Ga naar inhoud

Ewing

Lid
  • Items

    26
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door Ewing

  1. Het is opgelost, hartelijk bedankt!!!
  2. Ja, dan heb ik het probleem nog steeds. Het programma downloaden lukt niet omdat ik geen winzip heb, is er een andere manier?
  3. http://speccy.piriform.com/results/ZfTLka6qM8oautzLPM6ilqw Voila
  4. Allen, Ik zit al een tijdje met een probleem met de mousepad van mijn laptop. Als ik iets wil aanklikken werkt het niet meer als ik op de mousepad zelf klik. Doe ik het met de knoppen die bij de mousepad horen lukt het nog wel. In veilige modus lukt he allebei nog. Grt
  5. In de TAB "opstarten" ging alles goed. In de TAB "Services" had ik problemen met deze twee. MBAMScheduler Malwarebytes Corporation MBAMService Malwarebytes Corporation Deze heb ik uitgeschakeld en dan heb ik alles wat daarna kwam terug ingeschakeld en had ik geen problemen meer met opstarten. Nu heb ik nog een klein probleempje (als we toch bezig zijn ) ik kan nog wel bewegen met de muis via de mousepad maar ik kan er niet meer op klikken. Met de knoppen van de mousepad lukt het nog wel. Iemand een idee?
  6. Heb ik juist gedaan, op het einde van het blauwe scherm komt er "logbestand wordt voorbereid". Maar er komt niks. En als ik op de c schijf ga kijken vind ik alleen ComboFix 25/02/2014 14:22 teksdocument 1kb mbr 25/02/2014 14:22 teksdocument 1kb pend 25/02/2014 14:22 tekstdocument 1kb
  7. Ik zal Avast effe verwijderen want ik krijg de schilden niet afgezet. Als ik in mijn menu op het icoontje ga staan en ik druk op de rechter muisknop en neem dan "schilden uitschakelen" krijg ik een mekding of ik dit wel zeker wil doen. Klik ik op "ja" dan doet hij het niet. Ik zal Combofix nogmaals uitvoeren. Komt de log er automatisch op? Of moet ik hem ergens gaan zoeken? Bedankt
  8. Is het dat? ComboFix 14-02-24.02 - Robby 25/02/2014 12:04:39.1.2 - x86 NETWORK Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3066.2358 [GMT 1:00] Gestart vanuit: C:\Users\Robby\Downloads\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Nieuw herstelpunt werd aangemaakt (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\INSTALL.LOG C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\{7EB3FB6A-5634-4BCF-819F-7D7DD8384D45}.xps C:\Windows\iun6002.exe
  9. Daar zit ik met een probleem. Hij start wel terug op, maar niet automatisch in veilige modus. Dan blijft hij terug hangen en kan ik het logje niet lezen. Er zit wel verbetering in, ik krijg nu onderaan al een werkbalk, maar het scherm blijft nog zwart en is nog aan het laden.
  10. Nee, hij blijft nog steeds hangen op het welkom scherm.
  11. Nu staat het er drie keer, sorry. Mobiele verbinding is niet zo stabiel
  12. Zo Zoek.exe v5.0.0.0 Updated 19-February-2014 Tool run by Robby on ma 24/02/2014 at 15:00:20,37. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Robby\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\Program Files\MSXML 4.0 deleted successfully C:\PROGRA~2\Babylon deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\PROGRA~2\OviInstallerCache deleted successfully C:\Users\Robby\AppData\Roaming\.# deleted successfully C:\Users\Robby\AppData\Roaming\Sony Setup deleted successfully C:\Users\Robby\AppData\Roaming\WinRAR deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_CLASSES_ROOT\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_CLASSES_ROOT\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} deleted successfully HKEY_CLASSES_ROOT\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\bkmrksync@nokia.com deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default ---- Lines funmoods removed from prefs.js ---- user_pref("browser.search.defaultenginename", "Funmoods"); user_pref("browser.startup.homepage", "Funmoods Search user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.cntry", "BE"); user_pref("extensions.funmoods.cv", "cv5"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.hdrMd5", "3F1EBB0B0FDAE24CB97397C8A1FA4077"); user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "Funmoods Search user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); user_pref("extensions.funmoods.newTab", true); user_pref("extensions.funmoods.newTabUrl", "Funmoods Search user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.sg", "none"); user_pref("extensions.funmoods.smplGrp", "none"); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.tlbrSrchUrl", "Funmoods Search user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); ---- Lines funmoods modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines funmoods removed from user.js ---- user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "Funmoods Search"); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods.newTabUrl", "Funmoods Search"); user_pref("extensions.funmoods.tlbrSrchUrl", "Funmoods Search="); user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); ---- Lines ask.com removed from prefs.js ---- user_pref("extensions.asktb.default-channel-url-mask", "{query} - Ask.com Web Search"); user_pref("extensions.asktb.http-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \ user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WR user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); ---- Lines ask.com modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines babylon removed from prefs.js ---- user_pref("browser.search.order.1", "Search the web (Babylon)"); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "Babylon Search="); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("keyword.URL", "Babylon Search="); ---- Lines babylon removed from user.js ---- user_pref("yahoo.ytff.general.dontshowhpoffer", true);user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "Babylon Search="); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); ---- Lines conduit removed from prefs.js ---- user_pref("extensions.asktb.abar-war-regex", "conduit\\.com"); ---- Lines asktb removed from prefs.js ---- user_pref("extensions.asktb.abar-war-timeout", "4000"); user_pref("extensions.asktb.autofill-competitor-query-enabled", true); user_pref("extensions.asktb.autofill-text-highlight-enabled", true); user_pref("extensions.asktb.cbid", "UG"); user_pref("extensions.asktb.config-updated", true); user_pref("extensions.asktb.displaybehavior", ""); user_pref("extensions.asktb.displaytext", ""); user_pref("extensions.asktb.dtid", "YYYYYYYYBE"); user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "BEXX0005"); user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); user_pref("extensions.asktb.first-launch-url", "http://www.drivernavigator.com/buy.php?pmtid=3&affid=us2008&srcid="); user_pref("extensions.asktb.fresh-install", false); user_pref("extensions.asktb.guid", "07B53C07-38FC-485B-9DC3-6F2A6B648D6B"); user_pref("extensions.asktb.if", "su"); user_pref("extensions.asktb.l", "dis"); user_pref("extensions.asktb.last-config-req", "1349115838565"); user_pref("extensions.asktb.locale", "nl_EU"); user_pref("extensions.asktb.location", "Brussels,Belgium"); user_pref("extensions.asktb.lstation", ""); user_pref("extensions.asktb.news-native-on", true); user_pref("extensions.asktb.o", "15158"); user_pref("extensions.asktb.overlay-reloaded-using-restart", true); user_pref("extensions.asktb.pstate", ""); user_pref("extensions.asktb.qsrc", "2871"); user_pref("extensions.asktb.r", "8"); user_pref("extensions.asktb.sa", "NO"); user_pref("extensions.asktb.search-history-queries", "dikke schijven||retro hous"); user_pref("extensions.asktb.search-suggestions-enabled", true); user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true); user_pref("extensions.asktb.silent-upgrade", true); user_pref("extensions.asktb.socialmini-first", true); user_pref("extensions.asktb.socialmini-interval", "1200000"); user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); user_pref("extensions.asktb.socialmini-max-items", "30"); user_pref("extensions.asktb.socialmini-native-on", true); user_pref("extensions.asktb.socialmini-speed", "5000"); user_pref("extensions.asktb.socialmini-transition-first-open", false); user_pref("extensions.asktb.themeid", ""); user_pref("extensions.asktb.v", "3.14.1.100013"); user_pref("extensions.asktb.volume", ""); ---- Lines 99079a25-328f-4bd4-be04-00955acaa0a7 modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@disabled:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler ---- Lines Search-Results removed from prefs.js ---- user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline url(\"IMAGE\") right no ---- FireFox user.js and prefs.js backups ---- user_20142402_1513_.backup prefs_20142402_1513_.backup ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- "ApnUpdater"=- ==== Deleting Files \ Folders ====================== C:\Program Files\AVG not found C:\Program Files\Ask.com deleted C:\Program Files\MediaMonkey deleted C:\Program Files\Mozilla Firefox deleted C:\Users\Robby\AppData\Local\MediaMonkey deleted C:\Program Files\Conduit deleted C:\Program Files\Convesoft deleted C:\Program Files\Yahoo! deleted C:\Users\Robby\AppData\Roaming\Smiley.ico deleted C:\Users\Robby\AppData\Roaming\Babylon deleted C:\Users\Robby\AppData\Roaming\GetRightToGo deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\@themediafinder.com deleted C:\Users\Robby\AppData\Roaming\Media Finder deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~2\StarApp deleted C:\PROGRA~2\boost_interprocess deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Premium deleted C:\Users\Robby\AppData\Local\CRE deleted C:\Users\Robby\AppData\Local\WhiteListing deleted C:\Users\Robby\AppData\Local\jZip deleted C:\Users\Robby\AppData\Local\NativeMessaging deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder deleted C:\Users\Robby\Downloads\DownloadManagerSetup.exe deleted C:\Users\Robby\AppData\LocalLow\Yahoo! deleted C:\Users\Robby\AppData\LocalLow\searchqutoolbar deleted C:\Users\Robby\AppData\LocalLow\jZip deleted C:\Users\Robby\AppData\LocalLow\AskToolbar deleted C:\Users\Robby\AppData\LocalLow\DataMngr deleted C:\Users\Robby\AppData\LocalLow\Conduit deleted C:\Windows\SYSTEM32\TASKS\Scheduled Update for Ask Toolbar deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Search_Results.xml deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchqutoolbar deleted C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\ffxtlbr@funmoods.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\toolbar@ask.