ComboFix 13-12-20.01 - Brian_Pc 21-12-2013 13:58:44.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3959.2376 [GMT 1:00] Gestart vanuit: c:\users\Brian_Pc\Desktop\ComboFix.exe AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Nieuw herstelpunt werd aangemaakt . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Brian_Pc\AppData\Roaming\inst.exe c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome.manifest c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\asyncDB.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\background.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\browserAction.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\contextMenu.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\dbManager.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\dom_bg.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\fileManager.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\firefox.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\firefoxNotifications.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\firefoxOmnibox.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\message.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\pageAction.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\request.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\tabs.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\api\webRequest.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\background.html c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\baseObject.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\browser.xul c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\console.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\consts.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\delegate.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\extensionDataStore.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\folderIOWrapper.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\httpObserver.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\IDBWrapper.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\installer.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\logFile.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\prefs.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\progressListenerObserver.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\registry.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\reloadObserver.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\reports.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\requestObject.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\searchSettings.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\uninstallObserver.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\updateManager.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\utils.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\core\xhr.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\dialog.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\main.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\options.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\options.xul c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\chrome\content\search_dialog.xul c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\defaults\preferences\prefs.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\manifest.xml c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins.json c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\1_base.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\13_CrossriderAppUtils.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\14_CrossriderUtils.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\16_FFAppAPIWrapper.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\17_jQuery.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\177_crossriderDashboard.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\182_openUrl.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\183_tabsWrapper.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\21_debug.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\22_resources.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\28_initializer.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\4_jquery_1_7_1.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\47_resources_background.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\64_appApiMessage.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\72_appApiValidation.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\78_CrossriderInfo.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\plugins\98_omniCommands.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\userCode\background.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\extensionData\userCode\extension.js c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\install.rdf c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\locale\en-US\translations.dtd c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\button1.