe" /c /a /s UserSession2 \??\C:\Windows\system32\conhost.exe "-1483280548-198802752316634342191495978215-155972201320284151012048640709-145506585 taskeng.exe {4FC7BF28-F9D3-4EAA-9CC6-52EB63A109E1} "C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe" "C:\Program Files\P4G\BatteryLife.exe" "C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe" "C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe" "C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" "C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe" "C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe" "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1 ATKOSD.exe KBFiltr.exe WDC.exe "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe" "C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe" "C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" "C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe" "C:\Program Files\Internet Explorer\iexplore.exe" https://get3.adobe.com/nl/flashplayer/update/activex "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4624 CREDAT:267521 /prefetch:2 C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe -Embedding C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true C:\Windows\system32\svchost.exe -k SDRSVC "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4624 CREDAT:988458 /prefetch:2 C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe "C:\Users\Gebruiker\Desktop\RSITx64.exe" ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll [2013-05-31 509776] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL [2013-04-09 387040] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-22 463272] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] ZoneAlarm Security Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-22 171944] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {91da5e8a-3318-4f8c-b67e-5964de3ab546} - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll [2013-05-31 509776] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [2013-07-27 1028896] "NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2013-11-29 2273056] "ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2013-11-29 1096480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [2009-12-08 3058304] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe /icon=hidden [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-29 8123936] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "HControlUser"=C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [2009-06-19 105016] "ATKOSD2"=C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [2009-10-09 6937216] "ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [2009-08-20 170624] "NPSStartup"= [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro35Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-01-16 14:41:40 ----D---- C:\rsit 2014-01-16 14:41:40 ----D---- C:\Program Files\trend micro 2014-01-16 13:32:00 ----D---- C:\Users\Gebruiker\AppData\Roaming\Malwarebytes 2014-01-16 13:31:34 ----D---- C:\ProgramData\Malwarebytes 2014-01-16 13:31:33 ----A---- C:\Windows\system32\drivers\mbam.sys 2014-01-16 13:31:32 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-16 13:06:16 ----D---- C:\Program Files (x86)\Microsoft XNA 2014-01-16 13:03:41 ----D---- C:\Program Files\CCleaner 2014-01-16 12:37:12 ----A---- C:\Windows\SYSWOW64\wmploc.DLL 2014-01-16 12:37:12 ----A---- C:\Windows\system32\wmploc.DLL 2014-01-16 12:37:11 ----A---- C:\Windows\SYSWOW64\wmp.dll 2014-01-16 12:37:10 ----A---- C:\Windows\system32\wmp.dll 2014-01-16 12:34:19 ----A---- C:\Windows\SYSWOW64\ieui.dll 2014-01-16 12:34:19 ----A---- C:\Windows\system32\ieui.dll 2014-01-16 12:34:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iesysprep.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iesysprep.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iesetup.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iernonce.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\ie4uinit.exe 2014-01-16 12:34:16 ----A---- C:\Windows\system32\iertutil.dll 2014-01-16 12:34:15 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2014-01-16 12:34:15 ----A---- C:\Windows\SYSWOW64\jscript.dll 2014-01-16 12:34:15 ----A---- C:\Windows\system32\msfeeds.dll 2014-01-16 12:34:15 ----A---- C:\Windows\system32\jscript.dll 2014-01-16 12:34:14 ----A---- C:\Windows\system32\jscript9.dll 2014-01-16 12:34:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2014-01-16 12:34:13 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2014-01-16 12:34:13 ----A---- C:\Windows\system32\urlmon.dll 2014-01-16 12:34:11 ----A---- C:\Windows\SYSWOW64\wininet.dll 2014-01-16 12:34:11 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2014-01-16 12:34:11 ----A---- C:\Windows\system32\jsproxy.dll 2014-01-16 12:34:10 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2014-01-16 12:34:10 ----A---- C:\Windows\system32\wininet.dll 2014-01-16 12:34:08 ----A---- C:\Windows\system32\ieframe.dll 2014-01-16 12:34:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-01-16 12:34:05 ----A---- C:\Windows\system32\mshtml.dll ======List of files/folders modified in the last 1 month====== 2014-01-16 14:41:40 ----RD---- C:\Program Files 2014-01-16 14:41:26 ----D---- C:\Windows\Temp 2014-01-16 14:07:30 ----D---- C:\Windows\system32\config 2014-01-16 13:55:11 ----D---- C:\Windows\System32 2014-01-16 13:55:11 ----D---- C:\Windows\inf 2014-01-16 13:55:11 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-01-16 13:53:23 ----SHD---- C:\Windows\Installer 2014-01-16 13:51:16 ----SHD---- C:\System Volume Information 2014-01-16 13:51:10 ----D---- C:\Windows\system32\Tasks 2014-01-16 13:49:07 ----D---- C:\Windows\winsxs 2014-01-16 13:48:00 ----D---- C:\Windows\Panther 2014-01-16 13:47:26 ----D---- C:\Windows 2014-01-16 13:47:14 ----D---- C:\ProgramData\NVIDIA 2014-01-16 13:42:00 ----D---- C:\Windows\SysWOW64 2014-01-16 13:42:00 ----D---- C:\Program Files\Windows Media Player 2014-01-16 13:42:00 ----D---- C:\Program Files (x86)\Windows Media Player 2014-01-16 13:41:59 ----D---- C:\Program Files (x86)\Internet Explorer 2014-01-16 13:41:57 ----D---- C:\Program Files\Internet Explorer 2014-01-16 13:41:56 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-01-16 13:41:56 ----D---- C:\Windows\system32\nl-NL 2014-01-16 13:41:47 ----D---- C:\Windows\system32\DriverStore 2014-01-16 13:41:46 ----D---- C:\Windows\system32\drivers 2014-01-16 13:31:34 ----HD---- C:\ProgramData 2014-01-16 13:31:32 ----RD---- C:\Program Files (x86) 2014-01-16 13:25:15 ----SD---- C:\Users\Gebruiker\AppData\Roaming\Microsoft 2014-01-16 13:16:10 ----D---- C:\Users\Gebruiker\AppData\Roaming\Winamp 2014-01-16 13:16:07 ----D---- C:\Windows\Minidump 2014-01-16 13:16:07 ----D---- C:\Windows\Logs 2014-01-16 13:16:07 ----D---- C:\Windows\debug 2014-01-16 13:06:50 ----RSD---- C:\Windows\assembly 2014-01-16 13:02:56 ----D---- C:\Windows\system32\catroot 2014-01-16 13:02:52 ----D---- C:\Windows\system32\catroot2 2014-01-16 12:36:36 ----D---- C:\ProgramData\Microsoft Help ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2009-12-08 35384] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-06 408600] R0 ***laby;***laby; C:\Windows\system32\DRIVERS\***laby.sys [2009-06-18 15928] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2013-10-25 317808] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888] R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [2013-05-21 493656] R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [2013-05-23 1139800] R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20140110.001\BHDrvx64.sys [2014-01-10 1526488] R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [2013-04-16 169048] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-11-25 484952] R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20140115.001\IDSvia64.sys [2014-01-15 521944] R1 RapportCerberus_59849;RapportCerberus_59849; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [2014-01-16 606672] R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-10-25 284176] R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-10-25 399312] R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [2013-03-05 36952] R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [2013-03-05 224416] R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [2013-04-25 433752] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-25 137648] R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-09 140800] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-09-29 2005024] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-11-13 67072] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928] R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140115.032\ENG64.SYS [2014-01-16 126040] R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140115.032\EX64.SYS [2014-01-16 2099288] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-14 196384] R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-10-30 39200] R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400] R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [2013-05-16 796760] R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-07-21 177312] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] R4 RapportCerberus_56758;RapportCerberus_56758; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [2013-08-25 589872] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-22 48488] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832] S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-02-15 52736] S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008] R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2013-11-25 109352] R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [2013-05-21 144368] R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-11-29 1370912] R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-11-29 15128352] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-11-11 922912] R2 OberonGameConsoleService;Oberon Media Game Console service; C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [2009-09-15 44312] R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-10-25 1444120] R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096] S2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 359552] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-07 161384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-14 257416] S3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280] S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2013-05-31 641352] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-07 569768] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-06 1255736] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] -----------------EOF-----------------
  13. Op een notebook die wij hebben (windows 7 64 bit) staat nogal wat spyware zoals Conduite en Rocketfuel. Kunnen jullie helpen om dat te verwijderen? Bij voorbaat onze dank.
  14. Heel erg bedankt voor de hulp. De pc start weer een stuk vlugger op dan eerst.
  15. Er is alleen nog een probleem met het hoofdscherm van Norton Internet Security, dat na opstarten meteen weer verdwijnt. Maar dat zal niet samenhangen met een virus, maar naar ik vermoed met de interactie met een ander programma dat in het geheugen geladen is. Een tijdje terug had ik vergelijkbare problemen met andere programma's (die automatisch geminimaliseerd werden), en dat werd toen veroorzaakt door Samsung Magician (programma om de staat van een ssd in de gaten te houden).
  16. Logbestand van AdwCleaner: # AdwCleaner v3.016 - Report created 06/01/2014 at 08:52:34 # Updated 23/12/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Eigenaar - P55M-UD2 # Running from : C:\Users\Eigenaar\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\AGI Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freecorder Folder Deleted : C:\Windows\Freecorder Folder Deleted : C:\Users\Eigenaar\AppData\LocalLow\ZoneAlarm_Security Folder Deleted : C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freecorder ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject Key Deleted : HKLM\SOFTWARE\Classes\InstallerControl.InstallerObject.1 Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1060933 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2645238 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3015261 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_colin-mcrae-dirt_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_colin-mcrae-dirt_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4260E0CC-0F75-462E-88A3-1E05C248BF4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9E92257F-3F0A-451D-B231-6E2DB60CDC71} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4260E0CC-0F75-462E-88A3-1E05C248BF4C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4260E0CC-0F75-462E-88A3-1E05C248BF4C} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9E92257F-3F0A-451D-B231-6E2DB60CDC71} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1011A425-25FA-4972-B21B-06A5CD01E5ED} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED724667-4B38-4CC5-8615-8D3F0BE5BCDA} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3E18AAD-E335-471A-B3FE-7C1DB58AAE98} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4C38A8F-D5A6-4390-A42C-966FE2E0F3F4} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{1392B8D2-5C05-419F-A8F6-B9F15A596612}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}] Key Deleted : HKCU\Software\Ask&Record Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Freecorder Key Deleted : HKCU\Software\AppDataLow\Software\ZoneAlarm_Security Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Freecorder Key Deleted : HKLM\Software\ZoneAlarm_Security Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Freecorder Toolbar ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v27.0 (nl) [ File : C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\prefs.js ] [ File : C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default\prefs.js ] -\\ Google Chrome v [ File : C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [5387 octets] - [06/01/2014 08:10:34] AdwCleaner[s0].txt - [5212 octets] - [06/01/2014 08:52:34] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [5272 octets] ##########
  17. Het script in zoek.exe kon pas voltooid worden nadat ik windows in de veilige modus had gestart. Het log bestand van zoek.exe: Zoek.exe v5.0.0.0 Updated 23-December-2013 Tool run by Eigenaar on zo 05/01/2014 at 19:16:33,17. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Safe Mode MINIMAL No Internet Access Detected Launched: C:\Users\Eigenaar\Desktop\zoek\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-01-04-150027.log 1828 bytes C:\zoek-results2014-01-05-100903.log 410 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3ce45c4f-bfff-4988-9a3c-a75c1f491319} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{3ce45c4f-bfff-4988-9a3c-a75c1f491319} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default user.js not found ---- Lines CT1060933 removed from prefs.js ---- user_pref("CT1060933..clientLogIsEnabled", false); user_pref("CT1060933..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); user_pref("CT1060933..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); user_pref("CT1060933./9b+7e+x305.from_oldbar.enc", "JH4nQTM0NjN5RTo9KnIseXp+ejEoMztHSVNGLVhNUD0mPy0uMTVEO0ZOT1tWXmlbQm1iZVI7VEJDRklZUFtjfXN7blUhdXhlTm user_pref("CT1060933./9b+7e,x305.from_oldbar.enc", "JH4oQS8/Pjd5RTo9KnIseXt4fTEoMzxHSEAsV0xPPCU+LC4rL0M6RU5ZUFtXZ2pmQm1iRV5pVD1WREZDRltSXWZxbCFua1h9c2 user_pref("CT1060933./9b+7e-x305.from_oldbar.enc", "JH4pMnZBNjk3MzVFOX4/STsvdzF+ICUgNi04QkdKWFFaXFhdUF9ZOWRZXEkySzk6PzlQR1JcQXNoa2llZ3t5b217blUhdXhZJn user_pref("CT1060933./9b+7e06cg5el8:.from_oldbar.enc", "bm1pbnJvbHNveA=="); user_pref("CT1060933./9b+7e06cg5el;8i:k.from_oldbar.enc", "JH4tLyJqdHNvdHh1cnl1fiQvS0lHT0I1fV1cPQ=="); user_pref("CT1060933./9b+7e31;cj06?km\"mbe.from_oldbar.enc", "JH5hOT8jayV1dnB3dCsiLW9CUEVOM3s1PUNMWFovWk9SPzZBJGFWUVlUV1FKM0x5fE9GUTRxdGJWP1hIWlFcP2ts user_pref("CT1060933./9b+7e31;cj0b>d?\"mbe.from_oldbar.enc", "JH5hOT8jayV1c3ZyeSsiLW9CUEVOM3s1PU9LUUwvWk9SPzZBJGFWUVlUV1FKM0x5fE9GUTRxdGJWP1hJTFtSXUBs user_pref("CT1060933./9b+7e31;cj3gi k@c.from_oldbar.enc", "JH5hOT8jayVydHd1KiEsbkFPRE0yejQ/U1UsV0xPPDM+IV5TTlZRVE5HMEl2eUxDTjFucV9TPFVDV05ZPGhpcl5HYFF user_pref("CT1060933./9b+7e31;cj4f:ficggg&fi.from_oldbar.enc", "JH5hOT8jayVweHR5KiEsbkFPRE0yejRAUkZSVU9TU1MyUlVBOEMmY1hTW1ZZU0w1TiMmUUhTNnN2ZFhBWkhcU1 user_pref("CT1060933./9b+7e31;cj6; aeae$odg.from_oldbar.enc", "JH5hOT8jayV2dXFxeSsiLW9CUEVOM3s1Q0gtTlJOUjFcUVRBOEMmY2ZUSDFKOExDTjFdXmdTPFVGRVhPWmdrcl5 user_pref("CT1060933./9b+7e31;cj72?l@;kn%peh.from_oldbar.enc", "JH5hOT8jayV1d3hydisiLW9CUEVOM3s1RD9MWU1IWFsyXVJVQjlEJ2RZVFxXWlRNNk98IFJJVDdjZG1ZQltMS1 user_pref("CT1060933./9b+7e31;cj77=;i\"==mrgeg@sguw/zor.from_oldbar.enc", "JH5hOT8jayV1cXZycisiLW9CUEVOM3s1RERKSFYvSkpaX1RSVE1gVGJkPGdcX0xDTjFuY15mYWR user_pref("CT1060933./9b+7e31;cj77=;i\"oabgo(shk.from_oldbar.enc", "JH5hOT8jayVzdXNxKiEsbkFPRE0yejRDQ0lHVS5bTU5TWzRfVFdEO0YpZltWXllcVk84UX4iVEtWOXZ5Z1 user_pref("CT1060933./9b+7e31;cj7;=9ei7$odg.from_oldbar.enc", "JH5hOT8jayV1cXl2dCsiLW9CUEVOM3s1REhKRlJWRDFcUVRBOEMmY2ZUSDFKOz5NRE8yXl9oVD1WR0ZZUFttbHB user_pref("CT1060933./9b+7e31;cj7fk;kg#ncep@mc+vkn.from_oldbar.enc", "JH5hOT8jayVzdHFxKiEsbkFPRE0yejRDUldHV1MvWk9RXExZTzdiV1pHPkksWFReak84UTxTSlU4ZGVu user_pref("CT1060933./9b+7e31;cj7j?:9ai$odg.from_oldbar.enc", "JH5hOT8jayVzcXl3KiEsbkFPRE0yejRDVktGRU1VMFtQU0A3QiViZVNHMEk3S0JNMFxdZlI7VEVEV05ZZmpxXUZ user_pref("CT1060933./9b+7e31;cj:?k4\"n=hq&qfi.from_oldbar.enc", "JH5hOT8jayV0cHF4KiEsbkFPRE0yejRGS1dALlpJVF0yXVJVQjlEJ1NUXUkySzpNRE9cYGdTPFtWZnRzWkNc user_pref("CT1060933./9b+7e31;cj:b>?mldl?:a(shk.from_oldbar.enc", "JH5hOT8jayV1d3ZyeysiLW9CUEVOM3s1R09LTFpZUVlMR041YFVYRTxHKmdcV19aXVdQOVIgI1VMVzpmZ3B user_pref("CT1060933./9b+7e31;cj:j:lg@b%?dna?vft-xmp.from_oldbar.enc", "JH5hOT8jayV1cHB4disiLW9CUEVOM3s1R1dHWVRNTzJMUVtOTGNTYTplWl1KQUwvbGFcZF9iXFU+Vy user_pref("CT1060933./9b+7e31;cj:jj>mk.from_oldbar.enc", "JH5hOT8jayV1c3JyeisiLW9CUEVOM3s1R1dXSy5aWD00PyJfVE9XUlVPSDFKKylNRE9cYGdTPFtWZnRzWkNcY2x7IXAh user_pref("CT1060933./9b+7e31;cj;jh @c.from_oldbar.enc", "JH5hOT8jayV1dHV5cisiLW9CUEVOM3s1SFdVLU1QPDM+IV5TTlZRVE5HMEl9IUxDTjFucV9TPFVHQlhPWmxrb3trfm5i user_pref("CT1060933./9b+7e31;cj<<:9?a#ncf.from_oldbar.enc", "JH5hOT8jayV0cnd6KiEsbkFPRE0yejRISEZFS00vWk9SPzZBJGFWUVlUV1FKM0x5fE9GUTRxdGJWP1hHWlFcP2ts user_pref("CT1060933./9b+7e31;cj<f5hgh#ncf.from_oldbar.enc", "JH5hOT8jayV0c3JzKiEsbkFPRE0yejRIUkFUU1QvWk9SPzZBJGFWUVlUV1FKM0x5fE9GUTRgYWpWP1hJSFtSXWpu user_pref("CT1060933./9b+7e31;cj=b9j?\"be.from_oldbar.enc", "JH5hOT8jayV0dnN2KiEsbkFPRE0yejRJTkVWSy5OUT00PyJfVE9XUlVPSDFKfiJNRE8yXl9oVD1WR0ZZUFtobHNfS user_pref("CT1060933./9b+7e31;cj=fhdmbo?g?'gj.from_oldbar.enc", "JH5hOT8jayVxdnd2KiEsbkFPRE0yejRJUlRQWU5bS1NLM1NWQjlEJ2RZVFxXWlRNNk8kJ1JJVDd0d2VZQltJX user_pref("CT1060933./9b+7e31;cj>j<9??