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted "C:\Users\Robby\AppData\Roaming\File Templates" deleted "C:\Users\Robby\AppData\Roaming\Filesystems" deleted "C:\Users\Robby\AppData\Roaming\Filter" deleted "C:\ProgramData\Flags" deleted "C:\ProgramData\Flange Saw" deleted "C:\ProgramData\Flanger" deleted "C:\ProgramData\Galaxy Swirl" deleted "C:\ProgramData\Generic" deleted "C:\ProgramData\Grapher" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Funmoods.xml" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted "C:\Program Files\jZip\jZipShell.dll" deleted "C:\Program Files\jZip" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Robby\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\Robby\AppData\Roaming ====== ====== C:\Users\Robby ====== 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe ====== C: exe-files == 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Install\{5ED071C8-60B3-4CAB-A7D9-1B88AA2A83C8}\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-20 15:19:14 0FB86683779E34A7A9739E11E5CB62A1 1043232 ----a-w- C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn\10.26.7.519_0\nativeMessaging\TBMessagingHost.exe 2014-02-20 14:59:07 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe 2014-02-20 14:59:07 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateBroker.exe 2014-02-20 14:59:06 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateSetup.exe 2014-02-20 14:57:55 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler64.exe 2014-02-20 14:57:54 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe 2014-02-20 14:57:41 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdate.exe 2014-02-20 14:56:56 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ArcadeDeluxeAgent"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" "CLMLServer"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" "NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" "NvMediaCenter"="RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup" "AmIcoSinglun"="C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" "Skytel"="C:\Program Files\Realtek\Audio\HDA\Skytel.exe" "PLFSetI"="C:\Windows\PLFSetI.exe" "VitaKeyPdtWzd"="c:\Program Files\Acer Bio Protection\PdtWzd.exe" "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "LManager"="C:\Program Files\Launch Manager\LManager.exe" "BackupManagerTray"="C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe -k" "Acer ePower Management"="C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe" "EgisTecLiveUpdate"="C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" "mwlDaemon"="C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" "PlayMovie"="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe /hide" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "beid"="C:\Program Files\Belgium Identity Card\beid35gui.exe /startup" "avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent" "Malwarebytes Anti-Malware (cleanup)"="rundll32.exe C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll,ProcessCleanupScript" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Malwarebytes' Anti-Malware (reboot)] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Malwarebytes' Anti-Malware (reboot)" "hkey"="HKLM" "command"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Nikon Message Center 2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Nikon Message Center 2" "hkey"="HKLM" "command"="C:\\Program Files\\Nikon\\Nikon Message Center 2\\NkMC2.exe -s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMServer" "hkey"="HKLM" "command"="C:\\Program Files\\Common Files\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMusic FastStart] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMusic FastStart" "hkey"="HKLM" "command"="\"C:\\Program Files\\Nokia\\Ovi Player\\NokiaOviPlayer.exe\" /command:faststart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaOviSuite2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaOviSuite2" "hkey"="HKCU" "command"="C:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PC Suite Tray" "hkey"="HKCU" "command"="\"C:\\Users\\Robby\\Desktop\\Snelkoppelingen Bureaublad\\Nokia PC Suite 7\\PCSuite.exe\" -onlytray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Steam" "hkey"="HKCU" "command"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" "hkey"="HKLM" "command"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" ==== Startup Folders ====================== 2011-08-08 19:28:39 1105 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk 2009-09-10 16:24:31 0 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [22/02/2014 14:06] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\{DB3D65B2-7447-49F3-829D-B1242A857BBB}" ["c:\program files\google\chrome\application\chrome.exe"] "C:\Windows\system32\tasks\Acer\Burn Notification" [C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/12/2013 14:12] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default - avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF - Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension - Undetermined - C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - TVU Web Player - %ProfilePath%\extensions\firefox@tvunetworks.com - Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b} - Yahoo Toolbar - %ProfilePath%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - DealPly - %ProfilePath%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} ==== Firefox Plugins ====================== Profilepath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default 87B41E7975298577BC56B6E82F0E6B34 - C:\Program Files\Java\jre7\bin\npjpi170_25.dll - Java Platform SE 7 U25 73FB13F5D73EDC1DB8C66079903B19F6 - C:\Program Files\Java\jre7\bin\npoji610.dll - Java Platform SE 7 U25 6967C3D9BE67F6A5DEFADEDEE02FCB92 - c:\Program Files\Sony\Media Go\npmediago.dll - Media Go Detector AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery 24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java Platform SE 7 U25 D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.250.17 0B759CF1C312102F1F7FFC0F7BE67D0A - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll - InoViewer Plugin 5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin A82533DA1C7AFCE542B8E0D2714B8A4A - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector 07154B27860B999CC70EB6F7A1528794 - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 1BFD18699636B8F1AA26675BA43D2F8F - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll - Shockwave for Director / Shockwave for Director 6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director 58F41CA8F9C2014709F9547B2B81A468 - C:\Windows\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll - TVU Web Player for FireFox 5FBCD34D89D58D695D966A70C9829EE6 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.6.8 E764E340AD2CD744802B5CD51D234E28 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.6.8 5E689EEF06202E299F96E82DA9174255 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.6.8 C37A257E3C3D26AA3E75DDF72D861771 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.6.8 6D2329DFDA605E25D5FC3A3D6A0129B8 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.6.8 D4619DDAC3134E7D2737EE7B36143316 - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.6.8 1573E1AC2FDE21D2A936F00EDB919FAD - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.6.8 ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Windows\system32\TVUAx\npTVUAx.dll - TVU Web Player for FireFox ==== Deleted Firefox Extensions ====================== C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dednnpigldgdbpgcdpfppmlcnnbjciel - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx[] gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] lpmkgpnbiojfaoklbkpfneikocaobfai - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel AT_Porsche - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg Webcam Toy - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade BittorrentBar_NL - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm Red Bull TV - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbalkogcfbpplioohgihkidalmomblfc 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp Docs - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel DealPly - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje avast WebRep - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda ==== Chrome Fix ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0 deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" "Default_Page_URL"="iGoogle Redirect" "Search Page"="Google" "Search Bar"="Upgrade to Google Chrome" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search/?q=%s" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="Bing" "Search Bar"="Bing" "Default_Page_URL"="MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer!" "Start Page"="Google" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="%s - Bing" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing=" {23735B41-2CBD-5328-C66C-5FF7986F9BDE} Google Url="{searchTerms} - Google Search" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}" {70D46D94-BF1E-45ED-B567-48701376298E} Google Desktop Url="http://127.0.0.1:4664/search&s=dd3_8oGdgvRA8WnXL-FL5pT3vms?q={searchTerms}" {B1D44357-3BA0-4D84-9656-DCCE129AB563} Google Url="{searchTerms} - Google Search" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{44DDF452-62BA-F2EF-2B10-76C079E8936D} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B1D56A0-B9C4-A31A-5B4E-7E5E8A805515} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2 deleted successfully ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Robby\AppData\Local\Mozilla\Firefox\Profiles\27w4mn03.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2738 folders=544 295042543 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Robby\AppData\Local\Temp will be emptied at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Robby\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Program Files\jZip" not found ==== EOF on ma 24/02/2014 at 15:28:36,98 ====================== - - - Updated - - - Zo Zoek.exe v5.0.0.0 Updated 19-February-2014 Tool run by Robby on ma 24/02/2014 at 15:00:20,37. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Robby\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\Program Files\MSXML 4.0 deleted successfully C:\PROGRA~2\Babylon deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\PROGRA~2\OviInstallerCache deleted successfully C:\Users\Robby\AppData\Roaming\.# deleted successfully C:\Users\Robby\AppData\Roaming\Sony Setup deleted successfully C:\Users\Robby\AppData\Roaming\WinRAR deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_CLASSES_ROOT\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_CLASSES_ROOT\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} deleted successfully HKEY_CLASSES_ROOT\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\bkmrksync@nokia.com deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default ---- Lines funmoods removed from prefs.js ---- user_pref("browser.search.defaultenginename", "Funmoods"); user_pref("browser.startup.homepage", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0C user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.cntry", "BE"); user_pref("extensions.funmoods.cv", "cv5"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.hdrMd5", "3F1EBB0B0FDAE24CB97397C8A1FA4077"); user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tz user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); user_pref("extensions.funmoods.newTab", true); user_pref("extensions.funmoods.newTabUrl", "http://searchfunmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0 user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.sg", "none"); user_pref("extensions.funmoods.smplGrp", "none"); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.tlbrSrchUrl", "http://searchfunmoods.com/?f=3&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0 user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); ---- Lines funmoods modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines funmoods removed from user.js ---- user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463"); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods.newTabUrl", "http://searchfunmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463"); user_pref("extensions.funmoods.tlbrSrchUrl", "http://searchfunmoods.com/?f=3&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463&q="); user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); ---- Lines