Zoek.exe v5.0.0.0 Updated 28-08-2014 Tool run by Hans on vr 29/08/2014 at 22:15:46,45. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NNUPYSI\zoek.exe [Scan all users] [Checkboxes used] ==== System Restore Info ====================== 29/08/2014 22:18:14 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E159A987-9F1C-4E69-8F0E-A065F7826A3B} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 14 ActiveX Adobe Flash Player 14 Plugin Adobe Reader 8.1.4 - Nederlands ANT Drivers Installer x86 Atheros Driver Installation Program Atheros Wi-Fi Protected Setup Library AVG 2011 Belgium e-ID middleware 4.0.6 (build 7416) Bing Bar Canon MP250 series MP Drivers Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibiliteitspakket voor het 2007 Microsoft Office system D3DX10 Elevated Installer Facebook Video Calling 3.1.0.521 Garmin BaseCamp Garmin City Navigator Europe NT 2008 Garmin Express Garmin Express Tray Garmin MapSource Garmin USB Drivers Geluiddemper v. cd/dvd-station Google Chrome Google Desktop Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel(R) Graphics Media Accelerator Driver Intel© Matrix Storage Manager Java Auto Updater Java(TM) 6 Update 24 Java(TM) 6 Update 6 Junk Mail filter update McAfee Security Scan Plus Microsoft .NET Framework 3.5 Language Pack SP1 - nld Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4.5.1 Microsoft .NET Framework 4.5.1 (Nederlands) Microsoft .NET Framework 4.5.1 (NLD) Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (Dutch) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (Dutch) 2007 Microsoft Office PowerPoint MUI (Dutch) 2007 Microsoft Office PowerPoint Viewer 2007 (Dutch) Microsoft Office Proof (Dutch) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proofing (Dutch) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (Dutch) 2007 Microsoft Office Word MUI (Dutch) 2007 Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 Microsoft Works Microsoft XML Parser MSVCRT myphotobook 3.6 Octoshape add-in for Adobe Flash Player OGA Notifier 2.0.0048.0 Picasa 3 PIXresizer Realtek 8169 8168 8101E 8102E Ethernet Driver Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Rijbewijs B Examen Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697) Security Update for Microsoft .NET Framework 4.5.1 (KB2898869) Security Update for Microsoft .NET Framework 4.5.1 (KB2901126) Security Update for Microsoft .NET Framework 4.5.1 (KB2931368) Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2878233) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880513) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office OneNote 2007 (KB2596857) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2880515) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Segoe UI Skype Toolbars SkypeT 6.18 Stuurprogrammapakket voor Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) Stuurprogrammapakket voor Windows - Fedict SmartCard (09/23/2013 4.0.6.0) Stuurprogrammapakket voor Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) SUPERAntiSpyware Synaptics Pointing Device Driver Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL Tilt Mouse Software 1.1 Titan Casino TomTom HOME 2.8.2.2264 TomTom HOME Visual Studio Merge Modules TOSHIBA-handleidingen TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Face Recognition TOSHIBA Hardware Setup Toshiba Online Product Information TOSHIBA Recovery Disc Creator TOSHIBA Software Modem TOSHIBA Supervisor Password Toshiba TEMPRO TOSHIBA Value Added Package TRDCReminder TRORDCLauncher Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update voor Microsoft Office Excel 2007 Help (KB963678) Update voor Microsoft Office Powerpoint 2007 Help (KB963669) Update voor Microsoft Office Word 2007 Help (KB963665) VLC media player 2.0.5 VoipStunt Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Encoder 9 Series WinZip 15.5 ==== Running Processes ====================== C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Windows\system32\agrsmsvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe C:\Windows\system32\mfevtps.exe C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\RtHDVCpl.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Garmin\Express Tray\ExpressTray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.exe C:\Windows\system32\wuauclt.exe C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NNUPYSI\zoek.exe C:\Windows\system32\conime.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\?³?³0 not found C:\Program Files\Java deleted C:\Users\Ann\AppData\LocalLow\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted C:\Users\Ann\AppData\LocalLow\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted C:\Users\Ann\AppData\LocalLow\{45504A6C-7D57-08A8-1AA1-31A97015D16E} deleted C:\Users\Hans\AppData\LocalLow\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted C:\Users\Hans\AppData\LocalLow\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted C:\PROGRA~2\Adblocker deleted C:\Program Files\Adblocker deleted C:\PROGRA~2\NNextCoup deleted C:\Program Files\NNextCoup deleted C:\PROGRA~2\NextCoup deleted C:\Program Files\NextCoup deleted C:\Program Files\Uniblue\DriverScanner deleted C:\Program Files\PC Speed Maximizer deleted C:\Program Files\VDownloader deleted C:\Program Files\Yontoo deleted C:\found.000 deleted C:\Users\Hans\AppData\Roaming\Uniblue deleted C:\Users\Hans\AppData\Roaming\PC Speed Maximizer deleted C:\Users\Hans\AppData\Roaming\BabSolution deleted C:\Users\Hans\AppData\Roaming\Yontoo deleted C:\PROGRA~2\BrowserProtect deleted C:\PROGRA~2\y2gFndU0.dat deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Tarma Installer deleted C:\PROGRA~2\Package Cache deleted C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\bprotector web data deleted C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences deleted C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted C:\Users\Hans\Downloads\BearShareSetup-r20-n-bi.exe deleted C:\Users\Hans\AppData\LocalLow\Delta