=icc'sq.from_oldbar.enc", "JH5hOT8jayVxdnVyKiEsbkFPRE0yejRKVkhFS0tJVU9PM19dQjlEJ2RnVUkySzpNRE8yXl9oVD1WRVhPWmdrc user_pref("CT1060933./9b+7e31;cj?bg:cj;?il'sq.from_oldbar.enc", "JH5hOT8jayV1c3JyeysiLW9CUEVOM3s1TE9UR1BXSExWWTRgXkM6RShlWlVdWFtVTjdQMS9TSlViZm1ZQmFcb user_pref("CT1060933./9b+7e31;cj?bk k@c.from_oldbar.enc", "JH5hOT8jayV1cXV4cisiLW9CUEVOM3s1TE9YLVhNUD00PyJfYlBELUY3SD9KXFtfa1tuXlI7WlU4ZXRoZXN6eV5HYEt user_pref("CT1060933./9b+7e31;cja@gllad.from_oldbar.enc", "JH5hOT8jayV1cnd0KiEsbkFPRE0yejRNTFNYLVhNUD00PyJfVE9XUlVPSDFKd3pNRE8yb3JgVD1WQVhPWj1panNfSGF user_pref("CT1060933./9b+7e31;cjbj:ii<miiinbbhft-yw.from_oldbar.enc", "JH5hOT8jayV1dHB3eCsiLW9CUEVOM3s1T1dHVlZJWlZWVltPT1VTYTpmZElASy5rYFtjXmFbVD1WNzV user_pref("CT1060933./9b+7e31;cjc8?::@>l%qo.from_oldbar.enc", "JH5hOT8jayV1dHFycisiLW9CUEVOM3s1UEVMR0dNS1kyXlxBOEMmY1hTW1ZZU0w1Ti8tUUhTNnN2ZFhBWkxFXVR user_pref("CT1060933./9b+7e31;cjc9gh@bockrglhp+vkn.from_oldbar.enc", "JH5hOT8jayVueHN5KiEsbkFPRE0yejRPRVNUTE5bT1deU1hUXDdiV1pHPkksaV5ZYVxfWVI7VDA2V05Z user_pref("CT1060933./9b+7e31;cjc<=fbj#cf.from_oldbar.enc", "JH5hOT8jayV1dnRyKiEsbkFPRE0yejRPSElSTlYvT1I+NUAjYFVQWFNWUEkySyAjTkVQM19bZXFWP1hKWlFcP3txf user_pref("CT1060933./9b+7e31;cjc<=fbj#om.from_oldbar.enc", "JH5hOT8jayVxd3J2KiEsbkFPRE0yejRPSElSTlYvW1k+NUAjT0tVYUYvSDpKQUwvW1xlUTpTQlVMV2lobHhoe2tfS user_pref("CT1060933./9b+7e31;cjcj?h;;aa%peh.from_oldbar.enc", "JH5hOT8jayV1dndzKiEsbkFPRE0yejRPVktUR0dNTTFcUVRBOEMmY1hTW1ZZU0w1Tnt+UUhTNnN2ZFhBWkxIXV user_pref("CT1060933./9b+7e31;cjcj?h;?a=%peh.from_oldbar.enc", "JH5hOT8jayV2cXh1eSsiLW9CUEVOM3s1UFdMVUhMTkoyXVJVQjlEJ1NUXUkySzw7TkVQXWFoVD1cV2d1dFtEXW user_pref("CT1060933./9b+7e31;cjcj?h<<ip>n'rgj.from_oldbar.enc", "JH5hOT8jayV2dXVzcysiLW9CUEVOM3s1UFdMVUlJVl1LWzRfVFdEO0YpZltWXllcVk84UX4iVEtWOXZ5Z1tE user_pref("CT1060933./9b+7e31;cjdjihl@af%peh.from_oldbar.enc", "JH5hOT8jayV2cXJyeisiLW9CUEVOM3s1UVdWVVlNTlMyXVJVQjlEJ1NUXUkySzw7TkVQYmFlcWF0ZFhBIWFccX user_pref("CT1060933./9b+7e31;cje5cak@b=@dhiqee,wlo.from_oldbar.enc", "JH5hOT8jayV1cnB3disiLW9CUEVOM3s1UkJQTlhNT0pNUVVWXlJSOWRZXElASy5rYFtjXmFbVD1WJCd user_pref("CT1060933./9b+7e31;cjei=>c\"be.from_oldbar.enc", "JH5hOT8jayV2cHNzKiEsbkFPRE0yejRRVUlKTy5OUT00PyJOT1hELUY1SD9KV1tiTjdWUWFvblU+V15vdmNmb218b user_pref("CT1060933./9b+7e31;cjeik4kk.from_oldbar.enc", "JH5hOT8jayV2cXdyKiEsbkFPRE0yejRRVVdALVdXPDM+IV5TTlZRVE5HMEkoKExDTjFdXmdTPFVGRVhPWmp+cnZydmFK user_pref("CT1060933./9b+7e31;cjej~j?b.from_oldbar.enc", "JH5hOT8jayVxd3h1KiEsbkFPRE0yejRRVitWS047Mj0gXVJNVVBTTUYvSHV4S0JNMG1wXlI7VEZCV05ZPGhpcl5HYFFQ user_pref("CT1060933./9b+7e31;cjff@alad.from_oldbar.enc", "JH5hOT8jayV2dXB5KiEsbkFPRE0yejRSUkxNLVhNUD00PyJfVE9XUlVPSDFKd3pNRE8yb3JgVD1WRFhPWj1panNfSGF user_pref("CT1060933./9b+7e31;cjg2jh<cgcg&qfi.from_oldbar.enc", "JH5hOT8jayV1d3h0disiLW9CUEVOM3s1VD9XVUlQVFBUM15TVkM6RShlWlVdWFtVTjdQfSFTSlU4ZGVuWkNcT user_pref("CT1060933./9b+7e31;cjg<>;mk#om.from_oldbar.enc", "JH5hOT8jayVxdnd5KiEsbkFPRE0yejRTSEpHWVcvW1k+NUAjT1BZRS5HNklAS1hcY084V1JicG9WP1hfa31qeX5uf user_pref("CT1060933./9b+7e31;cjg<?=9;k???ecq*vt.from_oldbar.enc", "JH5hOT8jayV1c3F6eisiLW9CUEVOM3s1VElMSkZIWExMTFJQXjdjYUY9SCtoXVhgW15YUTpTNDJWTVg7eH user_pref("CT1060933./9b+7e31;cjg=g9lad.from_oldbar.enc", "JH5hOT8jayVudHMpICttQE5DTDF5M1JIUkQsV0xPPDM+IU1OV0MsRTRHPklWWmFNNlVQYG5tVD1WXWhldmpkQiUgVWg user_pref("CT1060933./9b+7e31;cjh63 @@>=ce'rgj.from_oldbar.enc", "JH5hOT8jayVveHBxKiEsbkFPRE0yejRUQj8sTExKSU9RM15TVkM6RShlWlVdWFtVTjdQLy9TSlU4dXhmWkNc user_pref("CT1060933./9b+7e31;cjh97?m\"be.from_oldbar.enc", "JH5hOT8jayVzc3IpICttQE5DTDF5M1NEQkpYLU1QPDM+IV5TTlZRVE5HMEl9IUxDTjFucV9TPFVHR1hPWj1panNfS user_pref("CT1060933./9b+7e31;cjh9k?jndem:'rg*cn.from_oldbar.enc", "JH5hOT8jayVvdnApICttQE5DTDF5M1NEVkpVWU9QWEUyXVI1TllEO0YpZltWXllcVk84US0zVEtWOWVmb1 user_pref("CT1060933./9b+7e31;cjh9ki5hodm@'rgj.from_oldbar.enc", "JH5hOT8jayV1c3R0eisiLW9CUEVOM3s1VUZYVkJVXFFaTTRfVFdEO0YpZltWXllcVk84UX4iVEtWOXZ5Z1tE user_pref("CT1060933./9b+7e31;cjh<@ k@c.from_oldbar.enc", "JH5hOT8jayVzc3ApICttQE5DTDF5M1NHSytWS047Mj0gXVJNVVBTTUYvSHwgS0JNMFxdZlI7VEVEV05ZZmpxXUZlYHB user_pref("CT1060933./9b+7e31;cjhb8iiikcnnb(shk.from_oldbar.enc", "JH5hOT8jayV1cnl6dysiLW9CUEVOM3s1VU9FVlZWWFBbW081YFVYRTxHKmdqWEw1Tj1QR1I1YWJrV0BZSkl user_pref("CT1060933./9b+7e31;cjhb>flad.from_oldbar.enc", "JH5hOT8jayVzc3kpICttQE5DTDF5M1NNSVEsV0xPPDM+IU1JU19ELUYxSD9KLVlaY084UUBTSlViZm1ZQiJiXW17emF user_pref("CT1060933./9b+7e31;cjhf9ae<<$dg.from_oldbar.enc", "JH5hOT8jayVxdnl1KiEsbkFPRE0yejRUUkVNUUhIMFBTPzZBJGFWUVlUV1FKM0whJE9GUTRgYWpWP1hHWlFcaW10 user_pref("CT1060933./9b+7e31;cjhf9ae<<$pn.from_oldbar.enc", "JH5hOT8jayVxcHF6KiEsbkFPRE0yejRUUkVNUUhIMFxaPzZBJGFWUVlUV1FKM0wtK09GUTRgYWpWP1hHWlFcaW10 user_pref("CT1060933./9b+7e31;cjhj:9;bg=%peh.from_oldbar.enc", "JH5hOT8jayV1dHZ2eysiLW9CUEVOM3s1VVdHRkhPVEoyXVJVQjlEJ2RnVUkySz0/TkVQXWFoVD1cV2d1dFtEXW user_pref("CT1060933./9b+7e31;cji6hdmc=$odg.from_oldbar.enc", "JH5hOT8jayV2c3V5eCsiLW9CUEVOM3s1VkNVUVpQSjFcUVRBOEMmY1hTW1ZZU0w1Ti0tUUhTNnN2ZFhBWktOXVR user_pref("CT1060933./9b+7e31;cji8a k@c.from_oldbar.enc", "JH5hOT8jayVvdSh+Kmw/TUJLMHgyU0JLKlVKTToxPH5LR1FdQitENkY9SCtXWGFNNk8+UUhTZWRodGR3Z1tEJGRfdCJ user_pref("CT1060933./9b+7e31;cji;<ai\"mbe.from_oldbar.enc", "JH5hOT8jayVuc3h2KiEsbkFPRE0yejRVR0hNVS5ZTlE+NUAjYFVQWFNWUEkyS3h7TkVQM3BzYVU+V0lCWlFcP2ts user_pref("CT1060933./9b+7e31;cji>h k@c.from_oldbar.enc", "JH5hOT8jayVudHZyKiEsbkFPRE0yejRVSlQsV0xPPDM+IV5TTlZRVE5HMEl2eUxDTjFucV9TPFVEV05ZZmpxXUZlYHB user_pref("CT1060933./9b+7e31;cji>k3?a#k@.from_oldbar.enc", "JH5hOT8jayV2dCh+Kmw/TUJLMHgyU0hVPUlLLVVKPDM+IV5TTlZRVE5HMEkmekxDTjFdXmdTPFVEV05ZZmpxXUZlY user_pref("CT1060933./9b+7e31;cji>k3?a#mm.from_oldbar.enc", "JH5hOT8jayVzdyh+Kmw/TUJLMHgyU0hVPUlLLVdXPDM+IV5TTlZRVE5HMEkoKExDTjFdXmdTPFVEV05ZZmpxXUZlY user_pref("CT1060933./9b+7e31;cji>k3?a#nc&?j.from_oldbar.enc", "JH5hOT8jayV2dyh+Kmw/TUJLMHgyU0hVPUlLLVhNMElUPzZBJGFWUVlUV1FKM0woLk9GUTRgYWpWP1hJSFtSXW user_pref("CT1060933./9b+7e31;cji>k3?a#ncf.from_oldbar.enc", "JH5hOT8jayV2eCh+Kmw/TUJLMHgyU0hVPUlLLVhNUD00PyJOT1hELUY1SD9KV1tiTjdWUTRicF54aWtuYltEXU9f user_pref("CT1060933./9b+7e31;cji?8h<ao=m&rp.from_oldbar.enc", "JH5hOT8jayVxcHdzKiEsbkFPRE0yejRVS0RUSE1bSVkyXlxBOEMmY1hTW1ZZU0w1Ti8tUUhTNnN2ZFhBWkhcU1 user_pref("CT1060933./9b+7e31;cjig=ki\"mbe.from_oldbar.enc", "JH5hOT8jayV0cXgpICttQE5DTDF5M1RSSFZULVhNUD00PyJfYlBELUY4NklASy5aW2RQOVJDQlVMV2Rob1tEY15u user_pref("CT1060933./9b+7e31;cjzz>h:\"mbe.from_oldbar.enc", "JH5hOT8jayV1dnlyeCsiLW9CUEVOM3s1KChLVUcvWk9SPzZBJGFkUkYvSDdKQUxZXWRQOVhTY3FwV0BZYGl4fW19 user_pref("CT1060933./9b+7e4x305.from_oldbar.enc", "JH4wLEB2Qjc6J28pd3t0di4lMEE+T0lKUitVVTojPCsvKClBOENUUV5dVmFfVmhcQm1iZVI7VENGSUpZUFtsaXp+IXAjcHZZJX user_pref("CT1060933./9b+7ebe3g=;d9n9=d.from_oldbar.enc", "NywtMml1di46PHs6OUNKSUhBQ0smUUZJKWVQRlZJZXFzTTNLVw=="); user_pref("CT1060933./9b-0?3g>d.from_oldbar.enc", "PmpAckJvRHR6RnVEdSBKSUt7JUwifVIqVFYlJFYlLVkpMS4r"); user_pref("CT1060933./9b-0?3g@6:5;.from_oldbar.enc", "AA=="); user_pref("CT1060933./9b-0?3gfa7ef.from_oldbar.enc", "Ky4sPQ=="); user_pref("CT1060933./9b-3=3eccja=f>.from_oldbar.enc", "JH4zPSxFL0E1J28pKiEsOT1EMHgyTEFCR34rLEhXS0hWXVw1U1JcY2JhWlxkP2pfYkJtbW1zYGpjS3hna2Q/bUM9Mz9ecH user_pref("CT1060933./9b/556,bi5a>g.from_oldbar.enc", "bm1scG9ucm5zdHd2ew=="); user_pref("CT1060933./9b/>01=9a6k6<im;krie@pdawm.from_oldbar.enc", "amlrcnN0dXY="); user_pref("CT1060933./9b3=>@44i48?.from_oldbar.enc", "NywtMml1djNCNjNBSEcgPj1HTk1MRUdPKlVKTS1YWFheS1VONmNSVk8="); user_pref("CT1060933./9b5ba==9cjag.from_oldbar.enc", "amdAbUJtdHV6d0ZGcnV7THwgTyF+"); user_pref("CT1060933./9b6b11g4c56b>f;p;anr@p.from_oldbar.enc", "bm1pbnJvbHR0cHdzeA=="); user_pref("CT1060933./9b9643g3/9e.from_oldbar.enc", "ag=="); user_pref("CT1060933./9b;45>:bi9i7ie.from_oldbar.enc", "Ky4sPQ=="); user_pref("CT1060933./9b<:222h64<.from_oldbar.enc", "OT81Lz4="); user_pref("CT1060933./9b<:222h64<l8daj.from_oldbar.enc", "bXBwcHZzdHl3cSp6dXJ4eXV7eA=="); user_pref("CT1060933./9b=+03eh8h8j?:.from_oldbar.enc", "REM="); user_pref("CT1060933./9b?+e2a52d8.from_oldbar.enc", "NywtMml1di46PHs6OUNKSUhBQ0smUUZJKWVQRlZkcHJ5UVVeXlI="); user_pref("CT1060933./9b?b0d:8aj62<h.from_oldbar.enc", "bQ=="); user_pref("CT1060933./9ba@0<0bi6a7gn:6@l?.from_oldbar.enc", "bA=="); user_pref("CT1060933.1000082.isPlayDisplay", "true"); user_pref("CT1060933.1000082.state", "{\"state\":\"stopped\",\"text\":\"KFOG\",\"description\":\"KFOG\",\"url\":\"http://live.cumulusstreaming.com/KFO user_pref("CT1060933.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); user_pref("CT1060933.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx"); user_pref("CT1060933.AppTrackingLastCheckTime", "Fri Nov 01 2013 14:15:50 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.BrowserCompStateIsOpen_129681785283868963", true); user_pref("CT1060933.BrowserCompStateIsOpen_129686665230467549", true); user_pref("CT1060933.BrowserCompStateIsOpen_130040833450137909", true); user_pref("CT1060933.BrowserCompStateIsOpen_130068876516309164", true); user_pref("CT1060933.BrowserCompStateIsOpen_130262967617041722", true); user_pref("CT1060933.CT1060933.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.conduit.com/?ctid=CT1060933&octid=CT1060933&Sea user_pref("CT1060933.CTID", "CT1060933"); user_pref("CT1060933.ConfigurationLastCheckTime", "Sun Nov 10 2013 16:27:55 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.CurrentServerDate", "11-11-2013"); user_pref("CT1060933.DSInstall", false); user_pref("CT1060933.DialogsAlignMode", "LTR"); user_pref("CT1060933.DialogsGetterLastCheckTime", "Fri Nov 08 2013 14:15:49 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.DownloadReferralCookieData", ""); user_pref("CT1060933.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); user_pref("CT1060933.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); user_pref("CT1060933.FirstServerDate", "13-3-2012"); user_pref("CT1060933.FirstTime", true); user_pref("CT1060933.FirstTimeFF3", true); user_pref("CT1060933.FixPageNotFoundErrors", true); user_pref("CT1060933.GroupingServerCheckInterval", 1440); user_pref("CT1060933.GroupingServiceUrl", "http://grouping.services.conduit.com/"); user_pref("CT1060933.HPInstall", false); user_pref("CT1060933.HasUserGlobalKeys", true); user_pref("CT1060933.HomePageProtectorEnabled", false); user_pref("CT1060933.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties"); user_pref("CT1060933.Initialize", true); user_pref("CT1060933.InitializeCommonPrefs", true); user_pref("CT1060933.InstallationAndCookieDataSentCount", 3); user_pref("CT1060933.InstallationId", "ConduitNSISIntegration"); user_pref("CT1060933.InstallationType", "ConduitXPEIntegration"); user_pref("CT1060933.InstalledDate", "Tue Mar 13 2012 17:31:23 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.InvalidateCache", false); user_pref("CT1060933.IsAlertDBUpdated", true); user_pref("CT1060933.IsGrouping", false); user_pref("CT1060933.IsInitSetupIni", true); user_pref("CT1060933.IsMulticommunity", false); user_pref("CT1060933.IsOpenThankYouPage", false); user_pref("CT1060933.IsOpenUninstallPage", true); user_pref("CT1060933.LanguagePackLastCheckTime", "Sun Nov 10 2013 16:27:56 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.LanguagePackReloadIntervalMM", 1440); user_pref("CT1060933.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx"); user_pref("CT1060933.LastLogin_3.10.0.1", "Mon Mar 19 2012 08:13:57 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.LastLogin_3.12.0.7", "Fri Apr 27 2012 14:22:54 GMT+0200 (Romance (zomertijd))"); user_pref("CT1060933.LastLogin_3.13.0.6", "Wed Jun 27 2012 16:53:07 GMT+0200 (Romance (zomertijd))"); user_pref("CT1060933.LastLogin_3.14.1.0", "Thu Jul 19 2012 23:26:24 GMT+0200 (Romance (zomertijd))"); user_pref("CT1060933.LastLogin_3.15.1.0", "Tue Nov 06 2012 16:27:42 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.LastLogin_3.16.0.3", "Tue Mar 05 2013 18:29:43 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.LastLogin_3.18.0.7", "Sat Jul 20 2013 19:32:16 GMT+0200 (Romance (standaardtijd))"); user_pref("CT1060933.LastLogin_3.19.0.3", "Tue Sep 03 2013 09:29:08 GMT+0200 (Romance (standaardtijd))"); user_pref("CT1060933.LastLogin_3.20.0.4", "Mon Nov 11 2013 09:40:33 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.LatestVersion", "3.20.0.4"); user_pref("CT1060933.Locale", "en-us"); user_pref("CT1060933.MCDetectTooltipHeight", "83"); user_pref("CT1060933.MCDetectTooltipShow", false); user_pref("CT1060933.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); user_pref("CT1060933.MCDetectTooltipWidth", "295"); user_pref("CT1060933.MyStuffEnabledAtInstallation", true); user_pref("CT1060933.OriginalFirstVersion", "3.10.0.1"); user_pref("CT1060933.PG_ENABLE", "dHJ1ZQ=="); user_pref("CT1060933.RadioIsPodcast", false); user_pref("CT1060933.RadioLastCheckTime", "Mon Nov 11 2013 09:40:32 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.RadioLastUpdateIPServer", "0"); user_pref("CT1060933.RadioLastUpdateServer", "129326918102570000"); user_pref("CT1060933.RadioMediaID", "21504191"); user_pref("CT1060933.RadioMediaType", "Media Player"); user_pref("CT1060933.RadioMenuSelectedID", "EBRadioMenu_CT106093321504191"); user_pref("CT1060933.RadioShrinkedFromSetup", false); user_pref("CT1060933.RadioStationName", "KFOG"); user_pref("CT1060933.RadioStationURL", "http://live.cumulusstreaming.com/KFOG-FM"); user_pref("CT1060933.SHRINK_TOOLBAR", 1); user_pref("CT1060933.SearchAPILastCheckTime", "Sun Nov 10 2013 16:27:55 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.SearchAppState", "%B9"); user_pref("CT1060933.SearchAppState.enc", "Mw=="); user_pref("CT1060933.SearchAppTracking", "%B7"); user_pref("CT1060933.SearchAppTracking.enc", "MQ=="); user_pref("CT1060933.SearchCaption", "Freecorder Customized Web Search"); user_pref("CT1060933.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); user_pref("CT1060933.SearchFromAddressBarIsInit", true); user_pref("CT1060933.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=2&q="); user_pref("CT1060933.SearchInNewTabEnabled", true); user_pref("CT1060933.SearchInNewTabIntervalMM", 1440); user_pref("CT1060933.SearchInNewTabLastCheckTime", "Mon Sep 02 2013 14:48:02 GMT+0200 (Romance (standaardtijd))"); user_pref("CT1060933.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID"); user_pref("CT1060933.SearchInNewTabURLFromSearchAPI", "http://search.conduit.com/?ctid=CT1060933&octid=CT1060933&SearchSource=15&CUI=SB_CUI&SSPV=EB_SS user_pref("CT1060933.SearchProtectorEnabled", false); user_pref("CT1060933.SearchProtectorToolbarDisabled", false); user_pref("CT1060933.SendProtectorDataViaLogin", true); user_pref("CT1060933.ServiceMapLastCheckTime", "Sun Nov 10 2013 16:27:55 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.SettingsLastCheckTime", "Mon Nov 11 2013 09:40:32 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.SettingsLastUpdate", "1384139575"); user_pref("CT1060933.TBHomePageUrl", "http://search.conduit.com/?ctid=CT1060933&SearchSource=13"); user_pref("CT1060933.ThirdPartyComponentsInterval", 504); user_pref("CT1060933.ThirdPartyComponentsLastCheck", "Fri Nov 01 2013 14:15:33 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.ThirdPartyComponentsLastUpdate", "1331805997"); user_pref("CT1060933.ToolbarShrinkedFromSetup", false); user_pref("CT1060933.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityTool user_pref("CT1060933.UserID", "UN04002027154910481"); user_pref("CT1060933.ValidationData_Search", 2); user_pref("CT1060933.ValidationData_Toolbar", 2); user_pref("CT1060933._9b90e_.3c;7b=?ofb>>rhiqs.from_oldbar.enc", "OT81Lz4="); user_pref("CT1060933._key_cl_active", "%BE%E7%B9%BC%B6%EA%E7%BE%B3%BA%BB%BC%EA%B3%BA%B7%BA%EC%B3%E8%EB%BA%BD%B3%BD%BF%B7%BB%BA%E9%BA%E9%E8%E9%EA%EA"); user_pref("CT1060933._key_cl_active.enc", "OGEzNjBkYTgtNDU2ZC00MTRmLWJlNDctNzkxNTRjNGNiY2Rk"); user_pref("CT1060933.addressBarTakeOverEnabledInHidden", "true"); user_pref("CT1060933.alertChannelId", "15651"); user_pref("CT1060933.approveUntrustedApps", false); user_pref("CT1060933.autoDisableScopes", -1); user_pref("CT1060933.autocompletepro_enable.from_oldbar.enc", "MQ=="); user_pref("CT1060933.autocompletepro_enable_auto.from_oldbar.enc", "MQ=="); user_pref("CT1060933.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426 user_pref("CT1060933.backendstorage./9b+7e-x305", "247E29327641363937333545397E3F493B2F77317E202520362D3842474A58515A5C585D505F593964595C49324B393A3F3 user_pref("CT1060933.backendstorage./9b+7e06cg5el8:", "6E6D696E726F6C736F78"); user_pref("CT1060933.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74736F7478757279757E242F4B49474F42357D5D5C3D"); user_pref("CT1060933.backendstorage./9b+7e31;cj06?km\"mbe", "247E61393F236B2575767077742B222D6F4250454E337B353D434C585A2F5A4F523F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cj0b>d?\"mbe", "247E61393F236B2575737672792B222D6F4250454E337B353D4F4B514C2F5A4F523F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cj3gi k@c", "247E61393F236B25727477752A212C6E414F444D327A343F53552C574C4F3C333E215E534E5651544E4730497679 user_pref("CT1060933.backendstorage./9b+7e31;cj4f:ficggg&fi", "247E61393F236B25707874792A212C6E414F444D327A3440524652554F535353325255413843266358535B5 user_pref("CT1060933.backendstorage./9b+7e31;cj6; aeae$odg", "247E61393F236B2576757171792B222D6F4250454E337B3543482D4E524E52315C5154413843266366544831 user_pref("CT1060933.backendstorage./9b+7e31;cj72?l@;kn%peh", "247E61393F236B2575777872762B222D6F4250454E337B35443F4C594D48585B325D5255423944276459545 user_pref("CT1060933.backendstorage./9b+7e31;cj77=;i\"==mrgeg@sguw/zor", "247E61393F236B2575717672722B222D6F4250454E337B3544444A48562F4A4A5A5F5452544D user_pref("CT1060933.backendstorage./9b+7e31;cj77=;i\"oabgo(shk", "247E61393F236B25737573712A212C6E414F444D327A3443434947552E5B4D4E535B345F5457443B462 user_pref("CT1060933.backendstorage./9b+7e31;cj7;=9ei7$odg", "247E61393F236B2575717976742B222D6F4250454E337B3544484A46525644315C5154413843266366544831 user_pref("CT1060933.backendstorage./9b+7e31;cj7fk;kg#ncep@mc+vkn", "247E61393F236B25737471712A212C6E414F444D327A344352574757532F5A4F515C4C594F3762575 user_pref("CT1060933.backendstorage./9b+7e31;cj7j?:9ai$odg", "247E61393F236B25737179772A212C6E414F444D327A3443564B46454D55305B505340374225626553473049 user_pref("CT1060933.backendstorage./9b+7e31;cj:?k4\"n=hq&qfi", "247E61393F236B25747071782A212C6E414F444D327A34464B57402E5A49545D325D52554239442753545 user_pref("CT1060933.backendstorage./9b+7e31;cj:b>?mldl?:a(shk", "247E61393F236B25757776727B2B222D6F4250454E337B35474F4B4C5A5951594C474E35605558453C47 user_pref("CT1060933.backendstorage./9b+7e31;cj:j:lg@b%?dna?vft-xmp", "247E61393F236B2575707078762B222D6F4250454E337B3547574759544D4F324C515B4E4C63536 user_pref("CT1060933.backendstorage./9b+7e31;cj:jj>mk", "247E61393F236B25757372727A2B222D6F4250454E337B354757574B2E5A583D343F225F544F5752554F48314A2B2 user_pref("CT1060933.backendstorage./9b+7e31;cj;jh @c", "247E61393F236B2575747579722B222D6F4250454E337B354857552D4D503C333E215E534E5651544E4730497D214 user_pref("CT1060933.backendstorage./9b+7e31;cj<<:9?a#ncf", "247E61393F236B257472777A2A212C6E414F444D327A34484846454B4D2F5A4F523F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cj<f5hgh#ncf", "247E61393F236B25747372732A212C6E414F444D327A344852415453542F5A4F523F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cj=b9j?\"be", "247E61393F236B25747673762A212C6E414F444D327A34494E45564B2E4E513D343F225F544F5752554F48314A user_pref("CT1060933.backendstorage./9b+7e31;cj=fhdmbo?g?'gj", "247E61393F236B25717677762A212C6E414F444D327A3449525450594E5B4B534B33535642394427645954 user_pref("CT1060933.backendstorage./9b+7e31;cj>j<9??=icc'sq", "247E61393F236B25717675722A212C6E414F444D327A344A5648454B4B49554F4F335F5D42394427646755 user_pref("CT1060933.backendstorage./9b+7e31;cj?bg:cj;?il'sq", "247E61393F236B25757372727B2B222D6F4250454E337B354C4F54475057484C565934605E433A4528655A user_pref("CT1060933.backendstorage./9b+7e31;cj?bk k@c", "247E61393F236B2575717578722B222D6F4250454E337B354C4F582D584D503D343F225F6250442D4637483F4A5C user_pref("CT1060933.backendstorage./9b+7e31;cja@gllad", "247E61393F236B25757277742A212C6E414F444D327A344D4C53582D584D503D343F225F544F5752554F48314A77 user_pref("CT1060933.backendstorage./9b+7e31;cjbj:ii<miiinbbhft-yw", "247E61393F236B2575747077782B222D6F4250454E337B354F57475656495A5656565B4F4F555361 user_pref("CT1060933.backendstorage./9b+7e31;cjc8?::@>l%qo", "247E61393F236B2575747172722B222D6F4250454E337B3550454C47474D4B59325E5C413843266358535B56 user_pref("CT1060933.backendstorage./9b+7e31;cjc9gh@bockrglhp+vkn", "247E61393F236B256E7873792A212C6E414F444D327A344F4553544C4E5B4F575E5358545C3762575 user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#cf", "247E61393F236B25757674722A212C6E414F444D327A344F4849524E562F4F523E354023605550585356504932 user_pref("CT1060933.backendstorage./9b+7e31;cjc<=fbj#om", "247E61393F236B25717772762A212C6E414F444D327A344F4849524E562F5B593E3540234F4B5561462F483A4A user_pref("CT1060933.backendstorage./9b+7e31;cjcj?h;;aa%peh", "247E61393F236B25757677732A212C6E414F444D327A344F564B5447474D4D315C5154413843266358535B5 user_pref("CT1060933.backendstorage./9b+7e31;cjcj?h;?a=%peh", "247E61393F236B2576717875792B222D6F4250454E337B3550574C55484C4E4A325D52554239442753545D4 user_pref("CT1060933.backendstorage./9b+7e31;cjcj?h<<ip>n'rgj", "247E61393F236B2576757573732B222D6F4250454E337B3550574C554949565D4B5B345F5457443B46296 user_pref("CT1060933.backendstorage./9b+7e31;cjdjihl@af%peh", "247E61393F236B25767172727A2B222D6F4250454E337B3551575655594D4E53325D52554239442753545D4 user_pref("CT1060933.backendstorage./9b+7e31;cje5cak@b=@dhiqee,wlo", "247E61393F236B2575727077762B222D6F4250454E337B355242504E584D4F4A4D5155565E525239 user_pref("CT1060933.backendstorage./9b+7e31;cjei=>c\"be", "247E61393F236B25767073732A212C6E414F444D327A345155494A4F2E4E513D343F224E4F58442D4635483F4A user_pref("CT1060933.backendstorage./9b+7e31;cjeik4kk", "247E61393F236B25767177722A212C6E414F444D327A34515557402D57573C333E215E534E5651544E47304928284 user_pref("CT1060933.backendstorage./9b+7e31;cjej~j?b", "247E61393F236B25717778752A212C6E414F444D327A3451562B564B4E3B323D205D524D5550534D462F4875784B4 user_pref("CT1060933.backendstorage./9b+7e31;cjff@alad", "247E61393F236B25767570792A212C6E414F444D327A3452524C4D2D584D503D343F225F544F5752554F48314A77 user_pref("CT1060933.backendstorage./9b+7e31;cjg2jh<cgcg&qfi", "247E61393F236B2575777874762B222D6F4250454E337B35543F57554950545054335E5356433A4528655A user_pref("CT1060933.backendstorage./9b+7e31;cjg<>;mk#om", "247E61393F236B25717677792A212C6E414F444D327A3453484A4759572F5B593E3540234F5059452E47364940 user_pref("CT1060933.backendstorage./9b+7e31;cjg<?