ask.com removed from prefs.js ---- user_pref("extensions.asktb.default-channel-url-mask", "http://eu.ask.com/web?qsrc={qsrc}&o={o}&l={l}&q={query}&dm=all"); user_pref("extensions.asktb.http-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \ user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WR user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); ---- Lines ask.com modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines babylon removed from prefs.js ---- user_pref("browser.search.order.1", "Search the web (Babylon)"); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=0c28b3c30000000000000022fa06e594&q="); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("keyword.URL", "http://search.babylon.com/?affID=110823&tt=300912_TORP_4012_8&babsrc=KW_ss&mntrId=0c28b3c30000000000000022fa06e594&q="); ---- Lines babylon removed from user.js ---- user_pref("yahoo.ytff.general.dontshowhpoffer", true);user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=0c28b3c30000000000000022fa06e594&q="); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); ---- Lines conduit removed from prefs.js ---- user_pref("extensions.asktb.abar-war-regex", "conduit\\.com"); ---- Lines asktb removed from prefs.js ---- user_pref("extensions.asktb.abar-war-timeout", "4000"); user_pref("extensions.asktb.autofill-competitor-query-enabled", true); user_pref("extensions.asktb.autofill-text-highlight-enabled", true); user_pref("extensions.asktb.cbid", "UG"); user_pref("extensions.asktb.config-updated", true); user_pref("extensions.asktb.displaybehavior", ""); user_pref("extensions.asktb.displaytext", ""); user_pref("extensions.asktb.dtid", "YYYYYYYYBE"); user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "BEXX0005"); user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); user_pref("extensions.asktb.first-launch-url", "http://www.drivernavigator.com/buy.php?pmtid=3&affid=us2008&srcid="); user_pref("extensions.asktb.fresh-install", false); user_pref("extensions.asktb.guid", "07B53C07-38FC-485B-9DC3-6F2A6B648D6B"); user_pref("extensions.asktb.if", "su"); user_pref("extensions.asktb.l", "dis"); user_pref("extensions.asktb.last-config-req", "1349115838565"); user_pref("extensions.asktb.locale", "nl_EU"); user_pref("extensions.asktb.location", "Brussels,Belgium"); user_pref("extensions.asktb.lstation", ""); user_pref("extensions.asktb.news-native-on", true); user_pref("extensions.asktb.o", "15158"); user_pref("extensions.asktb.overlay-reloaded-using-restart", true); user_pref("extensions.asktb.pstate", ""); user_pref("extensions.asktb.qsrc", "2871"); user_pref("extensions.asktb.r", "8"); user_pref("extensions.asktb.sa", "NO"); user_pref("extensions.asktb.search-history-queries", "dikke schijven||retro hous"); user_pref("extensions.asktb.search-suggestions-enabled", true); user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true); user_pref("extensions.asktb.silent-upgrade", true); user_pref("extensions.asktb.socialmini-first", true); user_pref("extensions.asktb.socialmini-interval", "1200000"); user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); user_pref("extensions.asktb.socialmini-max-items", "30"); user_pref("extensions.asktb.socialmini-native-on", true); user_pref("extensions.asktb.socialmini-speed", "5000"); user_pref("extensions.asktb.socialmini-transition-first-open", false); user_pref("extensions.asktb.themeid", ""); user_pref("extensions.asktb.v", "3.14.1.100013"); user_pref("extensions.asktb.volume", ""); ---- Lines 99079a25-328f-4bd4-be04-00955acaa0a7 modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@disabled:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler ---- Lines Search-Results removed from prefs.js ---- user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline url(\"IMAGE\") right no ---- FireFox user.js and prefs.js backups ---- user_20142402_1513_.backup prefs_20142402_1513_.backup ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- "ApnUpdater"=- ==== Deleting Files \ Folders ====================== C:\Program Files\AVG not found C:\Program Files\Ask.com deleted C:\Program Files\MediaMonkey deleted C:\Program Files\Mozilla Firefox deleted C:\Users\Robby\AppData\Local\MediaMonkey deleted C:\Program Files\Conduit deleted C:\Program Files\Convesoft deleted C:\Program Files\Yahoo! deleted C:\Users\Robby\AppData\Roaming\Smiley.ico deleted C:\Users\Robby\AppData\Roaming\Babylon deleted C:\Users\Robby\AppData\Roaming\GetRightToGo deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\@themediafinder.com deleted C:\Users\Robby\AppData\Roaming\Media Finder deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~2\StarApp deleted C:\PROGRA~2\boost_interprocess deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Premium deleted C:\Users\Robby\AppData\Local\CRE deleted C:\Users\Robby\AppData\Local\WhiteListing deleted C:\Users\Robby\AppData\Local\jZip deleted C:\Users\Robby\AppData\Local\NativeMessaging deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder deleted C:\Users\Robby\Downloads\DownloadManagerSetup.exe deleted C:\Users\Robby\AppData\LocalLow\Yahoo! deleted C:\Users\Robby\AppData\LocalLow\searchqutoolbar deleted C:\Users\Robby\AppData\LocalLow\jZip deleted C:\Users\Robby\AppData\LocalLow\AskToolbar deleted C:\Users\Robby\AppData\LocalLow\DataMngr deleted C:\Users\Robby\AppData\LocalLow\Conduit deleted C:\Windows\SYSTEM32\TASKS\Scheduled Update for Ask Toolbar deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Search_Results.xml deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchqutoolbar deleted C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\ffxtlbr@funmoods.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\toolbar@ask.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted "C:\Users\Robby\AppData\Roaming\File Templates" deleted "C:\Users\Robby\AppData\Roaming\Filesystems" deleted "C:\Users\Robby\AppData\Roaming\Filter" deleted "C:\ProgramData\Flags" deleted "C:\ProgramData\Flange Saw" deleted "C:\ProgramData\Flanger" deleted "C:\ProgramData\Galaxy Swirl" deleted "C:\ProgramData\Generic" deleted "C:\ProgramData\Grapher" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Funmoods.xml" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted "C:\Program Files\jZip\jZipShell.dll" deleted "C:\Program Files\jZip" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Robby\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\Robby\AppData\Roaming ====== ====== C:\Users\Robby ====== 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe ====== C: exe-files == 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Install\{5ED071C8-60B3-4CAB-A7D9-1B88AA2A83C8}\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-20 15:19:14 0FB86683779E34A7A9739E11E5CB62A1 1043232 ----a-w- C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn\10.26.7.519_0\nativeMessaging\TBMessagingHost.exe 2014-02-20 14:59:07 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe 2014-02-20 14:59:07 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateBroker.exe 2014-02-20 14:59:06 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateSetup.exe 2014-02-20 14:57:55 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler64.exe 2014-02-20 14:57:54 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe 2014-02-20 14:57:41 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdate.exe 2014-02-20 14:56:56 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ArcadeDeluxeAgent"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" "CLMLServer"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" "NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" "NvMediaCenter"="RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup" "AmIcoSinglun"="C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" "Skytel"="C:\Program Files\Realtek\Audio\HDA\Skytel.exe" "PLFSetI"="C:\Windows\PLFSetI.exe" "VitaKeyPdtWzd"="c:\Program Files\Acer Bio Protection\PdtWzd.exe" "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "LManager"="C:\Program Files\Launch Manager\LManager.exe" "BackupManagerTray"="C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe -k" "Acer ePower Management"="C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe" "EgisTecLiveUpdate"="C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" "mwlDaemon"="C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" "PlayMovie"="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe /hide" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "beid"="C:\Program Files\Belgium Identity Card\beid35gui.exe /startup" "avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent" "Malwarebytes Anti-Malware (cleanup)"="rundll32.exe C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll,ProcessCleanupScript" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Malwarebytes' Anti-Malware (reboot)] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Malwarebytes' Anti-Malware (reboot)" "hkey"="HKLM" "command"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Nikon Message Center 2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Nikon Message Center 2" "hkey"="HKLM" "command"="C:\\Program Files\\Nikon\\Nikon Message Center 2\\NkMC2.exe -s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMServer" "hkey"="HKLM" "command"="C:\\Program Files\\Common Files\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMusic FastStart] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMusic FastStart" "hkey"="HKLM" "command"="\"C:\\Program Files\\Nokia\\Ovi Player\\NokiaOviPlayer.exe\" /command:faststart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaOviSuite2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaOviSuite2" "hkey"="HKCU" "command"="C:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PC Suite Tray" "hkey"="HKCU" "command"="\"C:\\Users\\Robby\\Desktop\\Snelkoppelingen Bureaublad\\Nokia PC Suite 7\\PCSuite.exe\" -onlytray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Steam" "hkey"="HKCU" "command"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" "hkey"="HKLM" "command"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" ==== Startup Folders ====================== 2011-08-08 19:28:39 1105 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk 2009-09-10 16:24:31 0 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [22/02/2014 14:06] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\{DB3D65B2-7447-49F3-829D-B1242A857BBB}" ["c:\program files\google\chrome\application\chrome.exe"] "C:\Windows\system32\tasks\Acer\Burn Notification" [C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/12/2013 14:12] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default - avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF - Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension - Undetermined - C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - TVU Web Player - %ProfilePath%\extensions\firefox@tvunetworks.com - Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b} - Yahoo Toolbar - %ProfilePath%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - DealPly - %ProfilePath%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} ==== Firefox Plugins ====================== Profilepath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default 87B41E7975298577BC56B6E82F0E6B34 - C:\Program