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\button2.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\button3.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\button4.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\button5.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\crossrider_statusbar.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\icon128.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\icon16.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\icon24.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\icon48.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\panelarrow-up.png c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\popup.html c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\skin.css c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\3f85ebca-5ee0-4042-935e-20d7bb38c127@f20b526a-b828-41ab-9361-de1cad391506.com\skin\update.css . . (((((((((((((((((((( Bestanden Gemaakt van 2013-11-21 to 2013-12-21 )))))))))))))))))))))))))))))) . . 2013-12-21 00:54 . 2013-12-21 00:54 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-12-20 21:15 . 2013-12-20 21:15 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\aignes 2013-12-19 18:25 . 2013-12-19 18:25 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\GemistDownloader 2013-12-18 18:31 . 2013-12-18 18:31 -------- d-----w- c:\users\Brian_Pc\AppData\Local\Macroplant_LLC 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll 2013-12-18 18:31 . 2013-12-18 18:31 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll 2013-12-18 17:33 . 2013-12-18 19:36 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-18 17:32 . 2013-12-18 19:36 -------- d-----w- c:\program files (x86)\Common Files\Apple 2013-12-18 00:28 . 2013-12-18 00:28 -------- d-----w- c:\program files (x86)\TeamViewer 2013-12-17 21:23 . 2013-12-17 21:23 -------- d-----w- c:\users\Brian_Pc\AppData\Local\CutePDF Writer 2013-12-17 19:55 . 2013-12-17 19:55 -------- d-----w- c:\programdata\Synology 2013-12-17 14:03 . 2013-12-21 13:02 -------- d-----w- c:\users\Brian_Pc\AppData\Local\Temp 2013-12-17 13:51 . 2013-12-17 19:36 -------- d-----w- C:\zoek_backup 2013-12-17 01:42 . 2013-12-17 01:42 -------- d-----w- c:\program files (x86)\Hp 2013-12-15 15:36 . 2013-12-15 15:36 -------- d-----w- c:\windows\system32\wbem\Logs 2013-12-14 00:13 . 2013-12-19 16:59 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\vlc 2013-12-13 01:22 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BBAAC5EE-11FA-4E7D-BC47-02975294C40D}\mpengine.dll 2013-12-11 22:23 . 2013-12-11 22:23 -------- d-----w- c:\program files (x86)\Evernote 2013-12-10 20:30 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2013-12-10 20:30 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2013-12-10 20:30 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2013-12-10 20:30 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2013-12-10 20:30 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2013-12-10 20:25 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-12-08 22:15 . 2013-12-08 22:15 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\SeriousBit 2013-12-08 22:06 . 2013-12-08 22:06 -------- d-----w- c:\users\Brian_Pc\AppData\Local\Bump Technologies, Inc 2013-12-08 22:04 . 2007-04-04 17:55 403304 ----a-w- c:\windows\system32\xactengine2_7.dll 2013-12-08 21:33 . 2013-12-08 21:33 -------- d-----w- c:\users\Brian_Pc\FSL 2013-12-08 21:28 . 2013-12-08 22:21 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\SideSlide 2013-12-08 20:29 . 2013-12-08 20:29 -------- d-----w- c:\users\Brian_Pc\AppData\Roaming\Brynt Younce Software 2013-12-08 19:41 . 2013-12-08 20:03 -------- d-----w- c:\users\Brian_Pc\AppData\Local\Blue_Onion_Software 2013-12-08 19:36 . 2010-11-20 13:25 257024 ----a-w- c:\windows\system32\taskmgr.exe 2013-12-04 16:31 . 2013-12-04 16:33 -------- d-----w- C:\AdwCleaner 2013-12-04 00:41 . 2013-12-04 00:41 -------- d-----w- c:\windows\Migration 2013-12-02 22:34 . 2013-06-06 06:24 16376 ----a-w- c:\windows\system32\drivers\TVMonitor.sys 2013-12-02 21:56 . 2013-12-02 22:14 -------- d-----w- c:\users\Brian_Pc\AppData\Local\NPE 2013-11-25 17:25 . 2013-11-25 17:25 -------- d-----w- c:\programdata\Logs . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-17 14:15 . 2013-08-12 22:27 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-12-17 14:15 . 2013-08-12 22:26 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-12-10 20:28 . 2013-08-12 23:55 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-08 19:36 . 2013-08-13 00:37 2851840 ----a-w- c:\windows\system32\themeui.dll 2013-12-08 19:36 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll 2013-12-08 19:36 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll 2013-12-08 16:49 . 2013-08-15 00:43 82816 ----a-w- c:\users\Brian_Pc\AppData\Roaming\pcouffin.sys 2013-11-19 02:33 . 2013-08-12 22:22 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-11-13 12:34 . 2013-11-13 12:34 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-13 12:34 . 