=9;k???ecq*vt", "247E61393F236B257573717A7A2B222D6F4250454E337B3554494C4A4648584C4C4C52505E376361463 user_pref("CT1060933.backendstorage./9b+7e31;cjg=g9lad", "247E61393F236B256E747329202B6D404E434C317933524852442C574C4F3C333E214D4E57432C4534473E49565A user_pref("CT1060933.backendstorage./9b+7e31;cjh63 @@>=ce'rgj", "247E61393F236B256F7870712A212C6E414F444D327A3454423F2C4C4C4A494F51335E5356433A4528655 user_pref("CT1060933.backendstorage./9b+7e31;cjh97?m\"be", "247E61393F236B2573737229202B6D404E434C3179335344424A582D4D503C333E215E534E5651544E4730497D user_pref("CT1060933.backendstorage./9b+7e31;cjh9k?jndem:'rg*cn", "247E61393F236B256F767029202B6D404E434C3179335344564A55594F505845325D52354E59443B462 user_pref("CT1060933.backendstorage./9b+7e31;cjh9ki5hodm@'rgj", "247E61393F236B25757374747A2B222D6F4250454E337B355546585642555C515A4D345F5457443B46296 user_pref("CT1060933.backendstorage./9b+7e31;cjh<@ k@c", "247E61393F236B2573737029202B6D404E434C31793353474B2B564B4E3B323D205D524D5550534D462F487C204B user_pref("CT1060933.backendstorage./9b+7e31;cjhb8iiikcnnb(shk", "247E61393F236B257572797A772B222D6F4250454E337B35554F4556565658505B5B4F35605558453C47 user_pref("CT1060933.backendstorage./9b+7e31;cjhf9ae<<$dg", "247E61393F236B25717679752A212C6E414F444D327A345452454D5148483050533F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cjhf9ae<<$pn", "247E61393F236B257170717A2A212C6E414F444D327A345452454D514848305C5A3F364124615651595457514 user_pref("CT1060933.backendstorage./9b+7e31;cjhj:9;bg=%peh", "247E61393F236B25757476767B2B222D6F4250454E337B3555574746484F544A325D5255423944276467554 user_pref("CT1060933.backendstorage./9b+7e31;cji6hdmc=$odg", "247E61393F236B2576737579782B222D6F4250454E337B35564355515A504A315C5154413843266358535B56 user_pref("CT1060933.backendstorage./9b+7e31;cji8a k@c", "247E61393F236B256F75287E2A6C3F4D424B30783253424B2A554A4D3A313C7E4B47515D422B4436463D482B5758 user_pref("CT1060933.backendstorage./9b+7e31;cji;<ai\"mbe", "247E61393F236B256E7378762A212C6E414F444D327A345547484D552E594E513E35402360555058535650493 user_pref("CT1060933.backendstorage./9b+7e31;cji>h k@c", "247E61393F236B256E7476722A212C6E414F444D327A34554A542C574C4F3C333E215E534E5651544E4730497679 user_pref("CT1060933.backendstorage./9b+7e31;cji>k3?a#k@", "247E61393F236B257674287E2A6C3F4D424B3078325348553D494B2D554A3C333E215E534E5651544E47304926 user_pref("CT1060933.backendstorage./9b+7e31;cji>k3?a#mm", "247E61393F236B257377287E2A6C3F4D424B3078325348553D494B2D57573C333E215E534E5651544E47304928 user_pref("CT1060933.backendstorage./9b+7e31;cji>k3?a#nc&?j", "247E61393F236B257677287E2A6C3F4D424B3078325348553D494B2D584D3049543F3641246156515954575 user_pref("CT1060933.backendstorage./9b+7e31;cji>k3?a#ncf", "247E61393F236B257678287E2A6C3F4D424B3078325348553D494B2D584D503D343F224E4F58442D4635483F4 user_pref("CT1060933.backendstorage./9b+7e31;cji?8h<ao=m&rp", "247E61393F236B25717077732A212C6E414F444D327A34554B4454484D5B4959325E5C413843266358535B5 user_pref("CT1060933.backendstorage./9b+7e31;cjig=ki\"mbe", "247E61393F236B2574717829202B6D404E434C31793354524856542D584D503D343F225F6250442D463836494 user_pref("CT1060933.backendstorage./9b+7e31;cjzz>h:\"mbe", "247E61393F236B2575767972782B222D6F4250454E337B3528284B55472F5A4F523F364124616452462F48374 user_pref("CT1060933.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426 user_pref("CT1060933.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57"); user_pref("CT1060933.backendstorage./9b-0?3g>d", "3E6A4072426F44747A46754475204A494B7B254C227D522A5456252456252D5929312E2B"); user_pref("CT1060933.backendstorage./9b-0?3g@6:5;", ""); user_pref("CT1060933.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); user_pref("CT1060933.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D443078324C4142477E2B2C48574B48565D5C3553525C6362615A5C643F6A5 user_pref("CT1060933.backendstorage./9b/556,bi5a>g", "6E6D6C706F6E726E737477767B"); user_pref("CT1060933.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576"); user_pref("CT1060933.backendstorage./9b3=>@44i48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F"); user_pref("CT1060933.backendstorage./9b5ba==9cjag", "6A67406D426D74757A77464672757B4C7C204F217E"); user_pref("CT1060933.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D696E726F6C747470777378"); user_pref("CT1060933.backendstorage./9b90e@.3c;7b=?ofb>>rhiqs", "393F352F3E"); user_pref("CT1060933.backendstorage./9b9643g3/9e", "6A"); user_pref("CT1060933.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D"); user_pref("CT1060933.backendstorage./9b<:222h64<", "393F352F3E"); user_pref("CT1060933.backendstorage./9b<:222h64<l8daj", "6D7070707673747977712A7A75727879757B78"); user_pref("CT1060933.backendstorage./9b=+03eh8h8j?:", "4443"); user_pref("CT1060933.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52"); user_pref("CT1060933.backendstorage./9b?b0d:8aj62<h", "6D"); user_pref("CT1060933.backendstorage./9ba@0<0bi6a7gn:6@l?", "6C"); user_pref("CT1060933.backendstorage._key_cl_active", "38613336306461382D343536642D343134662D626534372D373931353463346362636464"); user_pref("CT1060933.backendstorage.autocompletepro_enable", "31"); user_pref("CT1060933.backendstorage.autocompletepro_enable_auto", "31"); user_pref("CT1060933.backendstorage.cb_experience_000", "35323437"); user_pref("CT1060933.backendstorage.cb_firstuse0100", "31"); user_pref("CT1060933.backendstorage.cb_user_id_000", "43423537313831373232323231335F46697265666F78"); user_pref("CT1060933.backendstorage.cbcountry_000", "4245"); user_pref("CT1060933.backendstorage.cbcountry_001", "4245"); user_pref("CT1060933.backendstorage.cbfirsttime", "547565204D617220313320323031322031373A33323A343520474D542B303130302028526F6D616E636520287374616E646 user_pref("CT1060933.backendstorage.cbopenmamsettings", "30"); user_pref("CT1060933.backendstorage.mam_gk_appsdefaultenabled", "6E756C6C"); user_pref("CT1060933.backendstorage.mam_gk_appstate_couponbuddy", "6F6E"); user_pref("CT1060933.backendstorage.mam_gk_appstate_pricegong", "6F6E"); user_pref("CT1060933.backendstorage.mam_gk_appstatereporttime", "31333834313539323336383334"); user_pref("CT1060933.backendstorage.mam_gk_calledsetupservice", "31"); user_pref("CT1060933.backendstorage.mam_gk_currentbadgevalue", "31"); user_pref("CT1060933.backendstorage.mam_gk_currentversion", "312E31312E342E32"); user_pref("CT1060933.backendstorage.mam_gk_dealply_appstate", "6F6E"); user_pref("CT1060933.backendstorage.mam_gk_eventscache", "7B2234316438353831642D653438312D343538382D613637352D393938373164663366633034223A7B22746F7069 user_pref("CT1060933.backendstorage.mam_gk_existingusersrecoverydone", "31"); user_pref("CT1060933.backendstorage.mam_gk_first_time", "31"); user_pref("CT1060933.backendstorage.mam_gk_globalkeysmigratedtolocalstorage", "31"); user_pref("CT1060933.backendstorage.mam_gk_lastlogintime", "31333834313539323337313137"); user_pref("CT1060933.backendstorage.mam_gk_localization", "7B22676164676574436F6E74656E74506F6C696379223A7B2254657874223A2242656C656964206265747265666 user_pref("CT1060933.backendstorage.mam_gk_mamenabled", "66616C7365"); user_pref("CT1060933.backendstorage.mam_gk_newapps", "5B7B226964223A22436C61726974795F416374697665222C226E616D65223A22436C6172697479222C22646573637269 user_pref("CT1060933.backendstorage.mam_gk_settings1.10.2.5", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A32343 user_pref("CT1060933.backendstorage.mam_gk_settings1.10.4.0", "7B22537461747573223A22737563636565646564222C2244617461223A7B2263757272656E7444617465223 user_pref("CT1060933.backendstorage.mam_gk_settings1.11.4.2", "7B22537461747573223A22737563636565646564222C2244617461223A7B2263757272656E7444617465223 user_pref("CT1060933.backendstorage.mam_gk_settings1.4.3.1", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.4.3.2", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.4.4.6", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.6.0.1", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.8.0.4", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.9.0.4", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_settings1.9.0.5", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A323430 user_pref("CT1060933.backendstorage.mam_gk_showclosebutton", "74727565"); user_pref("CT1060933.backendstorage.mam_gk_showwelcomegadget", "66616C7365"); user_pref("CT1060933.backendstorage.mam_gk_stamp", "35345F30"); user_pref("CT1060933.backendstorage.mam_gk_user_approval_interacted", "31"); user_pref("CT1060933.backendstorage.mam_gk_userid", "30656465626565662D333162632D346638612D386233622D393165353265346463346232"); user_pref("CT1060933.backendstorage.mam_gk_welcomedialogmode", "31"); user_pref("CT1060933.backendstorage.pg_enable", "74727565"); user_pref("CT1060933.backendstorage.printitgreenstatus", "74727565"); user_pref("CT1060933.backendstorage.sac-country-code", "22424522"); user_pref("CT1060933.backendstorage.sac-experiments-animation", "7B226E616D65223A22302E3735222C2276657273696F6E223A337D"); user_pref("CT1060933.backendstorage.sac-experiments-hover_effect", "7B226E616D65223A2273686F7274222C2276657273696F6E223A327D"); user_pref("CT1060933.backendstorage.sac-experiments-image_analysis", "7B226E616D65223A22776974686F75745375627469746C65222C2276657273696F6E223A317D"); user_pref("CT1060933.backendstorage.sac-experiments-placement", "7B226E616D65223A22777265636B2D77696465222C2276657273696F6E223A327D"); user_pref("CT1060933.backendstorage.sac-experiments-play_icon", "7B226E616D65223A22796573222C2276657273696F6E223A317D"); user_pref("CT1060933.backendstorage.sac-periodic-reports", "7B227974745F70696E675F30223A5B313336373334383934373932382C31343430303030305D7D"); user_pref("CT1060933.backendstorage.sac-user-id", "2234366239303064632D613039382D343563332D623839652D34393930386463663336623022"); user_pref("CT1060933.backendstorage.sac-yt-first-ping", "31333636363134313634393731"); user_pref("CT1060933.backendstorage.sac_impressions_count", "31"); user_pref("CT1060933.backendstorage.searchappstate", "33"); user_pref("CT1060933.backendstorage.searchapptracking", "31"); user_pref("CT1060933.backendstorage.shoppingapp.gk.exipres", "576564204F637420313720323031322031333A30363A353220474D542B303230302028526F6D616E63652028 user_pref("CT1060933.backendstorage.shoppingapp.gk.geolocation", "62656C6769756D"); user_pref("CT1060933.backendstorage.url_history0001", "68747470733A2F2F6B62636F6E6C696E652E6B62632E62652F4F4E4C2F413032363F616766457865637574696F6E3D5 user_pref("CT1060933.backendstorage.whitelist", "5B7B226E616D65223A2254696D65222C22646F6D61696E5F72656778223A22282E2A5C5C2E293F74696D652E636F6D222C226 user_pref("CT1060933.backendstorage.whitelist_ts", "31333637333433353432313932"); user_pref("CT1060933.backendstorage.wreck-country-code", "22424522"); user_pref("CT1060933.backendstorage.wreck-experiments-design", "7B226E616D65223A2273696465626172222C2276657273696F6E223A337D"); user_pref("CT1060933.backendstorage.wreck-experiments-feed", "7B226E616D65223A22777265636B416E645461626F6F6C61222C2276657273696F6E223A327D"); user_pref("CT1060933.backendstorage.wreck-experiments-hover_effect", "7B226E616D65223A2268616C66222C2276657273696F6E223A317D"); user_pref("CT1060933.backendstorage.wreck-experiments-trigger", "7B226E616D65223A2278302E35222C2276657273696F6E223A317D"); user_pref("CT1060933.backendstorage.wreck-periodic-reports", "7B22777265636B5F70696E675F30223A5B313336373334383934373932332C31343430303030305D7D"); user_pref("CT1060933.backendstorage.wreck-user-id", "2236626239633436612D653364392D343161652D626261352D39316231666364353137623722"); user_pref("CT1060933.cb_experience_000", "%BB%BA%BF%BE"); user_pref("CT1060933.cb_experience_000.enc", "NTQ5OA=="); user_pref("CT1060933.cb_firstuse0100", "%B7"); user_pref("CT1060933.cb_firstuse0100.enc", "MQ=="); user_pref("CT1060933.cb_user_id_000", "%C9%C8%BB%BD%B7%BE%B7%BD%B8%B8%B8%B8%B7%B9%E5%CC%EF%F8%EB%EC%F5%FE"); user_pref("CT1060933.cb_user_id_000.enc", "Q0I1NzE4MTcyMjIyMTNfRmlyZWZveA=="); user_pref("CT1060933.cbcountry_000.from_oldbar.enc", "QkU="); user_pref("CT1060933.cbcountry_001.from_oldbar.enc", "QkU="); user_pref("CT1060933.cbfirsttime", "%DA%FB%EB%A6%D3%E7%F8%A6%B7%B9%A6%B8%B6%B7%B8%A6%B7%BD%C0%B9%B8%C0%BA%BB%A6%CD%D3%DA%B1%B6%B7%B6%B6%A6%AE%D8%F5%F3 user_pref("CT1060933.cbfirsttime.enc", "VHVlIE1hciAxMyAyMDEyIDE3OjMyOjQ1IEdNVCswMTAwIChSb21hbmNlIChzdGFuZGFhcmR0aWpkKSk="); user_pref("CT1060933.cbopenmamsettings.from_oldbar.enc", "MA=="); user_pref("CT1060933.components.1000080", true); user_pref("CT1060933.countryCode", "BE"); user_pref("CT1060933.embeddedsData", "[{\"appId\":\"128280995260143876\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"get user_pref("CT1060933.firstTimeDialogOpened", true); user_pref("CT1060933.fixPageNotFoundErrorByUser", "TRUE"); user_pref("CT1060933.fixPageNotFoundErrorInHidden", "true"); user_pref("CT1060933.fullUserID", "UN04002027154910481.UP.206007"); user_pref("CT1060933.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit. user_pref("CT1060933.globalFirstTimeInfoLastCheckTime", "Fri Nov 01 2013 14:15:49 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.homepageProtectorEnableByLogin", true); user_pref("CT1060933.initDone", true); user_pref("CT1060933.installId", "ConduitNSISIntegration"); user_pref("CT1060933.installType", "ConduitXPEIntegration"); user_pref("CT1060933.isAppTrackingManagerOn", false); user_pref("CT1060933.isCheckedStartAsHidden", true); user_pref("CT1060933.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":true}"); user_pref("CT1060933.isFirstRadioInstallation", false); user_pref("CT1060933.isFirstTimeToolbarLoading", "false"); user_pref("CT1060933.isPerformedSmartBarTransition", "true"); user_pref("CT1060933.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); user_pref("CT1060933.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.conduit.com/?ctid=CT1060933&octid=CT1060933&SearchSource= user_pref("CT1060933.lastVersion", "10.22.5.510"); user_pref("CT1060933.mam_gk_appStateReportTime", "%B7%B9%BE%BB%B6%BB%BF%B8%BF%BE%B7%B7%B7"); user_pref("CT1060933.mam_gk_appStateReportTime.enc", "MTM4NTA1OTI5ODExMQ=="); user_pref("CT1060933.mam_gk_appState_Clarity_Active", "%F5%F4"); user_pref("CT1060933.mam_gk_appState_Clarity_Active.enc", "b24="); user_pref("CT1060933.mam_gk_appState_CouponBuddy", "%F5%F4"); user_pref("CT1060933.mam_gk_appState_CouponBuddy.enc", "b24="); user_pref("CT1060933.mam_gk_appState_PriceGong", "%F5%EC%EC"); user_pref("CT1060933.mam_gk_appState_PriceGong.enc", "b2Zm"); user_pref("CT1060933.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2"); user_pref("CT1060933.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); user_pref("CT1060933.mam_gk_appsdefaultenabled.from_oldbar.enc", "bnVsbA=="); user_pref("CT1060933.mam_gk_calledSetupService", "%B7"); user_pref("CT1060933.mam_gk_calledSetupService.enc", "MQ=="); user_pref("CT1060933.mam_gk_currentBadgeValue", "%B6"); user_pref("CT1060933.mam_gk_currentBadgeValue.enc", "MA=="); user_pref("CT1060933.mam_gk_currentVersion", "%B7%B4%B7%B7%B4%BA%B4%B8"); user_pref("CT1060933.mam_gk_currentVersion.enc", "MS4xMS40LjI="); user_pref("CT1060933.mam_gk_currentbadgevalue.from_oldbar.enc", "MQ=="); user_pref("CT1060933.mam_gk_currentversion.from_oldbar.enc", "MS4xMS40LjI="); user_pref("CT1060933.mam_gk_dealply_appstate.from_oldbar.enc", "b24="); user_pref("CT1060933.mam_gk_eventsCache.enc", "eyI0MWQ4NTgxZC1lNDgxLTQ1ODgtYTY3NS05OTg3MWRmM2ZjMDQiOnsidG9waWMiOiJyZXF1ZXN0U2V0dGluZ3MiLCJkYXRhIjoiIiw user_pref("CT1060933.mam_gk_existingUsersRecoveryDone", "%B7"); user_pref("CT1060933.mam_gk_existingUsersRecoveryDone.enc", "MQ=="); user_pref("CT1060933.mam_gk_first_time", "%B7"); user_pref("CT1060933.mam_gk_first_time.enc", "MQ=="); user_pref("CT1060933.mam_gk_globalKeysMigratedToLocalStorage", "%B7"); user_pref("CT1060933.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ=="); user_pref("CT1060933.mam_gk_lastLoginTime", "%B7%B9%BE%BB%B6%BB%BF%B8%BF%BE%BB%B6%B6"); user_pref("CT1060933.mam_gk_lastLoginTime.enc", "MTM4NTA1OTI5ODUwMA=="); user_pref("CT1060933.mam_gk_localization.enc", "eyJkaWFsb2dPSyI6eyJUZXh0IjoiT0sifSwiZG1ib3gxIjp7IlRleHQiOiJEZWFsXG52YW4gZGUgZGFnIn0sImRtYm94MiI6eyJUZX user_pref("CT1060933.mam_gk_mamEnabled", "%EC%E7%F2%F9%EB"); user_pref("CT1060933.mam_gk_mamEnabled.enc", "ZmFsc2U="); user_pref("CT1060933.mam_gk_newApps", "%E1%E3"); user_pref("CT1060933.mam_gk_newApps.enc", "W10="); user_pref("CT1060933.mam_gk_pgUnloadedOnce", "%FA%F8%FB%EB"); user_pref("CT1060933.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); user_pref("CT1060933.mam_gk_settings1.11.4.2", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9 user_pref("CT1060933.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMjEiLCJpbnRlcnZhbCI6MjQwLCJzdG user_pref("CT1060933.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB"); user_pref("CT1060933.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); user_pref("CT1060933.mam_gk_showclosebutton.from_oldbar.enc", "dHJ1ZQ=="); user_pref("CT1060933.mam_gk_showwelcomegadget.from_oldbar.enc", "ZmFsc2U="); user_pref("CT1060933.mam_gk_stamp", "%BB%BA%E5%B6"); user_pref("CT1060933.mam_gk_stamp.enc", "NTRfMA=="); user_pref("CT1060933.mam_gk_userId", "%B6%EB%EA%EB%E8%EB%EB%EC%B3%B9%B7%E8%E9%B3%BA%EC%BE%E7%B3%BE%E8%B9%E8%B3%BF%B7%EB%BB%B8%EB%BA%EA%E9%BA%E8%B8"); user_pref("CT1060933.mam_gk_userId.enc", "MGVkZWJlZWYtMzFiYy00ZjhhLThiM2ItOTFlNTJlNGRjNGIy"); user_pref("CT1060933.mam_gk_user_approval_interacted", "%B7"); user_pref("CT1060933.mam_gk_user_approval_interacted.enc", "MQ=="); user_pref("CT1060933.mam_gk_user_approval_interacted.from_oldbar.enc", "MQ=="); user_pref("CT1060933.mam_gk_welcomeDialogMode", "%B7"); user_pref("CT1060933.mam_gk_welcomeDialogMode.enc", "MQ=="); user_pref("CT1060933.mam_gk_welcomedialogmode.from_oldbar.enc", "MQ=="); user_pref("CT1060933.missingMachineIdSent", "true"); user_pref("CT1060933.myStuffEnabled", true); user_pref("CT1060933.myStuffPublihserMinWidth", 400); user_pref("CT1060933.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID" user_pref("CT1060933.myStuffServiceIntervalMM", 1440); user_pref("CT1060933.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUF user_pref("CT1060933.navigateToUrlOnSearch", false); user_pref("CT1060933.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"http%3A%2F%2Fwww.demorgen.be%2F\",\"EB_MAIN_FRAME_TITLE user_pref("CT1060933.