Files\Java\jre7\bin\npjpi170_25.dll - Java Platform SE 7 U25 73FB13F5D73EDC1DB8C66079903B19F6 - C:\Program Files\Java\jre7\bin\npoji610.dll - Java Platform SE 7 U25 6967C3D9BE67F6A5DEFADEDEE02FCB92 - c:\Program Files\Sony\Media Go\npmediago.dll - Media Go Detector AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery 24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java Platform SE 7 U25 D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.250.17 0B759CF1C312102F1F7FFC0F7BE67D0A - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll - InoViewer Plugin 5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin A82533DA1C7AFCE542B8E0D2714B8A4A - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector 07154B27860B999CC70EB6F7A1528794 - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 1BFD18699636B8F1AA26675BA43D2F8F - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll - Shockwave for Director / Shockwave for Director 6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director 58F41CA8F9C2014709F9547B2B81A468 - C:\Windows\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll - TVU Web Player for FireFox 5FBCD34D89D58D695D966A70C9829EE6 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.6.8 E764E340AD2CD744802B5CD51D234E28 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.6.8 5E689EEF06202E299F96E82DA9174255 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.6.8 C37A257E3C3D26AA3E75DDF72D861771 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.6.8 6D2329DFDA605E25D5FC3A3D6A0129B8 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.6.8 D4619DDAC3134E7D2737EE7B36143316 - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.6.8 1573E1AC2FDE21D2A936F00EDB919FAD - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.6.8 ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Windows\system32\TVUAx\npTVUAx.dll - TVU Web Player for FireFox ==== Deleted Firefox Extensions ====================== C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dednnpigldgdbpgcdpfppmlcnnbjciel - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx[] gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] lpmkgpnbiojfaoklbkpfneikocaobfai - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel AT_Porsche - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg Webcam Toy - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade BittorrentBar_NL - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm Red Bull TV - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbalkogcfbpplioohgihkidalmomblfc 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp Docs - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel DealPly - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje avast WebRep - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda ==== Chrome Fix ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0 deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" "Default_Page_URL"="http://homepage.acer.com/rdr.aspx?b=ACAW&l=0813&s=2&o=vp32&d=0509&m=aspire_7738" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search/?q=%s" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&r=" {23735B41-2CBD-5328-C66C-5FF7986F9BDE} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_nlBE328" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {70D46D94-BF1E-45ED-B567-48701376298E} Google Desktop Url="http://127.0.0.1:4664/search&s=dd3_8oGdgvRA8WnXL-FL5pT3vms?q={searchTerms}" {B1D44357-3BA0-4D84-9656-DCCE129AB563} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACAW_nlBE328" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{44DDF452-62BA-F2EF-2B10-76C079E8936D} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B1D56A0-B9C4-A31A-5B4E-7E5E8A805515} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2 deleted successfully ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Robby\AppData\Local\Mozilla\Firefox\Profiles\27w4mn03.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2738 folders=544 295042543 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Robby\AppData\Local\Temp will be emptied at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Robby\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Program Files\jZip" not found ==== EOF on ma 24/02/2014 at 15:28:36,98 ====================== - - - Updated - - - Zo Zoek.exe v5.0.0.0 Updated 19-February-2014 Tool run by Robby on ma 24/02/2014 at 15:00:20,37. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Robby\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\Program Files\MSXML 4.0 deleted successfully C:\PROGRA~2\Babylon deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\PROGRA~2\OviInstallerCache deleted successfully C:\Users\Robby\AppData\Roaming\.# deleted successfully C:\Users\Robby\AppData\Roaming\Sony Setup deleted successfully C:\Users\Robby\AppData\Roaming\WinRAR deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_CLASSES_ROOT\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_CLASSES_ROOT\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} deleted successfully HKEY_CLASSES_ROOT\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\!{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\bkmrksync@nokia.com deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default ---- Lines funmoods removed from prefs.js ---- user_pref("browser.search.defaultenginename", "Funmoods"); user_pref("browser.startup.homepage", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0C user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.cntry", "BE"); user_pref("extensions.funmoods.cv", "cv5"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.hdrMd5", "3F1EBB0B0FDAE24CB97397C8A1FA4077"); user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tz user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); user_pref("extensions.funmoods.newTab", true); user_pref("extensions.funmoods.newTabUrl", "http://searchfunmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0 user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.sg", "none"); user_pref("extensions.funmoods.smplGrp", "none"); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.tlbrSrchUrl", "http://searchfunmoods.com/?f=3&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0 user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); ---- Lines funmoods modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines funmoods removed from user.js ---- user_pref("extensions.funmoods.hmpg", true); user_pref("extensions.funmoods.hmpgUrl", "http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463"); user_pref("extensions.funmoods.dfltSrch", true); user_pref("extensions.funmoods.srchPrvdr", "Search"); user_pref("extensions.funmoods.dnsErr", true); user_pref("extensions.funmoods_i.newTab", true); user_pref("extensions.funmoods.newTabUrl", "http://searchfunmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463"); user_pref("extensions.funmoods.tlbrSrchUrl", "http://searchfunmoods.com/?f=3&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzutDtDtBtB0F0AtDyC0EyDzyyE0BtA0CtAtN0D0Tzu0CtByByDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=780983463&q="); user_pref("extensions.funmoods.id", "0022FA06E594B3C3"); user_pref("extensions.funmoods.instlDay", "15614"); user_pref("extensions.funmoods.vrsn", "1.5.23.22"); user_pref("extensions.funmoods.vrsni", "1.5.23.22"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2220:16:38"); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.aflt", "iron2"); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.instlRef", "iron2"); user_pref("extensions.funmoods.dfltLng", ""); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.autoRvrt", false); user_pref("extensions.funmoods.envrmnt", "production"); user_pref("extensions.funmoods.isdcmntcmplt", true); user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); ---- Lines ask.com removed from prefs.js ---- user_pref("extensions.asktb.default-channel-url-mask", "http://eu.ask.com/web?qsrc={qsrc}&o={o}&l={l}&q={query}&dm=all"); user_pref("extensions.asktb.http-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \ user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WR user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); ---- Lines ask.com modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@ask.com:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler@ ---- Lines babylon removed from prefs.js ---- user_pref("browser.search.order.1", "Search the web (Babylon)"); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=0c28b3c30000000000000022fa06e594&q="); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("keyword.URL", "http://search.babylon.com/?affID=110823&tt=300912_TORP_4012_8&babsrc=KW_ss&mntrId=0c28b3c30000000000000022fa06e594&q="); ---- Lines babylon removed from user.js ---- user_pref("yahoo.ytff.general.dontshowhpoffer", true);user_pref("extensions.BabylonToolbar.autoRvrt", "false"); user_pref("extensions.BabylonToolbar_i.newTab", false); user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=0c28b3c30000000000000022fa06e594&q="); user_pref("extensions.BabylonToolbar.id", "0c28b3c30000000000000022fa06e594"); user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); user_pref("extensions.BabylonToolbar.instlDay", "15614"); user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7"); user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.720:12:27"); user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar.aflt", "babsst"); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); user_pref("extensions.BabylonToolbar.instlRef", "sst"); user_pref("extensions.BabylonToolbar.dfltLng", "en"); user_pref("extensions.BabylonToolbar.excTlbr", false); user_pref("extensions.BabylonToolbar.admin", false); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110823&tt=300912_TORP_4012_8"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); ---- Lines conduit removed from prefs.js ---- user_pref("extensions.asktb.abar-war-regex", "conduit\\.com"); ---- Lines asktb removed from prefs.js ---- user_pref("extensions.asktb.abar-war-timeout", "4000"); user_pref("extensions.asktb.autofill-competitor-query-enabled", true); user_pref("extensions.asktb.autofill-text-highlight-enabled", true); user_pref("extensions.asktb.cbid", "UG"); user_pref("extensions.asktb.config-updated", true); user_pref("extensions.asktb.displaybehavior", ""); user_pref("extensions.asktb.displaytext", ""); user_pref("extensions.asktb.dtid", "YYYYYYYYBE"); user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "BEXX0005"); user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); user_pref("extensions.asktb.first-launch-url", "http://www.drivernavigator.com/buy.php?pmtid=3&affid=us2008&srcid="); user_pref("extensions.asktb.fresh-install", false); user_pref("extensions.asktb.guid", "07B53C07-38FC-485B-9DC3-6F2A6B648D6B"); user_pref("extensions.asktb.if", "su"); user_pref("extensions.asktb.l", "dis"); user_pref("extensions.asktb.last-config-req", "1349115838565"); user_pref("extensions.asktb.locale", "nl_EU"); user_pref("extensions.asktb.location", "Brussels,Belgium"); user_pref("extensions.asktb.lstation", ""); user_pref("extensions.asktb.news-native-on", true); user_pref("extensions.asktb.o", "15158"); user_pref("extensions.asktb.overlay-reloaded-using-restart", true); user_pref("extensions.asktb.pstate", ""); user_pref("extensions.asktb.qsrc", "2871"); user_pref("extensions.asktb.r", "8"); user_pref("extensions.asktb.sa", "NO"); user_pref("extensions.asktb.search-history-queries", "dikke