2013-11-13 12:34 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-13 12:34 . 2013-11-13 12:34 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-13 12:34 . 2013-11-13 12:34 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-13 12:34 . 2013-11-13 12:34 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-13 12:34 . 2013-11-13 12:34 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-13 12:34 . 2013-11-13 12:34 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-13 12:34 . 2013-11-13 12:34 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-13 12:34 . 2013-11-13 12:34 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-13 12:34 . 2013-11-13 12:34 774144 ----a-w- c:\windows\system32\jscript.dll 2013-11-13 12:34 . 2013-11-13 12:34 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-13 12:34 . 2013-11-13 12:34 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-13 12:34 . 2013-11-13 12:34 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-13 12:34 . 2013-11-13 12:34 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-13 12:34 . 2013-11-13 12:34 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-11-13 12:34 . 2013-11-13 12:34 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-13 12:34 . 2013-11-13 12:34 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-13 12:34 . 2013-11-13 12:34 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-13 12:34 . 2013-11-13 12:34 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-13 12:34 . 2013-11-13 12:34 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-13 12:34 . 2013-11-13 12:34 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-11-13 12:34 . 2013-11-13 12:34 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-13 12:34 . 2013-11-13 12:34 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-13 12:34 . 2013-11-13 12:34 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-13 12:34 . 2013-11-13 12:34 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-13 12:34 . 2013-11-13 12:34 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-11-13 12:34 . 2013-11-13 12:34 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-13 12:34 . 2013-11-13 12:34 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-13 12:34 . 2013-11-13 12:34 413696 ----a-w- c:\windows\system32\html.iec 2013-11-13 12:34 . 2013-11-13 12:34 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-13 12:34 . 2013-11-13 12:34 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-13 12:34 . 2013-11-13 12:34 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-13 12:34 . 2013-11-13 12:34 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-13 12:34 . 2013-11-13 12:34 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-13 12:34 . 2013-11-13 12:34 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-13 12:34 . 2013-11-13 12:34 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-13 12:34 . 2013-11-13 12:34 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-13 12:34 . 2013-11-13 12:34 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-13 12:34 . 2013-11-13 12:34 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-11-13 12:34 . 2013-11-13 12:34 235520 ----a-w- c:\windows\system32\url.dll 2013-11-13 12:34 . 2013-11-13 12:34 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-13 12:34 . 2013-11-13 12:34 195584 ----a-w- c:\windows\system32\msrating.dll 2013-11-13 12:34 . 2013-11-13 12:34 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-13 12:34 . 2013-11-13 12:34 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-13 12:34 . 2013-11-13 12:34 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-13 12:34 . 2013-11-13 12:34 147968 ----a-w- c:\windows\system32\occache.dll 2013-11-13 12:34 . 2013-11-13 12:34 143872 ----a-w- c:\windows\system32\wextract.exe 2013-11-13 12:34 . 2013-11-13 12:34 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-13 12:34 . 2013-11-13 12:34 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-13 12:34 . 2013-11-13 12:34 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-13 12:34 . 2013-11-13 12:34 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-13 12:34 . 2013-11-13 12:34 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-13 12:34 . 2013-11-13 12:34 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-13 12:34 . 2013-11-13 12:34 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-13 12:34 . 2013-11-13 12:34 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-13 12:34 . 2013-11-13 12:34 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-13 12:34 . 2013-11-13 12:34 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-13 12:34 . 2013-11-13 12:34 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-13 12:34 . 2013-11-13 12:34 101376 ----a-w- c:\windows\system32\inseng.dll 2013-10-30 19:28 . 2013-10-30 19:28 312744 ----a-w- c:\windows\system32\javaws.exe 2013-10-30 19:28 . 2013-10-30 19:28 189352 ----a-w- c:\windows\system32\javaw.exe 2013-10-30 19:28 . 2013-10-30 19:28 189352 ----a-w- c:\windows\system32\java.exe 2013-10-30 19:28 . 