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); user_pref("CT1060933.oldAppsList", "128346981843587669,128280995260143876,111,129272674122038321,129032145384800518,129032148247613461,129032152822456 user_pref("CT1060933.originalHomepage", "chrome://branding/locale/browserconfig.properties"); user_pref("CT1060933.originalSearchAddressUrl", ""); user_pref("CT1060933.originalSearchEngine", "chrome://browser-region/locale/region.properties"); user_pref("CT1060933.pg_enable.from_oldbar.enc", "dHJ1ZQ=="); user_pref("CT1060933.price-gong.isManagedApp", "true"); user_pref("CT1060933.printitgreenstatus.from_oldbar.enc", "dHJ1ZQ=="); user_pref("CT1060933.revertSettingsEnabled", true); user_pref("CT1060933.sac-country-code.from_oldbar.enc", "IkJFIg=="); user_pref("CT1060933.sac-experiments-animation.from_oldbar.enc", "eyJuYW1lIjoiMC43NSIsInZlcnNpb24iOjN9"); user_pref("CT1060933.sac-experiments-hover_effect.from_oldbar.enc", "eyJuYW1lIjoic2hvcnQiLCJ2ZXJzaW9uIjoyfQ=="); user_pref("CT1060933.sac-experiments-image_analysis.from_oldbar.enc", "eyJuYW1lIjoid2l0aG91dFN1YnRpdGxlIiwidmVyc2lvbiI6MX0="); user_pref("CT1060933.sac-experiments-placement.from_oldbar.enc", "eyJuYW1lIjoid3JlY2std2lkZSIsInZlcnNpb24iOjJ9"); user_pref("CT1060933.sac-experiments-play_icon.from_oldbar.enc", "eyJuYW1lIjoieWVzIiwidmVyc2lvbiI6MX0="); user_pref("CT1060933.sac-periodic-reports.from_oldbar.enc", "eyJ5dHRfcGluZ18wIjpbMTM2NzM0ODk0NzkyOCwxNDQwMDAwMF19"); user_pref("CT1060933.sac-user-id.from_oldbar.enc", "IjQ2YjkwMGRjLWEwOTgtNDVjMy1iODllLTQ5OTA4ZGNmMzZiMCI="); user_pref("CT1060933.sac-yt-first-ping.from_oldbar.enc", "MTM2NjYxNDE2NDk3MQ=="); user_pref("CT1060933.sac_impressions_count.from_oldbar.enc", "MQ=="); user_pref("CT1060933.search.searchAppId", "128280995260143876"); user_pref("CT1060933.search.searchCount", 2); user_pref("CT1060933.searchFromAddressBarEnabledByUser", "false"); user_pref("CT1060933.searchInNewTabEnabledByUser", "true"); user_pref("CT1060933.searchInNewTabEnabledInHidden", "true"); user_pref("CT1060933.searchProtectorDialogDelayInSec", 10); user_pref("CT1060933.searchProtectorEnableByLogin", true); user_pref("CT1060933.searchSuggestEnabledByUser", "false"); user_pref("CT1060933.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); user_pref("CT1060933.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); user_pref("CT1060933.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); user_pref("CT1060933.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT1060933\"}"); user_pref("CT1060933.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"http://Freecorder.Media-Toolbar.com user_pref("CT1060933.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Freecorder \"}"); user_pref("CT1060933.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); user_pref("CT1060933.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}"); user_pref("CT1060933.serviceLayer_services_Configuration_lastUpdate", "1385059283367"); user_pref("CT1060933.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1385059283287"); user_pref("CT1060933.serviceLayer_services_appsMetadata_lastUpdate", "1385059282944"); user_pref("CT1060933.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1384171936938"); user_pref("CT1060933.serviceLayer_services_login_10.20.101.5_lastUpdate", "1384250751833"); user_pref("CT1060933.serviceLayer_services_login_10.21.1.507_lastUpdate", "1384415094196"); user_pref("CT1060933.serviceLayer_services_login_10.22.3.518_lastUpdate", "1385059288868"); user_pref("CT1060933.serviceLayer_services_login_10.22.5.510_lastUpdate", "1385124249821"); user_pref("CT1060933.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1384171936859"); user_pref("CT1060933.serviceLayer_services_searchAPI_lastUpdate", "1385059283349"); user_pref("CT1060933.serviceLayer_services_serviceMap_lastUpdate", "1385059282937"); user_pref("CT1060933.serviceLayer_services_toolbarContextMenu_lastUpdate", "1385059282895"); user_pref("CT1060933.serviceLayer_services_toolbarSettings_lastUpdate", "1385124249825"); user_pref("CT1060933.serviceLayer_services_translation_lastUpdate", "1385059283239"); user_pref("CT1060933.settingsINI", true); user_pref("CT1060933.showToolbarPermission", "false"); user_pref("CT1060933.smartbar.CTID", "CT1060933"); user_pref("CT1060933.smartbar.Uninstall", "0"); user_pref("CT1060933.smartbar.toolbarName", "Freecorder "); user_pref("CT1060933.testingCtid", ""); user_pref("CT1060933.toolbarAppMetaDataLastCheckTime", "Sun Nov 10 2013 16:27:56 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.toolbarBornServerTime", "13-3-2012"); user_pref("CT1060933.toolbarContextMenuLastCheckTime", "Sun Nov 10 2013 16:27:56 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.toolbarCurrentServerTime", "22-11-2013"); user_pref("CT1060933.toolbarLoginClientTime", "Mon Nov 11 2013 13:12:17 GMT+0100 (Romance (standaardtijd))"); user_pref("CT1060933.upgradeFromOBVersion", true); user_pref("CT1060933.url_history0001", "%EE%FA%FA%F6%C0%B5%B5%FD%FD%FD%B4%EF%F6%E7%EA%E9%F2%FB%E8%B4%F4%F2%B5%C0%C0%C0%E9%F2%EF%E9%F1%EE%E7%F4%EA%F2%E user_pref("CT1060933.url_history0001.enc", "aHR0cDovL3d3dy5pcGFkY2x1Yi5ubC86OjpjbGlja2hhbmRsZXI6OjoxMzg1MDY4NTgwNTkyLCwsaHR0cDovL3d3dy5pcGFkY2x1Yi5ubC user_pref("CT1060933.usagesFlag", 2); user_pref("CT1060933.whitelist.from_oldbar.enc", "W3sibmFtZSI6IlRpbWUiLCJkb21haW5fcmVneCI6IiguKlxcLik/dGltZS5jb20iLCJkb21haW5fY2xhc3MiOiJOZXdzIn0seyJu user_pref("CT1060933.whitelist_ts.from_oldbar.enc", "MTM2NzM0MzU0MjE5Mg=="); user_pref("CT1060933.wreck-country-code.from_oldbar.enc", "IkJFIg=="); user_pref("CT1060933.wreck-experiments-design.from_oldbar.enc", "eyJuYW1lIjoic2lkZWJhciIsInZlcnNpb24iOjN9"); user_pref("CT1060933.wreck-experiments-feed.from_oldbar.enc", "eyJuYW1lIjoid3JlY2tBbmRUYWJvb2xhIiwidmVyc2lvbiI6Mn0="); user_pref("CT1060933.wreck-experiments-hover_effect.from_oldbar.enc", "eyJuYW1lIjoiaGFsZiIsInZlcnNpb24iOjF9"); user_pref("CT1060933.wreck-experiments-trigger.from_oldbar.enc", "eyJuYW1lIjoieDAuNSIsInZlcnNpb24iOjF9"); user_pref("CT1060933.wreck-periodic-reports.from_oldbar.enc", "eyJ3cmVja19waW5nXzAiOlsxMzY3MzQ4OTQ3OTIzLDE0NDAwMDAwXX0="); user_pref("CT1060933.wreck-user-id.from_oldbar.enc", "IjZiYjljNDZhLWUzZDktNDFhZS1iYmE1LTkxYjFmY2Q1MTdiNyI="); user_pref("CT1060933_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1385110709092,\"isWithState\":\"\",\"timeFromStar user_pref("CommunityToolbar.ETag.http://Settings.toolbar.search.conduit.com/root/CT1060933/CT1060933", "\"abf8ba52e13a966dd47db2fa69bfad593\""); user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT1060933", "\"1381823163\""); user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en-us&ctid=CT1060933", "uG7mdamLoNmpmgC2c0Jct user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en-us&ctid=CT1060933", "9uXRY86McHhmOreOHsv6MA user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en-us&ctid=CT1060933", "I1tfz7EBg4DmNytL9x55l user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en-us&ctid=CT1060933", "ZI41WLbm1fFgx4gn0bs99Q== user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en-us&ctid=CT1060933&UM=UM_UNINSTALL_ID", "ZI41W user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT1060933", "\"52c3f1538cb4af4ada257fcbc6b15d49\""); user_pref("CommunityToolbar.ToolbarsList", "CT1060933"); user_pref("CommunityToolbar.ToolbarsList2", "CT1060933"); user_pref("CommunityToolbar.ToolbarsList4", "CT1060933"); user_pref("smartbar.conduitSearchAddressUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=2&q="); user_pref("valueApps.CT1060933._key_cl_active", "38613336306461382D343536642D343134662D626534372D373931353463346362636464"); user_pref("valueApps.CT1060933._key_cl_active.storedInFile", false); user_pref("valueApps.CT1060933.cb_experience_000", "35353131"); user_pref("valueApps.CT1060933.cb_experience_000.storedInFile", false); user_pref("valueApps.CT1060933.cb_firstuse0100", "31"); user_pref("valueApps.CT1060933.cb_firstuse0100.storedInFile", false); user_pref("valueApps.CT1060933.cb_user_id_000", "43423537313831373232323231335F46697265666F78"); user_pref("valueApps.CT1060933.cb_user_id_000.storedInFile", false); user_pref("valueApps.CT1060933.cbfirsttime", "547565204D617220313320323031322031373A33323A343520474D542B303130302028526F6D616E636520287374616E64616172 user_pref("valueApps.CT1060933.cbfirsttime.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_appStateReportTime", "31333835313235313538393930"); user_pref("valueApps.CT1060933.mam_gk_appStateReportTime.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_appState_Clarity_Active", "6F6E"); user_pref("valueApps.CT1060933.mam_gk_appState_Clarity_Active.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_appState_CouponBuddy", "6F6E"); user_pref("valueApps.CT1060933.mam_gk_appState_CouponBuddy.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_appState_PriceGong", "6F6666"); user_pref("valueApps.CT1060933.mam_gk_appState_PriceGong.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_appsConfig.storedInFile", true); user_pref("valueApps.CT1060933.mam_gk_appsDefaultEnabled", "6E756C6C"); user_pref("valueApps.CT1060933.mam_gk_appsDefaultEnabled.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_calledSetupService", "31"); user_pref("valueApps.CT1060933.mam_gk_calledSetupService.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_currentBadgeValue", "30"); user_pref("valueApps.CT1060933.mam_gk_currentBadgeValue.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_currentVersion", "312E31312E342E32"); user_pref("valueApps.CT1060933.mam_gk_currentVersion.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_eventsCache.storedInFile", true); user_pref("valueApps.CT1060933.mam_gk_existingUsersRecoveryDone", "31"); user_pref("valueApps.CT1060933.mam_gk_existingUsersRecoveryDone.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_first_time", "31"); user_pref("valueApps.CT1060933.mam_gk_first_time.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_globalKeysMigratedToLocalStorage", "31"); user_pref("valueApps.CT1060933.mam_gk_globalKeysMigratedToLocalStorage.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_lastLoginTime", "31333835313235313539323030"); user_pref("valueApps.CT1060933.mam_gk_lastLoginTime.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_localization.storedInFile", true); user_pref("valueApps.CT1060933.mam_gk_mamEnabled", "66616C7365"); user_pref("valueApps.CT1060933.mam_gk_mamEnabled.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_migrated_from_ls", "31"); user_pref("valueApps.CT1060933.mam_gk_migrated_from_ls.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_newApps", "5B5D"); user_pref("valueApps.CT1060933.mam_gk_newApps.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_pgUnloadedOnce", "74727565"); user_pref("valueApps.CT1060933.mam_gk_pgUnloadedOnce.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_settings1.11.4.2.storedInFile", true); user_pref("valueApps.CT1060933.mam_gk_showWelcomeGadget", "66616C7365"); user_pref("valueApps.CT1060933.mam_gk_showWelcomeGadget.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_stamp", "35345F30"); user_pref("valueApps.CT1060933.mam_gk_stamp.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_userId", "30656465626565662D333162632D346638612D386233622D393165353265346463346232"); user_pref("valueApps.CT1060933.mam_gk_userId.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_user_approval_interacted", "31"); user_pref("valueApps.CT1060933.mam_gk_user_approval_interacted.storedInFile", false); user_pref("valueApps.CT1060933.mam_gk_welcomeDialogMode", "31"); user_pref("valueApps.CT1060933.mam_gk_welcomeDialogMode.storedInFile", false); user_pref("valueApps.CT1060933.url_history0001.storedInFile", true); ---- Lines conduit removed from prefs.js ---- user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/15651/15317/BE", "\"0\""); user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en-us", "G9mW7heT/8xIX1frcduu0A=="); user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en-us", "2E1/v7EfCEDbv3VaBQMELg=="); user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en-us", "UgzXjW7BIkfdx+x39Ruv3w=="); user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en-us", "FqddrIU7eyJgaaLyHDeVMQ=="); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"380ff24abc2ce1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10.0.1", "\"801a319dd78ccc1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.0.7", "\"4ead38b3e6bcd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0d648794549cd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16.0.3", "\"0343677cfb1cd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"0343677cfb1cd1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.19.0.3", "\"97e416bb586ce1:0\""); user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.20.0.4", "\"dfe74040abc2ce1:0\""); user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=en-us", "\"24cd66a6006eed0d0b7bf2cbc9b0dd16\""); user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Eigenaar\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\6h0biava.default\\conduitComm user_pref("CommunityToolbar.MiniIPageGadgetSize.Insert title here user_pref("CommunityToolbar.notifications.clientsServerUrl", "http://alert.client.conduit.com"); user_pref("CommunityToolbar.notifications.servicesServerUrl", "http://alert.services.conduit.com"); user_pref("plugin.state.npconduitfirefoxplugin", 2); ---- Lines CommunityToolbar removed from prefs.js ---- user_pref("CommunityToolbar.globalUserId", "7a40a731-e703-4367-9973-bf6c5c726bee"); user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.20.0.4"); user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Tue Nov 05 2013 14:42:00 GMT+0100 (Romance (standaardtijd))"); user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Nov 10 2013 16:28:04 GMT+0100 (Romance (standaardtijd))"); user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true); user_pref("CommunityToolbar.notifications.locale", "en"); user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Nov 10 2013 16:27:55 GMT+0100 (Romance (standaardtijd))"); user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); user_pref("CommunityToolbar.notifications.showTrayIcon", false); user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); user_pref("CommunityToolbar.notifications.userId", "0f8c68e0-b6ed-47d1-92bd-dbd324414a11"); user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties"); user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties"); user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); ---- Lines smartbar removed from prefs.js ---- user_pref("smartbar.machineId", "SSRIILT+JKF6HWRYOLZ/J26MLXJBIXZQ17WPHXUSV3F3PRBQDCODEHPI/8BVW6CAES/NJJCCJ1UPGSTME1MC9W"); user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- Lines {3ce45c4f-bfff-4988-9a3c-a75c1f491319} removed from prefs.js ---- user_pref("extensions.{3ce45c4f-bfff-4988-9a3c-a75c1f491319}.install-event-fired", true); ---- Lines {91da5e8a-3318-4f8c-b67e-5964de3ab546} removed from prefs.js ---- user_pref("extensions.{91da5e8a-3318-4f8c-b67e-5964de3ab546}.install-event-fired", true); ---- Lines {1392b8d2-5c05-419f-a8f6-b9f15a596612} removed from prefs.js ---- user_pref("extensions.{1392b8d2-5c05-419f-a8f6-b9f15a596612}.install-event-fired", true); ---- Lines {1392b8d2-5c05-419f-a8f6-b9f15a596612} modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{ABDE892B-13A8-4d1b-88E6-365A6E755758}\":{\"descriptor\":\"C:\\\\ ---- FireFox user.js and prefs.js backups ---- prefs_20140501_1926_.backup ProfilePath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- FireFox user.js and prefs.js backups ---- prefs_20140501_1926_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "fsm"=- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "NPSStartup"=- ""=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Freecorder deleted C:\Users\Eigenaar\.android deleted C:\PROGRA~2\Conduit deleted C:\Users\Eigenaar\AppData\Roaming\dm.ini deleted C:\Users\Eigenaar\AppData\Roaming\SamsungLiveUpdateConfig.ini deleted C:\Users\Eigenaar\AppData\Roaming\tsdnwin.dll deleted C:\Users\Eigenaar\AppData\Roaming\Desktopicon deleted C:\ProgramData\SMRResults410.dat deleted C:\ProgramData\Package Cache deleted C:\Users\Eigenaar\AppData\LocalLow\Freecorder deleted C:\Users\Eigenaar\AppData\LocalLow\boost_interprocess deleted C:\Users\Eigenaar\AppData\LocalLow\Conduit deleted C:\Windows\Syswow64\tmp202D.tmp deleted C:\Windows\Syswow64\tmp203D.tmp deleted C:\Windows\Syswow64\tmp95E9.tmp deleted C:\Windows\Syswow64\tmp95EA.tmp deleted C:\Windows\Syswow64\tmp9A76.tmp deleted C:\Windows\Syswow64\tmp9A77.tmp deleted C:\Windows\Syswow64\tmpF69D.tmp deleted C:\Windows\Syswow64\tmpF69E.tmp deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\valueApps deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\CT1060933 deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default\searchplugins\safesearch.xml deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\conduitCommon deleted C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\smartbar deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Eigenaar\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2013-12-29 20:49:13 82446D358A9FB51CB9DA32A5C901D7A0 21040 ----a-w- C:\Windows\Sysnative\sdnclean64.exe ====== C:\Windows\Sysnative\drivers ===== 2013-12-30 17:58:19 90AA9E273410AD7A41D2D06E0FB46022 89304 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys 2013-12-29 16:20:12 E16E2431516D904CED3946AD3FF8C86B 854 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.INF 2013-12-29 16:20:12 97E11C50CE52277B377396EA8838E539 177752 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.SYS 2013-12-29 16:20:12 7846ED59291A134CC5DD017C6EC7B433 8222 ----a-w- C:\Windows\Sysnative\drivers\SYMEVENT64x86.CAT 2013-12-28 20:03:56 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2013-12-12 01:44:50 E0D3CD5841E5C7BE7B94BA946AF1E498 116736 ----a-w- C:\Windows\Sysnative\drivers\drmk.sys 2013-12-12 01:44:50 1E0B4CBBA91C6B041A14ECC2186F7E24 230400 ----a-w- C:\Windows\Sysnative\drivers\portcls.sys 2013-12-06 21:52:14 FBB35875FEFE53D4280259842069ED72 13207552 ----a-w- C:\Windows\Sysnative\drivers\atikmdag.sys 2013-12-06 20:21:44 A32BCAD9377E3B75D034CAFBA463A0AE 626176 ----a-w- C:\Windows\Sysnative\drivers\atikmpag.sys 2013-12-06 20:18:12 E89C4463DEE1CBC3FF1A52283B988D8C 43520 ----a-w- C:\Windows\Sysnative\drivers\ati2erec.dll ====== C:\Windows\Tasks ====== 2013-12-29 20:50:05 -------- d-----w- C:\Windows\Sysnative\Tasks\Safer-Networking ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-01-04 11:15:46 -------- d-----w- C:\Program Files\trend micro 2013-12-19 07:44:50 -------- d-----w- C:\Program Files\AMD ======= C:\PROGRA~2 ===== 2014-01-02 17:27:01 -------- d-----w- C:\PROGRA~2\Futuremark 2013-12-28 10:35:56 -------- d-----w- C:\PROGRA~2\NVIDIA Corporation 2013-12-27 16:23:38 -------- d-----w- C:\PROGRA~2\2K Games 2013-12-19 07:53:04 -------- d-----w- C:\PROGRA~2\AMD AVT 2013-12-18 12:33:22 -------- d-----w- C:\PROGRA~2\Six Networks 2013-12-11 14:53:47 -------- d-----w- C:\PROGRA~2\Mozilla Thunderbird 2013-12-10 22:04:52 -------- d-----w- C:\PROGRA~2\Rockstar Games 2013-12-09 15:20:15 -------- d-----w- C:\PROGRA~2\Raptr ======= C: ===== 2014-01-04 14:51:33 3A67E538B88DC132197DEFCE31C30F34 3070 ----a-w- C:\runcheck.txt ====== C:\Users\Eigenaar\AppData\Roaming ====== 2013-12-21 11:07:50 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\PunkBuster 2013-12-19 15:06:52 -------- d-----w- C:\Users\Eigenaar\AppData\Local\DayZ 2013-12-18 12:32:03 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\SIX Networks 2013-12-18 12:32:00 -------- d-----w- C:\Users\Eigenaar\AppData\Local\SIX Networks 2013-12-10 12:34:28 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\Ohm Force 2013-12-09 15:21:30 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved 2013-12-09 15:21:17 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\library_dir 2013-12-09 15:20:15 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\Raptr ====== C:\Users\Eigenaar ====== 2014-01-04 10:59:12 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Eigenaar\Desktop\RSITx64.exe 2014-01-02 13:14:11 6D1476BFA5D5A8A4BD9BC573165F451A 11300208 ----a-w- C:\Users\Eigenaar\Downloads\withSIX-Play.exe 2014-01-02 13:14:10 E3ACA2C4CD8766C742463B8C4A53B988 62061024 ----a-w- C:\Users\Eigenaar\Downloads\UplayInstaller.exe 2014-01-02 13:14:09 CE9508CC06868BC07D66BB61897B341E 1142864 ----a-w- C:\Users\Eigenaar\Downloads\SteamSetup.exe 2014-01-02 13:14:04 7CCDB06729E2731AF9D0DFBD86B437DE 2326976 ----a-w- C:\Users\Eigenaar\Downloads\setup.exe 2014-01-02 13:14:04 