schijven||retro hous"); user_pref("extensions.asktb.search-suggestions-enabled", true); user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true); user_pref("extensions.asktb.silent-upgrade", true); user_pref("extensions.asktb.socialmini-first", true); user_pref("extensions.asktb.socialmini-interval", "1200000"); user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); user_pref("extensions.asktb.socialmini-max-items", "30"); user_pref("extensions.asktb.socialmini-native-on", true); user_pref("extensions.asktb.socialmini-speed", "5000"); user_pref("extensions.asktb.socialmini-transition-first-open", false); user_pref("extensions.asktb.themeid", ""); user_pref("extensions.asktb.v", "3.14.1.100013"); user_pref("extensions.asktb.volume", ""); ---- Lines 99079a25-328f-4bd4-be04-00955acaa0a7 modified from prefs.js ---- user_pref("extensions.enabledItems", "toolbar@disabled:3.14.1.100013,wrc@avast.com:8.0.1489,{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48,gencrawler ---- Lines Search-Results removed from prefs.js ---- user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline url(\"IMAGE\") right no ---- FireFox user.js and prefs.js backups ---- user_20142402_1513_.backup prefs_20142402_1513_.backup ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- "ApnUpdater"=- ==== Deleting Files \ Folders ====================== C:\Program Files\AVG not found C:\Program Files\Ask.com deleted C:\Program Files\MediaMonkey deleted C:\Program Files\Mozilla Firefox deleted C:\Users\Robby\AppData\Local\MediaMonkey deleted C:\Program Files\Conduit deleted C:\Program Files\Convesoft deleted C:\Program Files\Yahoo! deleted C:\Users\Robby\AppData\Roaming\Smiley.ico deleted C:\Users\Robby\AppData\Roaming\Babylon deleted C:\Users\Robby\AppData\Roaming\GetRightToGo deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\@themediafinder.com deleted C:\Users\Robby\AppData\Roaming\Media Finder deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~2\StarApp deleted C:\PROGRA~2\boost_interprocess deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Premium deleted C:\Users\Robby\AppData\Local\CRE deleted C:\Users\Robby\AppData\Local\WhiteListing deleted C:\Users\Robby\AppData\Local\jZip deleted C:\Users\Robby\AppData\Local\NativeMessaging deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder deleted C:\Users\Robby\Downloads\DownloadManagerSetup.exe deleted C:\Users\Robby\AppData\LocalLow\Yahoo! deleted C:\Users\Robby\AppData\LocalLow\searchqutoolbar deleted C:\Users\Robby\AppData\LocalLow\jZip deleted C:\Users\Robby\AppData\LocalLow\AskToolbar deleted C:\Users\Robby\AppData\LocalLow\DataMngr deleted C:\Users\Robby\AppData\LocalLow\Conduit deleted C:\Windows\SYSTEM32\TASKS\Scheduled Update for Ask Toolbar deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Search_Results.xml deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchqutoolbar deleted C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\ffxtlbr@funmoods.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\toolbar@ask.com deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted "C:\Users\Robby\AppData\Roaming\File Templates" deleted "C:\Users\Robby\AppData\Roaming\Filesystems" deleted "C:\Users\Robby\AppData\Roaming\Filter" deleted "C:\ProgramData\Flags" deleted "C:\ProgramData\Flange Saw" deleted "C:\ProgramData\Flanger" deleted "C:\ProgramData\Galaxy Swirl" deleted "C:\ProgramData\Generic" deleted "C:\ProgramData\Grapher" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\Funmoods.xml" deleted "C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted "C:\Program Files\jZip\jZipShell.dll" deleted "C:\Program Files\jZip" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Robby\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\Robby\AppData\Roaming ====== ====== C:\Users\Robby ====== 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe ====== C: exe-files == 2014-02-24 13:15:15 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Robby\Downloads\RSIT.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Install\{5ED071C8-60B3-4CAB-A7D9-1B88AA2A83C8}\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-22 18:05:51 A4F0C36642681927FA53CD6A90CA2975 7620312 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.117\33.0.1750.117_32.0.1700.107_chrome_updater.exe 2014-02-20 15:19:14 0FB86683779E34A7A9739E11E5CB62A1 1043232 ----a-w- C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn\10.26.7.519_0\nativeMessaging\TBMessagingHost.exe 2014-02-20 14:59:07 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe 2014-02-20 14:59:07 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateBroker.exe 2014-02-20 14:59:06 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateSetup.exe 2014-02-20 14:57:55 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler64.exe 2014-02-20 14:57:54 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe 2014-02-20 14:57:41 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdate.exe 2014-02-20 14:56:56 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-4138485238-1851768418-1376420245-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ArcadeDeluxeAgent"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" "CLMLServer"="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" "NvCplDaemon"="RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" "NvMediaCenter"="RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup" "AmIcoSinglun"="C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" "Skytel"="C:\Program Files\Realtek\Audio\HDA\Skytel.exe" "PLFSetI"="C:\Windows\PLFSetI.exe" "VitaKeyPdtWzd"="c:\Program Files\Acer Bio Protection\PdtWzd.exe" "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "LManager"="C:\Program Files\Launch Manager\LManager.exe" "BackupManagerTray"="C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe -k" "Acer ePower Management"="C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe" "EgisTecLiveUpdate"="C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" "mwlDaemon"="C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" "PlayMovie"="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe /hide" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "beid"="C:\Program Files\Belgium Identity Card\beid35gui.exe /startup" "avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent" "Malwarebytes Anti-Malware (cleanup)"="rundll32.exe C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll,ProcessCleanupScript" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"="C:\Program Files\Acer\WR_PopUp\ProductReg.exe" "Media Finder"="C:\Program Files\Media Finder\Media Finder.exe /opentotray" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Malwarebytes' Anti-Malware (reboot)] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Malwarebytes' Anti-Malware (reboot)" "hkey"="HKLM" "command"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Nikon Message Center 2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Nikon Message Center 2" "hkey"="HKLM" "command"="C:\\Program Files\\Nikon\\Nikon Message Center 2\\NkMC2.exe -s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMServer" "hkey"="HKLM" "command"="C:\\Program Files\\Common Files\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMusic FastStart] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMusic FastStart" "hkey"="HKLM" "command"="\"C:\\Program Files\\Nokia\\Ovi Player\\NokiaOviPlayer.exe\" /command:faststart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaOviSuite2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaOviSuite2" "hkey"="HKCU" "command"="C:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PC Suite Tray" "hkey"="HKCU" "command"="\"C:\\Users\\Robby\\Desktop\\Snelkoppelingen Bureaublad\\Nokia PC Suite 7\\PCSuite.exe\" -onlytray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Steam" "hkey"="HKCU" "command"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" "hkey"="HKLM" "command"="C:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" ==== Startup Folders ====================== 2011-08-08 19:28:39 1105 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk 2009-09-10 16:24:31 0 ----a-w- C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [22/02/2014 14:06] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [22/12/2009 17:25] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\{DB3D65B2-7447-49F3-829D-B1242A857BBB}" ["c:\program files\google\chrome\application\chrome.exe"] "C:\Windows\system32\tasks\Acer\Burn Notification" [C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/12/2013 14:12] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default - avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF - Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension - Undetermined - C:\Users\Robby\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Undetermined - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - TVU Web Player - %ProfilePath%\extensions\firefox@tvunetworks.com - Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b} - Yahoo Toolbar - %ProfilePath%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - DealPly - %ProfilePath%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} ==== Firefox Plugins ====================== Profilepath: C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default 87B41E7975298577BC56B6E82F0E6B34 - C:\Program Files\Java\jre7\bin\npjpi170_25.dll - Java Platform SE 7 U25 73FB13F5D73EDC1DB8C66079903B19F6 - C:\Program Files\Java\jre7\bin\npoji610.dll - Java Platform SE 7 U25 6967C3D9BE67F6A5DEFADEDEE02FCB92 - c:\Program Files\Sony\Media Go\npmediago.dll - Media Go Detector AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery 24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java Platform SE 7 U25 D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.250.17 0B759CF1C312102F1F7FFC0F7BE67D0A - C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll - InoViewer Plugin 5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin A82533DA1C7AFCE542B8E0D2714B8A4A - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector 07154B27860B999CC70EB6F7A1528794 - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 1BFD18699636B8F1AA26675BA43D2F8F - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll - Shockwave for Director / Shockwave for Director 6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director 58F41CA8F9C2014709F9547B2B81A468 - C:\Windows\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll - TVU Web Player for FireFox 5FBCD34D89D58D695D966A70C9829EE6 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.6.8 E764E340AD2CD744802B5CD51D234E28 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.6.8 5E689EEF06202E299F96E82DA9174255 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.6.8 C37A257E3C3D26AA3E75DDF72D861771 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.6.8 6D2329DFDA605E25D5FC3A3D6A0129B8 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.6.8 D4619DDAC3134E7D2737EE7B36143316 - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.6.8 1573E1AC2FDE21D2A936F00EDB919FAD - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.6.8 ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat ECD88CDFC178E6A84DB1346EABF9F03F - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Windows\system32\TVUAx\npTVUAx.dll - TVU Web Player for FireFox ==== Deleted Firefox Extensions ====================== C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} deleted C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dednnpigldgdbpgcdpfppmlcnnbjciel - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx[] gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] lpmkgpnbiojfaoklbkpfneikocaobfai - C:\Users\Robby\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files\DealPly\DealPly.