deleted C:\Windows\System32\searchplugins deleted C:\Windows\System32\Extensions deleted C:\PROGRA~2\NXYGBfmA.exe deleted "C:\Users\Hans\AppData\Roaming\start" deleted "C:\PROGRA~2\250039567275dee7\{3D0F43D9-C1D7-733C-01F8-4A3001BF8CC3}.20140710113003" deleted "C:\PROGRA~2\250039567275dee7\{3D0F43D9-C1D7-733C-01F8-4A3001BF8CC3}.20140723202747" deleted "C:\PROGRA~2\250039567275dee7\{3D0F43D9-C1D7-733C-01F8-4A3001BF8CC3}.20140723202827" deleted "C:\PROGRA~2\250039567275dee7\{3D0F43D9-C1D7-733C-01F8-4A3001BF8CC3}.20140723202828" deleted "C:\PROGRA~2\250039567275dee7\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.20140707164901" deleted "C:\PROGRA~2\250039567275dee7\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140707164824" deleted "C:\PROGRA~2\250039567275dee7\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140707164841" deleted "C:\PROGRA~2\250039567275dee7\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140710112916" deleted "C:\PROGRA~2\250039567275dee7\{FDB962F0-B5B8-9460-D12F-7966E97BAA43}.20140710113005" deleted "C:\PROGRA~2\250039567275dee7" deleted "C:\Users\Hans\AppData\Roaming\Samsung" deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted ==== System Specs ====================== Windows: Windows Vista Home Premium Edition Service Pack 2 (Build 6002) Memory (RAM): 2940 MB CPU Info: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz CPU Speed: 533,5 MHz Sound Card: Luidsprekers (Realtek High Defi | Display Adapters: Mobile Intel(R) 4 Series Express Chipset Family | Mobile Intel(R) 4 Series Express Chipset Family | RDPDD Chained DD | RDP Encoder Mirror Driver Monitors: 1x; Algemeen PnP-beeldscherm | Screen Resolution: 1440 X 900 - 32 bit Network: Network Present Network Adapters: Atheros AR5007EG Wireless Network Adapter | Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) CD / DVD Drives: 1x (F: | ) F: TSSTcorpCDDVDW TS-L633A Ports: COM3 LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 74,4GB | E: 73,2GB Hard Disks - Free: C: 739,3MB | E: 52,9GB Manufacturer *: INSYDE BIOS Info: AT/AT COMPATIBLE | 12/09/08 | TOSINV - 1 Time Zone: Romance (standaardtijd) Motherboard *: TOSHIBA Portable PC Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: Microsoft Security Essentials disabled (Outdated) Default Browser: Google Chrome 35.0.1916.153 Internet Explorer Version: 9.0.8112.16421 Google Chrome version: 35.0.1916.153 Adobe Reader version: 8.1.0.2007051100 Flash Player version: 14.0.0.145 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Hans\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== 2014-08-13 16:31:42 5C2C209CDEFBC51D83D66E8A53B2BE89 638400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-08-27 01:40:08 -------- d-----w- C:\Program Files\SUPERAntiSpyware ======= C: ===== ====== C:\Users\Hans\AppData\Roaming ====== 2014-08-27 01:40:38 -------- d-----w- C:\Users\Hans\AppData\Roaming\SUPERAntiSpyware.com 2014-08-24 12:38:50 -------- d-----w- C:\Users\Ann\AppData\Roaming\vlc 2014-08-24 12:36:58 -------- d-----w- C:\Users\Ann\AppData\Local\{F486821E-1F5A-4F0E-869A-11E954090C4A} 2014-08-18 16:14:36 -------- d-----w- C:\Users\Ann\AppData\Local\{E9FC2317-4F08-4ADD-AAB2-394B9F86A50C} 2014-08-10 10:20:32 -------- d-----w- C:\Users\Ann\AppData\Local\Windows Live 2014-08-10 10:20:11 -------- d-----w- C:\Users\Ann\AppData\Local\{4C9B2F3E-B3CA-452D-84F9-4367078EE39B} ====== C:\Users\Hans ====== 2014-08-27 01:40:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2014-08-27 01:40:08 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com ====== C: exe-files == 2014-08-27 18:34:32 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Hans.exe === C: other files == 2014-08-29 19:18:39 8A80554C91D9FCA8ACB82F023DE02F11 3 ----a-w- C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NNUPYSI\creative.rev2pub[1].com ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "RtHDVCpl"="RtHDVCpl.exe" "Skytel"="Skytel.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\00TCrdMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="00TCrdMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\FlashCards\\TCrdMain.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ACQTMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ACQTMOUSE" "hkey"="HKLM" "command"="\"C:\\Program Files\\TOSHIBA\\Tilt Mouse Software\\1.1\\ACQTMAPP.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe Reader Speed Launcher" "hkey"="HKLM" "command"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG_TRAY] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AVG_TRAY" "hkey"="HKLM" "command"="\"C:\\Program Files\\AVG\\AVG2012\\avgtray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\beid] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="beid" "hkey"="HKCU" "command"="C:\\Program Files\\Belgium Identity Card\\beid35gui.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Camera Assistant Software] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Camera Assistant Software" "hkey"="HKLM" "command"="\"C:\\Program Files\\Camera Assistant Software for Toshiba\\traybar.exe\" /start" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cfFncEnabler.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cfFncEnabler.exe" "hkey"="HKLM" "command"="cfFncEnabler.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GarminExpressTrayApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GarminExpressTrayApp" "hkey"="HKCU" "command"="\"C:\\Program Files\\Garmin\\Express Tray\\ExpressTray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Desktop Search] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Google Desktop Search" "hkey"="HKLM" "command"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google EULA Launcher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Google EULA Launcher" "hkey"="HKLM" "command"="c:\\Program Files\\Google\\Google EULA\\GoogleEULALauncher.exe IE PA" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HotKeysCmds] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HotKeysCmds" "hkey"="HKLM" "command"="C:\\Windows\\system32\\hkcmd.