35439867D389732D99F9641D0E84AE14 7539624 ----a-w- C:\Users\Eigenaar\Downloads\NRnR.exe 2014-01-02 13:14:04 029C5055974EE6FC6DF0B6FE5A1C3CD6 16952720 ----a-w- C:\Users\Eigenaar\Downloads\OriginThinSetup.exe 2014-01-02 13:14:04 015DB786B324FFE31FE2D90578D84AC4 2293880 ----a-w- C:\Users\Eigenaar\Downloads\reflectdlfull.exe 2014-01-02 13:14:02 8BBE63DF6DF1B042E8EFA88E3B358FC8 347304 ----a-w- C:\Users\Eigenaar\Downloads\MicrosoftFixit.Printing.Run.exe 2014-01-02 13:14:02 89F9799AC08FA3BB1F612CA4567B98FF 453545 ----a-w- C:\Users\Eigenaar\Downloads\mb_driver_intel_bootdisk_irst_64_7series.exe 2014-01-02 13:13:07 733C462E5B365E4BB5158E270FCF0B75 13545144 ----a-w- C:\Users\Eigenaar\Downloads\ifw_en_trial.exe 2014-01-02 13:13:01 6BD029F99468A66300F9F235ACCE0D0E 263251024 ----a-w- C:\Users\Eigenaar\Downloads\20131213-002-v5i64.exe 2014-01-02 13:12:58 BB8FD039069B195307D6AC5B000D6FD4 213478368 ----a-w- C:\Users\Eigenaar\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe 2013-12-31 13:01:46 -------- d-----w- C:\ProgramData\Age of Empires 3 2013-12-19 07:53:19 -------- d-----w- C:\ProgramData\ATI 2013-12-19 07:48:37 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2013-12-18 12:32:13 -------- d-----w- C:\ProgramData\SIX Networks 2013-12-13 10:56:55 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2013-12-12 17:57:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dead Space 3 2013-12-09 11:26:22 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2013-12-08 17:23:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reader for pc ====== C: exe-files == 2014-01-04 11:15:48 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Eigenaar.exe 2014-01-04 10:59:12 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Eigenaar\Desktop\RSITx64.exe 2014-01-03 13:18:55 76B1717148C114D3A47147B1A5CCFFEA 4379048 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\ccsetup407.exe 2014-01-02 13:22:10 BE0F9BF31176F1C580D5BE37DA559801 1312270 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\testdisk-6.14.win\testdisk-6.14\photorec_win.exe 2014-01-02 13:22:10 2BCB45A3B6B1F14FED3CEB3C6613A3DE 1247758 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\testdisk-6.14.win\testdisk-6.14\testdisk_win.exe 2014-01-02 13:22:09 9505CCE777E383B7545B57EA6BB49CBB 146944 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\testdisk-6.14.win\testdisk-6.14\fidentify_win.exe 2014-01-02 13:22:06 92E105FA3D77D56C8D8E35826740CD8C 17261096 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\Partition Recovery\PartRecoveryToolkit-Setup.exe 2014-01-02 13:22:03 EAA97DE614367FB579461DA25879ECF3 9822152 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\MiniTool Power Data Recovery\pdr6free.exe 2014-01-02 13:22:03 84730F8D388C71260B7DCBA25B7EFB30 65693528 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\MiniTool Power Data Recovery Boot Disk\pdrbootdisk-setup.exe 2014-01-02 13:22:02 D406055FC26F3AD98542D14059A5F3B6 20772800 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\MiniTool Partion Wizard\pwhe8.exe 2014-01-02 13:22:02 B6A2B5F3230000E417EF9277D96E0E11 2338824 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\HP Printer Installatie Wizard\hppiw.exe 2014-01-02 13:22:01 65689075A82A08BB797BB9A5CC2932C9 1728221 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\Find and Mount\fnmsetup.exe 2014-01-02 13:21:56 3B6C5805C31114752997EB6272D723EB 285251656 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\Acronis True Image 2014\ATIH2014_trial_nl-NL.exe 2014-01-02 13:18:15 0FC0CD177C2084FC4B09BB82ED481478 509827480 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\setup_fallout_2.0.0.14.exe 2014-01-02 13:14:17 2CFD505070EE1AE30C70F1CC8B4A3B23 528392 ----a-w- C:\Users\Eigenaar\Downloads\DirectX\DXSETUP.exe 2014-01-02 13:14:11 6D1476BFA5D5A8A4BD9BC573165F451A 11300208 ----a-w- C:\Users\Eigenaar\Downloads\withSIX-Play.exe 2014-01-02 13:14:10 E3ACA2C4CD8766C742463B8C4A53B988 62061024 ----a-w- C:\Users\Eigenaar\Downloads\UplayInstaller.exe 2014-01-02 13:14:09 CE9508CC06868BC07D66BB61897B341E 1142864 ----a-w- C:\Users\Eigenaar\Downloads\SteamSetup.exe 2014-01-02 13:14:04 7CCDB06729E2731AF9D0DFBD86B437DE 2326976 ----a-w- C:\Users\Eigenaar\Downloads\setup.exe 2014-01-02 13:14:04 35439867D389732D99F9641D0E84AE14 7539624 ----a-w- C:\Users\Eigenaar\Downloads\NRnR.exe 2014-01-02 13:14:04 029C5055974EE6FC6DF0B6FE5A1C3CD6 16952720 ----a-w- C:\Users\Eigenaar\Downloads\OriginThinSetup.exe 2014-01-02 13:14:04 015DB786B324FFE31FE2D90578D84AC4 2293880 ----a-w- C:\Users\Eigenaar\Downloads\reflectdlfull.exe 2014-01-02 13:14:02 8BBE63DF6DF1B042E8EFA88E3B358FC8 347304 ----a-w- C:\Users\Eigenaar\Downloads\MicrosoftFixit.Printing.Run.exe 2014-01-02 13:14:02 89F9799AC08FA3BB1F612CA4567B98FF 453545 ----a-w- C:\Users\Eigenaar\Downloads\mb_driver_intel_bootdisk_irst_64_7series.exe 2014-01-02 13:13:07 733C462E5B365E4BB5158E270FCF0B75 13545144 ----a-w- C:\Users\Eigenaar\Downloads\ifw_en_trial.exe 2014-01-02 13:13:01 6BD029F99468A66300F9F235ACCE0D0E 263251024 ----a-w- C:\Users\Eigenaar\Downloads\20131213-002-v5i64.exe 2014-01-02 13:12:58 BB8FD039069B195307D6AC5B000D6FD4 213478368 ----a-w- C:\Users\Eigenaar\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe === C: other files == 2014-01-02 13:22:12 82E32F760E8A275C5005F1101803E6B1 43521509 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\TV USB Stick\WindowsMediaCenter(4.0.0.098).zip 2014-01-02 13:22:12 5D4138611F2C6170E7E1E04A3FD6D422 339207 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\WAG160NV2_Setup_Wizard\WAG160NV2_Setup_Wizard\setup\extras\ylinksys.zip 2014-01-02 13:21:53 C07727C4D32BDC68D512A88EB70712F1 260625156 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\WAG160NV2_Setup_Wizard.zip 2014-01-02 13:21:52 DEB2D2527F2BC85A01DF628DCB299B08 595499 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\Autoruns.zip 2014-01-02 13:21:52 BA8284A81E31898334EE2D58892C7649 3736125 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\testdisk-6.14.win.zip 2014-01-02 13:21:52 62A2B7EDF92228BB04DB7D41FF0A5C30 12660742 ----a-w- C:\Users\Eigenaar\Downloads\Utilities\SysinternalsSuite.zip 2014-01-02 13:21:52 490C9282352E2626AF98E3BE0C82D236 1832692 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\threed.zip 2014-01-02 13:21:52 3C185F396620B58CC387E7A4CD294E6C 1403411 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\platform.zip 2014-01-02 13:21:52 08F5D0A74C0F1166EED9BC06FD488250 2157739 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\shooter.zip 2014-01-02 13:21:51 D0434DDEC58A22F3728EFF1729149448 703710 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\multiplayer.zip 2014-01-02 13:21:51 CF4869BA8486C6EF9B4A3BA8B201EAE1 530482 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\goodgame.zip 2014-01-02 13:21:51 B1D26DE38E907A655D85C742D6556233 1604423 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\maze.zip 2014-01-02 13:21:51 174DC7C9EF5DDA2943E2D06AFC1944D9 3024726 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\GameMaker\Tutorials\fps.zip 2014-01-02 13:21:48 D9877932D1FF3B004D9B483CCC12BA45 171038994 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\Eclipse\eclipse-SDK-3.5.2-win32-x86_64.zip 2014-01-02 13:21:47 C8F7539A9630B97051FF4AFDC1E9C647 170518025 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\Eclipse\eclipse-SDK-3.5.1-win32.zip 2014-01-02 13:21:46 DE2431C8D4786D127AE5BFC95B4605DF 8033750 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\Android_Eclipse\ADT-0.9.7.zip 2014-01-02 13:21:46 7C7FCEC3C6B5C7C3DF6AE654B27EFFB5 23293160 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\Android_Eclipse\android-sdk_r06-windows.zip 2014-01-02 13:21:39 D4C8BEBB1C3FCB90F0E970D19868DB65 690575348 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\CryENGINE_v3_3_5_2456_FreeSDK.zip 2014-01-02 13:21:38 4A851E1170B2A0216C2A19C79CCE2D0C 14107109 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\blendergamekit1-book.zip 2014-01-02 13:21:38 2B48D1BB58E077935984E0F125AE4A58 211079710 ----a-w- C:\Users\Eigenaar\Downloads\Systeemontwikkeling\blendergamekit1-cdrom.zip 2014-01-02 13:21:37 BD8BD397F0AD072C5CC6BE673463F4B8 1989275 ----a-w- C:\Users\Eigenaar\Downloads\Proscan - scannerprogramma\ProScan_Client_6_2.zip 2014-01-02 13:21:35 4192F5DCA6109B0BFFFB327A8BB02155 54873511 ----a-w- C:\Users\Eigenaar\Downloads\Muziek\Tiesto_Collection.zip 2014-01-02 13:21:34 FD47491F43719B12A037DA1AF2479673 8405728 ----a-w- C:\Users\Eigenaar\Downloads\Muziek\Ben Saunders - Grapevine.zip 2014-01-02 13:21:34 F7446DDB08EE7583C6E34BC0D9E121F3 7424567 ----a-w- C:\Users\Eigenaar\Downloads\Muziek\Ben Saunders - When A Man.zip 2014-01-02 13:21:34 282BDE4053DD2AFC07BC84C838B57D1E 8367719 ----a-w- C:\Users\Eigenaar\Downloads\Muziek\Lenny Keylard - Stand By Me.zip 2014-01-02 13:21:34 07A97CB2BC9077AF7C7F898E2DAB69FC 90209737 ----a-w- C:\Users\Eigenaar\Downloads\Muziek\nin_theslip_mp3.zip 2014-01-02 13:21:32 1B1BF0EBA081F9BA2A0AAA2089F3868B 169163594 ----a-w- C:\Users\Eigenaar\Downloads\HTC Desire\HTC_Desire_Android_2.3_Upgrade.zip 2014-01-02 13:21:29 380407253B52F29E6E92E4D3423DA9AD 143273 ----a-w- C:\Users\Eigenaar\Downloads\Gentlemen_of_the_Row_Saints_Row_2_Super_Mod_v1.9_final\Create_Custom_GotR_v1.9.bat 2014-01-02 13:21:29 14B6AADB05F138A9B5F80562B91E6F90 2381754 ----a-w- C:\Users\Eigenaar\Downloads\Games\Steam and Iron\NWS_SAI_DEMO.zip 2014-01-02 13:21:17 3453D4D698C78079E751092A73B9B7A0 661339 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\TDW Generic Patcher\TDW_GenericPatcher_v_1_0_74_0.zip 2014-01-02 13:21:14 EF50366D76E33CC516A3AB2F58A8586F 296711 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\Window_Lights_Redone_V1.1_Proper.zip 2014-01-02 13:21:14 8E6622D5E71B3B68E7DA11C557639ED6 135669 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\TDW_Ship_Inertia_1_1_0.zip 2014-01-02 13:21:11 0E8907D4730209209417192B50285D0D 24960614 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\Pascal-sh5-Crew-Uniforms.zip 2014-01-02 13:21:11 0E259675BA0ED0D1B9E7B2FB93CC3AFE 5835 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\No Damn Bubbles, No Damn Halo Mod.zip 2014-01-02 13:21:09 D97161D3BFD83EAEC3D17631F9C54642 2531261 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\MightyFine Crew Mod 1.2.1.zip 2014-01-02 13:21:02 5B98402CFA79937AB80954489AD51C15 278347 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\Cerberus62 Corrected Depth Charge Projector 1.0.zip 2014-01-02 13:21:01 EEA2E9F237B395A208BDDE08929864BE 41049500 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\Capthelms_SH5_Audio_Mod.zip 2014-01-02 13:21:00 0E8CDD1F812AEFF592E6C3E129FB1A8D 349147 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 5 Mods\Accurate German Flags.zip 2014-01-02 13:20:40 23C0FC21D194A1F1574705C8BE06339A 1011161 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 4 Mods\TMO - Pacific Campaign\TMO_Manual 2.5.zip 2014-01-02 13:20:29 B8042CA5889AA27EEF3BA764FD911A3E 1610417 ----a-w- C:\Users\Eigenaar\Downloads\Games\Silent Hunter 4 Mods\Real Fleet Boats\Real Fleet Boat 1.52 User Manual.zip 2014-01-02 13:20:04 F525EED5A771E2881DE366AB685B9A7F 69282985 ----a-w- C:\Users\Eigenaar\Downloads\Games\Shells of Fury Mods\UKWv1.0ENG.zip 2014-01-02 13:20:03 78A529FC38E8DC1AC7CCADB2E4939141 44594711 ----a-w- C:\Users\Eigenaar\Downloads\Games\Saints Row 3\Original Soundtrack\saintsrow3_ost_mp3_1374796048.zip 2014-01-02 13:20:03 5E9FF428470E188E460C6BEFBF51FC53 1702923 ----a-w- C:\Users\Eigenaar\Downloads\Games\Shells of Fury Mods\seerohr.zip 2014-01-02 13:20:02 96434F951E141D0044540EBC1B39AFC9 201578648 ----a-w- C:\Users\Eigenaar\Downloads\Games\Saints Row 3\Original Soundtrack\saintsrow3_ost_flac_1374796048.zip 2014-01-02 13:20:01 2B679436529B94761A804E106546671E 78491 ----a-w- C:\Users\Eigenaar\Downloads\Games\Saints Row 2 Notebook Problemen\SR2_Powertools_rev5.zip 2014-01-02 13:20:00 F22C10794EBFFADE39918C5921C0E9B3 216677810 ----a-w- C:\Users\Eigenaar\Downloads\Games\Sacred 2 Original Soundtrack\sacred2_ost_mp3_1374801478.zip 2014-01-02 13:19:59 FB3055AD1F0F819A2239ED41EE61195C 127249645 ----a-w- C:\Users\Eigenaar\Downloads\Games\Risen 2 Original Soundtrack\risen2_ost_mp3_1374801478.zip 2014-01-02 13:19:59 9D9B0A6E6ADBDBF10822BE4E08FCD26B 886409 ----a-w- C:\Users\Eigenaar\Downloads\Games\Nieuwe versie PunkBuster\pbsetup.zip 2014-01-02 13:19:59 274D4BD2C868F6AFAF38E1329446D3E1 910856 ----a-w- C:\Users\Eigenaar\Downloads\Games\Pacific War en Harpoon\PacificWarv3-2.zip 2014-01-02 13:19:59 037CEE295649AD0D55F300429BDC4DA6 28032761 ----a-w- C:\Users\Eigenaar\Downloads\Games\Pacific War en Harpoon\HCEDemo-2009.064.zip 2014-01-02 13:19:46 FFC21927BBA586B2E8665221FDD31B66 1456397 ----a-w- C:\Users\Eigenaar\Downloads\Games\Iron Front Missions\SPTheBattleOfSzydlow.zip 2014-01-02 13:19:46 4337BDC9E1DF98269132528E04644B0D 6449 ----a-w- C:\Users\Eigenaar\Downloads\Games\Iron Front Missions\Mayhem.Staszow.zip 2014-01-02 13:19:46 1863B1D06E5E36765DF5E18C70838E51 1714614 ----a-w- C:\Users\Eigenaar\Downloads\Games\Iron Front Missions\Flying_Fire_Brigade.zip 2014-01-02 13:19:45 F2CB8646CE43DDB7C4CC7B1C6ECB543A 26154826 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA3 Mods\Xbox Mod - Better Graphics\update2_for_xboxmodv1.zip 2014-01-02 13:19:45 B03B4A3010E06B608104CCCE86938936 422670 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA3 Mods\Xbox Mod - Better Graphics\steam_update_2.1.zip 2014-01-02 13:19:45 8B5E35972C1361F511DBBB6D5D5B4BA7 100047651 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA3 Mods\Xbox Mod - Better Graphics\Xbox_mod_v1.zip 2014-01-02 13:19:45 65466A2CF02304A910AC25A85EC70077 15225175 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA3 Mods\Xbox Mod - Better Graphics\update1_for_xboxmodv1.zip 2014-01-02 13:19:44 5D3ABD3237E0D8E5A6EACA5891B9F811 234729 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA Tools\imgtool20.zip 2014-01-02 13:19:44 0E0CE312A3F4ADD1D362069B6A9BF955 43447 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA3 Mods\The Exchange - Savegame GTA 3 all missions.zip 2014-01-02 13:19:43 4BCD0F979CB6904D4E3F717E92EB8FFF 3608251 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\Ultra Realistic HD Effects\Vehicle_Effects\Vehicle_Effects.zip 2014-01-02 13:19:43 14641497728A1B4AB90F769BAA91527D 4527291 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\Ultra Realistic HD Effects\vehicle2\vehicle2.zip 2014-01-02 13:19:42 EDF6DBA6F30B9CE11D4059E0C9889D65 4435131 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\Ultra Realistic HD Effects\ULTRA_HD_effects\ULTRA_HD_effects.zip 2014-01-02 13:19:42 B410AA33C49C453BE4EBDAD8A8BE9F55 2961475 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\Ultra Realistic HD Effects\GTA_3_version\GTA_3_version.zip 2014-01-02 13:19:39 54D9FD16C8FA6AC5AC2CF8A0BE06AD0E 237504037 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\SRT3 Mod\SRT3Final.zip 2014-01-02 13:19:15 9992398EF6D36E181F00DE84CC79D112 11967172 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas\GTASAFix.zip 2014-01-02 13:19:15 8A71A5CD77E2D95C7C2D66C46B4827F9 207147 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA San Andreas Mods\Enbseries graphics\enbseries_gtasa_v0158.zip 2014-01-02 13:19:14 D7AC9B9DBB09A3396FBFDFE7E202DA2D 17532198 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA IV Mods\ICEnhancer2\iCEnhancer2_1FINAL.zip 2014-01-02 13:18:29 4F43700320BB9DD0C7EFD7A3EC98DB0E 718859 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA IV\Save game GTA IV 100 % PlayStation 3\Savegame GTA IV PS3.zip 2014-01-02 13:18:26 33436C87052FA4F49671CE132F6D9583 4571624 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA IV\iCEnhancer2_1FINAL_reup\1.0.7.0 - EFLC\2 - Shaders\BACKUP\BACKUPShaders.zip 2014-01-02 13:18:26 0360C7669294DAAF108CBF46BB029783 6222133 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA IV\iCEnhancer2_1FINAL_reup\1.0.7.0 - EFLC\2 - Shaders\Shaders.zip 2014-01-02 13:18:22 D7AC9B9DBB09A3396FBFDFE7E202DA2D 17532198 ----a-w- C:\Users\Eigenaar\Downloads\Games\GTA IV\iCEnhancer2_1FINAL_reup.zip 2014-01-02 13:18:21 AD69F5B382CCB76FA56CD857C5B4DAF2 109635 ----a-w- C:\Users\Eigenaar\Downloads\Games\Far Cry Sandbox\sandbox_editor_FAQ.zip 2014-01-02 13:18:21 3DBB6F293DC475E6C5951464128D3F4C 6156367 ----a-w- C:\Users\Eigenaar\Downloads\Games\Far Cry Sandbox\FC_editor_manual_v1.1.zip 2014-01-02 13:18:15 FB2EA09415A8EDF049AB388A60AFBFFE 128584 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_pipboys_avatars.zip 2014-01-02 13:18:15 74D22B4925370D25B2FC32E0A3A39875 5057543 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_series_wallpaper.zip 2014-01-02 13:18:15 42C10C13405CAF6707ECB12A149EF7E8 132117 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_refcard.zip 2014-01-02 13:18:15 1DC05625BE866E90AE509492AC965DDB 9090506 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_wallpaper.zip 2014-01-02 13:18:15 1BED24B33C3F1FEC99B5393309C0950F 83937889 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_soundtrack.zip 2014-01-02 13:18:14 CBBF7FBB000F14BDCAE70D59E69F2C52 56527019 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\Fallout_Bible_gog.zip 2014-01-02 13:18:14 C17CD2543B155FFA01349BA698674F6D 7570685 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_manual.zip 2014-01-02 13:18:14 849F8B75A72293DE43B572C6B0DFF4BF 501528 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_avatars.zip 2014-01-02 13:18:14 40A3394FD9AE0C984DC719FA2723E9C0 2018992 ----a-w- C:\Users\Eigenaar\Downloads\Games\Fallout Games\Fallout\fallout_arts.zip 2014-01-02 13:17:45 620839D48D8ABACD0DA9EEFF46577971 371088091 ----a-w- C:\Users\Eigenaar\Downloads\Games\Dirt 2 patch\dirt2_efigs_1_1.zip 2014-01-02 13:17:43 97D0C65DB9052AB1EA580EB2CF2E5EF8 8866 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\Widescreen Fixes\GENERALINTENDENCIAHARD.zip 2014-01-02 13:17:43 807DEBF6D50363557EEB8C7087611FA9 24562266 ----a-w- C:\Users\Eigenaar\Downloads\Games\Dangerous Waters\dangerouswaterspatchv104.zip 2014-01-02 13:17:43 057D102306BF97899D3A908C127CB1CD 47818 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\Widescreen Fixes\INTERFAZ.zip 2014-01-02 13:17:41 CD73860A52B9C5FE665CF5BB4ED42A8B 277659 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\Resolution Hack\CommandosResolutionHack.zip 2014-01-02 13:17:41 CD73860A52B9C5FE665CF5BB4ED42A8B 277659 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\CommandosResolutionHack.zip 2014-01-02 13:17:41 97D0C65DB9052AB1EA580EB2CF2E5EF8 8866 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\GENERALINTENDENCIAHARD.zip 2014-01-02 13:17:41 057D102306BF97899D3A908C127CB1CD 47818 ----a-w- C:\Users\Eigenaar\Downloads\Games\Commandos\INTERFAZ.zip 2014-01-02 13:17:39 DDF19897AE209F30E7CEF1581AF1480E 39241489 ----a-w- C:\Users\Eigenaar\Downloads\Games\Bohemia Interactive Tools\BI_Editing_Tools_2_5_1.zip 2014-01-02 13:17:39 CB3F9A406C07606A38FE21096CE00085 97990 ----a-w- C:\Users\Eigenaar\Downloads\Games\Burnout Paradise Mods\enbseries_burnparadise_v0075b.zip 2014-01-02 13:17:34 636862228931B797F54D5EA6E74474AF 96428487 ----a-w- C:\Users\Eigenaar\Downloads\Games\ARMA 3 - Mods, Addons, Missions\POMIGIT_A3_PMCMOD_v0.5.zip 2014-01-02 13:17:30 9AAD0B87D12CB6F94A0EECC0E4C9B2AE 37011302 ----a-w- C:\Users\Eigenaar\Downloads\Games\ARMA 2 - Cold War rearmed 2\cwr2_missions.zip 2014-01-02 13:17:29 98C0EEF699D0746EBA9B15FF99F8F828 68884852 ----a-w- C:\Users\Eigenaar\Downloads\Games\ARMA 2 - Cold War rearmed 2\cwr2_1985_v108.zip 2014-01-02 13:14:53 F6433E0E7847C9C89B6248E93032EDD1 4530238 ----a-w- C:\Users\Eigenaar\Downloads\Games\shogun_totalwar_demo.zip 2014-01-02 13:14:51 F7BB3516E4323B17424DFB6DA105B6B0 136168763 ----a-w- C:\Users\Eigenaar\Downloads\Games\lotd_pc_demo-final.zip 2014-01-02 13:14:42 8E7A198ED42C72263D7290D02BEEA360 577893877 ----a-w- C:\Users\Eigenaar\Downloads\Games\FarCryResearchDemo.zip 2014-01-02 13:14:41 9475BCD960E81B5EE5E74F76E8BC07C1 35819142 ----a-w- C:\Users\Eigenaar\Downloads\Games\farcry2_teaser_01_hd.zip 2014-01-02 13:14:28 BCD20EC65169F43B6C6DA485864B5F62 802155532 ----a-w- C:\Users\Eigenaar\Downloads\Games\DutyCallsEU.zip 2014-01-02 13:14:28 9C59E9F1780BDFF49E5D30E109EA6C9B 2027357 ----a-w- C:\Users\Eigenaar\Downloads\Games\BSI_PC_ONLINE_MANUAL_DUT.zip 2014-01-02 13:14:28 4967E6FC321E1F26B0E9544A85BD1DD9 2459128 ----a-w- C:\Users\Eigenaar\Downloads\Games\BSI_360_ONLINE_MANUAL_DUT.zip 2014-01-02 13:14:26 261CA89E424692BDE56F2D9A48E699FE 647762 ----a-w- C:\Users\Eigenaar\Downloads\Drivers PC\PCTV_340e_801e_(2.3.3.32)\PCTV_340e_801e_(2.3.3.32).zip 2014-01-02 13:14:21 6300A26177A23F7FDD257C8DA3C2CC67 3395360 ----a-w- C:\Users\Eigenaar\Downloads\Drivers PC\Linksys WAG160N gateway ADSL2\WAG160Nv1-EU-ANNEXA-ETSI-1.00.16-code.zip 2014-01-02 13:14:20 0AF37E343EFFC9A4883F94FCC940098B 28488308 ----a-w- C:\Users\Eigenaar\Downloads\Drivers PC\Belkin USB Draadloze Netwerk Adaper\RTL8192SU_AutoInstallPackage.zip 2014-01-02 13:14:13 FEF9B0A947C2145EE41F26A0723A07EF 97062384 ----a-w- C:\Users\Eigenaar\Downloads\ASUS N61VG Notebook\VGA_nVidia_WIN7_64_815118631_ASUS.zip 2014-01-02 13:14:11 85FB310BF4A466E1BD77F7A1E36DF66E 34335877 ----a-w- C:\Users\Eigenaar\Downloads\WD_SmartWare_Installer_2.2.0.8.zip 2014-01-02 13:14:04 BD8BD397F0AD072C5CC6BE673463F4B8 1989275 ----a-w- C:\Users\Eigenaar\Downloads\ProScan_Client_6_2.zip 2014-01-02 13:14:03 91985B07432BC4895A21465F2E6C7E04 1807882 ----a-w- C:\Users\Eigenaar\Downloads\nl Manual Sony EbookReader.zip 2014-01-02 13:14:02 DF4F1C05C739DDADCD88D4334EB5B38F 27890416 ----a-w- C:\Users\Eigenaar\Downloads\Manuals.zip 2014-01-02 13:13:07 D7AC9B9DBB09A3396FBFDFE7E202DA2D 17532198 ----a-w- C:\Users\Eigenaar\Downloads\iCEnhancer2_1FINAL.zip 2014-01-02 13:13:07 97D0C65DB9052AB1EA580EB2CF2E5EF8 8866 ----a-w- C:\Users\Eigenaar\Downloads\GENERALINTENDENCIAHARD.zip 2014-01-02 13:13:07 057D102306BF97899D3A908C127CB1CD 47818 ----a-w- C:\Users\Eigenaar\Downloads\INTERFAZ.zip 2014-01-02 13:13:05 CD73860A52B9C5FE665CF5BB4ED42A8B 277659 ----a-w- C:\Users\Eigenaar\Downloads\CommandosResolutionHack.zip 2014-01-02 13:13:05 807DEBF6D50363557EEB8C7087611FA9 24562266 ----a-w- C:\Users\Eigenaar\Downloads\dangerouswaterspatchv104.zip 2013-12-30 17:58:19 90AA9E273410AD7A41D2D06E0FB46022 89304 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2316486509-3533402231-1566456508-1001\Software\Microsoft\Windows\CurrentVersion\Run] "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "Spotify Web Helper"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Google Update"="C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Spybot-S&D Cleaning"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe /autoclean" "Logitech Vid"="C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe -bootmode" "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Google Update"="C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "dlmMgr"="C:\Program Files (x86)\Common Files\Adobe\ESD\AdobeDownloadManager.exe restart=1" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" "Spotify"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "SystemExplorerAutoStart"="D:\Program Files (x86)\System Explorer\SystemExplorer.exe /TRAY" "Raptr"="C:\PROGRA~2\Raptr\raptrstub.exe --startup" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "amd_dc_opt"="C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" "WD Quick View"="C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" "TrueImageMonitor.exe"="C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" "AcronisTibMounterMonitor"="C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "SDTray"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" "LELA"="C:\Program Files (x86)\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe /minimized" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "NBKeyScan"="C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" "nmctxth"="C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "RemoteControl"="C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe" "AppleSyncNotifier"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "LanguageShortcut"="C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe" "LogitechQuickCamRibbon"="C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe /hide" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "ATICustomerCare"="C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" "DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW" "TkBellExe"="C:\Program Files (x86)\real\realplayer\update\realsched.exe -osboot" "Mobile Connectivity Suite"="C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe /startoptions" "Freecorder FLV Service"="C:\Program Files (x86)\Freecorder\FLVSrvc.exe /run" "HTC Sync Loader"="C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe -startup" "ArcSoft Connection Service"="C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup" "Name of App"="D:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "SES_FE"="D:\Program Files\Stormpowered\SES_Form.exe STARTUP" "Adobe Photo Downloader"="C:\Program Files (x86)\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Reader Application Helper"="C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "Spotify Web Helper"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Google Update"="C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Spybot-S&D Cleaning"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe /autoclean" "Logitech Vid"="C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe -bootmode" "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Google Update"="C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "dlmMgr"="C:\Program Files (x86)\Common Files\Adobe\ESD\AdobeDownloadManager.exe restart=1" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" "Spotify"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "SystemExplorerAutoStart"="D:\Program Files (x86)\System Explorer\SystemExplorer.exe /TRAY" "Raptr"="C:\PROGRA~2\Raptr\raptrstub.exe --startup" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "XboxStat"="C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe silentrun" "Acronis Scheduler2 Service"="C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" "Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" ==== Startup Folders ====================== 2013-11-22 18:53:20 1060 ----a-w- C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [11/12/2013 13:07] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/06/2010 17:21] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/06/2010 17:21] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001Core.job --a------ C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe [20/04/2010 08:16] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001UA.job --a------ C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe [20/04/2010 08:16] C:\Windows\tasks\Registry Reviver64-Eigenaar-Startup.job --a------ C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver64.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files (x86)\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001Core" [C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001UA" [C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Launch HTC Sync Loader" [C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe"] "C:\Windows\SysNative\tasks\RealUpgradeLogonTaskS-1-5-21-2316486509-3533402231-1566456508-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealUpgradeScheduledTaskS-1-5-21-2316486509-3533402231-1566456508-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\Registry Reviver64-Eigenaar-Startup" [C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver64.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{948F072B-E43B-4DF5-B9C5-7E973407AC0F}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\{093E6910-5B60-4007-9191-8846AB9B9D16}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{0C7F032A-54FD-444A-B934-308046A99C74}" [D:\Program Files\Steam\steamapps\common\Battlestations Pacific - Demo\bspdemo.exe] "C:\Windows\SysNative\tasks\{10BB6EDD-D948-4B5D-AB99-009DCD762A18}" [D:\Program Files\Steam\steamapps\common\Battlestations Pacific - Demo\bspdemo.exe] "C:\Windows\SysNative\tasks\{132DF420-39CB-44A4-9ADB-7546008B47DE}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{17206F54-715D-44D7-940A-12C7370C0965}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{1AE7F54B-6841-4B98-BF53-532CF265AF7C}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{1FF1A6C8-6A94-42EC-A7F4-1115D4E6B512}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{2443C7FD-3090-47EF-A7C7-C295AA2F5079}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{245CEDE3-B225-496B-93BA-9ED14F488A11}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{24A18401-E219-4768-A858-CE3FBC79B0C0}" [C:\Program Files (x86)\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe] "C:\Windows\SysNative\tasks\{26FC73F4-C6D5-4FB5-B36E-CF4F7862192B}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{2CA775BC-BA25-4B32-9F38-2F0997EF68C5}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{32B97432-12D3-4B85-8A92-E8379F920F16}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{32ECA8D4-9ABA-462B-AE0D-5619A996DE29}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{38D3FC5D-CDA0-4777-9D85-31B1363D8952}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{398B129F-D0EC-4457-B869-5CD9F2534CB1}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{3D2360B5-6180-4CA5-A06D-8CB2DCF469E7}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\ENations.exe] "C:\Windows\SysNative\tasks\{438E3080-0329-40E1-AD0E-5E030CF23F1B}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{49E901F8-1BF6-498F-9187-FB4AC010E53D}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{4BA2F7BB-A1E8-412A-9EE2-608BB135A725}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\ENations.exe] "C:\Windows\SysNative\tasks\{4D66F6D0-85C6-48B4-AFA4-7C2B4EE81190}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{4EF2C277-7E93-4A72-89FD-3A4DC6EB5E03}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{4F446F23-91BA-4A7F-AA60-93B9089B177A}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{5CAD60F3-4971-43A8-A1EA-CAED2991CBA9}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{64F34C0A-1138-493F-9D8F-0D4BE1E79A2E}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{659D5E27-C410-49DD-9AE9-389D5DBC3D4E}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{69BEAB52-18B5-4F87-8CE7-400FF9695856}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{72344C6A-F8C2-4DA5-96A9-B7D745CC1FD0}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{79AD77AC-8465-460C-9B7E-69311FAD0023}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{79EC2FF1-F92B-4AC5-848E-B24CBE6A007F}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{7E65ADBF-A7C7-4DBE-962E-807D9084B06A}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{82A2F240-3801-4735-9F50-66E82989E307}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{8474CBDA-C12B-46A3-8D36-01F959218BC1}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{8996ECC6-C804-4DB4-9625-FB8D832501DD}" [D:\Program Files\Steam\steamapps\common\Battlestations Pacific - Demo\bspdemo.exe] "C:\Windows\SysNative\tasks\{8C03E6E9-4671-440F-99DA-4AF852465D8B}" [D:\Program Files\Steam\steamapps\common\Battlestations Pacific - Demo\bspdemo.exe] "C:\Windows\SysNative\tasks\{8CEE6684-DAA8-465B-A01E-DD73DE94A628}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\ENations.exe] "C:\Windows\SysNative\tasks\{8E1254DC-57CE-4079-969E-4D1086A43B4E}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{8F18D116-59A9-46E4-9D4F-F15BCD43E5EE}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{90E6B942-6C3B-425C-B169-44FB7CC2D04E}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{92072518-7AB6-4BD0-AA7A-FA09FE111D27}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{95521529-65DF-4E3A-A239-2948F5FDB85C}" [C:\Program Files (x86)\Race Demo\Race Demo.exe] "C:\Windows\SysNative\tasks\{9B749020-9946-43B3-A633-9BD5C2EAD3E1}" [C:\Program Files (x86)\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe] "C:\Windows\SysNative\tasks\{9C9E961B-1C2B-4459-98B9-498FF83076F4}" [C:\Program Files (x86)\Microsoft Games\Age of Empires\Empires.exe] "C:\Windows\SysNative\tasks\{9D7F2FEB-B85B-4ED2-9025-B330B02B5235}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{A505E3D4-8C86-410B-9A05-284F8E638BCB}" [D:\Program Files\Steam\steamapps\common\Soldiers Heroes of World War 2\soldiers.exe] "C:\Windows\SysNative\tasks\{A6D67A77-45BE-4B7A-B8EC-99351963D86C}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{A8D9151D-7CD0-4664-A376-610A2313E2D6}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{A8F2D302-C748-47E1-9F39-5FBF2884FFAE}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{AC67269C-2664-482A-9250-E3B9466AD158}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{ACDFDC8E-0F27-4771-8AA4-38505AB476D4}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{AD69DB0F-FF0F-4BA1-96CF-9D6A230C4793}" [C:\Program Files (x86)\Microsoft Games\Combat Flight Simulator 2\cfs2.exe] "C:\Windows\SysNative\tasks\{AED73D16-A3CD-4035-ACD6-FB9787F92470}" [D:\Program Files\Codemasters\DiRT2\dirt2.exe] "C:\Windows\SysNative\tasks\{B2064A58-B865-48EF-BA49-0DD80E14A133}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{B22D80E5-690A-4B46-9EB9-216599534E19}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{B7A28746-5D40-40D4-BC4C-0959071785BC}" [C:\Program Files (x86)\xpadder_gamepad_profiler\Xpadder.exe] "C:\Windows\SysNative\tasks\{C0E546D0-6EC3-4A7F-82D0-A9F99AA7E25D}" [D:\Program Files\Codemasters\DiRT2\dirt2.exe] "C:\Windows\SysNative\tasks\{C5FC8606-F246-4C09-A4BD-8063FDB59C52}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{C72B3CA1-632B-42A9-BC9F-983C49E3F7FE}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\ENations.exe] "C:\Windows\SysNative\tasks\{C8F977D2-96B2-46F7-9F29-72D400F2F93D}" [D:\Program Files\Steam\steamapps\common\Silent Hunter 3\sh3.exe] "C:\Windows\SysNative\tasks\{CBEAE5E5-EBDA-4AAE-B9F7-403FE7B550EF}" [D:\Program Files\Steam\steamapps\common\Silent Hunter 3\sh3.exe] "C:\Windows\SysNative\tasks\{D1618DA9-BBD7-4BBB-9495-908DC03AD13E}" [C:\Users\Eigenaar\Downloads\Games\xpadder_gamepad_profiler\Xpadder.exe] "C:\Windows\SysNative\tasks\{D4100133-1ABF-4AF5-B104-44DC96B8C16E}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{D99806BE-4462-4315-9CF1-7A52CB860B5C}" [D:\Program Files (x86)\SCS\18 Wheels of Steel American Long Haul\alh.exe] "C:\Windows\SysNative\tasks\{DE1DB635-E1E0-496B-B257-ACC01805A7C5}" [E:\setup.exe] "C:\Windows\SysNative\tasks\{DEC744A4-5D57-4EDA-BCB5-3B3C441D664C}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{DFEC68AF-9304-4C1B-AB27-41933B89A8C2}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{E6CD0162-BB4D-46BF-9223-DDE7B9953201}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{E8674749-BC9F-4BA4-92B9-CD42441BC70D}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{E9637B78-2C04-4C26-97AD-BCF22FF07A2B}" [D:\Program Files (x86)\Strategy First\Dangerous Waters\dangerouswaters.exe] "C:\Windows\SysNative\tasks\{E980E8B9-97E7-4DB1-A953-A1F479C5FB87}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{E9BBB501-4024-465E-9D29-66517519ACCC}" [D:\Program Files (x86)\2K Games\BioShock\Builds\Release\Bioshock.exe] "C:\Windows\SysNative\tasks\{F14DFC7D-7E77-43B1-9E3B-55AE78B9438D}" [D:\Program Files\Codemasters\DiRT2\dirt2_game.exe] "C:\Windows\SysNative\tasks\{F1C9BA46-9449-4AC6-9B52-4B1AFCD4E5BB}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{F2B25863-A1FB-4387-A63C-A11B75C0DF11}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{F3D61DFF-BA82-4C7A-A79D-D2FA7462A514}" [C:\Users\Eigenaar\Downloads\Games\EnemyNations2\SETUP.EXE] "C:\Windows\SysNative\tasks\{F3F2359A-3D9A-4B18-A785-A1C692318E8C}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{FD22819A-A652-4993-B5E0-16E382293164}" [C:\Program Files (x86)\EA Games\Command and Conquer Generals\generals.exe] "C:\Windows\SysNative\tasks\{FE492D4E-5E14-470D-A234-80D719B2304E}" [D:\Program Files\Codemasters\DiRT2\dirt2.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\Norton Identity Safe\Norton Error Analyzer" [C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Identity Safe\Norton Error Processor" [C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\SymErr.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn" [04/01/2014 18:24] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default - DivX Plus Web Player HTML5 lt;videogt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 - Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF - GFACE Experience Plugin - %ProfilePath%\extensions\cryenginebrowserplugin@crytek.com - Bitdefender QuickScan - %ProfilePath%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} - Instrument Test - %ProfilePath%\extensions\testpilot@labs.mozilla.com.xpi - Freecorder YouTube Download Wizard - %ProfilePath%\extensions\ytvdw@pgport.com.xpi ProfilePath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default - DivX Plus Web Player HTML5 lt;videogt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 - Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF - Enhanced Steam - %ProfilePath%\extensions\jid0-SmvlvxGpvCyG252KbVMqIKR79Uc@jetpack.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} ==== Firefox Plugins ====================== Profilepath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default 83B4A7AA7A73FB4322FBAA2BCE96F499 - C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\extensions\cryenginebrowserplugin@crytek.com\plugins\npcry39.dll - GFACE Plugin 546A28FBC44B984FD92530227BF6F5C2 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll - Shockwave for Director / Shockwave for Director 053E986A84F5EE271D38896B8079157D - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.110.21 215BBC07AAD6CB4772D2A1CA5E048C37 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll - RealNetworks RealPlayer Chrome Background Extension Plug-In (32-bit) 8F323545429C457FE6F8CED13E62AB3D - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer HTML5VideoShim Plug-In (32-bit) 02232EAA0CB3418239D5F6333BE9B346 - C:\Program Files\Microsoft\Web Platform Installer\NPWPIDetector.dll - WPI Detector 1.1 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System Profilepath: C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default F891089A6AB9E12FEDEBCC5EC0F40D66 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll - Shockwave Flash C36444D7301A8C881FC7296B092609C7 - C:\Users\Eigenaar\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update 546A28FBC44B984FD92530227BF6F5C2 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll - Shockwave for Director / Shockwave for Director 053E986A84F5EE271D38896B8079157D - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.110.21 215BBC07AAD6CB4772D2A1CA5E048C37 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll - RealNetworks RealPlayer Chrome Background Extension Plug-In (32-bit) 8F323545429C457FE6F8CED13E62AB3D - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer HTML5VideoShim Plug-In (32-bit) 02232EAA0CB3418239D5F6333BE9B346 - C:\Program Files\Microsoft\Web Platform Installer\NPWPIDetector.dll - WPI Detector 1.1 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Deleted Firefox Extensions ====================== C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\6h0biava.default\extensions\ytvdw@pgport.com.xpi deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions jfmjfhklogoienhpfnppmbcbjfjnkonk - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx[28/07/2011 19:19] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx[09/12/2013 10:38] nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[12/12/2011 14:13] nppllibpnmahfaklnpggkibhkapjkeob - No path found[] GFACE Experience Plugin - Eigenaar - Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol AT_Porsche - Eigenaar - Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg RealPlayer HTML5Video Downloader Extension - Eigenaar - Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk Norton Identity Protection - Eigenaar - Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk Google Wallet - Eigenaar - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda DivX Plus Web Player HTML5 \u003Cvideo\u003E - Eigenaar - Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm ==== Chrome Fix ====================== C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx deleted successfully C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{F04D2D30-776C-4d02-8627-8E4385ECA58D} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nppllibpnmahfaklnpggkibhkapjkeob deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Eigenaar\AppData\Local\Mozilla\Firefox\Profiles\e1k6j9yo.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=943 folders=216 189239636 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\Eigenaar\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Eigenaar\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on zo 05/01/2014 at 19:43:10,59 ======================