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Robby\AppData\Local\CRE\ndgonipadfipmlmdfofnjnhhlgojnjdn.crx[] General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel AT_Porsche - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg Webcam Toy - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade BittorrentBar_NL - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm Red Bull TV - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbalkogcfbpplioohgihkidalmomblfc 20-20 3D Viewer for IKEA - Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp Docs - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake General Crawler - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel DealPly - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje avast WebRep - Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda ==== Chrome Fix ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bittorrentbarnl.ourtoolbar.com_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0.localstorage-journal deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ndgonipadfipmlmdfofnjnhhlgojnjdn_0 deleted successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" "Default_Page_URL"="http://homepage.acer.com/rdr.aspx?b=ACAW&l=0813&s=2&o=vp32&d=0509&m=aspire_7738" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search/?q=%s" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&r=" {23735B41-2CBD-5328-C66C-5FF7986F9BDE} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_nlBE328" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {70D46D94-BF1E-45ED-B567-48701376298E} Google Desktop Url="http://127.0.0.1:4664/search&s=dd3_8oGdgvRA8WnXL-FL5pT3vms?q={searchTerms}" {B1D44357-3BA0-4D84-9656-DCCE129AB563} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACAW_nlBE328" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{44DDF452-62BA-F2EF-2B10-76C079E8936D} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B1D56A0-B9C4-A31A-5B4E-7E5E8A805515} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2 deleted successfully ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Robby\AppData\Local\Mozilla\Firefox\Profiles\27w4mn03.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2738 folders=544 295042543 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Robby\AppData\Local\Temp will be emptied at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Robby\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Robby\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Program Files\jZip" not found ==== EOF on ma 24/02/2014 at 15:28:36,98 ======================
  13. Zoek.exe v5.0.0.0 Updated 19-February-2014 Tool run by Robby on ma 24/02/2014 at 15:00:20,37. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Robby\Downloads\zoek.exe [scan all users] [script inserted] ===== Runcheck 15:03:11,22 ===== --- Create Environment Variables 15:03:12,15 --- Create System Restore Point 15:03:18,66 --- Checking Input 15:03:19,45 --- AU AppData Check 15:03:24,41 --- Remove From Windows Installer 15:03:29,66 --- Empty Folders Check 15:04:14,48 - - - Updated - - - Deze is beter denk ik Zoek.exe v5.0.0.0 Updated 19-February-2014 Tool run by Robby on ma 24/02/2014 at 15:00:20,37. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Robby\Downloads\zoek.exe [scan all users] [script inserted] ===== Runcheck 15:03:11,22 ===== --- Create Environment Variables 15:03:12,15 --- Create System Restore Point 15:03:18,66 --- Checking Input 15:03:19,45 --- AU AppData Check 15:03:24,41 --- Remove From Windows Installer 15:03:29,66 --- Empty Folders Check 15:04:14,48 --- IE Startpage Check 15:06:20,41 --- Program Files DB Check 15:06:41,05 --- C:\Users\Default\AppData\Roaming DB Check 15:07:20,05 --- C:\Users\Default User\AppData\Roaming DB Check 15:07:20,05 --- C:\Users\Robby\AppData\Roaming DB Check 15:07:20,05 --- C:\Windows\system32\config\systemprofile\AppData\Roaming DB Check 15:07:20,05
  14. Zo dan? Logfile of random's system information tool 1.09 (written by random/random) Run by Robby at 2014-02-24 14:16:45 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 115 GB (39%) free of 292 GB Total RAM: 3066 MB (77% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:17:01, on 24/02/2014 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16526) Boot mode: Safe mode with network support Running processes: C:\Windows\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Robby\Downloads\RSIT.exe C:\Program Files\trend micro\Robby.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = iGoogle Redirect R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = This message is from the Microsoft Safety & Security Center R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O3 - Toolbar: (no name) - !{98889811-442D-49dd-99D7-DC866BE87DBC} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe O4 - HKLM\..\Run: [VitaKeyPdtWzd] c:\Program Files\Acer Bio Protection\PdtWzd.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe O4 - HKLM\..\Run: [backupManagerTray] "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe" O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript O4 - HKCU\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe" O4 - HKCU\..\Run: [Media Finder] "C:\Program Files\Media Finder\Media Finder.exe" /opentotray O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12] "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE O4 - Startup: Orion.lnk = ? O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000 O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\Program Files\Acer Bio Protection\PwdBank.exe O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\Program Files\Acer Bio Protection\PwdBank.exe O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing) O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - c:\Program Files\Acer Bio Protection\BASVC.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Robby\AppData\Local\TVersity\Media Server\MediaServer.exe -- End of file - 13834 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job =========Mozilla firefox========= ProfilePath - C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default prefs.js - "browser.startup.homepage" - "Funmoods Search" prefs.js - "extensions.enabledItems" - "toolbar@ask.com:3.14.1.100013, wrc@avast.com:8.0.1489, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.48, gencrawler@some.com:2.6, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33, {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {99079a25-328f-4bd4-be04-00955acaa0a7}:4.6.1.01, firefox@tvunetworks.com:2, 5, 3, 1, {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.4.7.20120315050400, ffxtlbr@funmoods.com:1.5.1, {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0, {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.17" prefs.js - "keyword.URL" - "Babylon Search=" "{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ "{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ "bkmrksync@nokia.com"=C:\Users\Robby\Desktop\Nokia PC Suite 7\bkmrksync\ "wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 10 "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=] "Description"=iTunes Detector Plug-in "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0] "Description"= "Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin] "Description"=Google Earth in your browser "Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@innoplus.de/ino3DViewer] "Description"=INNOVA ino3DViewer Plugin "Path"=C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5] "Description"=Office Live Update v1.5 "Path"=C:\Program Files\Microsoft\Office Live\npOLW.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5] "Description"=Windows Presentation Foundation plug-in for Mozilla browsers "Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pages.tvunetworks.com/WebPlayer] "Description"=TVU Web Player Plugin "Path"=C:\Windows\system32\TVUAx\npTVUAx.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0] "Description"= "Path"=c:\Program Files\Sony\Media Go\npmediago.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} C:\Program Files\Mozilla Firefox\components\ aboutCertError.js aboutPrivateBrowsing.js aboutRights.js aboutRobots.js aboutSessionRestore.js browser.xpt browserdirprovider.dll brwsrcmp.dll FeedConverter.js FeedProcessor.js FeedWriter.js fuelApplication.js GoogleDesktopMozilla.dll GoogleDesktopMozillaStub.js GoogleDesktopMozillaStub.xpt jsconsole-clhandler.js NetworkGeolocationProvider.js nsAddonRepository.js nsBadCertHandler.js nsBlocklistService.js nsBrowserContentHandler.js nsBrowserGlue.js nsContentDispatchChooser.js nsContentPrefService.js nsDefaultCLH.js nsDownloadManagerUI.js nsExtensionManager.js nsHandlerService.js nsHelperAppDlg.js nsIQTScriptablePlugin.xpt nsLivemarkService.js nsLoginInfo.js nsLoginManager.js nsLoginManagerPrompter.js nsMicrosummaryService.js nsPlacesDBFlush.js nsPlacesTransactionsService.js nsPostUpdateWin.js nsPrivateBrowsingService.js nsProxyAutoConfig.js nsSafebrowsingApplication.js nsSearchService.js nsSearchSuggestions.js nsSessionStartup.js nsSessionStore.js nsSetDefaultBrowser.js nsSidebar.js nsTaggingService.js nsTryToClose.js nsUpdateService.js nsUrlClassifierLib.js nsUrlClassifierListManager.js nsURLFormatter.js nsWebHandlerApp.js pluginGlue.js storage-Legacy.js storage-mozStorage.js txEXSLTRegExFunctions.js WebContentConverter.js C:\Program Files\Mozilla Firefox\plugins\ np-mswmp.dll npnul32.dll nppdf32.dll npqtplugin.dll npqtplugin2.dll npqtplugin3.dll npqtplugin4.dll npqtplugin5.dll npqtplugin6.dll npqtplugin7.dll QuickTimePlugin.class WMP Firefox Plugin License.rtf WMP Firefox Plugin RelNotes.txt C:\Program Files\Mozilla Firefox\searchplugins\ bolcom-nl.xml google.xml googledesktop.xml marktplaats-nl.xml Search_Results.xml vandale-nl.xml wikipedia-nl.xml yahoo-nl.xml C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\ ffxtlbr@funmoods.com firefox@tvunetworks.com toolbar@ask.com {20a82645-c095-46ed-80e3-08825760534b} {635abd67-4fe9-1b23-4f01-e679fa7484c1} {99079a25-328f-4bd4-be04-00955acaa0a7} {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\searchplugins\ Funmoods.xml Search_Results.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 77576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2012-08-16 4171424] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-08-16 463272] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-15 194128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-12-21 561552] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-08-16 171944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152] {8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288] {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688] !{2318C2B1-4965-11d4-9B18-009027A5CD4F} !