Zoek.exe v5.0.0.0 Updated 30-08-2014 Tool run by Hans on zo 31/08/2014 at 11:15:20,88. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Hans\Downloads\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-08-29-211043.log 81728 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\agrsmsvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe C:\Windows\system32\mfevtps.exe C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\RtHDVCpl.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Garmin\Express Tray\ExpressTray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe C:\Windows\system32\conime.exe C:\Users\Hans\Downloads\zoek.exe C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\?³?³0 not found C:\Windows\System32\RENAD3F.tmp deleted C:\Windows\System32\RENAD40.tmp deleted C:\Windows\System32\RENAD41.tmp deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted ==== System Specs ====================== Windows: Windows Vista Home Premium Edition Service Pack 2 (Build 6002) Memory (RAM): 2940 MB CPU Info: Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz CPU Speed: 525,1 MHz Sound Card: Luidsprekers (Realtek High Defi | Display Adapters: Mobile Intel(R) 4 Series Express Chipset Family | Mobile Intel(R) 4 Series Express Chipset Family | RDPDD Chained DD | RDP Encoder Mirror Driver Monitors: 1x; Algemeen PnP-beeldscherm | Screen Resolution: 1440 X 900 - 32 bit Network: Network Present Network Adapters: Atheros AR5007EG Wireless Network Adapter | Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) CD / DVD Drives: 1x (F: | ) F: TSSTcorpCDDVDW TS-L633A Ports: COM3 LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 74,4GB | E: 73,2GB Hard Disks - Free: C: 8,2GB | E: 53,1GB Manufacturer *: INSYDE BIOS Info: AT/AT COMPATIBLE | 12/09/08 | TOSINV - 1 Time Zone: Romance (standaardtijd) Motherboard *: TOSHIBA Portable PC Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: Microsoft Security Essentials disabled (Outdated) Default Browser: Google Chrome 35.0.1916.153 Internet Explorer Version: 9.0.8112.16421 Google Chrome version: 35.0.1916.153 Adobe Reader version: 8.1.0.2007051100 Flash Player version: 14.0.0.145 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Hans\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== 2014-08-30 10:36:58 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\System32\sqlite3.dll 2014-08-30 09:58:36 7350631241943D434C9DF900C079D8F7 2054656 ----a-w- C:\Windows\System32\win32k.sys 2014-08-30 09:58:35 9852A1B92487147563D83B638F1E8D37 297984 ----a-w- C:\Windows\System32\gdi32.dll ====== C:\Windows\system32\drivers ===== 2014-08-13 16:31:42 5C2C209CDEFBC51D83D66E8A53B2BE89 638400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\Hans\AppData\Roaming ====== 2014-08-29 21:05:03 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Temp 2014-08-29 21:05:03 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2014-08-29 21:05:03 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2014-08-29 21:05:02 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-08-29 21:05:02 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-08-29 21:05:02 -------- d-----w- C:\Users\Ann\AppData\Local\Temp 2014-08-29 21:04:57 -------- d-----w- C:\Users\Hans\AppData\Local\Temp 2014-08-24 12:38:50 -------- d-----w- C:\Users\Ann\AppData\Roaming\vlc 2014-08-24 12:36:58 -------- d-----w- C:\Users\Ann\AppData\Local\{F486821E-1F5A-4F0E-869A-11E954090C4A} 2014-08-18 16:14:36 -------- d-----w- C:\Users\Ann\AppData\Local\{E9FC2317-4F08-4ADD-AAB2-394B9F86A50C} 2014-08-10 10:20:32 -------- d-----w- C:\Users\Ann\AppData\Local\Windows Live 2014-08-10 10:20:11 -------- d-----w- C:\Users\Ann\AppData\Local\{4C9B2F3E-B3CA-452D-84F9-4367078EE39B} ====== C:\Users\Hans ====== 2014-08-30 10:33:45 9DED4724D695CFB01960426DA011ABAE 1364531 ----a-w- C:\Users\Hans\Downloads\adwcleaner_3.308.exe 2014-08-30 10:31:29 -------- d-----w- C:\ProgramData\Oracle 2014-08-30 10:27:17 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Users\Hans\Downloads\JavaSetup7u67 (1).exe 2014-08-30 10:01:26 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Users\Hans\Downloads\JavaSetup7u67.exe ====== C: exe-files == 2014-08-30 10:33:45 9DED4724D695CFB01960426DA011ABAE 1364531 ----a-w- C:\Users\Hans\Downloads\adwcleaner_3.308.exe 2014-08-30 10:29:00 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Users\Hans\AppData\LocalLow\Sun\Java\jre1.7.0_67\lzma.exe 2014-08-30 10:27:17 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Users\Hans\Downloads\JavaSetup7u67 (1).exe 2014-08-30 10:01:26 068014C9EACAD27DD8BC8CAF6BDECB06 918440 ----a-w- C:\Users\Hans\Downloads\JavaSetup7u67.exe 2014-08-27 18:34:32 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Hans.exe === C: other files == 2014-08-30 09:58:36 7350631241943D434C9DF900C079D8F7 2054656 ----a-w- C:\Windows\System32\win32k.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "RtHDVCpl"="RtHDVCpl.exe" "Skytel"="Skytel.