  18. Omdat zoek.exe al een paar uur geen processor- en schijfactiviteit had, had ik de pc opnieuw opgestart gisteren. De getoonde log is de (incomplete) zoek-results. Kan ik het script opnieuw draaien of moet er dan eerst iets aangepast worden? Alvast bedankt voor de snelle reacties steeds trouwens.
  19. Zo te zien is deze log niet volledig. Zoek.exe staat al een hele tijd open zonder (zo te zien) iets te doen.
  20. Het log bestand van Zoek.exe: Zoek.exe v5.0.0.0 Updated 02-Januari-2014 Tool run by Eigenaar on za 04/01/2014 at 15:51:34,82. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Eigenaar\Desktop\zoek\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== System Restore Info ====================== 4/01/2014 15:55:33 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\PROGRA~2\CheckPoint deleted successfully C:\PROGRA~2\MyeBookSoft deleted successfully C:\PROGRA~2\NeroInstall.bak deleted successfully C:\PROGRA~2\Origin Games deleted successfully C:\PROGRA~2\windows7inabox deleted successfully C:\PROGRA~2\COMMON~1\Merge Modules deleted successfully C:\Program Files\CheckPoint deleted successfully C:\ProgramData\Longbow Digital Arts deleted successfully C:\ProgramData\Malwarebytes' Anti-Malware (portable) deleted successfully C:\ProgramData\PCSettings deleted successfully C:\ProgramData\SanDisk deleted successfully C:\ProgramData\~0 deleted successfully C:\Users\Eigenaar\AppData\Roaming\AdobeUM deleted successfully C:\Users\Eigenaar\AppData\Roaming\Amazon deleted successfully C:\Users\Eigenaar\AppData\Roaming\My Games deleted successfully C:\Users\Eigenaar\AppData\Roaming\Panda Security deleted successfully C:\Users\Eigenaar\AppData\Roaming\TP deleted successfully C:\Users\Eigenaar\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Eigenaar\AppData\Local\DCS deleted successfully C:\Users\Eigenaar\AppData\Local\Wings of Prey deleted successfully C:\Users\Eigenaar\AppData\Local\WOP deleted successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\CrashDumps deleted successfully
  21. Dit is het log bestand: Logfile of random's system information tool 1.09 (written by random/random) Run by Eigenaar at 2014-01-04 12:15:46 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 156 GB (61%) free of 256 GB Total RAM: 8187 MB (69% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:15:56, on 4/01/2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.16428) Boot mode: Normal Running processes: C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Users\Eigenaar\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe C:\Program Files\trend micro\Eigenaar.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {3ce45c4f-bfff-4988-9a3c-a75c1f491319} - (no file) R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\prxtbFree.dll F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: Freecorder - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\prxtbFree.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.DLL O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_22\bin\ssv.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: ZoneAlarm Security - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.6.0_22\bin\jp2ssv.dll O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files (x86)\Freecorder\prxtbFree.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" O4 - HKLM\..\Run: [AcronisTibMounterMonitor] C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [sDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: AutorunsDisabled O4 - Startup: Dropbox.lnk = Eigenaar\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: AutorunsDisabled O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.clonewarsadventures.com O15 - Trusted Zone: *.freerealms.com O15 - Trusted Zone: *.soe.com O15 - Trusted Zone: *.sony.com O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.5.cab O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} (Battlefield Play4Free Updater) - https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.80.2.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: HitmanPro.Alert Service (hmpalertsvc) - SurfRight B.V. - C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - D:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe O23 - Service: TVService - Team MediaPortal - C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TVService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: WD Drive Manager (WDDriveService) - Western Digital Technologies, Inc. - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 17038 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe winlogon.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup "C:\Program Files\HitmanPro\hmpsched.exe" "C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe" /service C:\Windows\system32\svchost.exe -k NetworkService atieclxx C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe" "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe" "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe" "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" /rep_new "C:\Windows\system32\Dwm.exe" "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" C:\Windows\Explorer.EXE "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true "C:\Program Files\Bonjour\mDNSResponder.exe" "C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "C:\Program Files (x86)\Linksys\Linksys Updater\conf\wrapper.conf" "taskhost.exe" "C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe" "C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe" -Embedding "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS "C:\Windows\system32\java.exe" -Xmx100m -Djava.library.path="../lib" -classpath "../lib/agent-2.0.8109.789.jar;../lib/wrapper.jar;../lib/commons-lang-2.3.jar;../lib/commons-logging-1.1.jar;../lib/spring-2.0.6.jar;../lib/spring-ws-core-1.0.2.jar;../lib/spring-xml-1.0.2.jar;../lib/jdom-1.0.jar;../lib/jaxen-1.1.1.jar;../lib/xpp3_min-1.1.3.4.O.jar;../lib/xstream-1.2.2.jar" -Dwrapper.key="SisvCOnGKRnGo1iJ" -Dwrapper.port=32000 -Dwrapper.jvm.port.min=31000 -Dwrapper.jvm.port.max=31999 -Dwrapper.pid=2436 -Dwrapper.version="3.2.3" -Dwrapper.native_library="wrapper" -Dwrapper.service="TRUE" -Dwrapper.cpu.timeout="10" -Dwrapper.jvmid=1 com.linksys.agent.Main \??\C:\Windows\system32\conhost.exe "5938436950118793-2051023291-1905128321-1112686239-115239074-19679866381887880632 taskeng.exe {2EC711B8-F3E7-47BA-8F82-E8DB6C4F7531} taskeng.exe {1EF973B9-8477-4DD9-90AF-8C6517194C1E} taskeng.exe {EE9BDED7-7DFC-4A4C-9C2D-8398B8EBF657} "C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe" /s "NCO" /m "C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe" "C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe" C:\Windows\SysWOW64\IoctlSvc.exe C:\Windows\SysWOW64\PnkBstrA.exe "C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" "C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe" /c /a /s UserSession "C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe" /c /a /s UserSession "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" "C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe" "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TVService.exe" "C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe" "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" WLIDSvcM.exe 5100 C:\Windows\system32\wbem\wmiprvse.exe "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe" C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" HydraDM64.exe -h:66032 "Maximaliseren tot volledig bureaublad" "Maximaliseren tot volledig venster" "Bureaublad herstellen" "C:\Users\Eigenaar\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup "C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" "C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0 "C:\Program Files\Windows Media Player\wmpnetwk.exe" C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} "C:\Windows\System32\taskmgr.exe" "C:\Users\Eigenaar\Desktop\RSITx64.exe" C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\svchost.exe -k HPService C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\sppsvc.exe "C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe" "C:\Windows\system32\SearchFilterHost.exe" 0 568 572 580 65536 576 ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2316486509-3533402231-1566456508-1001UA.job C:\Windows\tasks\Registry Reviver64-Eigenaar-Startup.job =========Mozilla firefox========= ProfilePath - C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default prefs.js - "browser.startup.homepage" - "about:home" prefs.js - "extensions.enabledItems" - "belgiumeid@eid.belgium.be:1.0.11, {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03, {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.5, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145, {BBDA0591-3099-440a-AA10-41764D9DB4DB}:12.0.3.2 - 1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 11.9.900.170 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=] "Description"=iTunes Detector Plug-in "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0] "Description"= "Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@checkpoint.com/FFApi] "Description"=ZoneAlarm ForceField Api "Path"=C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0] "Description"=DivX Plus Web Player "Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4] "Description"=ESN Sonar browser plugin "Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.3] "Description"= "Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.2] "Description"= "Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin] "Description"=Google Earth in your browser "Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.11.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\SysWOW64\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre1.6.0_22\bin\new_plugin\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@live.heroesandgenerals.com/npretox] "Description"=Heroes & Generals downloader "Path"=D:\Program Files (x86)\Heroes & Generals\live\npretoxlive.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5] "Description"=Office Live Update v1.5 "Path"=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/wpi,version=1.1] "Description"= "Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647] "Description"=RealPlayer LiveConnect-Enabled Plug-In "Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647] "Description"=RealJukebox Netscape Plugin "Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.660] "Description"=RealNetworks RealPlayer Chrome Background Extension Plug-In "Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.660] "Description"=RealPlayer HTML5VideoShim Plug-In "Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.660] "Description"=12.0.1.660 "Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=] "Description"= "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@sony.com/ReaderDesktop] "Description"=Reader for PC is installed if this plugin exists "Path"=C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.2] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 11.9.900.170 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/wpi,version=1.0] "Description"= "Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\components\ nppl3260.xpt nsIQTScriptablePlugin.xpt nsjsrealplayerplugin.xpt C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7\plugins\ nppdf32.dll npqtplugin.dll npqtplugin2.dll npqtplugin3.dll npqtplugin4.dll npqtplugin5.dll QuickTimePlugin.class C:\Users\Eigenaar\AppData\Roaming\Mozilla\Firefox\Profiles\e1k6j9yo.default\searchplugins\ safesearch.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\coIEPlg.dll [2013-10-06 769360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-11 537576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-13 256080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}] Norton Identity Protection - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.6.0.27\coIEPlg.dll [2013-10-06 769360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-11 193512] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] Freecorder Toolbar - C:\Program Files (x86)\Freecorder\prxtbFree.dll [2011-05-09 176936] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}] RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-07-28 386264] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}] DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll [2013-10-06 526672] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.DLL [2013-09-29 388504] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.6.0_22\bin\ssv.dll [2011-03-14 325408] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] ZoneAlarm Security Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-13 194128] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.6.0_22\bin\jp2ssv.dll [2011-03-14 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-13 256080] {A13C2648-91D4-4bf3-BC6D-0079707C4389} - Norton Identity Safe Toolbar - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.6.0.27\coIEPlg.dll [2013-10-06 769360] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\coIEPlg.dll [2013-10-06 769360] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {91da5e8a-3318-4f8c-b67e-5964de3ab546} - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - Freecorder Toolbar - C:\Program Files (x86)\Freecorder\prxtbFree.dll [2011-05-09 176936] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-13 194128] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll [2013-10-06 526672] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-10-01 825184] "Acronis Scheduler2 Service"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2013-08-21 518960] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "fsm"= [] "HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2009-10-06 380928] "Spotify Web Helper"=C:\Users\Eigenaar\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2013-12-12 1168896] "Google Update"=C:\Users\Eigenaar\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-20 136176] "Spybot-S&D Cleaning"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [2013-09-20 3666224] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "NPSStartup"= [] "amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824] "WD Quick View"=C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [2013-08-14 5537136] "TrueImageMonitor.exe"=C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2013-11-14 7836312] "AcronisTibMounterMonitor"=C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [2013-10-10 1103272] ""= [] "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208] "SDTray"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [2013-07-25 5624784] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled Dropbox.lnk - C:\Users\Eigenaar\AppData\Roaming\Dropbox\bin\Dropbox.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avldr] avldr64.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro35Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\prwntdrv] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableLinkedConnections"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutorun"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "VIDC.I420"=lvcod64.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "MSVideo8"=VfWWDM32.dll "MSVideo"=vfwwdm32.dll "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux2"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "aux3"=wdmaud.drv "VIDC.FPS1"=frapsv64.dll "wave4"=wdmaud.drv "mixer4"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-01-04 12:15:46 ----D---- C:\rsit 2014-01-04 12:15:46 ----D---- C:\Program Files\trend micro 2014-01-02 18:27:01 ----D---- C:\Program Files (x86)\Futuremark 2013-12-31 14:01:46 ----D---- C:\ProgramData\Age of Empires 3 2013-12-31 13:49:58 ----D---- C:\Users\Eigenaar\AppData\Roaming\Apple Computer 2013-12-30 18:59:35 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-12-30 18:58:19 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2013-12-30 18:58:14 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Rootkit 2013-12-29 21:49:13 ----A---- C:\Windows\system32\sdnclean64.exe 2013-12-29 21:49:11 ----D---- C:\ProgramData\Spybot - Search & Destroy 2013-12-29 21:49:06 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-12-29 19:49:13 ----A---- C:\ProgramData\SMRResults410.dat 2013-12-29 19:30:51 ----A---- C:\Windows\ntbtlog.txt 2013-12-29 17:20:12 ----D---- C:\Program Files\Common Files\Symantec Shared 2013-12-29 17:20:12 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS 2013-12-29 17:17:46 ----D---- C:\Windows\system32\drivers\NISx64 2013-12-29 17:17:45 ----D---- C:\Program Files (x86)\Norton Internet Security 2013-12-29 16:59:11 ----D---- C:\Windows\system32\drivers\NSTx64 2013-12-29 16:59:10 ----D---- C:\Program Files (x86)\Norton Identity Safe 2013-12-28 21:04:24 ----D---- C:\Users\Eigenaar\AppData\Roaming\Malwarebytes 2013-12-28 21:03:57 ----D---- C:\ProgramData\Malwarebytes 2013-12-28 21:03:56 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-12-28 21:03:56 ----A---- C:\Windows\system32\drivers\mbam.sys 2013-12-28 11:35:56 ----D---- C:\Program Files (x86)\NVIDIA Corporation 2013-12-28 11:35:56 ----D---- C:\Program Files (x86)\AGEIA Technologies 2013-12-27 17:23:38 ----D---- C:\Program Files (x86)\2K Games 2013-12-27 16:33:56 ----D---- C:\Windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP 2013-12-22 15:33:18 ----D---- C:\Program Files (x86)\NortonInstaller 2013-12-21 12:07:50 ----D---- C:\Users\Eigenaar\AppData\Roaming\PunkBuster 2013-12-19 08:53:19 ----D---- C:\ProgramData\ATI 2013-12-19 08:53:04 ----D---- C:\Program Files (x86)\AMD AVT 2013-12-19 08:44:50 ----D---- C:\Program Files\AMD 2013-12-18 13:33:22 ----D---- C:\Program Files (x86)\Six Networks 2013-12-18 13:32:13 ----D---- C:\ProgramData\SIX Networks 2013-12-18 13:32:03 ----D---- C:\Users\Eigenaar\AppData\Roaming\SIX Networks 2013-12-18 08:02:34 ----D---- C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 7 2013-12-12 03:02:48 ----A---- C:\Windows\SYSWOW64\wmploc.DLL 2013-12-12 03:02:48 ----A---- C:\Windows\SYSWOW64\wmp.dll 2013-12-12 03:02:48 ----A---- C:\Windows\system32\wmploc.DLL 2013-12-12 03:02:47 ----A---- C:\Windows\system32\wmp.dll 2013-12-12 03:01:04 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 03:01:03 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2013-12-12 03:01:03 ----A---- C:\Windows\SYSWOW64\ieui.dll 2013-12-12 03:01:03 ----A---- C:\Windows\system32\jsproxy.dll 2013-12-12 03:01:03 ----A---- C:\Windows\system32\ieUnatt.exe 2013-12-12 03:01:03 ----A---- C:\Windows\system32\ieui.dll 2013-12-12 03:01:03 ----A---- C:\Windows\system32\iernonce.dll 2013-12-12 03:01:03 ----A---- C:\Windows\system32\ie4uinit.exe 2013-12-12 03:01:02 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2013-12-12 03:01:02 ----A---- C:\Windows\system32\mshtml.dll 2013-12-12 03:01:02 ----A---- C:\Windows\system32\iesetup.dll 2013-12-12 03:01:02 ----A---- C:\Windows\system32\ieetwproxystub.dll 2013-12-12 03:01:02 ----A---- C:\Windows\system32\ieetwcollector.exe 2013-12-12 03:01:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2013-12-12 03:01:01 ----A---- C:\Windows\system32\jscript9diag.dll 2013-12-12 03:01:01 ----A---- C:\Windows\system32\ieapfltr.dll 2013-12-12 03:01:00 ----A---- C:\Windows\SYSWOW64\wininet.dll 2013-12-12 03:01:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2013-12-12 03:01:00 