2013-10-30 19:28 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-10-18 14:40 . 2013-10-18 14:40 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2013-10-18 14:40 . 2013-10-18 14:40 856712 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2013-10-14 17:00 . 2013-11-13 12:36 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2013-10-12 02:30 . 2013-11-13 11:58 830464 ----a-w- c:\windows\system32\nshwfp.dll 2013-10-12 02:29 . 2013-11-13 11:58 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-12 02:29 . 2013-11-13 11:58 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2013-10-12 02:03 . 2013-11-13 11:58 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2013-10-12 02:01 . 2013-11-13 11:58 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL 2013-10-08 06:50 . 2013-10-31 20:11 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-10-05 20:25 . 2013-11-13 11:58 1474048 ----a-w- c:\windows\system32\crypt32.dll 2013-10-05 19:57 . 2013-11-13 11:58 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-10-04 02:28 . 2013-11-13 11:58 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll 2013-10-04 02:25 . 2013-11-13 11:58 197120 ----a-w- c:\windows\system32\credui.dll 2013-10-04 01:58 . 2013-11-13 11:58 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll 2013-10-04 01:56 . 2013-11-13 11:58 168960 ----a-w- c:\windows\SysWow64\credui.dll 2013-10-04 01:56 . 2013-11-13 11:58 1796096 ----a-w- c:\windows\SysWow64\authui.dll 2013-10-03 02:23 . 2013-11-13 11:58 404480 ----a-w- c:\windows\system32\gdi32.dll 2013-10-03 02:00 . 2013-11-13 11:58 311808 ----a-w- c:\windows\SysWow64\gdi32.dll 2013-10-02 02:22 . 2013-11-13 12:33 56832 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2013-10-02 02:11 . 2013-11-13 12:33 13824 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-10-02 02:08 . 2013-11-13 12:33 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-10-02 01:48 . 2013-11-13 12:33 56832 ----a-w- c:\windows\system32\MsRdpWebAccess.dll 2013-10-02 01:48 . 2013-11-13 12:33 18944 ----a-w- c:\windows\system32\wksprtPS.dll 2013-10-02 01:29 . 2013-11-13 12:33 62976 ----a-w- c:\windows\system32\tsgqec.dll 2013-10-02 01:10 . 2013-11-13 12:33 44544 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll 2013-10-02 00:15 . 2013-11-13 12:33 1057280 ----a-w- c:\windows\system32\rdvidcrl.dll 2013-10-02 00:14 . 2013-11-13 12:33 50176 ----a-w- c:\windows\SysWow64\MsRdpWebAccess.dll 2013-10-02 00:14 . 2013-11-13 12:33 17920 ----a-w- c:\windows\SysWow64\wksprtPS.dll 2013-10-02 00:08 . 2013-11-13 12:33 83968 ----a-w- c:\windows\system32\TSWbPrxy.exe . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinBar (x86)"="p:\winbar\WinBar.exe" [2009-09-29 271360] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2013-01-17 267792] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-23 343168] "OpwareSE4"="p:\canon\OpwareSE4.exe" [2007-02-04 79400] . c:\users\Brian_Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Facebook Messenger.lnk - c:\users\Brian_Pc\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe [2013-3-7 248240] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;p:\skype\Updater\Updater.exe;p:\skype\Updater\Updater.exe [x] R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] R3 BthAvrcp;Bluetooth AVRCP-profiel;c:\windows\system32\DRIVERS\BthAvrcp.sys;c:\windows\SYSNATIVE\DRIVERS\BthAvrcp.sys [x] R3 cleanhlp;cleanhlp;p:\emsisoft\RUN\cleanhlp64.sys;p:\emsisoft\RUN\cleanhlp64.sys [x] R3 DIRECTIO;DIRECTIO;t:\performancetest\DirectIo.sys;t:\performancetest\DirectIo.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys;c:\windows\SYSNATIVE\DRIVERS\lvpopf64.sys [x] R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x] R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 !SASCORE;SAS Core Service;t:\virus scanners\SASCORE64.EXE;t:\virus scanners\SASCORE64.EXE [x] R4 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\SYMEFA64.SYS [x] S1 A2DDA;A2 Direct Disk Access Support Driver;p:\emsisoft\RUN\a2ddax64.sys;p:\emsisoft\RUN\a2ddax64.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20131203.001\BHDrvx64.sys [x] S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\ccSetx64.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20131220.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20131220.001\IDSvia64.sys [x] S1 SASDIFSV;SASDIFSV;t:\virus scanners\SASDIFSV64.SYS;t:\virus scanners\SASDIFSV64.SYS [x] S1 SASKUTIL;SASKUTIL;t:\virus scanners\SASKUTIL64.SYS;t:\virus scanners\SASKUTIL64.SYS [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\NISx64\1404000.028\SYMNETS.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1404000.028\SYMNETS.SYS [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 BootRacerServ;BootRacerServ;c:\program files (x86)\BootRacer\BootRacerServ.exe;c:\program files (x86)\BootRacer\BootRacerServ.