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "GarminExpressTrayApp"="C:\Program Files\Garmin\Express Tray\ExpressTray.exe" "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\00TCrdMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="00TCrdMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\FlashCards\\TCrdMain.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ACQTMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ACQTMOUSE" "hkey"="HKLM" "command"="\"C:\\Program Files\\TOSHIBA\\Tilt Mouse Software\\1.1\\ACQTMAPP.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe Reader Speed Launcher" "hkey"="HKLM" "command"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cfFncEnabler.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cfFncEnabler.exe" "hkey"="HKLM" "command"="cfFncEnabler.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GarminExpressTrayApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GarminExpressTrayApp" "hkey"="HKCU" "command"="\"C:\\Program Files\\Garmin\\Express Tray\\ExpressTray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Desktop Search] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Google Desktop Search" "hkey"="HKLM" "command"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google EULA Launcher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Google EULA Launcher" "hkey"="HKLM" "command"="c:\\Program Files\\Google\\Google EULA\\GoogleEULALauncher.exe IE PA" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HotKeysCmds] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HotKeysCmds" "hkey"="HKLM" "command"="C:\\Windows\\system32\\hkcmd.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HSON] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HSON" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\TBS\\HSON.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IgfxTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="IgfxTray" "hkey"="HKLM" "command"="C:\\Windows\\system32\\igfxtray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NDSTray.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NDSTray.exe" "hkey"="HKLM" "command"="NDSTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Persistence] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Persistence" "hkey"="HKLM" "command"="C:\\Windows\\system32\\igfxpers.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RtHDVCpl" "hkey"="HKLM" "command"="RtHDVCpl.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sidebar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Sidebar" "hkey"="HKCU" "command"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skytel] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skytel" "hkey"="HKLM" "command"="Skytel.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmoothView] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SmoothView" "hkey"="HKLM" "command"="%ProgramFiles%\\Toshiba\\SmoothView\\SmoothView.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SynTPEnh] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SynTPEnh" "hkey"="HKLM" "command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TomTomHOME.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TomTomHOME.exe" "hkey"="HKCU" "command"="\"C:\\Program Files\\TomTom HOME 2\\TomTomHOMERunner.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\topi] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="topi" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\Toshiba Online Product Information\\topi.exe -startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TOSCDSPD] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TOSCDSPD" "hkey"="HKCU" "command"="TOSCDSPD.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba Registration] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba Registration" "hkey"="HKLM" "command"="C:\\Program Files\\Toshiba\\Registration\\ToshibaRegistration.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPRO] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba TEMPRO" "hkey"="HKLM" "command"="C:\\Program Files\\Toshiba TEMPRO\\TemproTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TPwrMain] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TPwrMain" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\Power Saver\\TPwrMain.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Windows Defender" "hkey"="HKLM" "command"="%ProgramFiles%\\Windows Defender\\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WMPNSCFG] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="WMPNSCFG" "hkey"="HKCU" "command"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk" "backup"="C:\\Windows\\pss\\WinZip Quick Pick.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE " "item"="WinZip Quick Pick" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Hans^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk] "path"="C:\\Users\\Hans\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2007 Schermopname en Snel starten.lnk" "backup"="C:\\Windows\\pss\\OneNote 2007 Schermopname en Snel starten.