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2013-12-12 03:01:00 ----A---- C:\Windows\system32\wininet.dll 2013-12-12 03:01:00 ----A---- C:\Windows\system32\iertutil.dll 2013-12-12 03:00:59 ----A---- C:\Windows\system32\urlmon.dll 2013-12-12 03:00:59 ----A---- C:\Windows\system32\ieframe.dll 2013-12-12 03:00:58 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2013-12-12 03:00:58 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2013-12-12 03:00:57 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2013-12-12 03:00:57 ----A---- C:\Windows\system32\jscript9.dll 2013-12-12 02:45:15 ----A---- C:\Windows\SYSWOW64\wscript.exe 2013-12-12 02:45:15 ----A---- C:\Windows\SYSWOW64\scrrun.dll 2013-12-12 02:45:15 ----A---- C:\Windows\SYSWOW64\cscript.exe 2013-12-12 02:45:15 ----A---- C:\Windows\system32\wscript.exe 2013-12-12 02:45:15 ----A---- C:\Windows\system32\scrrun.dll 2013-12-12 02:45:15 ----A---- C:\Windows\system32\cscript.exe 2013-12-12 02:45:10 ----A---- C:\Windows\SYSWOW64\msieftp.dll 2013-12-12 02:45:10 ----A---- C:\Windows\system32\msieftp.dll 2013-12-12 02:45:05 ----A---- C:\Windows\system32\win32k.sys 2013-12-12 02:45:04 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll 2013-12-12 02:45:04 ----A---- C:\Windows\system32\WMPhoto.dll 2013-12-12 02:44:59 ----A---- C:\Windows\SYSWOW64\imagehlp.dll 2013-12-12 02:44:59 ----A---- C:\Windows\system32\imagehlp.dll 2013-12-12 02:44:55 ----A---- C:\Windows\SYSWOW64\tzres.dll 2013-12-12 02:44:55 ----A---- C:\Windows\system32\tzres.dll 2013-12-12 02:44:50 ----A---- C:\Windows\system32\drivers\portcls.sys 2013-12-12 02:44:50 ----A---- C:\Windows\system32\drivers\drmk.sys 2013-12-11 20:28:25 ----A---- C:\Windows\SYSWOW64\vp6vfw.dll 2013-12-11 15:53:47 ----D---- C:\Program Files (x86)\Mozilla Thunderbird 2013-12-10 23:04:52 ----D---- C:\Program Files (x86)\Rockstar Games 2013-12-10 13:34:28 ----D---- C:\Users\Eigenaar\AppData\Roaming\Ohm Force 2013-12-09 16:21:17 ----D---- C:\Users\Eigenaar\AppData\Roaming\library_dir 2013-12-09 16:20:15 ----D---- C:\Users\Eigenaar\AppData\Roaming\Raptr 2013-12-09 16:20:15 ----D---- C:\Program Files (x86)\Raptr 2013-12-06 23:07:36 ----A---- C:\Windows\system32\atimpc64.dll 2013-12-06 23:07:36 ----A---- C:\Windows\system32\amdpcom64.dll 2013-12-06 23:07:14 ----A---- C:\Windows\SYSWOW64\atimpc32.dll 2013-12-06 23:07:14 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll 2013-12-06 23:03:00 ----A---- C:\Windows\system32\atiu9p64.dll 2013-12-06 23:02:38 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll 2013-12-06 22:59:00 ----A---- C:\Windows\SYSWOW64\atiumdva.dll 2013-12-06 22:58:10 ----A---- C:\Windows\SYSWOW64\atiumdag.dll 2013-12-06 22:57:20 ----A---- C:\Windows\system32\atiumd6a.dll 2013-12-06 22:56:54 ----A---- C:\Windows\system32\atiumd64.dll 2013-12-06 22:52:14 ----A---- C:\Windows\system32\drivers\atikmdag.sys 2013-12-06 22:38:52 ----A---- C:\Windows\system32\clinfo.exe 2013-12-06 22:38:34 ----A---- C:\Windows\system32\OpenVideo64.dll 2013-12-06 22:38:28 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll 2013-12-06 22:38:22 ----A---- C:\Windows\system32\OVDecode64.dll 2013-12-06 22:38:18 ----A---- C:\Windows\SYSWOW64\OVDecode.dll 2013-12-06 22:37:58 ----A---- C:\Windows\system32\amdocl64.dll 2013-12-06 22:35:36 ----A---- C:\Windows\SYSWOW64\amdocl.dll 2013-12-06 22:33:28 ----A---- C:\Windows\system32\OpenCL.dll 2013-12-06 22:33:24 ----A---- C:\Windows\SYSWOW64\OpenCL.dll 2013-12-06 22:26:44 ----A---- C:\Windows\system32\coinst_13.251.dll 2013-12-06 22:16:40 ----A---- C:\Windows\system32\atio6axx.dll 2013-12-06 22:13:02 ----A---- C:\Windows\system32\atiapfxx.exe 2013-12-06 22:12:52 ----A---- C:\Windows\system32\aticalrt64.dll 2013-12-06 22:12:50 ----A---- C:\Windows\SYSWOW64\aticalrt.dll 2013-12-06 22:12:42 ----A---- C:\Windows\system32\aticalcl64.dll 2013-12-06 22:12:40 ----A---- C:\Windows\SYSWOW64\aticalcl.dll 2013-12-06 22:12:26 ----A---- C:\Windows\system32\aticaldd64.dll 2013-12-06 22:09:18 ----A---- C:\Windows\SYSWOW64\aticaldd.dll 2013-12-06 21:58:50 ----A---- C:\Windows\SYSWOW64\atioglxx.dll 2013-12-06 21:53:18 ----A---- C:\Windows\system32\atidemgy.dll 2013-12-06 21:53:10 ----A---- C:\Windows\system32\atimuixx.dll 2013-12-06 21:53:04 ----A---- C:\Windows\system32\atieclxx.exe 2013-12-06 21:52:10 ----A---- C:\Windows\system32\atiesrxx.exe 2013-12-06 21:50:36 ----A---- C:\Windows\system32\atitmm64.dll 2013-12-06 21:22:42 ----A---- C:\Windows\system32\atiadlxx.dll 2013-12-06 21:22:28 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll 2013-12-06 21:22:12 ----A---- C:\Windows\system32\atig6pxx.dll 2013-12-06 21:22:08 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll 2013-12-06 21:22:08 ----A---- C:\Windows\system32\atiglpxx.dll 2013-12-06 21:22:04 ----A---- C:\Windows\system32\atig6txx.dll 2013-12-06 21:21:54 ----A---- C:\Windows\SYSWOW64\atigktxx.dll 2013-12-06 21:21:44 ----A---- C:\Windows\system32\drivers\atikmpag.sys 2013-12-06 21:18:12 ----A---- C:\Windows\system32\drivers\ati2erec.dll 2013-12-06 16:49:18 ----A---- C:\Windows\system32\kdbsdk64.dll 2013-12-06 16:44:26 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll 2013-12-05 13:55:28 ----A---- C:\Windows\game.ini 2013-12-05 12:31:57 ----A---- C:\Windows\CoDUO.INI ======List of files/folders modified in the last 1 month====== 2014-01-04 12:15:47 ----D---- C:\Windows\Temp 2014-01-04 12:15:46 ----RD---- C:\Program Files 2014-01-04 12:14:07 ----D---- C:\Windows\system32\config 2014-01-04 12:13:22 ----D---- C:\Users\Eigenaar\AppData\Roaming\Dropbox 2014-01-04 12:13:21 ----D---- C:\Windows\system32\drivers 2014-01-04 12:06:14 ----SHD---- C:\System Volume Information 2014-01-04 12:05:51 ----D---- C:\Windows\SysWOW64 2014-01-04 00:44:58 ----D---- C:\Windows\System32 2014-01-04 00:04:23 ----D---- C:\Windows\system32\catroot2 2014-01-03 14:25:41 ----D---- C:\Windows\Internet Logs 2014-01-03 14:25:41 ----D---- C:\Users\Eigenaar\AppData\Roaming\Winamp 2014-01-03 14:25:05 ----D---- C:\Windows 2014-01-03 14:20:14 ----D---- C:\Windows\system32\Tasks 2014-01-03 14:20:11 ----D---- C:\Program Files (x86)\CCleaner 2014-01-02 18:38:12 ----A---- C:\Windows\GPU-Z.INI 2014-01-02 18:27:06 ----SHD---- C:\Windows\Installer 2014-01-02 18:27:06 ----SHD---- C:\Config.Msi 2014-01-02 18:27:01 ----RD---- C:\Program Files (x86) 2014-01-02 17:32:46 ----D---- C:\Windows\inf 2014-01-02 17:32:46 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-01-02 17:29:52 ----D---- C:\Windows\system32\NDF 2014-01-01 21:20:16 ----D---- C:\Windows\Prefetch 2014-01-01 21:01:29 ----D---- C:\Windows\winsxs 2014-01-01 21:01:25 ----D---- C:\Windows\system32\catroot 2014-01-01 20:45:41 ----D---- C:\Ubisoft 2014-01-01 20:40:15 ----D---- C:\Windows\Minidump 2014-01-01 15:30:26 ----RSD---- C:\Windows\assembly 2013-12-31 14:01:46 ----HD---- C:\ProgramData 2013-12-30 13:57:13 ----D---- C:\Program Files (x86)\WinDirStat 2013-12-29 21:49:37 ----SD---- C:\ProgramData\Microsoft 2013-12-29 19:29:12 ----D---- C:\ProgramData\Norton 2013-12-29 17:20:12 ----D---- C:\Program Files\Common Files 2013-12-29 14:32:04 ----D---- C:\Program Files (x86)\TV 2013-12-28 21:23:35 ----D---- C:\Users\Eigenaar\AppData\Roaming\Desktopicon 2013-12-27 15:51:50 ----D---- C:\Users\Eigenaar\AppData\Roaming\Spotify 2013-12-27 10:29:06 ----D---- C:\ProgramData\Western Digital 2013-12-27 10:28:52 ----D---- C:\Program Files\Common Files\Western Digital 2013-12-27 10:28:52 ----D---- C:\Program Files (x86)\Western Digital 2013-12-22 15:46:33 ----D---- C:\Program Files (x86)\Common Files 2013-12-22 14:43:02 ----D---- C:\Windows\Tasks 2013-12-22 14:43:02 ----D---- C:\Windows\system32\wfp 2013-12-22 14:43:02 ----D---- C:\Windows\system32\wbem 2013-12-22 14:43:02 ----D---- C:\Windows\system32\DriverStore 2013-12-22 14:43:02 ----D---- C:\Windows\system32\drivers\etc 2013-12-21 22:22:32 ----D---- C:\ProgramData\Ubisoft 2013-12-21 21:55:26 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2013-12-21 12:08:08 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe 2013-12-21 12:07:55 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe 2013-12-21 01:38:37 ----D---- C:\ProgramData\Acronis 2013-12-20 10:04:54 ----D---- C:\Users\Eigenaar\AppData\Roaming\vlc 2013-12-19 11:27:23 ----D---- C:\Windows\Microsoft.NET 2013-12-19 09:20:47 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-19 08:53:11 ----D---- C:\ProgramData\AMD 2013-12-19 08:48:20 ----D---- C:\Program Files\ATI Technologies 2013-12-15 03:04:16 ----D---- C:\Windows\system32\MRT 2013-12-15 03:00:53 ----A---- C:\Windows\system32\MRT.exe 2013-12-13 11:56:51 ----D---- C:\Program Files (x86)\Google 2013-12-12 18:14:41 ----D---- C:\Windows\rescache 2013-12-12 07:13:44 ----D---- C:\Windows\system32\wdi 2013-12-12 07:10:29 ----D---- C:\Program Files (x86)\Windows Media Player 2013-12-12 07:10:27 ----D---- C:\Program Files\Windows Media Player 2013-12-12 07:10:10 ----D---- C:\Program Files (x86)\Internet Explorer 2013-12-12 07:10:07 ----D---- C:\Program Files\Internet Explorer 2013-12-12 07:09:50 ----D---- C:\Windows\SYSWOW64\nl-NL 2013-12-12 07:09:48 ----D---- C:\Windows\system32\nl-NL 2013-12-11 13:07:42 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe 2013-12-09 22:10:45 ----D---- C:\Users\Eigenaar\AppData\Roaming\Mozilla 2013-12-09 16:13:18 ----D---- C:\AMD 2013-12-09 16:08:00 ----D---- C:\ProgramData\Package Cache 2013-12-09 12:28:53 ----D---- C:\Program Files (x86)\Samsung Magician 2013-12-06 23:04:10 ----A---- C:\Windows\system32\atiuxp64.dll 2013-12-06 23:03:46 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll 2013-12-06 23:01:52 ----A---- C:\Windows\system32\aticfx64.dll 2013-12-06 23:01:04 ----A---- C:\Windows\SYSWOW64\aticfx32.dll 2013-12-06 23:00:16 ----A---- C:\Windows\system32\atidxx64.dll 2013-12-06 22:59:50 ----A---- C:\Windows\SYSWOW64\atidxx32.dll 2013-12-05 20:32:48 ----D---- C:\Program Files (x86)\Battlelog Web Plugins 2013-12-05 14:17:11 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll 2013-12-05 14:17:11 ----A---- C:\Windows\system32\OpenAL32.dll 2013-12-05 12:56:56 ----A---- C:\Windows\CoD.INI 2013-12-05 09:32:56 ----A---- C:\Windows\SYSWOW64\pbsvc.exe ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2013-12-03 116000] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2013-12-02 316248] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888] R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2013-12-03 269600] R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1501000.012\SYMDS64.SYS [2013-09-10 493656] R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1501000.012\SYMEFA64.SYS [2013-09-27 1147480] R0 tib;Acronis TIB Manager; C:\Windows\system32\DRIVERS\tib.sys [2013-12-03 1120032] R0 tib_mounter;Acronis TIB Mounter; C:\Windows\system32\DRIVERS\tib_mounter.sys [2013-12-03 198432] R0 vididr;Acronis Virtual Disk; C:\Windows\system32\DRIVERS\vididr.sys [2013-12-03 161568] R0 vidsflt;Acronis Disk Storage Filter; C:\Windows\system32\DRIVERS\vidsflt.sys [2013-12-03 117024] R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [2013-12-03 1526488] R1 ccSet_NIS;NIS Settings Manager; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [2013-09-26 162392] R1 ccSet_NST;Norton Identity Safe Settings Manager; C:\Windows\system32\drivers\NSTx64\7DE06000.01B\ccSetx64.sys [2013-09-27 162392] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-12-28 484952] R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140103.001\IDSvia64.sys [2013-12-27 521944] R1 RapportCerberus_59849;RapportCerberus_59849; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [2013-11-01 606672] R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-12-02 282648] R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-12-02 397784] R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [2013-09-10 36952] R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [2013-09-27 264280] R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\NISx64\1501000.012\SYMNETS.SYS [2013-09-26 590936] R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2012-08-26 314016] R2 hmpalert;HitmanPro.Alert Support Driver; \??\C:\Windows\system32\drivers\hmpalert.sys [2013-10-11 17416] R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2012-08-26 43680] R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-10-20 47632] R2 pnarp;Pure Networks Device Discovery Driver; C:\Windows\system32\DRIVERS\pnarp.sys [2009-07-07 33328] R2 purendis;Pure Networks Wireless Driver; C:\Windows\system32\DRIVERS\purendis.sys [2009-07-07 35376] R2 RtNdPt60;Realtek NDIS Protocol Driver; C:\Windows\system32\DRIVERS\RtNdPt60.sys [2009-07-20 27136] R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2013-12-03 367200] R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552] R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 626176] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-01-01 137648] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240] R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232] R3 LVUSBS64;Logitech USB Monitor Filter; C:\Windows\system32\DRIVERS\LVUSBS64.sys [2007-10-12 50072] R3 mod7700;DiBcom DIB7700 based TV tuner device; C:\Windows\System32\Drivers\dvb7700all.sys [2009-10-21 913408] R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140103.008\ENG64.SYS [2014-01-03 126040] R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140103.008\EX64.SYS [2014-01-03 2099288] R3 RRNetCapMP;RRNetCapMP; C:\Windows\system32\DRIVERS\rrnetcap.sys [2013-08-19 37480] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392] R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSP64.SYS [2013-09-27 858200] R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-12-29 177752] R3 tbhsd;Audials Sound Capturing; C:\Windows\system32\drivers\tbhsd.sys [2013-08-19 47240] S3 ACSSCR;ACR38 Smart Card Reader; C:\Windows\system32\DRIVERS\a38usb.sys [2011-05-23 44672] S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456] S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552] S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984] S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784] S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960] S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384] S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488] S3 GPUZ;GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [] S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-10-26 32768] S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928] S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232] S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928] S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\Windows\system32\DRIVERS\LV561V64.SYS [2009-04-30 588952] S3 Prot6Flt;Prot6Flt; C:\Windows\system32\DRIVERS\Prot6Flt.sys [] S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys [] S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys [] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720] S3 RRNetCap;RRNetCap Service; C:\Windows\system32\DRIVERS\rrnetcap.sys [2013-08-19 37480] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [] S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2); C:\Windows\system32\DRIVERS\RtVlan60.sys [2007-12-03 24064] S3 SliceDisk5;SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [2011-02-25 31824] S3 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2013-12-03 1464096] S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832] S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-05-10 51712] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496] S3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2); C:\Windows\system32\DRIVERS\RtVLAN60.sys [2007-12-03 24064] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152] R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2013-08-21 1144144] R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640] R2 afcdpsrv;Acronis Nonstop Backup Service; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2013-12-03 3881976] R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 239616] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2013-11-01 109352] R2 hmpalertsvc;HitmanPro.Alert Service; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [2013-10-11 1830768] R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136] R2 LinksysUpdater;Linksys Updater; C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-04-18 204800] R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000] R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408] R2 NCO;Norton Identity Safe; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe [2013-10-06 129424] R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [2008-12-02 877864] R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [2013-10-08 275696] R2 nmservice;Pure Networks Platform Service; C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [2009-07-07 647216] R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896] R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [2006-12-19 81920] R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-12-21 75136] R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-12-02 1444120] R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936] R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-10-15 3921880] R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-09-20 1042272] R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-09-13 171416] R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136] R2 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944] R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 153440] R2 syncagentsrv;Acronis Sync Agent Service; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2013-10-22 7148216] R2 TVService;TVService; C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TVService.exe [2009-05-08 192512] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-08-13 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-08-13 124088] S2 gupdate;Google Updateservice (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-20 136176] S2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-07 161384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416] S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-13 51808] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840] S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2013-11-21 520416] S3 getPlusHelper;@C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 27136] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-20 136176] S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-28 194032] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616] S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2013-10-23 641352] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-18 118896] S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2008-12-12 537896] S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2009-10-20 117264] S3 Sony SCSI Helper Service;Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [2013-11-26 73728] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-12-11 569768] S3 SystemExplorerHelpService;System Explorer Service; D:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [2012-11-25 821720] S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-08-13 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-08-13 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-08-13 139856] -----------------EOF-----------------
  22. Hoi, Het zou kunnen dat er (resten van) malware of een virus op mijn pc staat. Ik heb al gezocht met Norton Internet Security, Norton Power Eraser, Malwarebytes Anti-Malware en Anti-Rootkit en Spybot, maar niets gevonden. Een jaar geleden stond er zo'n politie virus op de pc, dat heb ik toen verwijderd in de veilige modus. Maar de laatste tijd kan het hoofdscherm van Norton Internet Security niet meer opstarten (rest van Norton werkt nog wel gewoon). Ook het overzetten van het besturingssysteem van de harde schijf naar een ssd is al twee keer mislukt, terwijl de ssd wel gewoon functioneert (ook zichtbaar en te booten in het BIOS). Alvast bedankt.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.