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 NIS;Norton Internet Security;p:\norton internet security 2013\Engine\20.4.0.40\ccSvcHst.exe;p:\norton internet security 2013\Engine\20.4.0.40\ccSvcHst.exe [x] S2 ReflectService.exe;Macrium Reflect Image Mounting Service;p:\macrium reflect\ReflectService.exe;p:\macrium reflect\ReflectService.exe [x] S2 SynoDrService;SynoDrService;t:\data replicator\SynoDrServicex64.exe;t:\data replicator\SynoDrServicex64.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 UsbClientService;UsbClientService;t:\assistant\UsbClientService.exe;t:\assistant\UsbClientService.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 BlackBerry Device Manager;BlackBerry Device Manager;c:\program files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe;c:\program files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [x] S3 busenum;Synology Virtual USB Hub;c:\windows\system32\DRIVERS\busenum.sys;c:\windows\SYSNATIVE\DRIVERS\busenum.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] S3 LVUVC64;Logitech HD Webcam C310(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys;c:\windows\SYSNATIVE\DRIVERS\TVMonitor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-12-06 14:04 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe . Inhoud van de 'Gedeelde Taken' map . 2013-12-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-12 14:15] . 2013-12-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2191765731-929917457-40214162-1000Core.job - c:\users\Brian_Pc\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-11 17:24] . 2013-12-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2191765731-929917457-40214162-1000UA.job - c:\users\Brian_Pc\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-11 17:24] . 2013-12-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-29 17:59] . 2013-12-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-29 17:59] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696] "CanonMyPrinter"="p:\canon\BJMyPrt.exe" [2010-07-26 2782096] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="c:\program files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2013-12-12 21720] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "p:\fences\Stardock\Fences\FencesMenu64.dll" [2010-06-22 253288] . ------- Bijkomende Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.nl/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: &Verzenden naar OneNote - p:\office~1\Office14\ONBttnIE.dll/105 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Afbeelding knippen - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 IE: E&xporteren naar Microsoft Excel - p:\office~1\Office14\EXCEL.EXE/3000 IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: Kopieer selectie - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 IE: Kopieer URL - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 IE: Nieuwe notitie - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html IE: Pagina opemen - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 Trusted Zone: dell.com TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\ FF - prefs.js: browser.search.selectedEngine - Norton Safe Search FF - prefs.js: browser.startup.homepage - hxxps://www.google.nl/ FF - ExtSQL: 2013-11-15 12:22; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn FF - ExtSQL: 2013-11-15 12:43; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFF FF - ExtSQL: 2013-11-15 19:37; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-11-15 21:34; {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}; c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi FF - ExtSQL: 2013-11-15 21:40; html5player@horning.us; c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\html5player@horning.us.xpi FF - ExtSQL: 2013-12-08 22:37; translator@zoli.bod; c:\users\Brian_Pc\AppData\Roaming\Mozilla\Firefox\Profiles\v3rmnfky.default\extensions\translator@zoli.bod.xpi . - - - - ORPHANS VERWIJDERD - - - - . c:\users\Brian_Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk - p:\evernote\EvernoteClipper.exe c:\users\Brian_Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FSL Launcher.lnk - t:\fsl_launcher\FSL_Launcher.exe auto SafeBoot-CleanHlp SafeBoot-CleanHlp.sys AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe AddRemove-{fd97d1e2-368a-4cd9-af63-8eeff938044a} - c:\programdata\Package Cache\{fd97d1e2-368a-4cd9-af63-8eeff938044a}\adblockplusie-1.1.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"p:\norton internet security 2013\Engine\20.4.0.40\ccSvcHst.exe\" /s \"NIS\" /m \"p:\norton internet security 2013\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-2191765731-929917457-40214162-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-2191765731-929917457-40214162-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*] "v5Licence0"="15-BDQC-7UK5-EXJX-PX69-4H1M-NKYDU2H" "Activated"="Y" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Voltooingstijd: 2013-12-21 14:03:11 ComboFix-quarantined-files.txt 2013-12-21 13:03 . Pre-Run: 89.101.754.368 bytes beschikbaar Post-Run: 88.914.935.808 bytes beschikbaar . - - End Of File - - 71C7C9C840B5E1C19916F38EBEBB54FD A36C5E4F47E84449FF07ED3517B43A31