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office12\\ONENOTEM.EXE /tsr" "item"="OneNote 2007 Schermopname en Snel starten" ==== Startup Folders ====================== 2008-08-19 11:40:54 1835 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2008-08-19 11:40:54 1835 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2011-09-25 14:26:14 3656 --sha-w- C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote-inhoudsopgave.onetoc2 ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [09/07/2014 16:15] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001Core.job --a------ C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe [06/04/2014 19:50] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001UA.job --a------ C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe [06/04/2014 19:50] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001Core" [C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-1623339857-17069801-107116736-1001UA" [C:\Users\Ann\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\GarminUpdaterTask" [C:\Program Files\Garmin\Express Self Updater\ExpressSelfUpdater.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{A3683E25-5584-47C0-A7F0-600F2C70A5E0}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\{0F3E8E4D-7AC8-43C9-A6B1-2B404D178E39}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{13C5F045-2ADD-4A3C-9782-DE0BAFA84CDB}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] "C:\Windows\system32\tasks\{15F9714E-290B-4BB9-AA09-F5DE4A58A2CF}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{5C558A12-2C54-4FD5-A2E4-471C49D74789}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] "C:\Windows\system32\tasks\{9A10785F-6C2C-4438-9AA1-771E00ECFCD7}" [C:\Program Files\Skype\Phone\Skype.exe] "C:\Windows\system32\tasks\{D9F56795-D11F-4AB2-8F20-D07CF8CC267C}" ["C:\Program Files\Google\Chrome\Application\chrome.exe"] "C:\Windows\system32\tasks\{DAF411F3-2AC2-4471-B3F5-ED53D8A998BF}" ["c:\program files\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/6.14.73.104.456/nl/abandoninstall?page=tsProgressBar] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [17/12/2013 16:41] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Hans\AppData\Roaming\TomTom\HOME\Profiles\mbz57onj.default - Map status indicator - C:\Program Files\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - TomTom HOME default theme - C:\Program Files\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com AppDir: C:\Program Files\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be ==== Firefox Plugins ====================== ==== Chrome Look ====================== Google Search - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Ann\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Wallet - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Startpages ====================== C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://www.google.com/", C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://nl.msn.com/?pc=UP97&ocid=UP97DHP", ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.nieuwsblad.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.nieuwsblad.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{BE2CF772-4CFF-4AC0-857F-428BBC5C5FF1}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rlz=1I7GGLL_nl&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" {BE2CF772-4CFF-4AC0-857F-428BBC5C5FF1} Google Url="http://www.google.be/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GGLL_nl" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_USERS\S-1-5-21-1623339857-17069801-107116736-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== HijackThis Entries ====================== O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEEM') O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user') O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user') O4 - Startup: OneNote-inhoudsopgave.onetoc2 O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Google Update-service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe ==== Empty IE Cache ====================== C:\Users\Ann\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Ann\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EG0XTG65 will be deleted at reboot C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Ann\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1670 folders=2315 244261952 bytes) ==== Empty Temp Folders ====================== C:\Users\Ann\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Hans\AppData\Local\Temp will be emptied at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Hans\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\PROGRA~2\????0" not deleted "C:\Users\Hans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EG0XTG65" not found ==== EOF on zo 31/08/2014 at 12:01:31,27 ======================