{98889811-442D-49dd-99D7-DC866BE87DBC} {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-15 194128] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184] "ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-01-21 156968] "CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2009-01-21 202024] "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-02-10 13605408] "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-02-10 92704] "Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-09-14 30192] "AmIcoSinglun"=C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [2008-10-24 237568] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-03-11 6957600] "Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-03-11 1833504] "PLFSetI"=C:\Windows\PLFSetI.exe [2009-05-19 200704] "VitaKeyPdtWzd"=c:\Program Files\Acer Bio Protection\PdtWzd.exe [2009-02-13 3549696] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-12-05 1410344] "LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-02-24 870920] "BackupManagerTray"=C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-03-20 249600] "Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe [2009-03-11 715296] "EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2009-05-13 199464] "mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-09-11 349480] "PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-12-26 173288] "LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-02-08 488984] "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2007-02-08 774168] "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600] "beid"=C:\Program Files\Belgium Identity Card\beid35gui.exe [2010-02-05 2056192] "avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968] ""= [] "ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-01-03 1391272] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888] "ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-12-19 41208] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816] "BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2013-04-04 532040] "Malwarebytes Anti-Malware (cleanup)"=C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll [2013-04-04 1127496] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-11-17 135168] "Media Finder"=C:\Program Files\Media Finder\Media Finder.exe /opentotray [] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-19 68856] "GoogleChromeAutoLaunch_39E54563CBD9FF53F840E2F8C1B32B12"=C:\Program Files\Google\Chrome\Application\chrome.exe [2014-02-20 859464] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2013-04-04 887432] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [2010-05-25 619008] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart] C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2010-03-04 2192672] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray] C:\Users\Robby\Desktop\Snelkoppelingen Bureaublad\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Program Files\Steam\Steam.exe [2011-08-07 1242448] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] C:\PROGRA~1\WinZip\WZQKPICK.EXE [2010-04-05 494920] C:\Users\Robby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup OneNote 2010 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE Orion.lnk - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2012-08-16 4171424] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "notification packages"=c:\Program Files\Acer Bio Protection\PwdFilter [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro35Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "VIDC.I420"=lvcodec2.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "MSVideo8"=VfWWDM32.dll "msacm.siren"=sirenacm.dll "MSVideo"=vfwwdm32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "aux2"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux1"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "aux3"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== ======List of files/folders modified in the last 1 month====== 2014-02-24 14:16:48 ----D---- C:\Program Files\Trend Micro 2014-02-24 10:09:36 ----D---- C:\Windows\system32\drivers 2014-02-24 08:26:12 ----A---- C:\Windows\ntbtlog.txt 2014-02-24 08:09:58 ----D---- C:\Windows\Temp 2014-02-22 21:06:38 ----D---- C:\Windows\ServiceProfiles 2014-02-22 20:56:28 ----RD---- C:\Program Files 2014-02-22 15:44:19 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2014-02-22 14:54:28 ----SHD---- C:\Windows\Installer 2014-02-22 14:54:16 ----D---- C:\ProgramData\Microsoft Help 2014-02-22 14:53:52 ----D---- C:\Windows\System32 2014-02-22 14:52:08 ----D---- C:\Windows\system32\catroot 2014-02-22 14:52:03 ----D---- C:\Windows\winsxs 2014-02-22 14:51:21 ----D---- C:\Windows\system32\catroot2 2014-02-22 14:47:21 ----RSD---- C:\Windows\assembly 2014-02-22 14:15:27 ----SHD---- C:\System Volume Information 2014-02-22 14:05:57 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2014-02-15 17:06:25 ----D---- C:\Windows\system32\MRT 2014-02-15 16:55:56 ----A---- C:\Windows\system32\mrt.exe 2014-02-15 16:55:07 ----D---- C:\Windows\Prefetch 2014-02-10 10:14:53 ----SD---- C:\Users\Robby\AppData\Roaming\Microsoft ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AlfaFF;AlfaFF; C:\Windows\system32\drivers\AlfaFF.sys [2009-02-13 42608] R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248] R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2011-03-18 25240] R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824] R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2013-05-09 49760] R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600] R3 hidshim;Service for HID-KMDF Shim layer; C:\Windows\system32\DRIVERS\hidshim.sys [2008-10-08 5632] R3 k57nd60x;Broadcom NetLink Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-09-25 3666432] R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2009-02-04 14848] R3 nuvotonhidgeneric;Nuvoton EC Generic HID; C:\Windows\system32\DRIVERS\nuvotonhidgeneric.sys [2008-10-08 22528] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-12-05 204976] R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560] S0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-05-09 49376] S0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-05-09 174664] S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-05-09 765736] S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-05-09 368944] S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-05-09 56080] S1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 18992] S1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 16432] S1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60976] S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05-09 29816] S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336] S2 FPSensor;EgisTech-Corp Fingerprint Reader Driver (FPSensor.sys); C:\Windows\System32\Drivers\FPSensor.sys [2008-12-24 26928] S2 int15;int15; \??\c:\Windows\system32\drivers\int15.sys [2009-02-13 69632] S2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744] S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712] S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632] S3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-03-11 2338720] S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-02-06 1691808] S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-02-06 1964064] S3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2007-02-06 25632] S3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-02-03 41504] S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888] S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016] S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2010-07-30 18048] S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbo.sys [2010-07-30 23040] S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsu.sys [2010-07-26 137600] S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsuc.sys [2010-07-26 8576] S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720] S3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-01-22 52768] S3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-02-10 7545120] S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816] S3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-02-03 14240] S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-02-03 938272] S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-07-30 8192] S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448] S3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344] S3 USBCCID;USB Smart Card reader; C:\Windows\system32\DRIVERS\usbccid.sys [2010-06-14 29184] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328] S3 usbser;Nokia USB Serial Port Driver ; C:\Windows\system32\drivers\usbser.sys [2013-08-29 27648] S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-07-30 8192] S3 usbvideo;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] S3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896] S3 WSDScan;Ondersteuning voor WSD-scan via UMB; C:\Windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656] S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616] S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== S2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152] S2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312] S2 Apple Mobile Device;Mobiel Apple apparaat; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672] S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808] S2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888] S2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-18 75048] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-03-11 666144] S2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504] S2 gupdate;Google Updateservice (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-22 133104] S2 IGBASVC;EgisTec Service; c:\Program Files\Acer Bio Protection\BASVC.exe [2009-02-13 3440640] S2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504] S2 LVPrcSrv;Process Monitor; c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe [2007-02-06 109344] S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-02-06 105248] S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] S2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-09-11 305448] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632] S2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-02-10 203296] S2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2008-11-27 237568] S2 SeaPort;SeaPort; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648] S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-03-01 161384] S2 TVersityMediaServer;TVersityMediaServer; C:\Users\Robby\AppData\Local\TVersity\Media Server\MediaServer.exe [2010-07-25 884736] S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-22 257928] S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160] S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-09-14 30192] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-22 133104] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-11 194032] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632] S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672] S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736] S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-06-30 529232] S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856] S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] -----------------EOF-----------------
  15. Als ik deze twee methodes probeer krijg ik telkens deze melding "er zijn geen herstelpunten op de systeemschijf van uw computer gemaakt. Open systeembeveilging als u een herstelpunt wilt maken."