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HSON] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HSON" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\TBS\\HSON.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IgfxTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="IgfxTray" "hkey"="HKLM" "command"="C:\\Windows\\system32\\igfxtray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\jswtrayutil] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jswtrayutil" "hkey"="HKLM" "command"="\"C:\\Program Files\\Jumpstart\\jswtrayutil.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Malwarebytes' Anti-Malware (reboot)] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Malwarebytes' Anti-Malware (reboot)" "hkey"="HKLM" "command"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msnmsgr" "hkey"="HKCU" "command"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NDSTray.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NDSTray.exe" "hkey"="HKLM" "command"="NDSTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Persistence] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Persistence" "hkey"="HKLM" "command"="C:\\Windows\\system32\\igfxpers.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RtHDVCpl" "hkey"="HKLM" "command"="RtHDVCpl.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sidebar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Sidebar" "hkey"="HKCU" "command"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skytel] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skytel" "hkey"="HKLM" "command"="Skytel.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmoothView] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SmoothView" "hkey"="HKLM" "command"="%ProgramFiles%\\Toshiba\\SmoothView\\SmoothView.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SynTPEnh] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SynTPEnh" "hkey"="HKLM" "command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TomTomHOME.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TomTomHOME.exe" "hkey"="HKCU" "command"="\"C:\\Program Files\\TomTom HOME 2\\TomTomHOMERunner.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\topi] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="topi" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\Toshiba Online Product Information\\topi.exe -startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TOSCDSPD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TOSCDSPD" "hkey"="HKCU" "command"="TOSCDSPD.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba Registration] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba Registration" "hkey"="HKLM" "command"="C:\\Program Files\\Toshiba\\Registration\\ToshibaRegistration.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPO] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba TEMPO" "hkey"="HKLM" "command"="C:\\Program Files\\Toshiba TEMPRO\\Toshiba.Tempo.UI.TrayApplication.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPRO] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba TEMPRO" "hkey"="HKLM" "command"="C:\\Program Files\\Toshiba TEMPRO\\TemproTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TPwrMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TPwrMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\Power Saver\\TPwrMain.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Windows Defender" "hkey"="HKLM" "command"="%ProgramFiles%\\Windows Defender\\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WMPNSCFG] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="WMPNSCFG" "hkey"="HKCU" "command"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Hans^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk] "path"="C:\\Users\\Hans\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2007 Schermopname en Snel starten.lnk" "backup"="C:\\Windows\\pss\\OneNote 2007 Schermopname en Snel starten.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office12\\ONENOTEM.EXE /tsr" "item"="OneNote 2007 Schermopname en Snel starten" ==== Startup Folders ====================== 2008-08-19 11:40:54 1835 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2008-08-19 11:40:54 1835 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2011-09-25 14:26:14 3656 --sha-w- C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote-inhoudsopgave.onetoc2 ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [09/07/2014 16:15] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001Core.job --a------ C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe [06/04/2014 19:50] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001UA.job --a------ C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe [06/04/2014 19:50] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001Core" [C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001UA" [C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\GarminUpdaterTask" [C:\Program Files\Garmin\Express Self Updater\ExpressSelfUpdater.