  16. Bedankt voor de reactie Jion, hieronder de gevraagde log. Malwarebytes Anti-Malware (-evaluatieversie-) 1.75.0.1300 www.malwarebytes.org Databaseversie: v2014.02.22.03 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Robby :: PCROBBY [administrator] Bescherming: Ingeschakeld 22/02/2014 15:52:29 mbam-log-2014-02-22 (15-52-29).txt Scan type: Volledige scan (C:\|) Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scan opties: P2P Objecten gescand: 463830 Verstreken tijd: 4 uur/uren, 3 minuut/minuten, 13 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 1 C:\Users\Robby\AppData\Local\TBHostSupport\TBHostSupport_0.dll (PUP.Optional.Conduit) -> Zal worden verwijderd tijdens het herstarten. Registersleutels gedetecteerd: 22 HKCR\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} (PUP.Optional.SearchQu) -> Geen actie ondernomen. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0} (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\TypeLib\{5B4144E1-B61D-495a-9A50-CD1A95D86D15} (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\BrowserConnection.Loader.1 (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\BrowserConnection.Loader (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0} (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0} (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0} (PUP.Optional.Bandoo.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} (PUP.Optional.Datamngr.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} (PUP.Optional.Datamngr.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\SearchQUIEHelper.DNSGuard (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKCR\SearchQUIEHelper.DNSGuard.1 (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\Software\Datamngr (PUP.Optional.DataMngr.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\Software\Conduit\ValueApps (PUP.Optional.ValueApps.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.Optional.FunMoods.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\DEALPLY (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.Optional.FunMoods.A) -> Succesvol in quarantaine geplaatst en verwijderd. Registerwaarden gedetecteerd: 6 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Data: Searchqu Toolbar -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{99079a25-328f-4bd4-be04-00955acaa0a7} (PUP.Optional.SearchQu) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|TBHostSupport (PUP.Optional.Conduit) -> Data: "C:\Windows\system32\Rundll32.exe" "C:\Users\Robby\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin -> Succesvol in quarantaine geplaatst en verwijderd. HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0C1O1P1K2W1FtGtBtH1QyB -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\DealPly|ChromeCrxPath (PUP.Optional.DealPly.A) -> Data: C:\Program Files\DealPly\DealPly.crx -> Succesvol in quarantaine geplaatst en verwijderd. HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|Tabs (PUP.Optional.FunMoods.A) -> Data: Funmoods Search -> Succesvol in quarantaine geplaatst en verwijderd. Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 3 C:\Program Files\DealPly (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly (PUP.OPtional.Dealply.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Local\TBHostSupport (PUP.Optional.Conduit) -> Zal worden verwijderd tijdens het herstarten. Bestanden gedetecteerd: 24 C:\Program Files\DealPly\DealPlyUpdate.exe (PUP.Optional.Dealply) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\DealPly\DealPlyUpdateRun.exe (PUP.Optional.Dealply) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\DealPly\uninst.exe (PUP.Optional.Dealply) -> Succesvol in quarantaine geplaatst en verwijderd. C:\ProgramData\InstallMate\{F44A240F-0E9A-4558-A7B3-46B82FA906F9}\Custom.dll (Adware.Agent) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Roaming\Mozilla\Firefox\Profiles\27w4mn03.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\DealPlyTune.dll (PUP.Optional.Dealply) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\Downloads\tour of duty season 1 till 3.exe (PUP.Optional.Installex) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\Downloads\SoftonicDownloader_voor_proficad.exe (PUP.Optional.Softonic.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\Downloads\setup (1).exe (PUP.Optional.Bundlore) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\Downloads\setup (2).exe (PUP.Optional.Bundlore) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\Downloads\setup (3).exe (PUP.Optional.Bundlore) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Windows\Temp\TMP0000006E1A3A46279A146047 (PUP.Optional.Dealply) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml (PUP.Optional.Babylon.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage (PUP.Optional.Pricegong) -> Zal worden verwijderd tijdens het herstarten. C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal (PUP.Optional.Pricegong) -> Zal worden verwijderd tijdens het herstarten. C:\Users\Robby\AppData\Local\funmoods-speeddial_sf.crx (PUP.Optional.FunMoods.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage (PUP.Optional.FunMoods.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\DealPly\DealPly.crx (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\DealPly\DealPlyUpdate.log (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Program Files\DealPly\icon.ico (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\Uninstall DealPly.lnk (PUP.OPtional.Dealply.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly Help.lnk (PUP.OPtional.Dealply.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly.lnk (PUP.OPtional.Dealply.A) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Local\TBHostSupport\TBHostSupport.dll (PUP.Optional.Conduit) -> Succesvol in quarantaine geplaatst en verwijderd. C:\Users\Robby\AppData\Local\TBHostSupport\TBHostSupport_0.dll (PUP.Optional.Conduit) -> Zal worden verwijderd tijdens het herstarten. (einde)
  17. Allemaal, Even het probleem uitleggen: Omdat mijn laptop traag begon te worden heb ik Malwarebytes Anti Malware gebruikt. Dat stond nog op mijn pc van vroeger, na een update van het programma heb ik een volledige scan gedaan. Uitslag: een deel infecties gevonden. Toen ben ik zo stom geweest om alle geïnfecteerde bestanden te verwijderen Gevolg: Laptop start op, ik geef mijn gebruikersnaam in en dan blijft hij hangen op "welkom" of soms gaat hij dan door maar krijg ik een zwart scherm. Ik zal vermoedelijk één of meerdere bestanden te veel gewist hebben. In veilige modus kan ik nog opstarten. Ik heb Windows vista home premium. Kan iemand me helpen? Alvast bedankt. Grt
  18. Ik denk niet dat ik daar iets mee ben, zo zien mijn luidsprekers er uit.
  19. Hallo, ik heb een vraag ivm de ipod nano en de radio hiervan. Ik heb een nano gekocht en ook een luidsprekersysteem (Altec Lansing iM500 v4). Nu zit ik met het volgende probleem, als de ipod in het luidsprekerstysteem zet dan kan ik geen radio luisteren omdat ik de oortjes er niet kan insteken (die dan dienen als antenne). Is er een hulpstukje dan ik kan kopen om mijn probleem op te lossen? mvg Ewing
  20. Ok dan weet ik wat me te doen staat, thx.
  21. Bedankt voor de info, het is wel spijtig want ze zit in mijn laptop en ze daar in upgraden zal misschien verloren geld zijn omdat de laptop toch aan vervanging toe is. Of kost zo'n kaart het geld toch niet?
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.