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{A3683E25-5584-47C0-A7F0-600F2C70A5E0}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\{0F3E8E4D-7AC8-43C9-A6B1-2B404D178E39}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{13C5F045-2ADD-4A3C-9782-DE0BAFA84CDB}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] "C:\Windows\system32\tasks\{15F9714E-290B-4BB9-AA09-F5DE4A58A2CF}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{5C558A12-2C54-4FD5-A2E4-471C49D74789}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] "C:\Windows\system32\tasks\{9A10785F-6C2C-4438-9AA1-771E00ECFCD7}" [C:\Program Files\Skype\Phone\Skype.exe] "C:\Windows\system32\tasks\{D9F56795-D11F-4AB2-8F20-D07CF8CC267C}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{DAF411F3-2AC2-4471-B3F5-ED53D8A998BF}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [17/12/2013 16:41] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Hans\AppData\Roaming\TomTom\HOME\Profiles\mbz57onj.default - Map status indicator - C:\Program Files\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - TomTom HOME default theme - C:\Program Files\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com AppDir: C:\Program Files\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bopakagnckmlgajfccecajhnimjiiedh - No path found[] jmfkcklnlgedgbglfkkgedjfmejoahla - C:\Program Files\AVG\AVG2012\Chrome\safesearch.crx[] NextCoup - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Administrator\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Administrator\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Administrator\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea Google Search - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf NextCoup - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea Google Wallet - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia NextCoup - Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Ann\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Ann\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Ann\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Gast\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Gast\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Gast\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea Google Wallet - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda NextCoup - Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea NextCoup - Hans\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc Pricechoep - Hans\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn NNextCoup - Hans\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea ==== Chromium Startpages ====================== C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://www.google.com/", "startup_urls": [ "http://www.google.com/" ], C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://nl.msn.com/?pc=UP97&ocid=UP97DHP", ==== Chrome Fix ====================== C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage-journal deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.delta-search.com_0.localstorage deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.delta-search.com_0.localstorage-journal deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Ann\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Hans\AppData\Local\Torch\User Data\Default\Extensions\ggjbccoalfgnifklnleakgblbemlgagc deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Ann\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Hans\AppData\Local\Torch\User Data\Default\Extensions\mnbnpekgicmhlhjkfdbpmehhepddplea deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Ann\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Ann\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Ann\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Ann\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Hans\AppData\Local\Chromatic Browser\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Hans\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Hans\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully C:\Users\Hans\AppData\Local\Torch\User Data\Default\Extensions\hneonkdcghbaailkogkdlfaennhieldn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.nieuwsblad.be/" "Search Page"="http://www.google.com" "Default_Page_URL"="http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;" "Search Bar"="http://www.google.com/ie" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA" "Default_Page_URL"="http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search/?q=%s" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.nieuwsblad.be/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{BE2CF772-4CFF-4AC0-857F-428BBC5C5FF1}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rlz=1I7GGLL_nl&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" {70D46D94-BF1E-45ED-B567-48701376298E} Google Desktop Url="http://127.0.0.1:4664/search&s=3yS3BA-WXLVinxjOpRzMgj2TNMc?q={searchTerms}" {BE2CF772-4CFF-4AC0-857F-428BBC5C5FF1} Google Url="http://www.google.be/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GGLL_nl" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted successfully HKEY_CLASSES_ROOT\CLSID\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15E3FE57-EFEF-2AB7-DA04-DFBD4358DF11} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted successfully HKEY_CLASSES_ROOT\CLSID\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3BBB2891-05FF-B0B8-976A-D5D84D65B14B} deleted successfully HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\beid deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jswtrayutil deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot) deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPO deleted successfully ==== HijackThis Entries ====================== O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEEM') O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user') O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user') O4 - Startup: OneNote-inhoudsopgave.onetoc2 O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Google Update-service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe ==== Empty IE Cache ====================== C:\Users\Ann\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Ann\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Ann\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NNUPYSI will be deleted at reboot C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1667 folders=2300 244259690 bytes) ==== Empty Temp Folders ====================== C:\Users\Ann\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Hans\AppData\Local\Temp will be emptied at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Hans\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NNUPYSI" not found ==== EOF on vr 29/08/2014 at 23:10:43,53 ======================